import type { MCPPromptDefinition, MCPPromptMessage } from '../../types/connector/index.js'; import type { ToolDefinition } from '../../types/tool/index.js'; import type { MCPClient } from './client.js'; /** * A server's prompt, as something the model can ask for. * * `listPrompts` and `getPrompt` reached the client and stopped there: a * server could publish prompts, the SDK could fetch them, and none of it * ever reached a model. Shipping the protocol half without this one left * exactly the shape this kernel keeps having to remove — a primitive with * no driver. * * **Why a tool and not system content.** Three routes were possible and * two are worse: * * - Folding a prompt into the system prompt puts remote text in the cached * prefix, so every turn pays for it and the cache breaks whenever the * server changes its wording. Worse, system position READS as * instruction, which is the last thing text from a remote party should * read as. * - A slash command routes through the host's UI, so a headless turn — the * case this kernel is built for — could never use one. * * A tool call is explicit, auditable, passes the same admission policy and * `allowedTools` filter every other capability does, and its answer lands * as a `tool_result`, which the model already treats as data returned by * something rather than as direction. */ /** * Marks where a remote party's words begin and end. * * A prompt is composed by a SERVER. Untrusted content arriving this way is * the standard prompt-injection surface, and an unlabelled block reads * exactly like the agent's own instructions — so this says whose words * they are. * * Marking, not stopping. See `tools/untrusted-envelope.ts` for the * measurement: delimiting reports near-zero attack success on a static * benchmark and above 95% once the attacker adapts (arXiv:2510.09023). * This paragraph used to call it "the mitigation that survives contact", * which was the same overstatement in a second file. */ export declare function renderPromptMessages(serverName: string, promptName: string, messages: readonly MCPPromptMessage[], description?: string): string; export declare function mcpPromptToToolDefinition(prompt: MCPPromptDefinition, client: MCPClient, serverName: string): ToolDefinition; //# sourceMappingURL=prompt-adapter.d.ts.map