/** * The single place an unlisted tool's fate is decided: covered by a field list, * exempt with a stated reason, or undeclared — nobody has classified it. * * `undeclared` is NOT a runtime alarm. Every arm returns the same * pass-through behaviour, because a stderr line on each of the many tools no * one has had a reason to classify (Task, TodoWrite, WebFetch, …) is alert * fatigue, and the doctrine here is precision over recall. The signal is the * partition test, which reads this function. * @param {string} tool * @returns {{ kind: "covered", fields: string[] } | { kind: "exempt", reason: string } | { kind: "undeclared" }} */ export function authoredScopeDecision(tool: string): { kind: "covered"; fields: string[]; } | { kind: "exempt"; reason: string; } | { kind: "undeclared"; }; /** @param {string[]} changed */ export function authoredContext(changed: string[]): string; /** * Strip authored stego / terminal-control sequences from the model-authored * fields of a tool call. Returns the updated input plus a per-field description * of what was stripped, or null when nothing changed. Throws on internal error * (caller fails closed). * @param {string} tool * @param {any} toolInput * @returns {{ updatedInput: any, changed: string[] } | null} */ export function sanitizeAuthoredContent(tool: string, toolInput: any): { updatedInput: any; changed: string[]; } | null; /** @type {Record} */ export const AUTHORED_FIELDS: Record; /** @type {Record} */ export const EXEMPT_TOOLS: Record; /** @type {ReadonlyArray<{ pattern: RegExp, reason: string }>} */ export const EXEMPT_TOOL_PATTERNS: ReadonlyArray<{ pattern: RegExp; reason: string; }>;