import type { AgentTool } from "@caupulican/pi-agent-core"; import type { TSchema } from "typebox"; import type { ArtifactStore } from "../context/context-artifacts.ts"; import { type CredentialExposureBoundary } from "../secrets/credential-exposure-guard.ts"; import { type RunToolkitScriptDependencies } from "../tools/run-toolkit-script.ts"; import { type ReadOnlySkillBroker } from "../tools/skill.ts"; import { type SkillAuditToolOptions } from "../tools/skill-audit.ts"; /** * Host-owned inputs available while constructing one fresh worker tool. * * An adapter is deliberately a factory, not a live AgentTool. This keeps worker retries and * concurrent lanes from sharing mutable foreground/session state. The host owns the broker * callbacks and is responsible for preserving its cancellation and credential boundaries. */ export interface WorkerToolAdapterContext { cwd: string; signal?: AbortSignal; credentialBoundary?: CredentialExposureBoundary; } export type WorkerToolAdapterFactory = (context: WorkerToolAdapterContext) => AgentTool; export interface WorkerToolAdapter { readonly name: string; readonly description: string; readonly create: WorkerToolAdapterFactory; } /** Root/session controls are never brokered into a leaf, even when a host registers factories. */ export declare const WORKER_TOOL_ADAPTER_FORBIDDEN_NAMES: ReadonlySet; /** Adapter names with host-owned factories; explicit profiles must have these active in foreground. */ export declare const WORKER_TOOL_ADAPTER_NAMES: ReadonlySet; export type WorkerToolAdapterMaterialization = { ok: true; tool: AgentTool; } | { ok: false; reason: string; }; export interface WorkerToolAdapterSources { /** Session-owned packed output store; retrieval is bounded and identifier-only. */ artifactStore?: ArtifactStore; /** Host-owned script registry and bounded executor. */ runToolkitScript?: RunToolkitScriptDependencies; /** Optional brokered read-only skill surface. */ skill?: ReadOnlySkillBroker; /** Optional read-only skill audit broker with host-path redaction. */ skillAudit?: Pick & Required>; } /** * Registry for the small set of foreground capabilities that can be brokered safely to a leaf * worker. It owns no session state and never clones or returns the foreground tool instance. * * Extension/MCP tools must be registered explicitly by a host broker. A missing registration is * a deterministic unsupported result so an omitted inherited tool cannot silently disappear. */ export declare class WorkerToolAdapterRegistry { private readonly adapters; register(adapter: WorkerToolAdapter): this; has(name: string): boolean; names(): readonly string[]; description(name: string): string | undefined; materialize(name: string, context: WorkerToolAdapterContext): WorkerToolAdapterMaterialization; } /** Build the default safe adapters from host-owned brokers. Omitted sources stay unsupported. */ export declare function createWorkerToolAdapterRegistry(sources?: WorkerToolAdapterSources): WorkerToolAdapterRegistry; export declare function unsupportedWorkerToolReason(name: string): string; //# sourceMappingURL=worker-tool-adapter-registry.d.ts.map