/** * Regex matching `value` tolerating invisible chars spliced between its * characters (mirrors the engine's env-value regex). Code-point split so * an astral character is escaped whole, not as two surrogate halves — and the * `u` flag, which the astral `\u{…}` class members in {@link ENV_INVIS_RUN} * require. * Memoized per distinct value: {@link ENV_INVIS_RUN} renders ~435 code points * as ~4 KB of source and is joined at EVERY interior gap, so a 20-char secret * compiles a ~75 KB pattern — and `hasEnvBoundSecret` builds one per configured * var on every PostToolUse output. Env values are stable for the process's * lifetime, so the cache is bounded by the number of distinct values. Sharing an * instance is safe because the regex carries no `g`/`y` flag, hence no * `lastIndex` state to leak between calls. * @param {string} value * @returns {RegExp} */ export function envValueRegex(value: string): RegExp; /** * True when tool output contains the literal value of a configured env-bound * secret. The shape-based secret hint can't match a prefix-less key or a host * credential, so the pre-gate must also fire on the value itself — otherwise * the engine's env-bound redaction never runs. Invisible-tolerant so a * value with spliced Cf chars (which the daemon still redacts) trips it too. * @param {string} text * @param {NodeJS.ProcessEnv} [env] * @returns {boolean} */ export function hasEnvBoundSecret(text: string, env?: NodeJS.ProcessEnv): boolean;