/** * Machine-readable command-classification lexicon + its projections. * * Data adapted from LeanHarness `.lh/policies/commands.yml` (MIT, * Copyright (c) 2026 LeanHarness contributors) — every `pattern` and `reason` * string keeps the source intent, with aih-specific hardening for secret-read and * inline-code execution paths. The Claude `permissions` mapping convention * (deny → `permissions.deny`, ask → `permissions.ask`, safe_* → `permissions.allow`, * each wrapped `Bash()`) is adapted from LeanHarness `.lh/policies/claude-code.yml` * (MIT). The aih plan/render integration, the enforce-vs-document table, and the * advisory framing are original to aih. * * Posture: this lexicon is DATA. aih projects it into a native permission seam only * where one exists (Claude `.claude/settings.json` + `.claude/managed-settings.json`) * and DOCUMENTS it everywhere else — a deny pattern does nothing unless the consuming * CLI's own permission/hook engine honors it. The patterns are prefix/glob matchers, * kept verbatim; matcher semantics live with the consuming CLI, not aih. */ /** Policy tiers, most-to-least restrictive. Ported from LeanHarness commands.yml (MIT). */ export type PolicyTier = "deny" | "ask" | "safe_read_only" | "safe_verification"; export interface CommandRule { /** Glob-ish command pattern, verbatim from the source lexicon. */ pattern: string; /** Human reason (deny/ask only; the safe tiers are self-explanatory). */ reason?: string; } export interface CommandPolicyTextMatch { tier: Extract; pattern: string; reason?: string; offset: number; end: number; } /** * The 4-tier command classification lexicon. Adapted from * `.lh/policies/commands.yml` (LeanHarness, MIT), with repo-specific hardening * for shell readers that can bypass native file-read deny rules. */ export declare const COMMAND_LEXICON: Record; export declare function commandPolicyMatchKind(match: CommandPolicyTextMatch): string; export declare function commandPolicyTextMatches(text: string): CommandPolicyTextMatch[]; /** * Project the lexicon into Claude-style `permissions` matchers (`Bash()`). * A pure 1:1 string map — no transformation, no dedupe — so any matcher semantics * live with the consuming CLI, not aih. deny → `permissions.deny`, ask → * `permissions.ask`, the two safe tiers → `permissions.allow`. */ export declare function claudeBashPermissions(): { deny: string[]; ask: string[]; allow: string[]; }; /** * Project the lexicon into the sandbox managed-settings exec-policy block. Spread * into the `sandbox` object so the command policy ships alongside the egress * allowlist in `.claude/managed-settings.json`. */ export declare function sandboxExecPolicy(): Record; /** Markdown reference table for humans (lives under the canonical context dir). */ export declare function commandPolicyDoc(): string;