Shaduf.Research preview
Jev: Use Cases, Alternatives & Products/Claude Code and MCP guardrails
Build6 integrations read in pinned source · checked , 07:09–07:14 UTC · versions rechecked (oh-my-claudecode checked at v5.6.0; jkudish at 0.13.0 on 2 Oct) · v5.6.1 release noted · 2 guard rows added and rechecked · 2 new releases noted, not read,

Jev (TypeSafe AI) in Claude Code and MCP: which server, hook or plugin fails open?

Claude Code hooks, plugins and MCP servers exist that ask Jev whether an agent's next step is safe. This page compares what eight of them do when Jev has no key, times out, returns an error, returns something malformed or is unsure. It also shows what each one sends to Jev and which mode it uses after installation. Every cell comes from the integration's source code at a stated commit.

Short answer

We read seven Jev guardrails in their source code. Only one of them stops the agent when Jev fails: LangChain AutoModeMiddleware. One, madisonrickert/jev-permission-gate, falls back to Claude Code's built-in classifier. Two ship in a shadow or log-only mode, one is advisory by design and one fails open. One, gulbaki/jev-llm-guard, only returns a verdict: it is not counted as a decision. The official TypeSafe plugin makes no Jev calls at all. Before you rely on any of them, check three things: its default mode, what it sends to Jev, and its timeout. Documented source at pinned commits, checked 29 Sep 2026; the two guard rows read 4 Oct and rechecked 6 Oct 2026

jev-kit (Codex and Claude Code), NiazMorshed2007/jev-review and pedroknigge/mcp_jev also target Claude Code; they are compared on coding agents.

Version checks, 2–7 Oct 2026

Two new releases, not yet read (7 Oct 2026, 05:21 UTC). oh-my-claudecode v5.6.2 is now a GitHub release (published 6 Oct 2026, 06:15 UTC). @jkudish/jev-mcp 0.14.1 was published on npm on 6 Oct 2026 (21:41 UTC; 0.14.0 at 20:54 UTC), a 0.x minor release after the 0.13.0 checked below. For both: targeted diff due in the next run; failure path not re-read. The rows below still give the failure paths checked at oh-my-claudecode v5.6.0 and jev-mcp 0.13.0. Documented (release v5.6.2, R10-S49; npm: @jkudish/jev-mcp 0.14.1, R10-S48)

oh-my-claudecode tag v5.6.2 (6 Oct). A git tag v5.6.2 exists with no GitHub release; the latest release is still v5.6.1 (checked 6 Oct 2026, 05:20 UTC). Its failure path was not re-read: the rows below still give the failure path checked at v5.6.0. Documented (tag and release listing)

oh-my-claudecode v5.6.1 (4 Oct). A patch release, v5.6.1, appeared on 3 Oct 2026 at 06:44 UTC. Its source was not re-read: the rows below give the failure path checked at v5.6.0. No other integration on this page had a new release when checked on 4 Oct 2026. Documented (release listing)

oh-my-claudecode v5.6.0 (3 Oct). oh-my-claudecode's latest release is v5.6.0 (1 Oct 2026). Checked at v5.6.0 (commit e74b22c) on 3 Oct 2026: failure path unchanged; default timeout now 2,000 ms. On a timeout, HTTP error or invalid response the heuristic twin still decides and "the resolver never throws" (resolver.ts L10–12); a point still stops calling Jev after 3 failures in a row; nothing is sent unless OMC_JEV lists points; excerpts are still cut to 200 characters; points still run in shadow by default. New in v5.6.0: OMC_JEV=<point>:active or OMC_JEV=all:active makes Jev decide (a warning is printed), and a script-side judgment channel follows the same degrade-never-block rule. The 250 ms default that made every call fall back (round trips of 465–605 ms reported by the maintainers, #4091, Reported) was raised to 2,000 ms in v5.6.0 (config.ts L36). If you run v5.5.0 or earlier, set OMC_JEV_TIMEOUT_MS=2000. Documented (source at commit e74b22cd, read 3 Oct 2026, 05:21 UTC).

jkudish/jev-mcp (2 Oct).

@jkudish/jev-mcp 0.12.0 (1 Oct) and 0.13.0 (2 Oct, 03:50 UTC) were compared with the audited 0.11.0 at their tagged commits: failure path unchanged. The server still only advises; malformed answers still come back as "review", and from 0.12.0 rate-limit and outage results come back as tool errors. 0.13.0 adds a repository example hook (not in the npm package) that denies a tool call at a block probability of 0.85 or more and, if Jev fails, defers to Claude Code's normal permission prompt. Documented (source diff), checked 2 Oct 2026, 05:22 UTC.

