import { g as TraceReadResult, h as TraceReadWarning } from './index-xUbdpcrP.js'; import { a as InspectRunTree, e as InspectNode, A as AttributionConfidence } from './inspect-event-ClM5Z8om.js'; import { P as PersistedInspectEvent } from './persisted-inspect-event-DG02LhEP.js'; import { a as ObservedOutcomeStatus } from './types-BA_IOdg4.js'; import { j as TraceMetadataStatus } from './types-BX1EPji1.js'; /** Known session/workflow metadata keys (v2.4 RFC). */ declare const SESSION_WORKFLOW_KEYS: readonly ["sessionId", "conversationId", "groupId", "parentGroupId", "attempt", "retryOf", "retryReason", "handoffFrom", "handoffTo", "subAgentId", "subAgentName", "jobId", "queueName", "workflowName", "workflowStep", "toolCallId", "mcpToolCallId", "linkedStepId", "operationId", "attemptId", "attemptNumber", "fallbackOf", "idempotencyKey", "correlationId", "requestId", "decisionId"]; type SessionWorkflowKey = (typeof SESSION_WORKFLOW_KEYS)[number]; type SessionConfidence = "explicit" | "correlated" | "heuristic" | "unknown"; type SessionEdgeSource = "manual" | "adapter" | "json-log" | "log4js" | "mcp-client" | "inferred"; interface SessionWorkflowMetadata { sessionId?: string; conversationId?: string; groupId?: string; parentGroupId?: string; attempt?: number; retryOf?: string; retryReason?: string; handoffFrom?: string; handoffTo?: string; subAgentId?: string; subAgentName?: string; jobId?: string; queueName?: string; workflowName?: string; workflowStep?: string; toolCallId?: string; mcpToolCallId?: string; linkedStepId?: string; operationId?: string; attemptId?: string; attemptNumber?: number; fallbackOf?: string; idempotencyKey?: string; correlationId?: string; requestId?: string; decisionId?: string; } interface SessionRunRecord { runId: string; name?: string; status?: TraceMetadataStatus; startedAt?: number; endedAt?: number; durationMs?: number; filePath?: string; metadata?: Record; } interface SessionWarning { code: string; message: string; runId?: string; sessionId?: string; } interface HandoffEdge { from: string; to: string; source: SessionEdgeSource; confidence: SessionConfidence; } interface RetryLink { runId: string; retryOf?: string; attempt?: number; source: SessionEdgeSource; confidence: SessionConfidence; } interface SessionGroup { groupId: string; parentGroupId?: string; runIds: string[]; } interface CriticalPathStep { runId: string; name?: string; startedAt?: number; durationMs?: number; source: SessionEdgeSource; confidence: SessionConfidence; } /** Session lifecycle status (v4.2 RFC). */ type SessionStatus = "running" | "waiting_input" | "idle" | "completed" | "error" | "stale" | "unknown"; interface SessionLastError { runId: string; message: string; code?: string; } interface SessionCheckSummary { pass: number; fail: number; warn: number; } interface EnrichSessionSummaryOptions { /** Reference clock for staleness (default Date.now()). */ nowMs?: number; /** Inactivity threshold before marking a session stale (default 24h). */ staleThresholdMs?: number; } interface ActivityEntry { sessionId: string; status: SessionStatus; summary: string; lastActivity: string; runCount: number; } interface ActivitySummary { since: string; sessions: number; failed: number; stale: number; guardrailWarnings: number; entries: ActivityEntry[]; } interface BuildActivitySummaryOptions { /** Duration window (e.g. 7d, 24h). Default 7d. */ since?: string; /** Reference clock (default Date.now()). */ nowMs?: number; /** Max entries returned (default 20). */ limit?: number; } interface SessionSummary { sessionId: string; runIds: string[]; groups: SessionGroup[]; handoffs: HandoffEdge[]; retries: RetryLink[]; criticalPath: CriticalPathStep[]; /** Derived session status (v4.2+). */ status: SessionStatus; /** Earliest run start time in the session. */ startedAt?: number; /** Latest run end time when all runs have ended. */ endedAt?: number; /** endedAt - startedAt when both are present. */ durationMs?: number; correlationId?: string; jobId?: string; workflowId?: string; lastError?: SessionLastError; /** ISO-8601 timestamp of the most recent run activity. */ lastActivity: string; retryCount: number; observationSummary?: string; checkSummary?: SessionCheckSummary; } interface SessionIndex { runs: SessionRunRecord[]; sessions: SessionSummary[]; unscopedRunIds: string[]; warnings: SessionWarning[]; } interface BuildSessionIndexOptions { /** When true, group runs that share only `groupId` under a synthetic session key. */ correlateByGroupId?: boolean; /** Reference clock for session staleness (v4.2+). */ nowMs?: number; /** Inactivity threshold before marking a session stale (v4.2+, default 24h). */ staleThresholdMs?: number; } /** * Logical lifecycle projection for trace checks. * * Projects raw persisted rows (including v0.1 start/complete bridges) into * completed lifecycle events for semantic/structure rules. Does not mutate * input; does not replace public experimental `events` (raw rows). * * @experimental Available through `agent-inspect/checks`; may evolve. */ /** * Diagnostic emitted while projecting logical lifecycle events. * * @experimental */ interface LogicalProjectionDiagnostic { code: "AI_LOGICAL_PAIR_AMBIGUOUS" | "AI_LOGICAL_PAIR_UNMATCHED_START" | "AI_LOGICAL_PAIR_UNMATCHED_COMPLETE" | "AI_LOGICAL_PARENT_REMAPPED" | "AI_LOGICAL_PARENT_UNRESOLVED" | "AI_LOGICAL_SELF_PARENT_REMOVED"; message: string; eventIds?: readonly string[]; } /** * A persisted event after lifecycle pairing and parent normalization. * Compatible with rule helpers that read PersistedInspectEvent fields. * * @experimental */ type LogicalTraceEvent = PersistedInspectEvent & { /** Raw event ids merged into this logical row (start first when paired). */ readonly sourceEventIds: readonly string[]; readonly projection: { readonly paired: boolean; readonly absorbedEventIds: readonly string[]; readonly parentNormalized: boolean; readonly originalParentId?: string; }; }; interface ProjectLogicalEventsResult { readonly logicalEvents: readonly LogicalTraceEvent[]; readonly diagnostics: readonly LogicalProjectionDiagnostic[]; } /** * Pair v0.1 run/step start+complete