export interface ExtractedLesson { heading?: string; tags: string[]; text: string; scope?: string; suspiciousFlags?: string[]; } export declare const MAX_SUSPICIOUS_HEADING_LENGTH = 60; /** Defensive keywords suggesting instructional/security discussion context. */ export declare const DEFENSIVE_KEYWORD_RE: RegExp; /** Characters of context to check around a match for defensive keywords. */ export declare const DEFENSIVE_PROXIMITY_WINDOW = 100; /** * Collect all [start, end] ranges of code-fenced regions in the text. * Uses inline regexes via matchAll to avoid module-level global state mutation. */ export declare function collectCodeRanges(text: string): Array<[number, number]>; /** * Check if ALL matches of a pattern in text occur in instructional context * (inside backticks/code blocks AND near defensive keywords). * Both conditions must be met for EVERY match to suppress a flag. * If any single match is outside instructional context, returns false (fail closed). */ export declare function isInstructionalContext(text: string, // totem-ignore pattern: RegExp, codeRanges?: Array<[number, number]>): boolean; /** * Scans extracted lessons for heuristic indicators of prompt injection or * LLM constraint violations. Returns a new array with `suspiciousFlags` * populated on any lesson that triggers one or more checks. * * For XML tag and instructional leakage patterns, a context-aware heuristic * suppresses false positives: if the match is inside backticks/code fences * AND defensive keywords are nearby, it's treated as instructional discussion. */ export declare function flagSuspiciousLessons(lessons: ExtractedLesson[]): ExtractedLesson[]; //# sourceMappingURL=suspicious-lesson.d.ts.map