The other four are unchanged: langchain-typesafe is still 0.0.1a3; danna-zhou/jev-mcp was last pushed 23 Sep, brunopivetta88/jev-claude 25 Sep and typesafe-ai/skills 12 Sep (checked 2 Oct, 05:14 UTC). Sources: 0.11.0 to 0.12.0, 0.12.0 to 0.13.0, example hook. Plugins that pick which model answers, rather than allow or deny a tool call, are compared on Jev Router or your own model router?

What you get by default

Installing a Jev guardrail can mean anything from no runtime effect to a guard that halts the agent whenever Jev is unavailable. The figure places each audited integration by what it does as installed. Dashed entries are modes you have to switch on yourself.

Effect on the agent as installed, from none (top) to strongest (bottom)

  1. No Jev callText instructions for your agent only
    • Official typesafe@typesafe-ai plugin
  2. Records onlyShadow or display mode; nothing is blocked
    • jev-claude (default shadow)
    • oh-my-claudecode Jev points (shadow; its built-in heuristic decides)
    • danna-zhou Stop hook
  3. Advises the agentReturns a recommendation; the agent may ignore it
    • jkudish/jev-mcp
    • danna-zhou MCP tools
  4. Gates, but lets the call through if Jev failsCan deny or ask; fails open
    • danna-zhou PreToolUse hook
    • jev-claude enforce (default failOpen)
  5. Gates, and stops or asks if Jev failsFails closed
    • LangChain AutoModeMiddleware (stops the run)
    • jev-claude enforce with JEV_GUARD_FAIL_OPEN=false (asks a person)
Built from the failure matrix below. Documented source read at the pinned commits, 29 Sep 2026. It shows behaviour, not quality: none of these integrations was run against the live Jev API.

Failure matrix: what happens to the tool call

Each cell says what happens to the agent's action in one failure class. "Normal permission flow" means the hook emits no decision, so Claude Code's own permission rules apply. It is not an approval. Use the filter to compare default modes with the opt-in ones.

