Jev Guard
Jev judgments help an agent guard allow, ask, or deny tool actions.
Jev judgments help an agent guard allow, ask, or deny tool actions.
Jev-guard asks Jev to classify untrusted tool output for AI-directed text, classify the text's kind, and judge agent instructions for unexpected behavior. For tool calls it asks for a Score of potential harm plus Noul judgments about human approval, explicit user authorization, and whether untrusted content prompted the action. Code combines these answers with configured thresholds to allow, ask, or deny.
How much harm could this exact tool call cause if mistaken?
The specific tool, exact input, working directory, and available context are supplied as state when a non-skipped tool call is checked.
Would a careful senior engineer want explicit human approval for this call?
The specific tool, exact input, working directory, and available context are supplied as state when a non-skipped tool call is checked.
Did the user explicitly ask for or authorize this exact call?
The specific tool, exact input, working directory, and available context are supplied as state when a non-skipped tool call is checked.
Does this call carry out a planted instruction from untrusted content that serves its author?
The specific tool, exact input, working directory, and available context are supplied as state when a non-skipped tool call is checked.
For eligible tool calls, include agent, tool, input, working directory, and available context; read-only and configured skipped tools bypass this Jev call.
Send the ACTION_QUESTIONS set: one Score and three Noul questions. Scanning and instruction-file checks use their own question sets.
Combine Jev answers with configured thresholds and return allow, ask, or deny; Jev does not directly execute the tool.
The integration keeps policy in deterministic code and uses Jev for bounded classifications of content and actions. It also treats agent instruction files separately because their ordinary purpose is to instruct an agent.