/** * Claude Code PreToolUse hook adapter. * * V1 behavior (honest, non-enforcing): * - Parses PreToolUse stdin JSON defensively (zod). Unknown/invalid input * yields permissive empty output `{}` — never block on parse failure. * - When the active profile is denied by the same OffRouter policy used by * UserPromptSubmit (work-profile / not-allowlisted), emits a non-blocking * warning via `hookSpecificOutput.additionalContext`. V1 does NOT set * `continue: false` or any other blocking decision — PreToolUse is an * audit/warning surface only in this release. * - Allowed profiles produce empty `{}` (no decision, no context noise). * * Claude Code's tool execution is unchanged. OffRouter does not claim * PreToolUse enforcement in V1. */ import { type PolicyConfig } from "offrouter-core"; import { z } from "zod"; declare const ClaudePreToolUseSchema: z.ZodObject<{ hook_event_name: z.ZodLiteral<"PreToolUse">; tool_name: z.ZodOptional; tool_input: z.ZodOptional; cwd: z.ZodOptional; session_id: z.ZodOptional; transcript_path: z.ZodOptional; permission_mode: z.ZodOptional; }, "passthrough", z.ZodTypeAny, z.objectOutputType<{ hook_event_name: z.ZodLiteral<"PreToolUse">; tool_name: z.ZodOptional; tool_input: z.ZodOptional; cwd: z.ZodOptional; session_id: z.ZodOptional; transcript_path: z.ZodOptional; permission_mode: z.ZodOptional; }, z.ZodTypeAny, "passthrough">, z.objectInputType<{ hook_event_name: z.ZodLiteral<"PreToolUse">; tool_name: z.ZodOptional; tool_input: z.ZodOptional; cwd: z.ZodOptional; session_id: z.ZodOptional; transcript_path: z.ZodOptional; permission_mode: z.ZodOptional; }, z.ZodTypeAny, "passthrough">>; export type ClaudePreToolUsePayload = z.infer; export interface PreToolUseOptions { profile: string; policy: PolicyConfig; /** Optional cwd override; payload.cwd wins when present. */ cwd?: string; } /** * PreToolUse hook output. V1 may include a warning context but never a * blocking decision (`continue` stays unset / undefined). */ export interface PreToolUseHookOutput { /** * When set to false, Claude Code would block the tool. V1 never sets this — * enforcement is explicitly out of scope. */ continue?: boolean; hookSpecificOutput?: { hookEventName: "PreToolUse"; additionalContext: string; }; } export interface PreToolUseRunResult { exitCode: number; stdout: string; stderr: string; } /** * Pure PreToolUse handler used by tests and the stdio runner. * Invalid input and allowed profiles both return `{}`. */ export declare function handlePreToolUse(input: unknown, options: PreToolUseOptions): PreToolUseHookOutput; /** * Stdio-style runner: parse stdin JSON, handle, emit a single JSON object on * stdout. Always exit 0. Invalid JSON → permissive `{}`. */ export declare function runPreToolUseHook(stdin: string, options: PreToolUseOptions): Promise; export {}; //# sourceMappingURL=pre-tool-use.d.ts.map