import { z } from "zod"; import { AihError } from "../errors.js"; import type { PlanContext } from "../internals/plan.js"; export declare const POLICY_HTTPS_ORIGIN_PATTERN = "^https://[A-Za-z0-9](?:[A-Za-z0-9.-]{0,251}[A-Za-z0-9])?(?::(?:[0-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?$"; export declare function normalizePolicyHost(value: string, source?: string): string; export declare function normalizeHttpsOrigin(value: string, source?: string): string; /** * AIH hard ceilings for the declarative Strix security policy. These are not * claimed as upstream Strix limits: this repository has no upstream owner * ceiling yet, so the conservative bounds keep a future headless scan bounded * until an execution consumer owns tighter per-mode budgets. */ export declare const STRIX_POLICY_LIMITS: Readonly<{ readonly maxBudgetCents: 1000; readonly maxTurns: 20; readonly timeoutMs: 300000; }>; export declare const StrixSecurityPolicySchema: z.ZodDiscriminatedUnion<[z.ZodObject<{ targetKind: z.ZodLiteral<"local-fixture">; mode: z.ZodEnum<{ deep: "deep"; quick: "quick"; standard: "standard"; }>; maxBudgetCents: z.ZodNumber; maxTurns: z.ZodNumber; timeoutMs: z.ZodNumber; telemetry: z.ZodLiteral<"off">; imageDigest: z.ZodString; allowLiveTargets: z.ZodDefault>; allowMounts: z.ZodDefault>; enabled: z.ZodLiteral; required: z.ZodBoolean; }, z.core.$strict>, z.ZodObject<{ targetKind: z.ZodLiteral<"local-fixture">; mode: z.ZodEnum<{ deep: "deep"; quick: "quick"; standard: "standard"; }>; maxBudgetCents: z.ZodNumber; maxTurns: z.ZodNumber; timeoutMs: z.ZodNumber; telemetry: z.ZodLiteral<"off">; imageDigest: z.ZodString; allowLiveTargets: z.ZodDefault>; allowMounts: z.ZodDefault>; enabled: z.ZodLiteral; required: z.ZodLiteral; }, z.core.$strict>], "enabled">; export declare const SupportedCliSchema: z.ZodEnum<{ antigravity: "antigravity"; claude: "claude"; codex: "codex"; copilot: "copilot"; cursor: "cursor"; gemini: "gemini"; kimi: "kimi"; kiro: "kiro"; opencode: "opencode"; windsurf: "windsurf"; zed: "zed"; }>; export declare function enterpriseSupportedClisJsonSchemaConstraint(): Record; /** Command arguments that are only safe when they carry an exact HTTPS origin. */ export declare const HTTPS_ORIGIN_ARGUMENT_PREFIXES: readonly ["--registry=", "--index-url="]; export declare function safePolicyCommandArgument(value: string): boolean; export declare const CandidateSourceSchema: z.ZodUnion; repository: z.ZodString; commit: z.ZodString; tree: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"package">; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"command">; command: z.ZodString; args: z.ZodDefault>; executableDigest: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"stdio">; resolver: z.ZodEnum<{ npx: "npx"; uvx: "uvx"; }>; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodUnion; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; administrativeStatus: z.ZodEnum<{ approved: "approved"; revoked: "revoked"; }>; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"remote">; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; toolSurfaceDigest: z.ZodString; verdict: z.ZodEnum<{ approved: "approved"; drifted: "drifted"; revoked: "revoked"; }>; }, z.core.$strict>]>, z.ZodObject<{ type: z.ZodLiteral<"mcp">; server: z.ZodString; subject: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"hook">; handler: z.ZodLiteral<"usage-metering">; scriptDigest: z.ZodString; }, z.core.