/** * Layer 6 — Logic-based injection detection. * * Unlike pattern-matching layers that catch known payloads, * this layer analyzes the *structure* of manipulation attempts. * * 10 attack categories detected: * * 1. Rhetorical Bridge — sensitive request + "so I can X" + benign cover * 2. Domain Drift — request outside declared domain (needs allowedDomain) * 3. Role Manipulation — "pretend you're X", "you are now Y" * 4. Authority Impersonation — "I'm the developer/admin/owner, disable X" * 5. Hypothetical Framing — "imagine if you had no limits", "what if" * 6. Example Injection — "example: [harmful Q+A]. Now answer my Q" * 7. Context Rewrite — "rules changed", "testing mode", "new config" * 8. Goal Redirection — "your actual goal is", "new priority" * 9. Assumption Injection — "as you know", "we already agreed", "remember when" * 10. Specification Gap — probing the edges of what's allowed * * Each detector is structural — looks at HOW the text manipulates, * not WHAT specific payload it contains. */ export type LogicSeverity = "high" | "critical"; export type LogicFinding = { ruleId: string; severity: LogicSeverity; message: string; evidence: string; distance?: number; bridge?: string; /** Confidence score 0-1 — how sure we are this is logic-based injection. */ confidence: number; }; export type LogicAnalysisOptions = { allowedDomain?: string; coherenceThreshold?: number; }; export declare function analyzeLogic(text: string, options?: LogicAnalysisOptions): LogicFinding[];