import type { ApprovalPolicy, ExecutionProfile, LoopTask } from "../contracts/index.js"; export type SafetySurface = "command" | "filesystem" | "secret" | "spend" | "network" | "dependency"; export type SafetyViolationKind = "command_blocked" | "path_not_allowed" | "path_denied" | "path_outside_repo" | "network_blocked" | "dependency_approval_required" | "migration_approval_required" | "config_change_approval_required" | "secret_value" | "protected_path"; export interface SafetyViolation { kind: SafetyViolationKind; message: string; command?: string; file?: string; match?: string; } export interface SafetyLeashDecision { allowed: boolean; blocked: boolean; riskLevel: "safe" | "blocked"; surface: SafetySurface; profile?: ExecutionProfile; blockedCommands: string[]; violations: SafetyViolation[]; reason?: string; } export interface ResolvedExecutionProfile { name: ExecutionProfile; networkMode: "off" | "allowlisted" | "open"; allowedNetworkDomains: string[]; requireDependencyApproval: boolean; requireMigrationApproval: boolean; requireConfigApproval: boolean; } export declare function evaluateVerificationLeash(task: Pick): SafetyLeashDecision; export declare function evaluateFilesystemLeash(input: { repoRoot?: string; changedFiles: string[]; allowedPaths?: string[]; deniedPaths?: string[]; }): SafetyLeashDecision; export declare function evaluateSecretLeash(input: { values: string[]; }): SafetyLeashDecision; export declare function resolveExecutionProfile(input: { executionProfile?: ExecutionProfile; allowedNetworkDomains?: string[]; }): ResolvedExecutionProfile; export declare function evaluateChangeApprovalLeash(input: { changedFiles: string[]; executionProfile?: ExecutionProfile; approvalPolicy?: ApprovalPolicy; }): SafetyLeashDecision; export declare function redactSecretsFromText(input: string): string;