Show
Failure classes (a)–(e) for 8 integrations, 13 rows including modes. "Fail-open switched off" means JEV_GUARD_FAIL_OPEN=false. Documented from source at the pinned commits in the next table, checked 29 Sep 2026 (jev-permission-gate and jev-llm-guard: read 4 Oct, rechecked 6 Oct 2026), unless a cell says Tested.
Integration and mode after install(a) No key(b) Timeout (default)(c) HTTP 4xx / 5xx(d) Malformed response(e) Low confidence
Official TypeSafe plugin (typesafe@typesafe-ai)Mode: Instructions onlyn/aNo runtime pathn/an/an/an/a
danna-zhou/jev-mcp: PreToolUse hookMode: Enforcing (deny or ask) once added to settings.jsonProceeds anyway (fail-open)Sends Bearer local; any failure → normal permission flow Tested offlineProceeds anyway (fail-open)8,000 msProceeds anyway (fail-open)Proceeds anyway (fail-open)Holds for a person (held)"dangerous" below 0.6 confidence, or "moderate" → ask. "safe" proceeds unless needs_human ≥ 0.6
danna-zhou/jev-mcp: Stop hookMode: Display onlyFlags only (advisory)The turn ends normallyFlags only (advisory)8,000 msFlags only (advisory)Flags only (advisory)Flags only (advisory)Scores are displayed only
danna-zhou/jev-mcp: MCP toolsMode: AdvisoryFlags only (advisory)Error returned to the agentNo timeout in codeBehaviour on a hang not testedFlags only (advisory)Error to the agentFlags only (advisory)JSON parse error to the agentFlags only (advisory)Raw answer returned; the agent decides
jev-claude ("jev-guard" 0.1.0), as installedMode: Shadow (log and note)Flags only (advisory)Flags only (advisory)Flags only (advisory)Flags only (advisory)Flags only (advisory)Every decision becomes "allow" plus a note
jev-claude, enforce mode with the default fail-openMode: Opt-inProceeds anyway (fail-open)Its own deterministic rules still applyProceeds anyway (fail-open)1,500 ms; hard deadline 8,000 ms → allowProceeds anyway (fail-open)Rules still applyProceeds anyway (fail-open)A 200 without usable answers counts as a failure, not an all-clearAllow, warn, ask or block (conditional)Per-signal thresholds, e.g. destructive: block 0.85, ask 0.6, warn 0.35
jev-claude, enforce mode with fail-open switched offMode: Opt-inHolds for a person (fail-closed)Holds for a person (fail-closed)Holds for a person (fail-closed)Holds for a person (fail-closed)Allow, warn, ask or block (conditional)As above
jkudish/jev-mcp v0.11.0 (12 tools)Mode: Advisory: "The server never blocks on its own". Checked at 0.13.0: failure path unchangedFlags only (advisory)The tool call returns an errorFlags only (advisory)60 s over all attempts (OpenRouter, Cloudflare, compatible endpoints). TypeSafe direct and Vercel: unknownFlags only (advisory)3 attempts on 408/409/429/5xx (fetch transports)Flags only (advisory)invalid_response with a "review" recommendation, not "pass"Flags only (advisory)pass / review / block / skip advice; jev_screen blocks at ≥ 0.75, reviews at ≥ 0.25
LangChain AutoModeMiddleware (langchain-typesafe 0.0.1a3)Mode: Enforcing for listed tools only; other tools bypass itStops (fail-closed)The middleware cannot be constructed (ValueError), so the agent is not builtStops (fail-closed)30 s; the exception ends the agent run and the tool is not executedStops (fail-closed)The run raises; tests assert the tool did not runStops (fail-closed)ExceptionTool runs below 0.5 (acts-anyway)Noul "is_risky" below 0.5 → the tool runs; at 0.5 or above → error message to the agent, which continues. Threshold fixed at 0.5
oh-my-claudecode Jev judgment points, as installed (default shadow) (audited v5.5.0 at 9fd35ec; rechecked at v5.6.0, 3 Oct: failure path unchanged)Mode: Shadow by default: Jev never decides, so the points are advisory; the built-in heuristic decides whether or not Jev answers. A key alone sends nothing: no point runs unless OMC_JEV lists it. After 3 failures in a row a point stops calling for the processHeuristic decides (advisory)The point is off; nothing is sentHeuristic decides (advisory)2,000 ms default from v5.6.0; 250 ms up to v5.5.0Heuristic decides (advisory)Jev's answer is only logged in shadow modeHeuristic decides (advisory)The response is validatedNo gate (advisory)Jev never decides at default settings
oh-my-claudecode, active modeMode: Opt-in from v5.6.0: OMC_JEV=<point>:active or all:active makes Jev decide (a warning is printed). On any Jev failure the heuristic decidesHeuristic decides (fallback-heuristic)The point is off; nothing is sentHeuristic decides (fallback-heuristic)2,000 ms default from v5.6.0Heuristic decides (fallback-heuristic)Heuristic decides (fallback-heuristic)The response is validatedNo confidence gateJev's first answer is used
madisonrickert/jev-permission-gate (7349bc9)Mode: Enforcing by default (gate_mode "enforce"); acts only when Claude Code's own engine says "ask" in auto mode. Bypassed when the engine already decided or not in auto mode, for tools other than Bash, WebFetch and WebSearch, for input with secrets or too long, in measure mode and on cache hitsBuilt-in classifier decides (fallback)Claude Code's built-in classifier decides (register.ts L333–341)Built-in classifier decides (fallback)1,500 ms (policy.ts L37; register.ts L360–365, L377–381)Built-in classifier decides (fallback)Error caught (register.ts L377–381)Built-in classifier decides (fallback)hooks/typesafe.ts L54–74; register.ts L198, L377–381Built-in classifier decides (fallback)Defers unless allow (serves_request ≥ 0.5, every risk ≤ 0.1) or deny (a risk ≥ 0.8, serves_request ≤ 0.3) (policy.ts L27–42, L423–445)
gulbaki/jev-llm-guard (7c7b1b5)Mode: Returns verdict; not a decision. The jev-guard CLI exits 0 for allow, review and block; the demo server enforces nothing. Not a Claude Code hook; not countedReturns verdict; not a decision (no-decision)Throws "TYPESAFE_API_KEY is required" (guard.js L50); the CLI exits 1Returns verdict; not a decision (no-decision)30,000 ms (guard.js L51); throws, the CLI exits 1Returns verdict; not a decision (no-decision)Rethrown (guard.js L61–63); the CLI exits 1Returns verdict; not a decision (no-decision)Strict validators throw (guard.js L27–40, L67–71); the CLI exits 1Returns verdict; not a decision (no-decision)Signal below 0.4 → allow; 0.4 or above → review; 0.8 or above → block, except LLM07 (policy.js L32, L42–45). Nothing enforces it: the CLI exits 0 for all three
  • fail-closed: stops the call or run, or holds it for a person (held)
  • fail-open or acts-anyway: the tool call goes ahead
  • advisory: flags only, Jev never decides; conditional: thresholds you set decide
  • fallback: a built-in heuristic or classifier decides
  • no-decision: an error, and no verdict
  • Not applicable or not set

