import { z } from "zod"; /** * Marketplace manifest (`marketplace.json`) at the root of a built marketplace * ARTIFACT — a reproducible, verifiable DISTRIBUTION directory packaged from the * approval evidence aih already emits, never a registry or server. The committed * `aih-skills.lock.json` stays the APPROVAL AUTHORITY: `marketplace build` only * packages what the lock approves (skill files + committed cards + vet evidence), * and every entry here is a receipt of that packaging, never a second approval. * Consumers keep using the existing `aih workspace add` channel — the vet gate * still runs at consume time, so a hosted artifact grants nothing by itself. */ export declare const AIH_MARKETPLACE_FILE = "marketplace.json"; /** Default output directory for `marketplace build` (gitignored `.aih/`). */ export declare const DEFAULT_MARKETPLACE_OUT = ".aih/marketplace"; /** * Artifact-relative paths come from a HOSTED, hand-editable manifest and later * feed filesystem reads on the consumer side — a crafted path like `../../.ssh/x` * would traverse out of the artifact directory. Mirrors the `skillNameSchema` * refinement per SEGMENT: forward-slash-separated segments only, no empty/`.`/ * `..` segments, no absolute/drive forms, no backslashes or control characters. */ export declare const marketplaceRelPathSchema: z.ZodString; /** One packaged file: artifact-relative path + the exact bytes it must hash to. */ export declare const MarketplaceFileSchema: z.ZodObject<{ path: z.ZodString; sha256: z.ZodString; bytes: z.ZodNumber; }, z.core.$strict>; /** * One packaged skill — the lock entry's identity (name/source/commit/verdict) * plus the artifact-relative receipts: the committed card copy, the * content-addressed vet evidence copy, and every shipped file with its hash. * Verdict is restricted to the two APPROVABLE grades by construction — a RED or * UNKNOWN skill never has a lock entry, so it can never be packaged. */ export declare const MarketplaceSkillSchema: z.ZodObject<{ name: z.ZodString; source: z.ZodString; commit: z.ZodString; verdict: z.ZodEnum<{ GREEN: "GREEN"; YELLOW: "YELLOW"; }>; license: z.ZodOptional; riskClass: z.ZodOptional; card: z.ZodString; evidence: z.ZodString; files: z.ZodArray>; }, z.core.$strict>; export declare const MarketplaceManifestSchema: z.ZodObject<{ schemaVersion: z.ZodLiteral<1>; name: z.ZodString; stamp: z.ZodOptional; skills: z.ZodArray; license: z.ZodOptional; riskClass: z.ZodOptional; card: z.ZodString; evidence: z.ZodString; files: z.ZodArray>; }, z.core.$strict>>; }, z.core.$strict>; export type MarketplaceFile = z.infer; export type MarketplaceSkill = z.infer; export type MarketplaceManifest = z.infer; export type MarketplaceManifestRead = { ok: true; manifest: MarketplaceManifest; } | { ok: false; reason: string; }; /** * Read an artifact's manifest. Fail-CLOSED, but as a RESULT rather than a throw * (the inverse of `readSkillsLock`'s fail-soft): `marketplace validate` is a * checker, so a malformed manifest is a FINDING it must report — never a crash, * and never a fail-soft read that would let a half-valid manifest keep grading * files while silently dropping the entries it could not parse. */ export declare function readMarketplaceManifest(dir: string): MarketplaceManifestRead;