import type { Tool } from "@github/copilot-sdk"; import type { AccessContext, FactStore } from "./facts-store.js"; import type { GraphStore } from "./graph-store.js"; export interface CreateGraphToolsOptions { /** Host-reserved fact key prefixes (see PilotSwarmWorkerOptions.reservedFactPrefixes). */ reservedFactPrefixes?: readonly string[] | null; graphStore: GraphStore; /** Base fact store — graph_stats reads crawl-queue counts from it. */ factStore: FactStore; /** The session's agent identity, used for role gating. */ agentIdentity?: string; /** * Whether this session holds the app-assigned CRAWLER role. This gates ONLY * the crawl work queue (`facts_read_uncrawled` / `facts_set_crawled`); the * facts-manager additionally receives the queue (dormant), and agent-tuner * never does. Graph write/delete is NOT gated by this flag — it is available * to every non-tuner session (see `canWriteGraph`). */ isCrawler?: boolean; /** @deprecated Use `isCrawler`; accepted as a compatibility alias. */ isHarvester?: boolean; /** * Resolve the caller's ACL context for graph reads (evidence filtering + * seed gating). REQUIRED for correct isolation: without it, a reader would * see every session's evidence. Mirrors the read_facts lineage model — * returns { readerSessionId, grantedSessionIds } (or { unrestricted: true } * for the tuner). If omitted, graph reads FAIL CLOSED to the caller's own * session only (never unrestricted). */ resolveAccess?: (sessionId: string | undefined) => Promise; /** Agent id recorded on graph writes. */ agentId?: string; /** * Fire-and-forget hook recording a `graph.searched` event (query + result * digest) for tuner forensics (07 P4 observability). Errors swallowed. */ recordEvent?: (sessionId: string, eventType: string, data: unknown) => Promise; } /** * Build the graph + crawl-queue tools (enhancedfactstore 07 P4). Registered * ONLY when a `graphStore` is present. Reader tools (search/neighbourhood) go to * every session; graph write/delete (`graph_upsert_*` / `graph_merge_nodes` / * `graph_delete_*`) go to EVERY session EXCEPT the read-only agent-tuner, so any * agent can incorporate into the SHARED graph; the crawl work queue * (`facts_read_uncrawled` / `facts_set_crawled`) stays crawler-role + * facts-manager only (it reads facts across ALL scopes, bypassing per-session * ACL); `graph_stats` (read-only) goes to facts-manager + agent-tuner. * agent-tuner never gets a mutating tool. */ export declare function createGraphTools(opts: CreateGraphToolsOptions): Tool[]; //# sourceMappingURL=graph-tools.d.ts.map