import { Media } from "../../common"; import type { DispatchContext } from "../../types"; import type { RetrievableTrustTier } from "../../common"; import type { MediaTrustTier } from "../../common"; /** The skill trust tiers the battery threads through, shared by scripts and typed output. */ export type SkillTrustTier = 'first-party' | 'third-party-public' | 'third-party-private'; /** * The output kind a descriptor may DECLARE for a tool. When present, a runtime shape that disagrees * is a detectable failure rather than a silent reinterpretation; when absent, the wrapper sniffs. */ export type SkillOutputKind = 'text' | 'binary' | 'media' | 'retrievable'; /** Bytes-with-a-content-type: the framework-agnostic path to typed binary. */ export interface SkillBinaryOutput { /** The raw bytes. The host wraps them in a reader via `ctx.storeMediaBytes`. */ readonly bytes: Uint8Array; /** MIME type of the bytes; the `MediaKind` and modality hazard are inferred from it. */ readonly mimeType: string; /** Optional filename; a stable default derived from the tool name is used when omitted. */ readonly filename?: string; } /** A framework-agnostic retrievable descriptor. `content` is plain text; the host spools it. */ export interface SkillRetrievableOutput { /** The retrievable to construct. Its text is spooled behind a handle and its tier is floored. */ readonly retrievable: { /** Plain text the model can cite, search, and hold a handle to. */ readonly content: string; /** Optional provenance string (URL, document path, knowledge-base id). */ readonly source?: string; /** Optional semantic label (e.g. `'reference'`, `'policy'`); defaults to `'skill-tool'`. */ readonly kind?: string; /** Optional relevance score in `[0, 1]`. */ readonly score?: number; /** Render inline rather than as a handle; defaults to `false`. */ readonly inline?: boolean; }; } /** * Floor a skill's trust tier onto its output, shared with tier-3 scripts: `first-party` becomes * `third-party-private`; both third-party tiers pass through. Program output from a first-party * skill is still program output, never deployer-authored prose, so it never gets the first-party * envelope. */ export declare const floorOutputTier: (tier: SkillTrustTier | undefined) => MediaTrustTier & RetrievableTrustTier; /** * Validate a raw skill-tool return and resolve it to a core-legal tool result, constructing typed * primitives from framework-agnostic descriptors host-side. `declared`, when the descriptor set it, * is enforced: a runtime shape that disagrees fails rather than being silently reinterpreted. */ export declare const resolveSkillToolOutput: (o: { raw: unknown; ctx: DispatchContext; toolName: string; trustTier: SkillTrustTier | undefined; declared?: SkillOutputKind; }) => Promise;