Colours follow the shared legend used on when Jev fails and framework integrations. Changed 6 Oct 2026: until then this page coloured "Stops" red and "Proceeds anyway" green. The cells themselves did not change, except that the AutoModeMiddleware low-confidence cell now leads with what happens below 0.5 (the tool runs), as on when Jev fails.

Owner, version, data sent and grade

IntegrationOwner and typeSends to JevPinned version or commit (date)Grade and label
typesafe-ai/skills: plugin typesafe@typesafe-aiOfficial (TypeSafe AI). Claude Code plugin with one skill; no hook, no MCP server, no scriptNothing. The skill tells your agent to read docs.typesafe.aiv0.5.7, 65a39f3 (12 Sep)A · Documented all contents read · checked 29 Sep
danna-zhou/jev-mcpCommunity. Two Claude Code hook scripts (PreToolUse on Bash, Stop) added by hand to settings.json, plus an MCP serverPreToolUse: the full Bash command, only if it matches a "high-stakes" pattern (git push, publish, kubectl delete, terraform apply, DROP TABLE…); no redaction. Stop: the agent's full final message436469a (23 Sep); no tagsA · Documented; no-key cell also Tested offline · 29 Sep
brunopivetta88/jev-claude ("jev-guard")Community. Claude Code hook plugin (SessionStart, UserPromptSubmit, PreToolUse, PostToolUse, Stop); Codex adapter not auditedUser goal (≤ 1,500 characters), tool name and full tool input (regex-redacted; strings ≤ 4,000 characters), last 8 action summaries, working directory. Read-only tools with a clean rule check are not sent0.1.0, 7d7e876; PR #1 merged 25 SepA · Documented · 29 Sep
jkudish/jev-mcp (@jkudish/jev-mcp)Community. MCP server with 12 judgment tools (verify, screen, noul, find, classify, decide, rerank, compare, extract, audit, review, gate); no hookOnly what the agent passes to a tool (for example jev_screen: the text and an optional purpose)Checked at 0.13.0: failure path unchanged (audited 0.11.0, 53fe575, 29 Sep, 05:30 UTC)A for the tool layer and fetch transports; TypeSafe-direct timeout unknown (dependency not read) · Documented; README "never blocks on its own" Reported · 29 Sep
langchain-typesafe AutoModeMiddlewareLangChain (framework vendor, not TypeSafe). Python agent middleware that guards the tools you list; experimental alphaThe proposed tool call (id, name, full arguments), the tool description and the last 30 messages of the agent state, all roles, full text. No redaction0.0.1a3 (released 20 Sep): tag langchain-typesafe==0.0.1a3 = 4af7ab8; sdist sha256 d77647a7…3272A · Documented released package read · 29 Sep
oh-my-claudecode Jev judgment pointsCommunity. A Jev layer inside the plugin's own hooksNothing unless OMC_JEV lists points ("a key alone sends nothing anywhere"); then per-point text, each string cut to 200 charactersv5.5.0 = main = 9fd35ec (22 Sep); dev differsA · Documented · 29 Sep
madisonrickert/jev-permission-gateCommunity. Claude Code plugin on tool.check (hooks/hooks.json L3; hooks/register.ts L293–382); shadow and measure modes optionalLast 3 user and 3 peer messages (each cut to 1,500 characters head and tail), the Bash command (≤ 2,000 characters) and description (cut to 300), WebFetch URL and prompt, WebSearch query, project directory (policy.ts L348–414). Calls carrying a secret are never sent (L279–320)7349bc9 (3 Oct). HEAD 7349bc9 = run-7 pin on 6 Oct; failure files unchangedA candidate (code read; not verified in production) · Documented · read 4 Oct, rechecked 6 Oct. README "1 unsafe allow in 3,664 risky calls" Reported
gulbaki/jev-llm-guardCommunity. Node library (evaluateGuardrail), jev-guard CLI and demo web server; not a Claude Code hook. Returns verdict; not a decision (not counted)Untrusted text (≤ 20,000 characters; longer input is rejected, not cut; context.js L2, L15), context, optional trusted task and app context; 13 questions (guard.js L18–25); up to 2 more calls for quotations7c7b1b5 (1 Oct). HEAD 7c7b1b5 = run-7 pin on 6 Oct; failure files unchangedA candidate (code read; not verified in production) · Documented · read 4 Oct, rechecked 6 Oct

Grades use the same scale as Products and projects: A means the pool read the code that calls Jev. It does not mean the integration works well or has users. Star counts are not adoption.