rows and normalize parent references. * * - Keeps start kind/name; applies terminal status/timing/error from complete. * - Absorbs matching complete rows (not emitted as separate logical events). * - Remaps parentId from stepId or absorbed complete eventId → logical eventId. */ declare function projectLogicalEvents(events: readonly PersistedInspectEvent[]): ProjectLogicalEventsResult; /** * Resolve a human-meaningful tool name from a (logical or raw) event. * Precedence: toolName → tool → metadata.toolName → metadata.tool → name prefixes. * * @experimental */ declare function resolveCanonicalToolName(event: PersistedInspectEvent): string; /** * Explicit actor/run projection for TraceContract evaluation (#320). * * Selectors use only declared metadata (or explicit event ids). Zero matches * and singular-actor ambiguity fail closed. No timestamp or display-name * inference. * * @experimental */ interface TraceContractScope { runId?: string; subAgentId?: string; groupId?: string; workflowStep?: string; /** Explicit root event id; evaluation projects to that event and descendants. */ rootEventId?: string; } interface ResolvedContractScope { runId: string; rootEventId?: string; matchedSelectors: Record; evidenceEventCount: number; input: TraceCheckInput; } /** * Collect explicit session/workflow metadata for a run from persisted events. * Prefers RUN-kind attributes; never invents identity from timestamps. */ declare function workflowMetadataForRun(events: readonly PersistedInspectEvent[], runId: string): SessionWorkflowMetadata; /** * Resolve TraceContract `scope` against a check input. * Returns diagnostics on zero/ambiguous matches or missing root events. */ declare function resolveTraceContractScope(input: TraceCheckInput, scope: TraceContractScope | undefined): { resolved?: ResolvedContractScope; diagnostics: TraceCheckDiagnostic[]; }; /** * Declared-versus-enforced control checks for TraceContract (6.23). * * A stored declaration is not proof of enforcement. * * @experimental */ type ControlStage = "declared" | "presented" | "validated" | "enforced" | "observed" | "accepted"; interface TraceContractControlRules { /** * Tools declared/presented to the agent (inline). Distinct from `enforcedTools`. */ declaredTools?: string[]; /** * Tools the harness claims to enforce (inline allowlist). */ enforcedTools?: string[]; /** * RUN/event attribute holding a string[] of declared tool names. * Used when `declaredTools` is omitted. */ declaredToolsAttribute?: string; /** * RUN/event attribute holding a string[] of enforced tool names. */ enforcedToolsAttribute?: string; /** * Fail when both declared and enforced sets resolve and differ. */ requireDeclaredMatchesEnforced?: boolean; /** * Fail when any observed finished tool is outside the enforced set. */ requireObservedWithinEnforced?: boolean; /** * Fail when any observed finished tool is outside the declared set. */ requireObservedWithinDeclared?: boolean; /** * Require observation names for control stages (default `control.`). */ requiredStages?: Array<{ stage: ControlStage; /** Observation name; defaults to `control.`. */ observation?: string; }>; } /** * Bounded safe recovery operation contracts (6.27). * * Additive `retry.operations[]` rules for read-first recovery oracles. * AgentInspect evaluates traces; it does not perform retries. * * @experimental */ /** How same-argument evidence may be compared across attempts. */ type RecoverySameArgumentsMode = "structured-or-digest"; /** * Side-effect class for conservative write recovery semantics. * Read-only tools may recover without write idempotency proof. * Write tools treat timeout/unknown completion as fail/unevaluable * unless authoritative idempotency evidence is present. */ type RecoverySideEffectClass = "read" | "write"; interface TraceContractRecoveryRetryableErrors { /** Allowed error codes on failed attempts that precede a retry. */ codes?: readonly string[]; } interface TraceContractRecoverySuccessfulResultDependency { /** Consumer kind that must observe the successful tool result. */ consumerKind: "LLM"; /** * When true, an LLM event must explicitly reference the successful tool * event id (attributes / workflow metadata), not merely follow it in time. */ requireExplicitReference?: boolean; } /** * Per-tool bounded recovery oracle (additive under `retry.operations`). * * @experimental Additive in 6.27. */ interface TraceContractRecoveryOperation { tool: string; maxAttempts?: number; retryableErrors?: TraceContractRecoveryRetryableErrors; requireFailureBeforeRetry?: boolean; /** * When true or `"structured-or-digest"`, retries must share structured * arguments or matching digests. Missing evidence fails closed. */ requireSameArguments?: boolean | RecoverySameArgumentsMode; requireTerminalSuccess?: boolean; requireRecoveredFailureVisible?: boolean; successfulResultDependency?: TraceContractRecoverySuccessfulResultDependency; /** * Defaults to `"read"`. Write tools apply conservative timeout/unknown rules. */ sideEffectClass?: RecoverySideEffectClass; } /** * Retry / side-effect safety checks for TraceContract (6.23+; corrected in 6.25.1). * * Uses explicit attempt identity from session workflow metadata. * AgentInspect evaluates; it does not perform retries. * * @experimental */ interface TraceContractRetryRules { /** * Maximum attempts per `operationId` (or `attemptOf` grouping). * Prefers distinct `attemptId` values, else validated contiguous `attemptNumber`s, * else finished tool/LLM events in the operation. */ maxAttempts?: number; /** * When true, every operation with attempts must include a non-running terminal event. */ requireTerminalResult?: boolean; /** * Fail when `fallbackOf` is set without an earlier failure for the referenced operation * that chronologically precedes the fallback event. */ fallbackOnlyAfterFailure?: boolean; /** * Tool names treated as non-idempotent. A later attempt after an `ok` occurrence fails * unless idempotency / no-side-effect evidence is present on the retry. */ nonIdempotentTools?: string[]; /** * When true, genuine retries (including error→success) require `idempotencyKey` * or `attributes.noSideEffect === true` / `sideEffect === false`. * A client key alone is not proof of exactly-once mutation. */ requireIdempotencyEvidenceForRetry?: boolean; /** * When true, recovered success paths must retain an earlier error attempt in the * same operation/retry chain (not merely coexistence of ok+error). */ requireRecoveredFailureVisible?: boolean; /** * Per-tool bounded recovery oracles (read-first; write timeout/unknown fails closed). * * @experimental Additive in 6.27. */ operations?: readonly TraceContractRecoveryOperation[]; } /** * Resolve an RFC 6901 JSON Pointer against a JSON-like value. * Returns `{ found: false }` when the path does not exist. */ declare function resolveJsonPointer(document: unknown, pointer: string): { found: true; value: unknown; } | { found: false; }; type ToolArgumentOperator = "exists" | "type" | "equals" | "oneOf"; type ToolArgumentOccurrence = "first" | "last" | "any" | "all"; interface ToolArgumentCheck { tool: string; path: string; operator: ToolArgumentOperator; occurrence?: ToolArgumentOccurrence; /** Required for `equals`. */ expected?: unknown; /** Required for `oneOf`. */ oneOf?: readonly unknown[]; /** Required for `type` (`string` | `number` | `boolean` | `object` | `array` | `null`). */ type?: "string" | "number" | "boolean" | "object" | "array" | "null"; } type ToolArgumentEval = { status: "pass"; } | { status: "fail"; message: string; code: string; } | { status: "unavailable"; message: string; code: "AI_CHECK_TOOL_ARGUMENT_EVIDENCE_UNAVAILABLE"; }; /** * Extract structured tool-argument evidence from a tool event. * * Precedence (first structured object/array wins): * 1. top-level `attributes.arguments` / `input` / `toolArguments` * 2. nested `attributes.metadata.arguments` / `input` / `toolArguments` * (manual instrumentation stores caller metadata here) * 3. `inputSummary` when it is already a structured object/array * * Preview strings and digests do not count as structured evidence. * This does not enable default raw argument capture. */ declare function extractToolArgumentPayload(event: { attributes?: Record; inputSummary?: unknown; }): { present: boolean; value: unknown; }; declare function evaluateToolArgumentValue(value: unknown, check: ToolArgumentCheck, evidencePresent: boolean): ToolArgumentEval; /** * @experimental Typed trace contract input. Evolves during v6.5.x. */ interface TraceContractRunRules { requireCompleted?: boolean; allowedStatuses?: string[]; maxDurationMs?: number; } interface TraceContractToolRules { /** * Unconditional tool presence invariant. Every named tool must appear at least * once. Do not use for cache-hit or alternate-path shortcuts — prefer * `alternatives.anyOf` or `observations.required` when a legitimate path may * skip the tool. * * @see docs/TRACE-CONTRACTS.md */ required?: string[]; /** Alias of `required` (TraceContract v2 normalization). */ requiredTools?: string[]; forbidden?: string[]; /** Alias of `forbidden`. */ forbiddenTools?: string[]; allowed?: string[]; maxCalls?: number; /** * Required tool order expanded into adjacent pairs. * * `[A, B, C]` expands to “A before B” and “B before C”, each comparing the * selected `requiredOrderMode` to every pair. Unlisted intermediate tools * are allowed. * * TraceContract `requiredOrder` **implies presence**: every listed name is * added to the effective required-tool set. Low-level `createToolOrderingRule` * alone may still pass vacuously when an endpoint is missing. * * The default `first-occurrence` mode preserves first-occurrence encounter * ordering; overlapping intervals emit a non-failing warning. `happens-before` * requires the first before event to finish before the first after event starts. * `all-occurrences` applies that causal boundary to every occurrence. * * @see docs/TRACE-CONTRACTS.md * @beta Available through `agent-inspect/checks`. Additive changes may ship * in minor releases; breaking changes require a future major. */ requiredOrder?: string[]; /** * Ordering semantics applied to every adjacent pair in `requiredOrder`. * Causal modes fail closed when a required interval boundary is unavailable. * * @defaultValue `"first-occurrence"` * @beta Available through `agent-inspect/checks`. */ requiredOrderMode?: "first-occurrence" | "happens-before" | "all-occurrences"; /** * Bounded structured tool-argument checks (JSON Pointer + limited operators). * * Missing structured evidence fails closed as unevaluable (not pass). * Findings never embed full actual inputs. * * @experimental Additive in 6.23. */ arguments?: ToolArgumentCheck[]; /** * Default occurrence mode for `orderRules` when a rule omits `occurrenceMode`. * * @experimental Additive in 6.23. */ defaultOccurrenceMode?: "first-occurrence" | "happens-before" | "all-occurrences"; /** * Mixed per-pair ordering rules (additive alongside `requiredOrder`). * * @experimental Additive in 6.23. */ orderRules?: Array<{ before: string; after: string; occurrenceMode?: "first-occurrence" | "happens-before" | "all-occurrences"; requireEndpoints?: boolean; }>; } interface TraceContractLlmRules { maxCalls?: number; maxTotalTokens?: number; allowedModels?: string[]; } /** * Explicit TOOL or LLM step endpoint for typed cross-kind ordering. * * @experimental Additive in 6.31. */ type TraceContractStepKind = "TOOL" | "LLM"; /** * Named step endpoint with an explicit event kind. * * @experimental Additive in 6.31. */ interface TraceContractStepRef { kind: TraceContractStepKind; name: string; } /** * One typed before/after ordering relation across TOOL and/or LLM steps. * * Unlike `tools.requiredOrder` / `orderRules`, endpoints are kind-qualified so * an LLM named `generate_answer` does not satisfy a TOOL endpoint (and vice versa). * * @experimental Additive in 6.31. */ interface TraceContractStepOrderRelation { before: TraceContractStepRef; after: TraceContractStepRef; /** * Ordering semantics for this pair. * * @defaultValue `"first-occurrence"` */ mode?: "first-occurrence" | "happens-before" | "all-occurrences"; /** * When true (default), missing endpoints of the declared kind fail. * Wrong-kind