/** * Per-tool allowlist registry. Each tool whitelists exactly one * executable path plus an args-pattern array (regex strings). Optional * cwd glob via picomatch. Default-deny: a tool that has not been * registered cannot execute anything. */ export type SandboxProfile = "strict" | "standard" | "permissive"; export interface AllowlistEntryInput { toolName: string; executable: string; argsPatterns: string[]; cwdPattern?: string; sandboxProfile?: SandboxProfile; } export interface AllowlistEntry { toolName: string; executable: string; argsRegex: readonly RegExp[]; cwdMatch?: (cwd: string) => boolean; cwdPattern?: string; sandboxProfile: SandboxProfile; } export interface AllowlistMatchInput { toolName: string; executable: string; args: readonly string[]; cwd?: string; } export interface AllowlistMatchResult { allowed: boolean; reason?: string; entry?: AllowlistEntry; } export declare class AllowlistRegistry { private readonly entries; register(input: AllowlistEntryInput): AllowlistEntry; unregister(toolName: string): boolean; get(toolName: string): AllowlistEntry | undefined; list(): AllowlistEntry[]; has(toolName: string): boolean; clear(): void; match(input: AllowlistMatchInput): AllowlistMatchResult; } //# sourceMappingURL=allowlist.d.ts.map