$strict>]>; export declare const PolicyDangerCodeSchema: z.ZodEnum<{ "auto-executing-hook": "auto-executing-hook"; "dependency-confusion": "dependency-confusion"; "evidence-identity-drift": "evidence-identity-drift"; "hidden-unicode": "hidden-unicode"; "malicious-code": "malicious-code"; "mandatory-detector-failed": "mandatory-detector-failed"; "missing-projector": "missing-projector"; "normalized-collision": "normalized-collision"; "ownership-conflict": "ownership-conflict"; "prompt-injection": "prompt-injection"; secrets: "secrets"; "unpinned-source": "unpinned-source"; "unsafe-path": "unsafe-path"; "unsupported-target": "unsupported-target"; }>; export declare const PolicyApprovalSchema: z.ZodObject<{ id: z.ZodString; candidate: z.ZodString; kind: z.ZodEnum<{ framework: "framework"; hook: "hook"; mcp: "mcp"; }>; source: z.ZodUnion; repository: z.ZodString; commit: z.ZodString; tree: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"package">; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"command">; command: z.ZodString; args: z.ZodDefault>; executableDigest: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"stdio">; resolver: z.ZodEnum<{ npx: "npx"; uvx: "uvx"; }>; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodUnion; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; administrativeStatus: z.ZodEnum<{ approved: "approved"; revoked: "revoked"; }>; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"remote">; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; toolSurfaceDigest: z.ZodString; verdict: z.ZodEnum<{ approved: "approved"; drifted: "drifted"; revoked: "revoked"; }>; }, z.core.$strict>]>, z.ZodObject<{ type: z.ZodLiteral<"mcp">; server: z.ZodString; subject: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"hook">; handler: z.ZodLiteral<"usage-metering">; scriptDigest: z.ZodString; }, z.core.$strict>]>; issuer: z.ZodString; sourceDigest: z.ZodString; evidenceDigest: z.ZodString; projector: z.ZodEnum<{ "framework-contract": "framework-contract"; "hook-managed-settings": "hook-managed-settings"; "mcp-managed-settings": "mcp-managed-settings"; "usage-hook": "usage-hook"; }>; policyVersion: z.ZodString; reason: z.ZodString; clarification: z.ZodOptional; scope: z.ZodArray>; notBefore: z.ZodString; expiresAt: z.ZodString; github: z.ZodObject<{ repository: z.ZodString; attestationId: z.ZodString; subjectDigest: z.ZodString; }, z.core.$strict>; }, z.core.$strict>; /** The one copy of native-field validation, shared by the grammar and the projector. */ export declare function nativeHookFieldIssues(fields: unknown, reserved?: readonly string[]): string[]; export declare const ThirdPartyLauncherPinSchema: z.ZodObject<{ repository: z.ZodString; commit: z.ZodString; path: z.ZodString; launcherSha256: z.ZodString; runtimeVersion: z.ZodString; }, z.core.$strict>; declare const HookRegistrationOwnerSchema: z.ZodDiscriminatedUnion<[z.ZodObject<{ kind: z.ZodLiteral<"aih">; }, z.core.$strict>, z.ZodObject<{ kind: z.ZodLiteral<"third-party">; framework: z.ZodString; declaredControls: z.ZodDefault>; pin: z.ZodObject<{ repository: z.ZodString; commit: z.ZodString; path: z.ZodString; launcherSha256: z.ZodString; runtimeVersion: z.ZodString; }, z.core.$strict>; }, z.core.$strict>, z.ZodObject<{ kind: z.ZodLiteral<"unknown">; launcherSha256: z.ZodString; }, z.core.$strict>], "kind">; /** * The `hook-managed-settings` projector's own registration shape, carried by * the policy grammar as `governance.hookRegistrations` (G1). It lives here so * the grammar and the projector validate through ONE copy; the projector module * imports it rather than restating it. */ export declare const HookRegistrationSchema: z.ZodObject<{ id: z.ZodString; event: z.ZodString; command: z.ZodString; functionTags: z.ZodArray; spawns: z.ZodNumber; timeout: z.ZodOptional; sourceDisabled: z.ZodDefault; nativeGroup: z.ZodOptional>; nativeHook: z.ZodOptional>; owner: z.ZodDiscriminatedUnion<[z.ZodObject<{ kind: z.ZodLiteral<"aih">; }, z.core.$strict>, z.ZodObject<{ kind: z.ZodLiteral<"third-party">; framework: z.ZodString; declaredControls: z.ZodDefault>; pin: z.ZodObject<{ repository: z.ZodString; commit: z.ZodString; path: z.ZodString; launcherSha256: z.ZodString; runtimeVersion: z.ZodString; }, z.core.