/** * Trust-tier derivation per registered tool. * * - LOW : tool not registered → default-deny applies, cannot run * - MEDIUM : executable whitelisted but args wide open * - HIGH : executable + args regex constrained * - CRITICAL: HIGH + active sandbox + active replay window */ import type { AllowlistRegistry } from "./allowlist.js"; export type TrustTier = "LOW" | "MEDIUM" | "HIGH" | "CRITICAL"; export interface TrustTierDescriptor { tier: TrustTier; reasons: string[]; improvementHints: string[]; } export interface TrustTierContext { /** Is the process sandbox active for this tool's invocations? */ sandboxActive: boolean; /** Is the replay window active and recording? */ replayActive: boolean; } export declare function deriveTrustTier(registry: AllowlistRegistry, toolName: string, ctx: TrustTierContext): TrustTierDescriptor; //# sourceMappingURL=tier.d.ts.map