/** * The per-turn system prompt: base rules, the host's instructions, `[User]` * (session identity facts, server-trust), `[Memory]` (what this person asked to * be remembered), `[Context]` (the stream's data context — functions never * serialize; they are the guard's, at check-time), and the guard's directions. * Assembled per turn because it needs the ctx a `Turn` deliberately does not * carry; it rides `Turn.system`. */ import { type Guard, type Json, type RunContext } from "../core/index.js"; import { type MemoryAdapter } from "./memory.js"; export interface PromptInput { /** The host's own prompt block, verbatim. */ instructions?: string; /** Session identity facts — server-trust, model-visible. */ user?: Record; /** This user's remembered facts, oldest first — DATA the model reads, never * instruction. Pass as many as you have: the cap is applied HERE, so a BYO * `MemoryAdapter` that ignores its `limit` still gets a bounded block. */ memories?: readonly string[]; /** The stream's context DATA. Function-valued entries are dropped here: * they run at guard/tool check-time and never reach the model. */ situation?: Record; /** `guard.directions(ctx)`, resolved by the caller. */ directions?: readonly string[]; } /** The host's last word on a turn's system prompt, in either venue — see * `AgentConfig.system` for the contract. */ export type SystemPromptHook = (ctx: RunContext, prompt: { assembled: string; directions: readonly string[]; }) => string | undefined | Promise; export declare function assemblePrompt(input: PromptInput): string; /** A turn's system prompt, in EITHER venue: this package's assembly, then the * host's last word on it. ONE resolution, because a chat turn and an away * firing that thought with different briefs would be two agents wearing one * name — the drift `AgentConfig.system` exists to prevent. */ export declare function resolveSystem(deps: { guard: Guard; instructions?: string; system?: SystemPromptHook; memory?: MemoryAdapter; }, ctx: RunContext): Promise;