export type TrustState = "trusted" | "untrusted"; export interface ProjectTrustRecord { readonly projectRoot: string; readonly state: TrustState; readonly createdAt: string; readonly updatedAt: string; readonly label?: string; } export declare class ProjectTrustRequiredError extends Error { readonly code: "PROJECT_TRUST_REQUIRED"; constructor(message?: string); } /** Local-only trust state. It is deliberately not part of ConfigStore export/import. */ export declare class TrustStore { private readonly file; private readonly clock; private records; constructor(options: { readonly root: string; readonly clock?: () => Date; }); private load; private persist; get(projectRoot: string): ProjectTrustRecord; isTrusted(projectRoot: string): boolean; trust(projectRoot: string, label?: string): ProjectTrustRecord; revoke(projectRoot: string): ProjectTrustRecord; list(): readonly ProjectTrustRecord[]; } export type SafetyDecision = "ALLOW" | "REVIEW_REQUIRED" | "BLOCK"; export interface SafetyResult { readonly decision: SafetyDecision; readonly reason: string; readonly path?: string; readonly code?: string; } export interface PathSafetyOptions { readonly projectRoot: string; readonly trusted?: boolean; readonly trustStore?: TrustStore; readonly protectedPaths?: readonly string[]; readonly internalRoots?: readonly string[]; } /** Central application-level path policy; it is not an OS sandbox. */ export declare class PathSafetyPolicy { readonly projectRoot: string; private readonly trusted; private readonly protectedPaths; constructor(options: PathSafetyOptions); get isTrusted(): boolean; canonicalize(path: string): string; check(path: string, operation?: "read" | "write" | "execute"): SafetyResult; authorizeRead(path: string): SafetyResult; authorizeRecursiveRead(path: string): SafetyResult; authorizeWrite(path: string): SafetyResult; authorizeExecute(path: string): SafetyResult; assertWrite(path: string): string; } export declare class PathSafetyError extends Error { readonly result: SafetyResult; readonly code: string; constructor(result: SafetyResult); } export interface CommandSafetyOptions { readonly projectRoot?: string; readonly trusted?: boolean; readonly pathPolicy?: PathSafetyPolicy; readonly explicitlyAuthorized?: boolean; } export interface CommandSafetyResult extends SafetyResult { readonly command: string; } /** Conservative command policy. Shell parsing is intentionally bounded; ambiguity is reviewed, not guessed. */ export declare class CommandSafetyPolicy { evaluate(command: string, options?: CommandSafetyOptions): CommandSafetyResult; } export declare function evaluateCommandSafety(command: string, options?: CommandSafetyOptions): CommandSafetyResult; export interface SecretSanitizerOptions { readonly maxDepth?: number; readonly maxItems?: number; readonly maxStringLength?: number; } /** In-memory value-based redaction. The secret dictionary is never serializable. */ export declare class SecretSanitizer { private readonly secrets; private readonly maxDepth; private readonly maxItems; private readonly maxStringLength; constructor(options?: SecretSanitizerOptions); register(value: unknown): void; registerMany(values: Iterable): void; sanitizeText(value: unknown): string; sanitize(value: T, depth?: number): T; safeError(error: unknown): { readonly message: string; readonly code?: string; }; } export interface CapabilityRow { readonly profile: "investigation" | "implementation" | "verification" | "recommendation-analyst"; readonly tools: readonly string[]; readonly mutation: boolean; readonly bash: boolean; readonly trustRequired: boolean; readonly protectedPathRestrictions: string; } export declare function getCapabilityMatrix(): readonly CapabilityRow[]; export declare const permissionMatrix: typeof getCapabilityMatrix; export declare function fingerprintSafetyInput(value: unknown): string;