/** * The token contract, as ONE source of truth. * * Required token names are derived from this object's keys, so the template, * the substitution map and the validator cannot drift apart — the previous * shape kept a separate array that could silently disagree (PR #2331 review). */ export interface SkillTokenValues { nodeVersion: string; baseUrl: string; peerId: string; nodeRole: string; extractionPipelines: string; } /** * Static text for the STANDALONE copy, which has no node to describe. Prose * rather than an internal placeholder: a reader of a delivered skill file * should get an instruction, not a broken-looking template artifact. */ export declare const STANDALONE_SKILL_VALUES: SkillTokenValues; export declare const REQUIRED_SKILL_TOKENS: ReadonlyArray; export declare function loadSkillTemplate(): string; /** Required tokens the template is missing. */ export declare function missingSkillTokens(template?: string): string[]; /** * Tokens the template uses that nothing supplies. Without this, adding * `{{networkId}}` to SKILL.md would render it verbatim into the served doc and * `missingSkillTokens()` would still report a clean bill of health. */ export declare function unknownSkillTokens(template?: string): string[]; /** * Substitute every token in ONE pass. * * Two distinct hazards, both reachable from the `X-Forwarded-Host` / `Host` * headers because `/.well-known/skill.md` is public and unauthenticated: * * 1. `$` EXPANSION. `String.replace(needle, replacementString)` interprets * `$&`, `$'`, "$`" and `$n` in the REPLACEMENT. A crafted Host could * re-insert the placeholder block or append the ~94 KB template suffix per * `$'`. The replacement is a FUNCTION, which makes the value literal. * * 2. TOKEN RE-ENTRY. Substituting one token at a time rescans the growing * OUTPUT on later iterations, so a value could itself invoke the template * language: `baseUrl: "http://{{peerId}}"` rendered the real peer ID into * the advertised API URL, and `http://{{nodeVersion}}` left raw token * syntax because that key had already been processed (PR #2331 review). * One pass over the ORIGINAL template closes this — a callback resolves * each match against `values` and its result is never re-examined. * * Neither property is incidental. Do not reintroduce a per-token loop, and do * not turn the callback back into a string. */ export declare function renderSkillTemplate(values: SkillTokenValues, template?: string): string; /** SERVED mode — live node state, for `/.well-known/skill.md`. */ export declare function buildSkillMd(opts: { version: string; baseUrl: string; peerId: string; nodeRole: string; extractionPipelines: string[]; }): string; /** * DELIVERED mode — the standalone artifact copied into a client's skill * directory. Every caller that used to read the bundled file directly must go * through this, or it ships raw `{{token}}` syntax to end users. */ export declare function renderStandaloneDkgNodeSkill(): string; export declare function skillEtag(content: string): string; //# sourceMappingURL=skill-template.d.ts.map