import { type ExtractedTool } from "../../actions/index.js"; /** * ALL prompt content for the judgment channel lives HERE — the judge pass and * the skeptic pass, and nothing else in the module composes model-facing text. * * The judge rules are the enrichment rules carried over with exactly three * changes, each one a consequence of the judgment layer replacing the * restrictive-only clamp: * * 1. risk may move in BOTH directions. Under the clamp a downgrade was refused * and forgotten, so a model that correctly noticed a read-only handler graded * destructive had no way to say so. It may now say so; the direction rule * routes the claim to a human instead of discarding it. * 2. a wake-up (`disabled: false`) may be PROPOSED for a scanner-disabled tool. * Same reasoning: fail-closed extraction disables what it cannot classify, * and a model reading the handler is exactly the right thing to notice that * the tool is a plain authenticated read. * 3. every proposal REQUIRES `evidence` — a verbatim quoted snippet from the * handler. A grade with no evidence is an opinion, and opinions do not move * capability. The skeptic pass then checks the quote against the real source, * which is what makes the requirement bite rather than decorate. * * Nothing here is trusted. The rules tell the model what may land; the * deterministic direction rule in `@vendoai/vendo/actions` decides what actually does. * * The risk section also carries three LABELING-POLICY rules the mutation test * cannot derive on its own. Each one is here because a corpus row had to be * parked without it (PR #684): a catch-all URL is graded at its worst operation * because per-method reachability lives inside the dependency; `destructive` * needs bulk or irreversible loss, so a single re-creatable row delete is a * `write`; and an unrecallable outbound effect (mail sent, payment captured) is * a `write` with no row written. They are conventions, not derivations — a model * cannot guess them, so they have to be stated. */ export declare const JUDGE_OUTPUT_RULES: string; /** The per-tool projection the model reasons over: judgment fields only, never * the machine skeleton. Schemas stay on disk where the model can read them if * it needs to — putting them in the prompt only invites restatement. */ export declare function judgmentFacts(tools: ExtractedTool[]): string; export interface JudgeChunkInput { appName: string; /** The chunk's candidates, each already carrying its standing judgment (the * EFFECTIVE state — otherwise the model re-proposes what already holds). */ tools: ExtractedTool[]; /** Tool names with HUMAN overrides — read-only context. */ overrideNames: string[]; chunk: { index: number; total: number; }; /** The last chunk carries the coverage question. */ last: boolean; } export declare function composeJudgeInstructions(input: JudgeChunkInput): string; /** One proposal put in front of the skeptic: the tool as it stands, the moves * proposed on it, and the evidence those moves rest on. */ export interface SkepticSubject { tool: ExtractedTool; moves: Array<{ field: string; from: unknown; to: unknown; }>; evidence: string; reason?: string; } export declare function composeSkepticInstructions(input: { appName: string; subjects: SkepticSubject[]; /** The single re-ask covering whatever the first look left unexamined. */ reask?: boolean; }): string;