What leaves your machine

Data sent to Jev per guarded action, audited range

  1. Official plugin; oh-my-claudecode unless enabledNothing
  2. oh-my-claudecode with points enabledPer-point text, each string cut to 200 characters
  3. danna-zhou PreToolUse hookOne full shell command, only if it matches the high-stakes pattern; not redacted
  4. jev-claudeGoal, full tool input and 8 action summaries, with regex redaction of keys and tokens
  5. LangChain AutoModeMiddlewareThe last 30 messages in full, including tool outputs, plus the full tool call; not redacted
Bar lengths show order, not measured byte counts. MCP servers (jkudish, danna-zhou tools) send only what the agent passes to them. Documented 29 Sep 2026. What each hosted route then does with that data (training, retention, zero data retention) is on data handling by route.

A timeout shorter than the round trip turns the guard off

If the timeout is shorter than the time Jev takes to answer, every call fails. The integration then takes its failure path on every call, which is "proceed" or "heuristic" for most of the integrations above. oh-my-claudecode defaulted to 250 ms up to v5.5.0, below the 465–605 ms round trips its maintainers measured; v5.6.0 (1 Oct 2026) defaults to 2,000 ms.

Default timeouts against one project's measured round trips (shaded band)

  • oh-my-claudecode up to v5.5.0250 ms
  • Measured Jev round trips (#4091, 22 Sep) Reported465–605 ms
  • jev-claude enforce1,500 ms
  • oh-my-claudecode from v5.6.0 (1 Oct)2,000 ms
Scale 0–2,000 ms. Off the scale: danna-zhou hooks 8,000 ms; LangChain 30 s; jkudish 60 s over all attempts (fetch transports). The danna-zhou MCP server sets no timeout. Your own round trip depends on route and region; measure it and set OMC_JEV_TIMEOUT_MS (or the equivalent) above it. Documented timeouts from source, 29 Sep 2026; oh-my-claudecode v5.6.0 read 3 Oct 2026.

Caveats before you rely on this table

  • "Normal permission flow" means Claude Code's own rules apply. It is not an approval. Documented 29 Sep
  • LangChain AutoModeMiddleware 0.0.1a3 sends no risk criteria unless you pass criteria=NoulCriteria(...). The constructor's criteria=None default replaces the documented default criteria (auto_mode.py L66–71, L147, L164), and a unit test asserts criteria is None. Documented 29 Sep
  • danna-zhou hooks: set JEV_MODEL=jev-1.13.0 when you point them at TypeSafe. The default kev-latest is meant for a local Kev server. Whether TypeSafe rejects kev-latest was not tested. Earlier third-party reports say unknown models return 400, and this hook would treat that as "skip review". Documented defaults; the consequence is the pool's inference 29 Sep
  • oh-my-claudecode: defaulted to 250 ms up to v5.5.0, while the maintainers measured 465–605 ms round trips (Reported, #4091, 22 Sep); v5.6.0 defaults to 2,000 ms. On v5.5.0 or earlier, set OMC_JEV_TIMEOUT_MS above your round trip. From v5.6.0, OMC_JEV=<point>:active lets Jev decide, so check your environment for it. Documented 29 Sep; v5.6.0 on 3 Oct
  • jev-claude's own tests run in enforce mode; the shipped default is shadow. Passing tests do not show that the installed plugin blocks anything. Documented 29 Sep
  • No integration was run against the live Jev API, and star counts are not adoption.

Worked example: the danna-zhou hook with no key

Tested (offline, no Jev call) Node v24.20.0, 29 Sep 2026, about 07:12 UTC. The hook (86 lines) and its helper (62 lines) use only Node built-ins and were read in full before running. They were fetched at commit 436469a2 into a temporary directory, then deleted. Nothing was installed.

The pool piped four PreToolUse events into the hook with an empty environment (no key). The endpoint pointed at ports on 127.0.0.1 that were confirmed closed.

