import type { CommandSpec, Plan, PlanContext } from "../internals/plan.js"; import type { Check } from "../internals/verify.js"; import { type TrustSource } from "../trust/fetch.js"; import { type SkillShape } from "./shape.js"; import { type SkillVerdict } from "./verdict.js"; /** * `aih skill vet` — slice 1 of the skill lifecycle: a READ-ONLY gate pipeline * (resolve → fetch-under-apply → shape → license → trust scan → verdict → * evidence artifact → digest). It NEVER installs anything; the exit code stays * binary through the existing VerificationReport, and the GREEN/YELLOW/RED/ * UNKNOWN verdict rides the digest / `--json` only. */ interface SkillVetPlanOptions { cleanupQuarantine?: boolean; skillName?: string; } /** Evidence artifact schema written to `.aih/skill-reports/` under --apply. */ export interface SkillVetEvidence { schemaVersion: 1; source: string; pinnedSha?: string; /** Present when the evidence was scoped to one logical skill via `--name`. */ skillName?: string; /** Present when `--name` narrowed a multi-skill source to a curated artifact. */ sourceScope?: SkillSourceScope; /** Absent when the remote source was not fetched (dry-run / fetch failure). */ shape?: SkillShape; checks: Array<{ name: string; verdict: Check["verdict"]; code?: Check["code"]; detail?: string; }>; analyzersRun: string[]; verdict: SkillVerdict; reasons: string[]; } export interface SkillSourceScope { selectedSkillNames: string[]; includedPaths: string[]; excludedSkillPaths: string[]; } export declare function skillVetPlanForSource(ctx: PlanContext, source: TrustSource, options?: SkillVetPlanOptions): Promise; export declare const skillVetCommand: CommandSpec; export {};