import type { Posture } from "../config/posture.js"; import { type DigestAction, type PlanContext } from "../internals/plan.js"; export interface McpGovernanceSummary { posture: Posture; denied: { name: string; reason: string; }[]; warned: { name: string; reason: string; }[]; allowed: string[]; counts: { denied: number; warned: number; allowed: number; }; } /** Shared MCP governance spine: one catalog scan and policy engine for every report consumer. */ export declare function mcpGovernanceSummary(ctx: PlanContext, posture?: Posture): McpGovernanceSummary; /** * MCP governance panel — aih's curated server set (at project scope) judged under the * ENTERPRISE posture, the strict gate, so a reviewer sees at a glance what an * enterprise rollout would flag. Reuses the policy engine ({@link evaluateMcpPolicy}): * reads only the risk axes, contacts nothing. The default vibe posture blocks nothing — * aih REPORTS these verdicts, it never silently drops a server from `.mcp.json`. This * is the "would it survive enterprise friction?" answer in the local dashboard. * * Renders as a clean note panel (HTML) / fenced section (markdown) today; the planned * report v4 restyle reuses this digest's `data`, so building it now is forward-safe. */ export declare function mcpGovernanceDigest(ctx: PlanContext): DigestAction;