/** Expand `~` / `~/...` to the current user home directory. */ export declare function expandHome(input: string): string; /** * Path-pattern matching used by the child-safety policy. Supports `~/`, * directory prefixes (`foo/`), and `*` wildcards against both the absolute * target and its repo-relative form. */ export declare function pathMatches(targetPath: string, pattern: string, cwd: string, policyRoot?: string): boolean; /** Sanitize an arbitrary string into a filesystem-safe stem (≤ 80 chars). */ export declare function safeFileStem(value: string): string; /** Generate a run id from a prefix, current epoch ms, and a random suffix. */ export declare function newRunId(prefix: string): string; /** Return a sanitized run id, generating one from the prefix if absent. */ export declare function safeRunId(value: string | undefined, prefix: string): string; /** Resolve a repo-relative requested path, erroring if it escapes the root. */ export declare function resolveRepoPath(repoRoot: string, requestedPath: string): { path: string; errors: string[]; }; /** True for a single safe artifact filename (no separators, no `..`). */ export declare function isSafeArtifactName(value: string): boolean;