same-name events do not satisfy the endpoint. * * @defaultValue `true` */ requireEndpoints?: boolean; } /** * Cross-kind step ordering (TOOL ↔ LLM). Does not change TOOL-only * `tools.requiredOrder` / `orderRules` semantics. * * @experimental Additive in 6.31. */ interface TraceContractStepRules { orderRelations?: TraceContractStepOrderRelation[]; } /** * Structural provenance requirements for named observed outcomes (#321). * * These checks prove method/evidence linkage was recorded. They do **not** * prove the claim is semantically true, authorized, complete, or externally * trusted. * * @experimental */ interface TraceContractObservationProvenance { /** Require a non-empty method from the bounded ObservedOutcomeMethod vocabulary. */ method?: boolean; /** * Require bounded evidence references. Supported shapes: * `string` event id, `{ eventId }`, or `{ eventIds: string[] }` (max 16 ids). */ evidence?: boolean; /** When true with evidence, each referenced event id must exist in the same run. */ sameRunEventReference?: boolean; } interface TraceContractObservationRules { required?: string[]; failOn?: Array<"failed" | "unknown" | "skipped">; /** * Structural provenance gates for `required` observation names. * * @experimental */ requireProvenance?: TraceContractObservationProvenance; } /** * One deterministic alternate path. Branch contracts are one level only — * nested `alternatives` are rejected. * * @experimental */ interface TraceContractAlternativeBranch { /** Unique branch id within `alternatives.anyOf`. */ id: string; description?: string; /** Branch body: run/tools/llm/observations only (no nested alternatives). */ contract: TraceContractBody; } /** * Bounded alternative valid paths for legitimate shortcuts (GitHub #309). * * @experimental */ interface TraceContractAlternatives { /** * One level of named branches. The overall contract passes when the base * rules pass and **at least one** complete branch passes. */ anyOf: TraceContractAlternativeBranch[]; } /** Contract body without alternatives (base or branch). */ type TraceContractBody = { run?: TraceContractRunRules; tools?: TraceContractToolRules; llm?: TraceContractLlmRules; /** * Typed cross-kind step ordering (TOOL / LLM endpoints). * * @experimental Additive in 6.31. */ steps?: TraceContractStepRules; observations?: TraceContractObservationRules; /** * Declared-versus-enforced control invariants. * * @experimental Additive in 6.23. */ controls?: TraceContractControlRules; /** * Retry / side-effect safety using explicit attempt identity. * Additive `retry.operations[]` recovery oracles land in 6.27. * * @experimental Additive in 6.23; operations in 6.27. */ retry?: TraceContractRetryRules; }; interface TraceContractInput extends TraceContractBody { /** * Optional actor/run projection applied before evaluation (#320). * * @experimental */ scope?: TraceContractScope; alternatives?: TraceContractAlternatives; } interface TraceContract extends TraceContractBody { /** * Optional actor/run projection applied before evaluation (#320). * * @experimental */ scope?: TraceContractScope; alternatives?: TraceContractAlternatives; } /** * Lint diagnostic for brittle or invalid TraceContract shapes. * * @experimental */ interface TraceContractLintDiagnostic { code: string; severity: "error" | "warning" | "info"; message: string; path?: string; } /** * Define a normalized trace contract object. * * @experimental */ declare function defineTraceContract(input: TraceContractInput): TraceContract; /** * Evaluate a trace contract against an opened trace read result. * * Base rules always apply. When `alternatives.anyOf` is present, at least one * complete branch must also pass. * * @experimental */ declare function evaluateTraceContract(input: TraceCheckInput, contract: TraceContract, options?: { runId?: string; }): TraceCheckResult; /** * Convenience: evaluate a contract against a TraceReadResult directly. * * @experimental Additive wrapper over `evaluateTraceContract({ read }, …)`. */ declare function evaluateTraceContractRead(read: TraceReadResult, contract: TraceContract, options?: { runId?: string; }): TraceCheckResult; /** * Lint a TraceContract for invalid or brittle shapes (does not evaluate a trace). * * @experimental */ declare function lintTraceContract(contract: TraceContract): TraceContractLintDiagnostic[]; /** * Explain a TraceContract as short human-readable lines (does not evaluate a trace). * * @experimental */ declare function explainTraceContract(contract: TraceContract): string[]; /** * Experimental trace-check finding severity. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ type TraceCheckSeverity = "error" | "warning" | "info"; /** * Experimental trace-check rule category. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ type TraceCheckRuleCategory = "run" | "tool" | "llm" | "structure" | "baseline" | "safety" | "reader"; /** * Experimental safety finding taxonomy (additive on `TraceCheckFinding`). * * Distinct from `TraceCheckRuleCategory` (which classifies rules, not findings). * * @experimental Available through `agent-inspect/checks`; see `docs/SAFETY-POLICY.md`. */ type SafetyFindingCategory = "credential" | "personal-data" | "identifier" | "raw-content" | "path" | "size" | "structure"; /** * Experimental detector confidence for safety findings. * * @experimental Available through `agent-inspect/checks`; see `docs/SAFETY-POLICY.md`. */ type SafetyFindingConfidence = "high" | "medium" | "low"; /** * Experimental trace-check finding status. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ type TraceCheckFindingStatus = "pass" | "fail" | "warning"; /** * Experimental trace-check aggregate status. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ type TraceCheckStatus = "pass" | "fail" | "error"; /** * Experimental stable diagnostic code for check execution and input errors. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ type TraceCheckDiagnosticCode = "AI_CHECK_INVALID_ARGUMENTS" | "AI_CHECK_INVALID_CONFIG" | "AI_CHECK_CONFIG_LOAD_FAILED" | "AI_CHECK_CONFIG_UNKNOWN_KEY" | "AI_CHECK_CONFIG_INVALID_VALUE" | "AI_CHECK_CONFIG_NO_EFFECTIVE_RULES" | "AI_CHECK_NO_RULES_EVALUATED" | "AI_CHECK_TRACE_UNREADABLE" | "AI_CHECK_UNSUPPORTED_FORMAT" | "AI_CHECK_AMBIGUOUS_FORMAT" | "AI_CHECK_RUN_SELECTION_REQUIRED" | "AI_CHECK_BASELINE_UNREADABLE" | "AI_CHECK_BASELINE_INCOMPATIBLE" | "AI_CHECK_RULE_FAILED" | "AI_CHECK_INTERNAL_ERROR"; /** * Experimental evidence pointing at trace data relevant to a finding. * * Evidence intentionally identifies runs/events/spans and bounded paths rather * than embedding raw prompts, outputs, request bodies, headers, or tool payloads. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface TraceCheckEvidence { runId?: string; eventId?: string; parentId?: string; traceId?: string; spanId?: string; kind?: string; name?: string; status?: string; path?: string; } /** * Experimental finding emitted by a trace-check rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface TraceCheckFinding { ruleId: string; severity: TraceCheckSeverity; status: TraceCheckFindingStatus; message: string; expected?: unknown; actual?: unknown; evidence: TraceCheckEvidence[]; /** * Additive safety taxonomy (6.9+). Omitted for non-safety / structural rules. * * @experimental */ category?: SafetyFindingCategory; /** * Additive detector confidence (6.9+). * * @experimental */ confidence?: SafetyFindingConfidence; /** * Detector id when known (rule id or redaction detector id). * * @experimental */ detector?: string; /** * Recommended remediation action (e.g. redact, review, keep). * * @experimental */ action?: string; } /** * Experimental diagnostic emitted when check execution cannot complete normally. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface TraceCheckDiagnostic { code: TraceCheckDiagnosticCode; message: string; severity: TraceCheckSeverity; ruleId?: string; } /** * Experimental input projection for trace checks. * * The `read` value must come from `agent-inspect/readers` or an equivalent * already-normalized `TraceReadResult`. The checks engine does not read files * or reparse source payloads. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface TraceCheckInput { read: TraceReadResult; selectedRun?: InspectRunTree; sourceLabel?: string; } /** * Experimental normalized facts available to trace-check rules. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface TraceCheckFacts { format: string; runs: readonly InspectRunTree[]; /** * Raw persisted rows (public experimental contract; unchanged meaning). */ events: readonly PersistedInspectEvent[]; /** * Lifecycle-paired projection for built-in semantic/structure rules. * * @experimental Additive in 6.12.2; formal TraceFacts land in 6.13. */ logicalEvents: readonly LogicalTraceEvent[]; /** * Non-fatal projection notes (ambiguous pairs, remapped parents, etc.). * * @experimental */ logicalProjectionDiagnostics: readonly LogicalProjectionDiagnostic[]; readerWarnings: readonly TraceReadWarning[]; unsupportedFields: readonly string[]; sourceFiles: readonly string[]; nodesByEventId: ReadonlyMap; childrenByParentId: ReadonlyMap; rootNodes: readonly InspectNode[]; } /** * Experimental rule evaluation context. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface TraceCheckContext extends TraceCheckFacts { selectedRun?: InspectRunTree; sourceLabel?: string; } /** * Experimental trace-check rule definition. * * Rules are synchronous and pure: they receive normalized facts and return * findings without reading files, mutating input, or performing network I/O. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface TraceCheckRule { id: string; category: TraceCheckRuleCategory; defaultSeverity: TraceCheckSeverity; evaluate(context: TraceCheckContext): readonly TraceCheckFinding[]; } /** * Experimental options for `runTraceChecks`. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface RunTraceChecksOptions { rules?: readonly TraceCheckRule[]; select?: readonly string[]; runId?: string; } /** * Experimental options for the built-in run status rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface RunStatusRuleOptions { expected?: "ok" | "error" | "running"; allowIncomplete?: boolean; } /** * Experimental options for the built-in run duration rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface RunDurationRuleOptions { maxDurationMs: number; } /** * Experimental options for the built-in max step duration rule. */ interface MaxStepDurationRuleOptions { maxDurationMs: number; } /** * Experimental options for stall detection (running / incomplete events). */ interface StallDetectionRuleOptions { /** When true, events with startedAt but no endedAt also fail. */ requireEndedAt?: boolean; } /** * Experimental options for the built-in event count rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface RunEventCountRuleOptions { kind?: PersistedInspectEvent["kind"]; min?: number; max?: number; } /** * Experimental options for the built-in run depth rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface RunDepthRuleOptions { maxDepth: number; } /** * Experimental options for the built-in tool usage rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface ToolUsageRuleOptions { required?: readonly string[]; forbidden?: readonly string[]; allowed?: readonly string[]; minCount?: number; maxCount?: number; } /** Kind-aware endpoint for typed step ordering (TOOL / LLM). */ type StepOrderingKind = "TOOL" | "LLM"; /** * Named step endpoint with an explicit event kind. * * @experimental Available through `agent-inspect/checks`. */ interface StepOrderingEndpoint { kind: StepOrderingKind; name: string; } /** * Experimental options for kind-aware step ordering (cross-kind TOOL↔LLM). * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface StepOrderingRuleOptions { before: StepOrderingEndpoint; after: StepOrderingEndpoint; /** * Explicit rule id. Defaults to `step.order`. TraceContract-generated * relations use unique ids such as `contract.step.orderRelation.0`. */ id?: string; /** * Ordering semantics. `first-occurrence` preserves first-occurrence encounter * ordering, `happens-before` requires the first before event to finish before * the first after event starts, and `all-occurrences` applies that causal * boundary to every matching occurrence. * * @defaultValue `"first-occurrence"` */ mode?: "first-occurrence" | "happens-before" | "all-occurrences"; /** * When true, missing endpoints of the declared kind fail (instead of * vacuously passing). Wrong-kind same-name events do not satisfy the * endpoint. * * @defaultValue `false` (compositional low-level default) */ requireEndpoints?: boolean; } /** * Experimental options for the built-in tool ordering rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface ToolOrderingRuleOptions { before: string; after: string; /** * Explicit rule id. Defaults to `tool.order`. TraceContract-generated * adjacent pairs use unique ids such as `contract.tool.order.0`. */ id?: string; /** * Ordering semantics. `first-occurrence` preserves first-occurrence encounter * ordering, `happens-before` requires the first before event to finish before * the first after event starts, and `all-occurrences` applies that causal * boundary to every matching occurrence. * * @defaultValue `"first-occurrence"` * @experimental Available through `agent-inspect/checks`. */ mode?: "first-occurrence" | "happens-before" | "all-occurrences"; } /** * Experimental options for the built-in tool failure rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface ToolFailureRuleOptions { maxFailures?: number; maxRetries?: number; } /** * Experimental options for the built-in LLM usage rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface LlmUsageRuleOptions { allowedModels?: readonly string[]; allowedProviders?: readonly string[]; maxCalls?: number; maxInputTokens?: number; maxOutputTokens?: number; maxTotalTokens?: number; maxCachedTokens?: number; finishReasons?: readonly string[]; } /** * Experimental options for the built-in structure incomplete rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface StructureIncompleteRuleOptions { allowRunning?: boolean; requireEndedAtForStarted?: boolean; } /** * Experimental options for the built-in structure orphan rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface StructureOrphanRuleOptions { allowMarkedUnresolved?: boolean; } /** * Experimental options for the built-in structure relationship rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface StructureRelationshipRuleOptions { minConfidence?: AttributionConfidence; requireParentBeforeChild?: boolean; requireTraceParentSpan?: boolean; } /** * Experimental options for the built-in structure parallel-width rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface StructureParallelWidthRuleOptions { maxChildren?: number; maxConcurrent?: number; } /** * Experimental options shared by built-in signal rules. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface TraceSignalRuleOptions { required?: readonly string[]; forbidden?: readonly string[]; allowed?: readonly string[]; minCount?: number; maxCount?: number; } /** * Experimental options for the built-in retrieval signal rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface RetrievalRuleOptions extends TraceSignalRuleOptions { } /** * Experimental options for the built-in guardrail signal rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface GuardrailRuleOptions extends TraceSignalRuleOptions { } /** * Experimental options for the built-in decision signal rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface DecisionRuleOptions extends TraceSignalRuleOptions { } /** * Experimental options for the built-in safety redaction rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface SafetyRedactionRuleOptions { sensitiveKeys?: readonly string[]; redactedMarkers?: readonly string[]; maxFindings?: number; } /** * Experimental options for the built-in raw content path rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface SafetyRawContentRuleOptions { forbiddenKeys?: readonly string[]; /** * Path prefixes (dot-separated, case-insensitive) whose terminal keys are * treated as metrics rather than raw prompts (e.g. `tokenUsage`, `usage`). */ safePathPrefixes?: readonly string[]; /** * When a raw-content key's value is entirely a redaction/hash marker, skip * the finding. Partial `[REDACTED] + residual text` still fails. */ redactedMarkers?: readonly string[]; includeSummaries?: boolean; maxFindings?: number; } /** * Experimental secret pattern used by the built-in secret safety rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface SafetySecretPattern { id: string; pattern: RegExp; } /** * Experimental options for the built-in secret pattern safety rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface SafetySecretPatternRuleOptions { patterns?: readonly SafetySecretPattern[]; maxStringLength?: number; maxFindings?: number; } /** * Experimental options for the built-in oversized attribute safety rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface SafetyOversizedAttributeRuleOptions { maxStringLength?: number; maxArrayLength?: number; maxObjectKeys?: number; maxSerializedBytes?: number; maxFindings?: number; } /** * Experimental options for the built-in baseline regression rule. * * The baseline must already be normalized through `agent-inspect/readers` or an * equivalent `TraceReadResult`; this rule does not read files or parse traces. * `durationToleranceMs` defaults to `0`, meaning exact duration comparison. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface BaselineRegressionRuleOptions { baseline: TraceCheckInput; baselineRunId?: string; durationToleranceMs?: number; compareFormat?: boolean; } /** * Per-rule execution status recorded on every check result. