import { Tool } from "../../common"; import { type ToolGateFn } from "../tools/_shared/index"; import type { SkillRecord } from "./manager"; import type { SandboxPolicy } from "../sandbox/types"; import type { SkillScriptConfig, SkillWorkspace } from "./types"; import type { SkillScriptSpec } from "./contracts"; /** Validate a value before putting it in argv. Values are never shell-interpolated. */ export declare const assertArgvValue: (value: unknown, name: string) => string; /** Validate and normalise a source-owned filename. Leading separators are rejected first. */ export declare const validateSkillSourcePath: (value: string) => string; /** * Check the battery's path-aware policy subset relation. This is intentionally conservative: * globs supplied by a per-call policy are undecidable and fail closed. */ export declare const assertPolicySubset: (perCall: SandboxPolicy, session: SandboxPolicy) => void; /** Validate a declaration, including the provider-safe generated tool name. */ export declare const validateSkillScript: (skillId: string, spec: SkillScriptSpec) => string; /** Forge one fixed-schema script tool. The record liveness check is synchronous and precedes all awaits. */ export declare const forgeSkillScriptTool: (o: { skill: { readonly id: string; readonly version: string; readonly trustTier?: "first-party" | "third-party-public" | "third-party-private"; }; record: SkillRecord; spec: SkillScriptSpec; config: SkillScriptConfig; sessionPolicy: SandboxPolicy; gate?: ToolGateFn; materializedRoot: string; }) => Tool; /** Materialise a source file list after validating every source-owned path. */ export declare const validateMaterializedPaths: (paths: readonly string[]) => readonly string[]; /** Keep the workspace type visible to consumers implementing the materialisation seam. */ export type { SkillWorkspace };