$strict>; }, z.core.$strict>, z.ZodObject<{ kind: z.ZodLiteral<"unknown">; launcherSha256: z.ZodString; }, z.core.$strict>], "kind">; }, z.core.$strict>; export type ThirdPartyLauncherPin = z.infer; export type HookRegistrationOwner = z.infer; export interface HookRegistration extends z.input { } export type ResolvedHookRegistration = z.infer; export declare function hookCommandDigest(command: string): string; /** * The one copy of registration-set validation: the policy grammar refuses * through it at parse time and the projector refuses through it before * emitting. A launcher whose hash no longer matches its pin is drift — refused, * never projected, because projecting it would be a silent update of code AIH * cannot read. */ export declare function hookRegistrationSetIssues(registrations: readonly ResolvedHookRegistration[]): { index: number; message: string; }[]; declare const GovernedPolicyGovernanceSchema: z.ZodObject<{ policyVersion: z.ZodString; catalog: z.ZodObject<{ reviewed: z.ZodDefault; description: z.ZodString; capabilities: z.ZodDefault>; risks: z.ZodDefault>; source: z.ZodUnion; repository: z.ZodString; commit: z.ZodString; tree: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"package">; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"command">; command: z.ZodString; args: z.ZodDefault>; executableDigest: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"stdio">; resolver: z.ZodEnum<{ npx: "npx"; uvx: "uvx"; }>; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodUnion; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; administrativeStatus: z.ZodEnum<{ approved: "approved"; revoked: "revoked"; }>; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"remote">; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; toolSurfaceDigest: z.ZodString; verdict: z.ZodEnum<{ approved: "approved"; drifted: "drifted"; revoked: "revoked"; }>; }, z.core.$strict>]>, z.ZodObject<{ type: z.ZodLiteral<"mcp">; server: z.ZodString; subject: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"hook">; handler: z.ZodLiteral<"usage-metering">; scriptDigest: z.ZodString; }, z.core.$strict>]>; targets: z.ZodArray>; projector: z.ZodEnum<{ "framework-contract": "framework-contract"; "hook-managed-settings": "hook-managed-settings"; "mcp-managed-settings": "mcp-managed-settings"; "usage-hook": "usage-hook"; }>; lifecycle: z.ZodEnum<{ deprecated: "deprecated"; retired: "retired"; supported: "supported"; }>; evidence: z.ZodObject<{ record: z.ZodString; }, z.core.$strict>; findings: z.ZodDefault>>; autoExecute: z.ZodDefault; framework: z.ZodOptional>; clarification: z.ZodOptional; annotation: z.ZodOptional; }, z.core.$strict>>>; custom: z.ZodDefault; description: z.ZodString; capabilities: z.ZodDefault>; risks: z.ZodDefault>; source: z.ZodUnion; repository: z.ZodString; commit: z.ZodString; tree: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"package">; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"command">; command: z.ZodString; args: z.ZodDefault>; executableDigest: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"stdio">; resolver: z.ZodEnum<{ npx: "npx"; uvx: "uvx"; }>; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodUnion; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; administrativeStatus: z.ZodEnum<{ approved: "approved"; revoked: "revoked"; }>; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"remote">; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; toolSurfaceDigest: z.ZodString; verdict: z.ZodEnum<{ approved: "approved"; drifted: "drifted"; revoked: "revoked"; }>; }, z.core.$strict>]>, z.ZodObject<{ type: z.ZodLiteral<"mcp">; server: z.ZodString; subject: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"hook">; handler: z.ZodLiteral<"usage-metering">; scriptDigest: z.ZodString; }, z.core.