/** * Minimal structural view of a CDP page. The guard only needs to evaluate JS, * so callers may pass any page-like object (the CLI has its own page type). */ export interface GuardPageLike { ws: { send(data: string): void; }; } export type TypingStopReason = 'human-edited-field' | 'human-input-events' | 'field-lost-focus'; export interface TypingGuardTarget { selector?: string; isCodeEditor?: boolean; } export interface TypingGuardOptions { enabled: boolean; page?: GuardPageLike | null; /** Arm the OS-level probe (stealth mode) instead of the DOM signals. */ osLevel?: boolean; /** Label used in log lines (element text/label). */ label?: string; } export declare class TypingGuard { readonly enabled: boolean; private readonly page; private readonly osLevel; private readonly label; private stoppedFlag; private reason; private externalCount; private charCount; private baseline; private target; private key; private osSignature; private lastOsPoll; constructor(opts: TypingGuardOptions); get stopped(): boolean; get stopReason(): TypingStopReason | null; get externalEvents(): number; /** Human-readable reason for the run console. */ describeStop(): string; /** * Arm the sentinel for one typing stream. Must be called after the field has * been focused/cleared and immediately before the first character. */ arm(target: TypingGuardTarget): Promise; /** * Called after every character the agent dispatched (or every few chars for * code editors). Sets `stopped` when the human has taken over the field. */ tick(expected: string): Promise; /** Mark the field's own characters as agent-originated (Signal B brackets). */ markOwn(char: string, key?: string): Promise; dispose(): Promise; private fail; private matches; private buildInstallScript; private buildReadScript; /** * Windows UI Automation probe: value + identity of the focused control. * Returns null on any failure (never throws into the typing loop). */ currentOsControl(): Promise<{ value: string; signature: string; name: string; } | null>; private readOsFocusedControl; } /** Bounded wait used while a guard is stopping a stream (keeps logs readable). */ export declare function guardSettle(ms?: number): Promise;