import { MCPClientManager, MCPTool } from './mcp-client-manager.js'; import { ApprovalService } from './approval.js'; import { GuardrailsService } from '../guardrails/service.js'; export interface FunctionDefinition { name: string; description: string; parameters: Record; } export interface FunctionCallResult { success: boolean; needsApproval?: boolean; approvalId?: string; data?: unknown; error?: string; message?: string; } export declare class FunctionBridge { private mcpManager; private approvalService; private trustedTools; private trustedToolsByServer; private ajv; private toolSchemas; private approvalMode; private guardrailsService?; constructor(mcpManager: MCPClientManager, approvalService: ApprovalService, trustedTools?: string[], approvalMode?: 'always' | 'trusted' | 'never', trustedToolsByServer?: Record, guardrailsService?: GuardrailsService); /** * A global trusted-tools list containing '*' trusts nothing: the global list is * matched literally in handleFunctionCall, so every call still hits the approval * gate. That fail-closed behaviour is deliberate — honouring a global wildcard * would silently switch off every approval prompt on upgrade — but it is invisible * to a user who believes they disabled the prompts, so say so loudly instead. */ private warnIfGlobalWildcard; getFunctionDefinitions(): Promise; private convertMCPToolToFunction; private validateToolArguments; handleFunctionCall(duckName: string, functionName: string, args: Record): Promise; private extractServerFromFunctionName; private extractToolFromFunctionName; isToolAvailable(serverName: string, toolName: string): Promise; getAvailableToolsByServer(): Promise>; updateTrustedTools(trustedTools: string[], trustedToolsByServer?: Record): void; getStats(): { totalFunctions: number; serverCount: number; trustedToolCount: number; connectedServers: string[]; }; } //# sourceMappingURL=function-bridge.d.ts.map