$strict>]>; targets: z.ZodArray>; projector: z.ZodEnum<{ "framework-contract": "framework-contract"; "hook-managed-settings": "hook-managed-settings"; "mcp-managed-settings": "mcp-managed-settings"; "usage-hook": "usage-hook"; }>; lifecycle: z.ZodEnum<{ deprecated: "deprecated"; retired: "retired"; supported: "supported"; }>; evidence: z.ZodObject<{ record: z.ZodString; }, z.core.$strict>; findings: z.ZodDefault>>; autoExecute: z.ZodDefault; framework: z.ZodOptional>; clarification: z.ZodOptional; annotation: z.ZodOptional; }, z.core.$strict>>>; }, z.core.$strict>; activations: z.ZodDefault; targets: z.ZodArray>; clarification: z.ZodOptional; }, z.core.$strict>>>; authority: z.ZodDefault; source: z.ZodUnion; repository: z.ZodString; commit: z.ZodString; tree: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"package">; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"command">; command: z.ZodString; args: z.ZodDefault>; executableDigest: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"stdio">; resolver: z.ZodEnum<{ npx: "npx"; uvx: "uvx"; }>; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodUnion; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; administrativeStatus: z.ZodEnum<{ approved: "approved"; revoked: "revoked"; }>; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"remote">; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; toolSurfaceDigest: z.ZodString; verdict: z.ZodEnum<{ approved: "approved"; drifted: "drifted"; revoked: "revoked"; }>; }, z.core.$strict>]>, z.ZodObject<{ type: z.ZodLiteral<"mcp">; server: z.ZodString; subject: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"hook">; handler: z.ZodLiteral<"usage-metering">; scriptDigest: z.ZodString; }, z.core.$strict>]>; issuer: z.ZodString; sourceDigest: z.ZodString; evidenceDigest: z.ZodString; projector: z.ZodEnum<{ "framework-contract": "framework-contract"; "hook-managed-settings": "hook-managed-settings"; "mcp-managed-settings": "mcp-managed-settings"; "usage-hook": "usage-hook"; }>; policyVersion: z.ZodString; reason: z.ZodString; clarification: z.ZodOptional; scope: z.ZodArray>; notBefore: z.ZodString; expiresAt: z.ZodString; github: z.ZodObject<{ repository: z.ZodString; attestationId: z.ZodString; subjectDigest: z.ZodString; }, z.core.$strict>; }, z.core.$strict>>>; }, z.core.$strict>>; externalCuration: z.ZodDefault; items: z.ZodDefault; id: z.ZodString; source: z.ZodObject<{ repository: z.ZodString; commit: z.ZodString; path: z.ZodString; }, z.core.$strict>; audit: z.ZodObject<{ record: z.ZodString; digest: z.ZodString; }, z.core.$strict>; clarification: z.ZodOptional; }, z.core.$strict>>>; }, z.core.$strict>>>; externalSelections: z.ZodDefault; items: z.ZodDefault; id: z.ZodString; source: z.ZodObject<{ repository: z.ZodString; commit: z.ZodString; path: z.ZodString; }, z.core.$strict>; }, z.core.$strict>>>; }, z.core.$strict>>>; eccMcpApprovals: z.ZodDefault; sourceContentSha256: z.ZodLiteral<"a4426254c55a5352db2672bc86a87f10b0029f5e4ae1b74817841e87d9ab1e57">; state: z.ZodEnum<{ approved: "approved"; revoked: "revoked"; }>; approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>>>; eccHookControls: z.ZodOptional; disabledIds: z.ZodOptional>>; }, z.core.$strict>, z.ZodTransform<{ profile: "minimal" | "standard" | "strict"; disabledIds?: string[] | undefined; }, { profile: "minimal" | "standard" | "strict"; disabledIds?: string[] | undefined; }>>>; supportedClis: z.ZodOptional>>; hookRegistrations: z.ZodDefault; spawns: z.ZodNumber; timeout: z.ZodOptional; sourceDisabled: z.ZodDefault; nativeGroup: z.ZodOptional>; nativeHook: z.ZodOptional>; owner: z.ZodDiscriminatedUnion<[z.ZodObject<{ kind: z.ZodLiteral<"aih">; }, z.core.$strict>, z.ZodObject<{ kind: z.ZodLiteral<"third-party">; framework: z.ZodString; declaredControls: z.ZodDefault>; pin: z.ZodObject<{ repository: z.ZodString; commit: z.ZodString; path: z.ZodString; launcherSha256: z.ZodString; runtimeVersion: z.ZodString; }, z.core.