CaseCommand in the eventEndpointExitOutputSent to Jev?
Agit push origin maindefault 127.0.0.1:8009 (closed)0 (159 ms)"jev guardrail unreachable, skipping review: fetch failed"Attempted; failed → proceeds
Bgit push origin main127.0.0.1:9 (closed)0 (152 ms)Same messageAttempted; failed → proceeds
Cls -la127.0.0.1:9 (closed)0 (83 ms)NoneNo: not in the high-stakes pattern
Drm -rf / --no-preserve-root127.0.0.1:9 (closed)0 (73 ms)NoneNo: not in the high-stakes pattern

Reading. Exit 0 with no permissionDecision means Claude Code's normal permission flow applies, so the Jev layer fails open. Case D shows that the pattern list, not Jev, decides what this guard checks: a destructive command outside the list is never sent. The run does not show the behaviour against the real API with a missing or invalid key (the 401/403 path). The code sends that path to the same fail-open helper.

Runner script and raw output
# bash, pool-authored; run in a temporary directory with the two hook files
run(){ echo "--- case: $1"; shift; start=$(date +%s%N)
  out=$(echo "$PAYLOAD" | env -i PATH=$PATH "$@" node hooks/pretooluse-guardrail.mjs 2>err.txt); code=$?
  end=$(date +%s%N); echo "exit=$code ms=$(( (end-start)/1000000 ))"; echo "stdout=$out"; echo "stderr=$(cat err.txt)"; }
PAYLOAD='{"hook_event_name":"PreToolUse","tool_name":"Bash","tool_input":{"command":"git push origin main"}}'
run "A no key, no env (default base 127.0.0.1:8009, closed)"
run "B no key, JEV_BASE_URL=http://127.0.0.1:9 (closed)" JEV_BASE_URL=http://127.0.0.1:9
PAYLOAD='{"hook_event_name":"PreToolUse","tool_name":"Bash","tool_input":{"command":"ls -la"}}'
run "C non-high-stakes command, closed port" JEV_BASE_URL=http://127.0.0.1:9
PAYLOAD='{"hook_event_name":"PreToolUse","tool_name":"Bash","tool_input":{"command":"rm -rf / --no-preserve-root"}}'
run "D rm -rf / (not in high-stakes regex), closed port" JEV_BASE_URL=http://127.0.0.1:9
--- case: A no key, no env (default base 127.0.0.1:8009, closed)
exit=0 ms=159
stdout={"hookSpecificOutput":{"hookEventName":"PreToolUse","additionalContext":"jev guardrail: could not reach http://127.0.0.1:8009 (fetch failed); skipping review."},"systemMessage":"jev guardrail unreachable, skipping review: fetch failed"}
--- case: B no key, JEV_BASE_URL=http://127.0.0.1:9 (closed)
exit=0 ms=152
stdout={"hookSpecificOutput":{"hookEventName":"PreToolUse","additionalContext":"jev guardrail: could not reach http://127.0.0.1:9 (fetch failed); skipping review."},"systemMessage":"jev guardrail unreachable, skipping review: fetch failed"}
--- case: C non-high-stakes command, closed port
exit=0 ms=83
--- case: D rm -rf / (not in high-stakes regex), closed port
exit=0 ms=73

File hashes: lib.mjs sha256 2064e808…089e; pretooluse-guardrail.mjs sha256 d6890148…d079. Empty stderr lines are omitted from the output above.

Before you install: eight checks

  1. Owner. Official means github.com/typesafe-ai only. Every other server, hook or plugin is community code. (The github.com/TypeSafeAI organisation is an unofficial community organisation.)
  2. What it installs. A skill is instructions only. An MCP server is advisory, because the agent can ignore it. Only hooks can deny or ask. Look for hooks/hooks.json, .claude-plugin/plugin.json or settings.json snippets in the README.
  3. Default mode. Two of the seven audited guardrails ship in a shadow or log-only mode (jev-claude shadow; oh-my-claudecode shadow points). Installing them gates nothing until you change the mode.
  4. What leaves your machine. Find where the state is built. The audited range runs from nothing to the last 30 messages in full (see the figure above).
  5. Failure branch. Find the catch, the timeout constant and the no-key check (see the next section). Decide whether that behaviour is acceptable for the action being guarded. The general choice between failing closed, holding for review and failing open is on Errors and rate limits.
  6. Timeout against round trip. A guard whose timeout is shorter than the real round trip fails on every call. oh-my-claudecode defaulted to 250 ms up to v5.5.0 and to 2,000 ms from v5.6.0.
  7. Model ID. Check the model string the integration sends on your route: jev-1.13.0 direct, typesafe/jev-1.13 on OpenRouter, typesafe-ai/jev on Vercel (route matrix). A local-model default such as kev-latest sent to TypeSafe is a likely silent failure.
  8. Key scope. Prefer a plugin's sensitive userConfig field or an environment variable over a key in a project settings.json that may be committed.