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ type TraceCheckRuleExecutionStatus = "pass" | "warning" | "fail" | "error"; /** * Evidence that a specific rule was evaluated (or failed before evaluation). * * Distinguishes “all intended rules passed” from “no intended rules ran.” * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface TraceCheckRuleExecution { ruleId: string; category: TraceCheckRule["category"]; status: TraceCheckRuleExecutionStatus; findingCount: number; runId?: string; } /** * Experimental aggregate counts for trace-check results. * * `passed` / `failed` / `warnings` count findings. `rulesEvaluated` counts * rules that were selected and executed (or attempted). * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface TraceCheckSummary { passed: number; failed: number; warnings: number; errors: number; rulesEvaluated: number; } /** * Experimental trace-check result. * * `status: "fail"` means rules ran and at least one error-severity finding * failed. `status: "error"` means execution could not complete because of * invalid input, invalid rule selection, zero rules selected, or a thrown * rule error. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ interface TraceCheckResult { ok: boolean; status: TraceCheckStatus; format: string; runId?: string; summary: TraceCheckSummary; findings: TraceCheckFinding[]; diagnostics: TraceCheckDiagnostic[]; ruleExecutions: TraceCheckRuleExecution[]; } /** * Create the experimental built-in run status rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ declare function createRunStatusRule(options?: RunStatusRuleOptions): TraceCheckRule; /** * Create the experimental built-in run duration rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ declare function createRunDurationRule(options: RunDurationRuleOptions): TraceCheckRule; /** * Fail when any step duration exceeds the configured maximum. */ declare function createMaxStepDurationRule(options: MaxStepDurationRuleOptions): TraceCheckRule; /** * Detect stalled runs: running events and optionally started-but-unended events. */ declare function createStallDetectionRule(options?: StallDetectionRuleOptions): TraceCheckRule; /** * Require a completed run with no running events. */ declare function createRequireCompletedRule(): TraceCheckRule; /** * Create the experimental built-in event count rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ declare function createRunEventCountRule(options: RunEventCountRuleOptions): TraceCheckRule; /** * Create the experimental built-in run depth rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ declare function createRunDepthRule(options: RunDepthRuleOptions): TraceCheckRule; /** * Create the experimental built-in tool usage rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ declare function createToolUsageRule(options: ToolUsageRuleOptions): TraceCheckRule; /** * Kind-aware step ordering over finished TOOL / LLM events. * * Low-level default: missing endpoints yield no finding when `requireEndpoints` * is false (compositional). TraceContract `steps.orderRelations` defaults * `requireEndpoints` to true. * * TOOL-only pairs preserve historical `tool.order*` finding codes and messages * used by {@link createToolOrderingRule}. * * @experimental Available through `agent-inspect/checks`. */ declare function createStepOrderingRule(options: StepOrderingRuleOptions): TraceCheckRule; /** * Create the experimental built-in tool ordering rule. * * Low-level default: first-occurrence start/encounter order among finished * tool events. Missing endpoints yield no finding (compositional). TraceContract * `requiredOrder` additionally requires presence of listed tools. * * When order passes by encounter order but intervals overlap, emits a * non-failing `tool.order.overlap` warning (not causal happens-before). * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ declare function createToolOrderingRule(options: ToolOrderingRuleOptions): TraceCheckRule; /** * Create the experimental built-in tool failure/retry rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ declare function createToolFailureRule(options: ToolFailureRuleOptions): TraceCheckRule; /** * Create the experimental built-in LLM usage rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ declare function createLlmUsageRule(options: LlmUsageRuleOptions): TraceCheckRule; /** * Create the experimental built-in structure incomplete rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ declare function createStructureIncompleteRule(options?: StructureIncompleteRuleOptions): TraceCheckRule; /** * Create the experimental built-in structure orphan rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ declare function createStructureOrphanRule(options?: StructureOrphanRuleOptions): TraceCheckRule; /** * Create the experimental built-in structure cycle rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ declare function createStructureCycleRule(): TraceCheckRule; /** * Create the experimental built-in structure relationship rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ declare function createStructureRelationshipRule(options?: StructureRelationshipRuleOptions): TraceCheckRule; /** * Create the experimental built-in structure parallel-width rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ declare function createStructureParallelWidthRule(options: StructureParallelWidthRuleOptions): TraceCheckRule; /** * Create the experimental built-in retrieval signal rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ declare function createRetrievalRule(options: RetrievalRuleOptions): TraceCheckRule; /** * Create the experimental built-in guardrail signal rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ declare function createGuardrailRule(options: GuardrailRuleOptions): TraceCheckRule; /** * Create the experimental built-in decision signal rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ declare function createDecisionRule(options: DecisionRuleOptions): TraceCheckRule; /** * Create the experimental built-in safety redaction rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ declare function createSafetyRedactionRule(options?: SafetyRedactionRuleOptions): TraceCheckRule; /** * Create the experimental built-in raw content path safety rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ declare function createSafetyRawContentRule(options?: SafetyRawContentRuleOptions): TraceCheckRule; /** * Create the experimental built-in secret pattern safety rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ declare function createSafetySecretPatternRule(options?: SafetySecretPatternRuleOptions): TraceCheckRule; /** * Create the experimental built-in oversized attribute safety rule. