export type HallucinationSignal = "phantom_import" | "typosquat" | "deceptive_prefix" | "nonexistent" | "new_package" | "low_adoption" | "single_maintainer" | "unmaintained" | "deprecated"; export type Severity = "critical" | "high" | "medium" | "low"; export interface HallucinationFinding { name: string; ecosystem: "npm"; signals: HallucinationSignal[]; severity: Severity; similarTo?: string; tier: "offline" | "online"; ruleId: string; fix: string; } export interface HallucinationResult { schema: "guardvibe.slopscan.v1"; root: string; declaredCount: number; importedCount: number; deterministic: boolean; networkStatus: "ok" | "unreachable" | "skipped"; findings: HallucinationFinding[]; } /** * Blank out comments and template-literal (backtick) bodies, preserving newlines and * single/double-quoted strings. Real ES import specifiers are single/double-quoted in * code context and survive; example imports living inside backtick templates or comments * are removed so they are never counted as real dependencies. */ export declare function stripCommentsAndTemplates(src: string): string; /** * Names that resolve to LOCAL first-party modules via tsconfig/jsconfig `baseUrl` or * `paths` — e.g. `import x from "models/user"` under `baseUrl: "."`. These are source * directories, NOT npm packages, so they must never be flagged phantom/typosquat * (juice-shop's `models`/`data`/`lib` are the canonical false-positive case). * Deterministic: reads the config + lists the baseUrl dir under root only; no network. */ export declare function baseUrlLocalNames(root: string): Set; /** Real npm package roots imported via import/require STATEMENTS in a file's source. */ export declare function extractStatementImports(code: string): Set; /** Walk a source tree and collect every package root imported via a real statement. */ export declare function collectStatementImports(root: string, opts?: { exclude?: string[]; maxFiles?: number; }): Set; export interface DeclaredInfo { /** Every dependency name declared across all package.json files under root. */ declared: Set; /** `name` field of every package.json found (workspace-internal / self packages). */ selfNames: Set; } /** Collect declared dependency names + workspace self-names from every package.json under root. */ export declare function collectDeclaredPackages(root: string, opts?: { exclude?: string[]; }): DeclaredInfo; /** * OFFLINE / deterministic core. Pure — no network, no filesystem. Unit-testable with * injected sets. Flags phantom imports (imported ∉ declared) and typosquats. */ export declare function detectOffline(imported: Set, declared: Set, opts?: { allow?: string[]; selfNames?: Set; }): HallucinationFinding[]; /** * Repo-level orchestrator. Runs the offline tier, then (unless online === false) * enriches with npm-registry truth, gracefully degrading to offline on any network error. */ export declare function scanHallucinatedPackages(root: string, format?: "markdown" | "json", opts?: { online?: boolean; }): Promise; /** * OFFLINE-only repo scan, for use inside full_audit (never makes a network call → * keeps the audit result hash deterministic). Returns the deterministic finding list. */ export declare function detectHallucinatedOffline(root: string): HallucinationFinding[];