Documented method derived from the six audits, 29 Sep 2026; it makes no claim about live behaviour

How to check an integration yourself

  1. Pin a commit. Open the repository and press y on a file view, or use the tags page, to get a permanent URL.
  2. Search the source for fetch(, systemone, evaluate( and system_one( to find the one call site.
  3. From the call site, read four things: the timeout constant (timeout, AbortController, timeoutMs), the catch block, the check for a missing key, and what the code does when the response lacks the expected field.
  4. Map each branch to one of four outcomes: stops, asks a person, proceeds, or only flags.
  5. Search the tests for "fail", "timeout", "unreachable" and "invalid". Note whether they use a fake server and which mode they set.
  6. If the hook is a small standard-library script, run it with no key and the endpoint pointed at a closed local port, as in the worked example, and read the exit code and output. Testing without a key covers mocks for your own code.

Source notes per integration

Official plugin typesafe@typesafe-ai
  • Install: claude plugin marketplace add typesafe-ai/skills, then claude plugin install typesafe@typesafe-ai. Other agents: npx skills add typesafe-ai/skills --skill typesafe-ai ("project-local by default; add -g to install globally"). Source: docs.typesafe.ai/agent-skill. Documented
  • The tree at the tag has 9 entries: marketplace and plugin manifests, README, licences and one SKILL.md (about 150 lines). The skill says "The live TypeSafe docs are the source of truth" and "Keep API credentials server-side in web apps" (SKILL.md). Any Jev call you see after installing it is made by your agent, not by the plugin. Licence MIT.
  • The skill links a v1 migration guide that returns 404. This is open issue #13, and the pool confirmed the 404 on 29 Sep. Issue #2 asks that the skill stop triggering on "TypeScript" requests. Reported
  • Whether claude plugin install installs for the user or the project is not stated in TypeSafe's docs and was not tested.
danna-zhou/jev-mcp (hooks and MCP server)
  • Fail-open helper: every exception (no key, unreachable, 8,000 ms abort, non-2xx, invalid JSON, missing fields) prints a warning and exits 0 (lib.mjs L46–61; pretooluse-guardrail.mjs L24–85).
  • Mapping: Choice risk (safe / moderate / dangerous) and Noul needs_human. "dangerous" with confidence ≥ 0.6 → deny.
  • Stop hook: SHOULD_BLOCK = false. A local log ~/.claude/jev-quality-log.jsonl stores scores, cwd, session ID and a 200-character preview (stop-guardrail.mjs).
  • Defaults: JEV_BASE_URL=http://127.0.0.1:8009, JEV_API_KEY="local", JEV_MODEL="kev-latest" (index.ts L16–18). No retries, no tests. package.json says MIT, but there is no LICENSE file.
brunopivetta88/jev-claude ("jev-guard")
  • Defaults: mode: 'shadow', timeoutMs: 1500, failOpen: true, redaction on (config.mjs). Shadow mode turns every decision into allow (policy.mjs L81–105).
  • Missing key, timeout, non-2xx or "no usable answers" all count as failure (jev-client.mjs). An 8 s watchdog exits with "allowing" (entry.mjs).
  • Payload built in run.mjs L131–139. Redaction masks private keys, cloud and chat tokens, sk-… keys, JWTs and *SECRET/TOKEN/PASSWORD/API_KEY= values. Results are cached for 60 s under .jev-guard/ in the project directory.
  • A deterministic rule floor runs first, with or without Jev; a test asserts rm -rf / is blocked with no key, in enforce mode. The manifests name a different owner (bruno-ship-it); this was not investigated.
jkudish/jev-mcp
  • Malformed or missing answers become status: "invalid_response" with recommendation: review (index.ts L296–372). Error texts redact the configured key.
  • Transports: OpenRouter, Cloudflare and compatible endpoints use one 60 s deadline, up to 3 attempts, retrying 408/409/429/5xx with 0.5–4 s jittered backoff (provider.ts L28–49). TypeSafe direct and Vercel go through @jkudish/jev-agent-tools, which was not read: timeout and retries unknown.
  • "The server never blocks on its own; enforcement stays with the calling agent" (README L242). Reported
