export declare function createGit(cwd: string): (args: string) => string; /** * As {@link createGit}, but WITHOUT trimming — for commands whose output has * significant leading whitespace. * * `git status --porcelain` is the case that matters: its format is * `XYpath`, and a file modified in the worktree but not staged is * reported as ` M path` — with a leading space. `.trim()` strips that space off * the FIRST line of the output, so a caller slicing a fixed 3-character status * field loses the first character of the path: * `.project-ai/skill-outputs/x` arrives as `project-ai/skill-outputs/x`, which * fails every prefix check built on it. That silently broke two fail-closed * guards (the semantic-agent containment check and the probe's commit binding). * Read porcelain through this, and parse it with {@link parsePorcelainPaths}. */ export declare function createGitRaw(cwd: string): (args: string) => string; /** * Parse `git status --porcelain` into the set of touched paths. Both sides of a * rename (`old -> new`) are returned: moving a file INTO an allowed directory * still means the working tree is not the commit, so a guard has to see the * source path too. */ export declare function parsePorcelainPaths(porcelain: string): Set; /** * Defense-in-depth + a clear error before git runs: reject a caller-supplied * ref that isn't a plausible git rev. Security does not depend on this (the * shell-free git call already neutralizes injection), but it turns a hostile or * fat-fingered `--base` into an explicit failure instead of a confusing git * error. Allows the characters git revs actually use. */ export declare function assertSafeRef(ref: string, label?: string): string; //# sourceMappingURL=exec.d.ts.map