/** * [WHO]: ToolPolicyPipeline and typed pre-execution policy contracts * [FROM]: Depends on node:crypto and ./run-checkpoint checkpoint port * [TO]: Consumed by both agent loop implementations and runtime policy adapters * [HERE]: core/lib/agent-core/src/tool-policy.ts - deterministic, fail-closed tool policy evaluation */ import type { CheckpointStore } from "./run-checkpoint.js"; import type { AgentToolResult } from "./types.js"; export interface AgentToolPolicyEvent { toolCallId: string; toolName: string; requestedToolName: string; input: unknown; rawInput: unknown; } export type AgentToolPolicyDecision = { decision: "allow"; input?: unknown; } | { decision: "deny"; reason?: string; policyId?: string; } | { decision: "pause"; reason: string; policyId?: string; metadata?: Record; checkpointId?: string; }; export interface AgentToolPolicy { id: string; /** Set false only when the policy is guaranteed never to return pause. */ mayPause?: boolean; beforeTool?(event: AgentToolPolicyEvent): AgentToolPolicyDecision | void | Promise; afterTool?(event: AgentToolPolicyResultEvent): AgentToolPolicyResultDecision | void | Promise; } export interface AgentToolPolicyResultDecision { result: AgentToolResult; isError?: boolean; } export interface AgentToolPolicyResultEvent extends AgentToolPolicyEvent { result: AgentToolResult; isError: boolean; } export declare class ToolPolicyPipeline { #private; constructor(policies: readonly AgentToolPolicy[], options?: ToolPolicyPipelineOptions); evaluateBefore(event: AgentToolPolicyEvent): Promise; evaluateAfter(event: AgentToolPolicyResultEvent): Promise>; } export interface ToolPolicyPipelineOptions { checkpointStore?: CheckpointStore; checkpointTtlMs?: number; sessionId?: string; conversationBoundary?: { messageCount: number; assistantTimestamp?: number; }; createCheckpointId?: () => string; now?: () => number; /** Absolute index represented by policies[0], used when resuming mid-pipeline. */ policyIndexOffset?: number; }