import { CommandSafetyPolicy, PathSafetyPolicy, type SafetyResult, type TrustStore } from "../security/index.js"; import { type WorkerProfileId } from "./profiles.js"; /** Existing application trust state supplied to a worker boundary. */ export interface WorkerSafetyContext { readonly trusted?: boolean; readonly trustStore?: TrustStore; } export interface WorkerSafetyGuardOptions extends WorkerSafetyContext { readonly projectRoot: string; readonly profile: WorkerProfileId; /** Requested tools are intersected with the profile; they never expand it. */ readonly requestedTools: readonly string[]; readonly resultToolName?: string; } /** * Single pre-execution worker policy. Pi's beforeToolCall hook is the only * place where this guard can prevent the built-in tool from running. */ export declare class WorkerSafetyGuard { readonly projectRoot: string; readonly profile: WorkerProfileId; readonly pathPolicy: PathSafetyPolicy; readonly commandPolicy: CommandSafetyPolicy; readonly trusted: boolean; private readonly activeTools; private readonly profileTools; private readonly resultToolName; constructor(options: WorkerSafetyGuardOptions); authorize(toolName: string, args: unknown): SafetyResult; private authorizeBash; private authorizePath; } export declare function createWorkerSafetyGuard(options: WorkerSafetyGuardOptions): WorkerSafetyGuard; export declare function workerSafetyBlockMessage(toolName: string, result: SafetyResult): string;