import type { ISkillManifest } from '../discovery/ISkillManifest.ts'; export interface RemoteSkillSource { url?: string; git?: string; path?: string; name?: string; } export declare const GIT_TIMEOUT_MS = 60000; /** * Only https to public hostname resolvers — blocks http, file (local read), * credentials in URL, localhost, IPv6 literals, and IPv4 literals in * private/reserved ranges (SSRF). * ponytail: DNS rebinding between validate() and fetch is not closed — host * pinning via resolve4 + SNI check if a hosted multi-tenant service ever * exposes discoverRemote to user input. */ export declare function validateRemoteUrl(raw: string): string; export declare class RemoteSkillFetcher { private readonly cacheDir; private readonly parser; constructor(projectDir: string); fetch(source: RemoteSkillSource): Promise; private fetchFromGit; private getCacheKey; private loadFromCache; private saveToCache; } /** * Fetch a text body from a validated https URL with per-hop SSRF re-validation * on redirects, a hard timeout, and a size cap. Shared by remote skill * discovery and `agenthood install`. */ export declare function fetchRemoteText(raw: string): Promise; //# sourceMappingURL=RemoteSkillSource.d.ts.map