jev-guard
Auto mode for every coding agent: Jev risk on each tool call, injection scan on results, skill checks; npm jev-guard with multi-host adapters.
Overview
jev-guard (github.com/leepokai/jev-guard, npm jev-guard) from leepokai implements Claude Code auto mode semantics as three typed Jev questions (risk, user_requested, from_untrusted) on every tool call, plus result scanning for prompt injection and skill or plugin checks across hosts. README cites Vercel AI Gateway pricing near four hundredths of a cent per typical call and measured gateway p50 near five hundred eighty milliseconds in calibration runs. Adapters cover plugins, hooks, and npm global install with keys in ~/.jev-guard/config.json. Upgraded from a thin catalog row with refreshed stars and npm badge.
Problem: Auto mode style safety exists inside Claude Code, but other agents lack a cheap per-tool-call classifier with session memory and injection scanning.
Built for: Teams on Claude Code, Codex, Copilot, Gemini, Cursor, pi, OpenCode, or ACP who want Jev risk scoring before tools run and on untrusted results.
First indexed on Jev Directory: 2026-09-24
Creator and team
- Name
- leepokai
- Handle
- @leepokai
How Jev is used
- Role in the product flow
- Pre-tool risk gate, post-tool injection scan, and instruction file integrity checks
- Primitives
- ScoreNoul
- State in
- Tool name and payload before execution; tool stdout, files, and MCP output after; skill and plugin text on load per README tables.
- Decision out
- Deny, ask, or allow decisions plus untrusted flags stored for the session with calibrated probabilities.
- Hook or plugin intercepts agent tool call with session context
- Jev scores risk, user intent match, and untrusted instruction signals
- Policy maps scores to deny, ask, or allow per host capabilities
- After results return, Jev scans for agent-directed injection and canaries
- Skills and AGENTS files checked on load and via scan-skills command
jev-guard generalizes auto mode beyond Anthropic's host: same three-question batch, many adapters. coldteadotai-abide judges instruction compliance on diffs; qkal-canny refuses done without check evidence; jev-guard lives on the tool boundary and on poisoned outputs. y0usaf-pi-jev targets Pi specifically with batched nouls. Running jev-guard plus Abide plus Canny is heavy but each layer catches a different failure mode teams actually see in incident reviews.
Sourced performance claims
- README pricing table cites about four hundredths of a cent per typical thousand-token call via Vercel AI Gateway model card.Source: github.com/leepokai/jev-guard README
- README measured AI Gateway p50 near five hundred eighty milliseconds over a twenty one call calibration run.Source: github.com/leepokai/jev-guard README
- Public GitHub repo leepokai/jev-guard had about thirty three stars when this listing was drafted; npm package jev-guard at 0.3.1.Source: GitHub and npm September 2026
Features and stack
Features
- Claude Code, Codex, Copilot, Gemini, Cursor, pi, OpenCode, and ACP adapters
- Pre-tool deny and ask policy with session memory
- Post-tool injection and canary scanning
- Skill and plugin integrity checks
- npm global CLI with jev-guard check debugging
Stack
- JavaScript
- npm jev-guard
- Agent hook and plugin APIs
- TypeSafe Jev
Pricing: MIT npm package; Jev calls bill per README gateway or api.typesafe.ai pricing.
Links
FAQ
- Does jev-guard replace Claude Code auto mode?
- README positions it as the same classifier idea with Jev for many hosts, or a second opinion inside Claude Code.
- How is jev-guard different from Canny?
- Canny blocks finish without ledger check evidence. jev-guard scores each tool call and scans results for injection before work continues.
- Where does the API key live?
- jev-guard key writes ~/.jev-guard/config.json mode 0600; environment variables override when set per README.
Related learn guides
Original Jev guidance that pairs with this product pattern.
- Jev use cases
The patterns builders actually search for: moderation, routing, triage, RAG verify, and agent gates.
- Jev vs LLM classification
When to gate with System One probabilities instead of asking a chat model to label things.
Related products
Hand-picked neighbors with rich profiles or overlapping tags.