/** * Safe shell helper for the discovery probes. * * Rules: * - Never interpolate user strings into a shell; always pass argv. * - Always cap wall-time with a timeout; probes run from an MCP tool * that the agent blocks on, so a hung kubectl is an outage. * - Return structured {stdout, stderr, exitCode, ms} — no throwing * on non-zero exit. Callers decide what a failure means * (e.g., `aws sts` failing ≠ a bug; it just means AWS isn't configured). */ export interface ShellResult { stdout: string; stderr: string; exitCode: number; ms: number; /** The argv we ran, joined for display. Safe to log — no secrets here. */ cmd: string; /** True if we killed the process for exceeding the timeout. */ timedOut: boolean; } export interface RunOpts { /** Hard wall-time cap, milliseconds. Default 10_000. */ timeoutMs?: number; /** Extra env vars to set for the child. Merged on top of process.env. */ env?: Record; /** If true, stdout > this many bytes is truncated. Default 2MB. */ maxBytes?: number; } /** * Run a command with structured argv. Never passes through a shell. * * await run('kubectl', ['get', 'pods', '-n', 'demo']) */ export declare function run(bin: string, args: string[], opts?: RunOpts): Promise; /** Same as run(), but parse stdout as JSON. Returns undefined on non-zero exit or parse error. */ export declare function runJson(bin: string, args: string[], opts?: RunOpts): Promise<{ result: ShellResult; parsed?: T; }>;