// Blocks any tool call whose input holds a full Social Security number:
// three digits, two digits, four digits, with a dash, a space, or nothing
// between the groups. The last four digits on their own pass.
// Same pattern as guard/ssn-check.sh.
const FULL_SSN = /(^|[^0-9])[0-9]{3}[- ]?[0-9]{2}[- ]?[0-9]{4}([^0-9]|$)/;

export default function (pi: any) {
  pi.on("tool_call", async (event: any) => {
    if (FULL_SSN.test(JSON.stringify(event.input))) {
      return {
        block: true,
        reason: "Blocked: a full Social Security number. Use only the last four digits.",
      };
    }
  });
}