$strict>; }, z.core.$strict>, z.ZodObject<{ kind: z.ZodLiteral<"unknown">; launcherSha256: z.ZodString; }, z.core.$strict>], "kind">; }, z.core.$strict>>>; }, z.core.$strict>; /** Stable flattened input leaves for mechanical consumer-completeness contracts. */ export declare function schemaLeafPaths(schema: unknown, path?: string): string[]; /** Exact authorable governance leaves used by the policy consumer-completeness gate. */ export declare function policyGovernanceLeafPaths(): string[]; /** Exact authorable Strix leaves used by the policy consumer-completeness gate. */ export declare function policySecurityLeafPaths(): string[]; export declare const OrgPolicySchema: z.ZodObject<{ schemaVersion: z.ZodLiteral<2>; minimumPosture: z.ZodEnum<{ enterprise: "enterprise"; vibe: "vibe"; }>; references: z.ZodObject<{ repoContract: z.ZodString; }, z.core.$strip>; command: z.ZodOptional; }, z.core.$strict>>>; remove: z.ZodDefault>; }, z.core.$strict>>; ask: z.ZodOptional; }, z.core.$strict>>>; remove: z.ZodDefault>; }, z.core.$strict>>; }, z.core.$strict>>; riskGates: z.ZodOptional>; commandPatterns: z.ZodDefault>; }, z.core.$strict>>>; override: z.ZodDefault; pathPatterns: z.ZodOptional>; commandPatterns: z.ZodOptional>; }, z.core.$strict>>>; }, z.core.$strict>>; licenses: z.ZodOptional>>; }, z.core.$strict>>; security: z.ZodOptional; mode: z.ZodEnum<{ deep: "deep"; quick: "quick"; standard: "standard"; }>; maxBudgetCents: z.ZodNumber; maxTurns: z.ZodNumber; timeoutMs: z.ZodNumber; telemetry: z.ZodLiteral<"off">; imageDigest: z.ZodString; allowLiveTargets: z.ZodDefault>; allowMounts: z.ZodDefault>; enabled: z.ZodLiteral; required: z.ZodBoolean; }, z.core.$strict>, z.ZodObject<{ targetKind: z.ZodLiteral<"local-fixture">; mode: z.ZodEnum<{ deep: "deep"; quick: "quick"; standard: "standard"; }>; maxBudgetCents: z.ZodNumber; maxTurns: z.ZodNumber; timeoutMs: z.ZodNumber; telemetry: z.ZodLiteral<"off">; imageDigest: z.ZodString; allowLiveTargets: z.ZodDefault>; allowMounts: z.ZodDefault>; enabled: z.ZodLiteral; required: z.ZodLiteral; }, z.core.$strict>], "enabled">; }, z.core.$strict>>; mcp: z.ZodOptional>; approvals: z.ZodDefault; acceptEgress: z.ZodLiteral; reason: z.ZodString; reviewer: z.ZodOptional; approvedAt: z.ZodString; }, z.core.$strict>>>; allowManagedOnly: z.ZodDefault; incumbentHosts: z.ZodDefault>>>; githubHost: z.ZodOptional>>; disabledServers: z.ZodDefault>; }, z.core.$strict>>; trust: z.ZodOptional; reason: z.ZodOptional; }, z.core.$strict>>>; requireSignedSource: z.ZodDefault; requiredDetectors: z.ZodOptional>>; requiredChecks: z.ZodOptional>; baselineOverrides: z.ZodOptional; owner: z.ZodString; repo: z.ZodString; pinnedSha: z.ZodString; bundle: z.ZodString; signingRepository: z.ZodString; reason: z.ZodString; reviewer: z.ZodString; approvedAt: z.ZodString; }, z.core.$strict>>>; internalScopes: z.ZodDefault>; skillspector: z.ZodOptional; approvedAt: z.ZodString; }, z.core.$strict>>>; }, z.core.$strict>>; }, z.core.$strict>>; capabilityPackages: z.ZodOptional; repository: z.ZodString; }, z.core.$strict>; roots: z.ZodArray; }, z.core.$strict>>; governance: z.ZodOptional>; }, z.core.$strict>, z.ZodObject<{ policyVersion: z.ZodString; catalog: z.ZodObject<{ reviewed: z.ZodDefault; description: z.ZodString; capabilities: z.ZodDefault>; risks: z.ZodDefault>; source: z.ZodUnion; repository: z.ZodString; commit: z.ZodString; tree: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"package">; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"command">; command: z.ZodString; args: z.ZodDefault>; executableDigest: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"stdio">; resolver: z.ZodEnum<{ npx: "npx"; uvx: "uvx"; }>; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodUnion; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; administrativeStatus: z.ZodEnum<{ approved: "approved"; revoked: "revoked"; }>; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"remote">; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; toolSurfaceDigest: z.ZodString; verdict: z.ZodEnum<{ approved: "approved"; drifted: "drifted"; revoked: "revoked"; }>; }, z.core.