/** * The inference-provider key env vars. Their values authenticate the agent to a * model backend, so they are masked like any other credential. * @returns {string[]} */ export function inferenceKeyVars(): string[]; /** * Adopt a host's own secret config in place of the package's: `minSecretLen` * replaces the placeholder floor, and `extraVars` are unioned into the * env-bound redaction set. This seam is what lets a host whose credential * registry already names its forwarded secrets (and their length floor) drive * the packaged helpers from that registry instead of forking this module — * a fork is the drift channel that lets the two redaction sets silently * disagree. Unset fields keep their package derivation; `undefined` and `null` * both restore it entirely. Like the missing-package remedy seam there is no * too-late window: the source is consulted at each helper call, never resolved * at module scope, so a later call steers every later answer. A malformed * source — a non-object, a key this seam does not read, a bad field — throws * on first use, not here (see {@link hostSource}). * @param {{ minSecretLen?: number, extraVars?: string[] } | null} source * host config, or null to restore the package derivation * @returns {void} */ export function configureEnvConfigSource(source: { minSecretLen?: number; extraVars?: string[]; } | null): void; /** * The placeholder floor: a candidate value shorter than this is too short to be a * real secret and is skipped by the env-bound redaction pre-gate. A malformed * host floor throws rather than degrading to the package's — a host that set 32 * must not silently run at a laxer floor, and a non-positive one would admit * empty placeholders as secrets. * @returns {number} */ export function minEnvSecretLen(): number; /** * True when `name` looks like a credential-bearing variable (and isn't a known * non-secret lookalike). * @param {string} name * @returns {boolean} */ export function looksLikeCredentialVar(name: string): boolean; /** * Credential-shaped env-var names present in `env` with a value long enough to be * a real secret (the min_secret_len floor the daemon also applies), beyond the * curated set. Reads the live environment so a newly-forwarded token is redacted * without a code change. * @param {Record} [env] * @returns {string[]} */ export function dynamicSecretVars(env?: Record): string[]; /** * The operator-declared extra secret variable names, or throw. A malformed entry * fails CLOSED — dropping it silently would leave the operator believing a * forwarded credential is masked while its value flows to the model verbatim. * @param {Record} [env] * @returns {string[]} */ export function extraSecretVars(env?: Record): string[]; /** * True when the operator opted into the secret-redaction layer. `=== "1"` * matches the other public knobs (`AGENT_SANITIZER_*_DISABLED`): any other * value — unset, "true", "yes" — keeps the layer off, so a typo can only fail * toward the default (no secret machinery), never silently enable it. * @param {NodeJS.ProcessEnv | Record} [env] * @returns {boolean} */ export function secretsEnabled(env?: NodeJS.ProcessEnv | Record): boolean; /** * True when the operator opted into flagging digest-shaped URL values. `=== "1"` * for the reason {@link secretsEnabled} gives: a typo fails toward the default, * which is the exemption the precision rule prefers. * @param {NodeJS.ProcessEnv | Record} [env] * @returns {boolean} */ export function digestFlaggingEnabled(env?: NodeJS.ProcessEnv | Record): boolean; /** * The env-bound redaction set: the UNION of the inference keys, the curated host * credentials, any credential-shaped var present in the environment, the * operator's declared extras, and the host's configured extras. The redactor * binds the same union; every consumer (the sanitize-output pre-gate, the * redactor client's per-request env snapshot) must mirror it exactly, else a * credential value would never trip the daemon. * @param {Record} [env] * @returns {string[]} */ export function envBoundSecretVars(env?: Record): string[]; export const SECRETS_ENABLED_ENV: "AGENT_SANITIZER_SECRETS_ENABLED"; export const FLAG_DIGEST_VALUES_ENV: "AGENT_SANITIZER_FLAG_DIGEST_VALUES";