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ declare function createSafetyOversizedAttributeRule(options: SafetyOversizedAttributeRuleOptions): TraceCheckRule; /** * Create the experimental built-in baseline regression rule. * * The rule compares safe structural summaries from a normalized baseline * against the candidate context. It intentionally ignores raw prompt/output, * request/response body, header, and tool payload text. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ declare function createBaselineRegressionRule(options: BaselineRegressionRuleOptions): TraceCheckRule; /** * Experimental rule for observed real-world outcomes (v4.4+). */ interface ObservedOutcomeRuleOptions { failOn?: readonly ObservedOutcomeStatus[]; /** * When true, fail if the trace contains zero observed outcomes. * Default false preserves low-level programmatic compatibility. * CLI `--fail-on-observation` sets this to true. */ requireAny?: boolean; } declare function createObservedOutcomeRule(options?: ObservedOutcomeRuleOptions): TraceCheckRule; /** * Run experimental deterministic trace checks against normalized reader output. * * The engine is local-only and pure: it does not discover config files, read * trace files, call providers, perform network I/O, or mutate input objects. * * @experimental Available through `agent-inspect/checks`. Additive changes may ship in minor releases; breaking changes require a future major. */ declare function runTraceChecks(input: TraceCheckInput, options?: RunTraceChecksOptions): TraceCheckResult; export { type TraceCheckSummary as $, type ToolOrderingRuleOptions as A, type BaselineRegressionRuleOptions as B, type ControlStage as C, type DecisionRuleOptions as D, type ToolUsageRuleOptions as E, type TraceCheckContext as F, type GuardrailRuleOptions as G, type TraceCheckDiagnostic as H, type TraceCheckDiagnosticCode as I, type TraceCheckEvidence as J, type TraceCheckFacts as K, type LogicalTraceEvent as L, type MaxStepDurationRuleOptions as M, type TraceCheckFinding as N, type ObservedOutcomeRuleOptions as O, type TraceCheckFindingStatus as P, type TraceCheckInput as Q, type RecoverySameArgumentsMode as R, type SafetyFindingCategory as S, type ToolArgumentCheck as T, type TraceCheckResult as U, type TraceCheckRule as V, type TraceCheckRuleCategory as W, type TraceCheckRuleExecution as X, type TraceCheckRuleExecutionStatus as Y, type TraceCheckSeverity as Z, type TraceCheckStatus as _, type LogicalProjectionDiagnostic as a, type EnrichSessionSummaryOptions as a$, type TraceContract as a0, type TraceContractAlternativeBranch as a1, type TraceContractAlternatives as a2, type TraceContractBody as a3, type TraceContractControlRules as a4, type TraceContractInput as a5, type TraceContractLintDiagnostic as a6, type TraceContractLlmRules as a7, type TraceContractObservationProvenance as a8, type TraceContractObservationRules as a9, createSafetyRedactionRule as aA, createSafetySecretPatternRule as aB, createStallDetectionRule as aC, createStepOrderingRule as aD, createStructureCycleRule as aE, createStructureIncompleteRule as aF, createStructureOrphanRule as aG, createStructureParallelWidthRule as aH, createStructureRelationshipRule as aI, createToolFailureRule as aJ, createToolOrderingRule as aK, createToolUsageRule as aL, defineTraceContract as aM, evaluateToolArgumentValue as aN, evaluateTraceContract as aO, evaluateTraceContractRead as aP, explainTraceContract as aQ, extractToolArgumentPayload as aR, lintTraceContract as aS, projectLogicalEvents as aT, resolveCanonicalToolName as aU, resolveJsonPointer as aV, resolveTraceContractScope as aW, runTraceChecks as aX, workflowMetadataForRun as aY, type SessionWorkflowMetadata as aZ, type SessionRunRecord as a_, type TraceContractRecoveryOperation as aa, type TraceContractRecoveryRetryableErrors as ab, type TraceContractRecoverySuccessfulResultDependency as ac, type TraceContractRetryRules as ad, type TraceContractRunRules as ae, type TraceContractScope as af, type TraceContractStepKind as ag, type TraceContractStepOrderRelation as ah, type TraceContractStepRef as ai, type TraceContractStepRules as aj, type TraceContractToolRules as ak, type TraceSignalRuleOptions as al, createBaselineRegressionRule as am, createDecisionRule as an, createGuardrailRule as ao, createLlmUsageRule as ap, createMaxStepDurationRule as aq, createObservedOutcomeRule as ar, createRequireCompletedRule as as, createRetrievalRule as at, createRunDepthRule as au, createRunDurationRule as av, createRunEventCountRule as aw, createRunStatusRule as ax, createSafetyOversizedAttributeRule as ay, createSafetyRawContentRule as az, type LlmUsageRuleOptions as b, type SessionStatus as b0, type SessionSummary as b1, type SessionIndex as b2, type BuildActivitySummaryOptions as b3, type ActivitySummary as b4, type SessionWarning as b5, type BuildSessionIndexOptions as b6, type ActivityEntry as b7, type CriticalPathStep as b8, type HandoffEdge as b9, type RetryLink as ba, SESSION_WORKFLOW_KEYS as bb, type SessionCheckSummary as bc, type SessionConfidence as bd, type SessionEdgeSource as be, type SessionGroup as bf, type SessionLastError as bg, type SessionWorkflowKey as bh, type RecoverySideEffectClass as c, type RetrievalRuleOptions as d, type RunDepthRuleOptions as e, type RunDurationRuleOptions as f, type RunEventCountRuleOptions as g, type RunStatusRuleOptions as h, type RunTraceChecksOptions as i, type SafetyFindingConfidence as j, type SafetyOversizedAttributeRuleOptions as k, type SafetyRawContentRuleOptions as l, type SafetyRedactionRuleOptions as m, type SafetySecretPattern as n, type SafetySecretPatternRuleOptions as o, type StallDetectionRuleOptions as p, type StepOrderingEndpoint as q, type StepOrderingKind as r, type StepOrderingRuleOptions as s, type StructureIncompleteRuleOptions as t, type StructureOrphanRuleOptions as u, type StructureParallelWidthRuleOptions as v, type StructureRelationshipRuleOptions as w, type ToolArgumentOccurrence as x, type ToolArgumentOperator as y, type ToolFailureRuleOptions as z };