import { type Json, type RunContext, type ToolRegistry } from "./core/index.js"; /** * Design §4's vendo-verb family, projected as ordinary tools on the one * registry — so the guard, the audit trail, and `find_tools` treat them exactly * like a host tool. There is no privileged side door. * * `records_list/put/delete` are deliberately NOT here: an app's own data has * ONE door, `vendo_apps_sql` (packages/vendo/src/apps/doors/sql-tool.ts), and a * second spelling of it would be a second place for the mine./shared. fence to * be got wrong. */ export declare const VENDO_VERB_TOOLS: readonly ["validate", "schedule"]; export interface VendoVerbFinding { severity: "block" | "warn"; where?: string; message: string; } export interface VendoVerbPorts { /** Check a stored app against our catalog and the host's schemas. Returns * findings; it does not throw on a bad screen. * * `request` is the PERSON's ask, verbatim, from whichever gate is standing at * the end of a finished screen (`screen-agent.ts`'s `judgeScreen`). Half the * reviewer's rubric — a section nobody asked for, work quietly dropped — is * written against it and could not be applied without it. Absent is what every * caller that has no ask to hand over passes, and it reads exactly as it always * did: no ask, no carve-out. * * `viewport` is the surface the screen renders into, in CSS pixels, from the * same gate — the fact the writer was given and the reviewer was not. With it * the reviewer is shown the screen's first paint framed by those pixels, so * content below the fold or behind a later step stops reading like content on * screen. Absent, the reviewer's prompt is unchanged. * * `ctx` is the CALLER's, handed down from `execute` — never assembled by the * port and never taken from the model's input. Both of the app-touching verbs * are owner-scoped behind it, so a model naming someone else's appId gets a * not-found rather than a look at their app. */ validate(input: { appId?: string; request?: string; viewport?: { width: number; height: number; }; }, ctx: RunContext): Promise<{ ok: boolean; findings: VendoVerbFinding[]; }>; /** Arm or change an app's schedule. Owner-scoped through `ctx`. */ schedule(input: { appId: string; cron: string; }, ctx: RunContext): Promise; } /** Every verb is a read or a non-destructive write, so none is withheld from an * unattended run — automations legitimately validate and schedule. The law * filters destructive and external work, which this family has none of. */ export declare function vendoVerbsRegistry(ports: VendoVerbPorts): ToolRegistry;