$strict>]>, z.ZodObject<{ type: z.ZodLiteral<"mcp">; server: z.ZodString; subject: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"hook">; handler: z.ZodLiteral<"usage-metering">; scriptDigest: z.ZodString; }, z.core.$strict>]>; targets: z.ZodArray>; projector: z.ZodEnum<{ "framework-contract": "framework-contract"; "hook-managed-settings": "hook-managed-settings"; "mcp-managed-settings": "mcp-managed-settings"; "usage-hook": "usage-hook"; }>; lifecycle: z.ZodEnum<{ deprecated: "deprecated"; retired: "retired"; supported: "supported"; }>; evidence: z.ZodObject<{ record: z.ZodString; }, z.core.$strict>; findings: z.ZodDefault>>; autoExecute: z.ZodDefault; framework: z.ZodOptional>; clarification: z.ZodOptional; annotation: z.ZodOptional; }, z.core.$strict>>>; custom: z.ZodDefault; description: z.ZodString; capabilities: z.ZodDefault>; risks: z.ZodDefault>; source: z.ZodUnion; repository: z.ZodString; commit: z.ZodString; tree: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"package">; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"command">; command: z.ZodString; args: z.ZodDefault>; executableDigest: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"stdio">; resolver: z.ZodEnum<{ npx: "npx"; uvx: "uvx"; }>; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodUnion; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; administrativeStatus: z.ZodEnum<{ approved: "approved"; revoked: "revoked"; }>; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"remote">; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; toolSurfaceDigest: z.ZodString; verdict: z.ZodEnum<{ approved: "approved"; drifted: "drifted"; revoked: "revoked"; }>; }, z.core.$strict>]>, z.ZodObject<{ type: z.ZodLiteral<"mcp">; server: z.ZodString; subject: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"hook">; handler: z.ZodLiteral<"usage-metering">; scriptDigest: z.ZodString; }, z.core.$strict>]>; targets: z.ZodArray>; projector: z.ZodEnum<{ "framework-contract": "framework-contract"; "hook-managed-settings": "hook-managed-settings"; "mcp-managed-settings": "mcp-managed-settings"; "usage-hook": "usage-hook"; }>; lifecycle: z.ZodEnum<{ deprecated: "deprecated"; retired: "retired"; supported: "supported"; }>; evidence: z.ZodObject<{ record: z.ZodString; }, z.core.$strict>; findings: z.ZodDefault>>; autoExecute: z.ZodDefault; framework: z.ZodOptional>; clarification: z.ZodOptional; annotation: z.ZodOptional; }, z.core.$strict>>>; }, z.core.$strict>; activations: z.ZodDefault; targets: z.ZodArray>; clarification: z.ZodOptional; }, z.core.$strict>>>; authority: z.ZodDefault; source: z.ZodUnion; repository: z.ZodString; commit: z.ZodString; tree: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"package">; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"command">; command: z.ZodString; args: z.ZodDefault>; executableDigest: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"stdio">; resolver: z.ZodEnum<{ npx: "npx"; uvx: "uvx"; }>; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodUnion; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; administrativeStatus: z.ZodEnum<{ approved: "approved"; revoked: "revoked"; }>; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"remote">; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; toolSurfaceDigest: z.ZodString; verdict: z.ZodEnum<{ approved: "approved"; drifted: "drifted"; revoked: "revoked"; }>; }, z.core.