import { type RiskLabel, type RunContext, type ToolCall, type ToolOutcome, type ToolRegistry } from "../../core/index.js"; import type { CompoundTool } from "../formats.js"; /** What a compound step may target: a registered primitive host/connector tool. */ export interface PrimitiveStepTarget { risk: RiskLabel; disabled?: boolean; } export interface CapabilityIssue { tool: string; message: string; } /** * Semantic validation shared by the load path (registry quarantine) and any * compound-authoring write path (originally ENG-250): steps must reference * enabled primitive host/connector tools only, and the declared risk must * equal the max of the step risks — both computed POST-override-merge by the * caller. * * `primitives` maps tool name → post-merge risk/disabled for host + connector * tools ONLY (never compounds, never `add()`-registry capability tools). */ export declare function validateCapabilities(file: { tools: CompoundTool[]; }, primitives: ReadonlyMap): CapabilityIssue[]; export interface CompoundExecutor { execute(tool: CompoundTool, call: ToolCall, ctx: RunContext): Promise; } /** * One executor per createActions closure (never module-global: resume state is * scoped to a registry instance). Resume state is in-memory and single-process * — the stated v0 durability model (same assumption as guard's AsyncLock): a * restart re-walks the compound from step 0 on re-execution. */ export declare function createCompoundExecutor(options: { /** The live RegistryConfig slice — `invokeTool` is read at EXECUTION time so the umbrella can wire it after `guard.bind`. */ config: { invokeTool?: ToolRegistry["execute"]; }; /** Defense in depth: re-checks against the CURRENT load that a step target is still a primitive host/connector tool. */ isPrimitive(name: string): Promise; }): CompoundExecutor;