export type PathPolicyOptions = { cwd?: string; home?: string; env?: NodeJS.ProcessEnv; allowedRoots?: string[]; /** Include the current working directory (default: true). */ includeCwd?: boolean; /** Include the two discovered AI-session roots (default: false). */ includeSessionRoots?: boolean; }; export declare function isWithinRoot(root: string, target: string): boolean; /** Build a validator that canonicalizes both roots and targets before testing containment. */ export declare function createPathValidator(options?: PathPolicyOptions): (filePath: string) => string;