$strict>]>, z.ZodObject<{ type: z.ZodLiteral<"mcp">; server: z.ZodString; subject: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"hook">; handler: z.ZodLiteral<"usage-metering">; scriptDigest: z.ZodString; }, z.core.$strict>]>; issuer: z.ZodString; sourceDigest: z.ZodString; evidenceDigest: z.ZodString; projector: z.ZodEnum<{ "framework-contract": "framework-contract"; "hook-managed-settings": "hook-managed-settings"; "mcp-managed-settings": "mcp-managed-settings"; "usage-hook": "usage-hook"; }>; policyVersion: z.ZodString; reason: z.ZodString; clarification: z.ZodOptional; scope: z.ZodArray>; notBefore: z.ZodString; expiresAt: z.ZodString; github: z.ZodObject<{ repository: z.ZodString; attestationId: z.ZodString; subjectDigest: z.ZodString; }, z.core.$strict>; }, z.core.$strict>>>; }, z.core.$strict>>; externalCuration: z.ZodDefault; items: z.ZodDefault; id: z.ZodString; source: z.ZodObject<{ repository: z.ZodString; commit: z.ZodString; path: z.ZodString; }, z.core.$strict>; audit: z.ZodObject<{ record: z.ZodString; digest: z.ZodString; }, z.core.$strict>; clarification: z.ZodOptional; }, z.core.$strict>>>; }, z.core.$strict>>>; externalSelections: z.ZodDefault; items: z.ZodDefault; id: z.ZodString; source: z.ZodObject<{ repository: z.ZodString; commit: z.ZodString; path: z.ZodString; }, z.core.$strict>; }, z.core.$strict>>>; }, z.core.$strict>>>; eccMcpApprovals: z.ZodDefault; sourceContentSha256: z.ZodLiteral<"a4426254c55a5352db2672bc86a87f10b0029f5e4ae1b74817841e87d9ab1e57">; state: z.ZodEnum<{ approved: "approved"; revoked: "revoked"; }>; approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>>>; eccHookControls: z.ZodOptional; disabledIds: z.ZodOptional>>; }, z.core.$strict>, z.ZodTransform<{ profile: "minimal" | "standard" | "strict"; disabledIds?: string[] | undefined; }, { profile: "minimal" | "standard" | "strict"; disabledIds?: string[] | undefined; }>>>; supportedClis: z.ZodOptional>>; hookRegistrations: z.ZodDefault; spawns: z.ZodNumber; timeout: z.ZodOptional; sourceDisabled: z.ZodDefault; nativeGroup: z.ZodOptional>; nativeHook: z.ZodOptional>; owner: z.ZodDiscriminatedUnion<[z.ZodObject<{ kind: z.ZodLiteral<"aih">; }, z.core.$strict>, z.ZodObject<{ kind: z.ZodLiteral<"third-party">; framework: z.ZodString; declaredControls: z.ZodDefault>; pin: z.ZodObject<{ repository: z.ZodString; commit: z.ZodString; path: z.ZodString; launcherSha256: z.ZodString; runtimeVersion: z.ZodString; }, z.core.$strict>; }, z.core.$strict>, z.ZodObject<{ kind: z.ZodLiteral<"unknown">; launcherSha256: z.ZodString; }, z.core.$strict>], "kind">; }, z.core.$strict>>>; }, z.core.$strict>]>>; }, z.core.$strict>; type ParsedOrgPolicy = z.infer; export type OrgPolicy = Omit & { governance?: z.infer; }; type GovernedOrgPolicy = OrgPolicy & { governance: NonNullable; }; /** * A supported-CLI allow-list is a sanction gate, not a request to take over * MCP or hook projection. Only a policy carrying governed inventory, decisions, * authority, curation, or registrar records owns those AIH surfaces. */ export declare function governanceOwnsAihSurfaces(policy: OrgPolicy | undefined): policy is GovernedOrgPolicy; export declare class OrgPolicyError extends AihError { constructor(message: string); } export declare function parseOrgPolicy(value: unknown): OrgPolicy; /** * A governed inventory is the sole authority for AIH-owned MCP and hook * mutations. Generic commands must not union legacy selections into it. */ export declare function assertGovernanceOwnsSurface(ctx: PlanContext, surface: "mcp" | "usage"): void; export declare function orgPolicyPath(root: string, env: NodeJS.ProcessEnv): string; /** Did the operator explicitly name a policy file, rather than relying on the repo default? */ export declare function hasExplicitOrgPolicySource(env: NodeJS.ProcessEnv): boolean; export declare function readOrgPolicy(root: string, env: NodeJS.ProcessEnv): OrgPolicy | undefined; export {};