  • Node ≥ 22; depends on @typesafe-ai/sdk ^0.6.0. Extensive mocked tests exist; not run by the pool.
LangChain AutoModeMiddleware
  • Class langchain_typesafe.experimental.middleware.AutoModeMiddleware, installed with the [experimental] extra. It was read from the PyPI source distribution, not installed. The release tag langchain-typesafe==0.0.1a3 is commit 4af7ab8, read for framework integrations on 5 Oct 2026.
  • "Classification failures propagate and the tool handler is not called, so failures are fail-closed." "This middleware blocks risky calls; it does not request human approval." (auto_mode.py L94–98)
  • Timeout 30 s; no retry code (classifier.py L36–38). This matches the single-attempt row on Errors and rate limits. With no key, TypeSafeClassifier() raises "TypeSafe API key is required" (classifier.py L255–265).
  • Payload: messages[-30:], the tool call id, name and full arguments, and the tool description (auto_mode.py L170–182). The trace policy hides this payload from LangChain traces only.
oh-my-claudecode Jev judgment points
  • Configuration: OMC_JEV=off or a list of points; OMC_JEV_TIMEOUT_MS default 250 (2,000 from v5.6.0); OMC_JEV_EXCERPT_CHARS default 200; ACTIVATED_POINTS is empty, so enabled points run in shadow (config.ts L1–31). Model jev-latest is hard-coded.
  • On timeout, HTTP error or invalid response the heuristic "twin" decides and the call is logged as degraded (resolver.ts). The project's decision record rejects fail-closed: "blocking the orchestration on an external judgment API would make OMC hostage to one dependency" (ADR 03665).
  • Timeout history: PR #4092 raised it to 2,000 ms and was merged on 22 Sep, 22:21 UTC, into the dev branch. On 29 Sep, v5.5.0 and main still set 250 ms (L27); only dev set 2,000 ms (L36). The change was released in v5.6.0 on 1 Oct 2026 (config.ts L36 at e74b22c, read 3 Oct). v5.6.0 also adds environment activation (OMC_JEV=<point>:active, commit 3681dcb3, #4093) and fixes the request shape (lowercase types; Score criteria sent as a list). Documented
  • No retries ("the interactive path degrades instead"). Tests use injected fetch stubs; not run by the pool. Which hook events each point runs in (points.ts) was not read.
madisonrickert/jev-permission-gate
  • Pin 7349bc9 (3 Oct). HEAD checked by git ls-remote on 6 Oct 2026, 05:20:19 UTC (R9-S70): HEAD 7349bc9 = run-7 pin; failure files unchanged. Cells from the run-7 read of the source, 4 Oct 2026 (R7-S85). Documented
  • Default gate_mode "enforce" (register.ts L88, L222). Timeout 1,500 ms (policy.ts L37). No key (register.ts L333–341), timeout (L360–365) and errors (L377–381) fall back to Claude Code's built-in classifier. Malformed answers: typesafe.ts L54–74; register.ts L198. Thresholds and defer: policy.ts L27–42, L423–445.
  • Bypass: engine already decided or not auto mode (register.ts L305–316); tools other than Bash, WebFetch and WebSearch; secrets, too-long or empty input (policy.ts L28, L348–383); measure mode; cache hits reuse a stored verdict. Opt-in logs in enforce mode; a write failure never affects the decision (register.ts L47–70). 4 test files; not read.
gulbaki/jev-llm-guard
  • Pin 7c7b1b5 (1 Oct; Show HN 49919953, 1 Oct). HEAD checked by git ls-remote on 6 Oct 2026, 05:20:19 UTC (R9-S70): HEAD 7c7b1b5 = run-7 pin; failure files unchanged. Cells from the run-7 read of the source, 4 Oct 2026 (R7-S84). Documented
  • Returns verdict; not a decision: the jev-guard CLI prints Decision: <ACTION> and exits 0 for allow, review and block (cli.js L31–41); it exits 1 only when evaluation throws (L41) or input is over 20,000 characters (L28). The demo server returns the analysis as JSON and enforces nothing (web-server.js L76–100). A CI step that runs jev-guard fails only on an error, not on a "block" verdict.
  • No key, 30,000 ms timeout, HTTP errors and malformed answers all throw (guard.js L50–71). Thresholds 0.4 and 0.8 are set in code (policy.js L32, L42–45). No audit log; tests stubbed, not run.

Seen, not audited

These are one-line self-descriptions by their authors, recorded on 29 Sep 2026 (Reported). The pool did not read their failure paths, so this page makes no fail-open or fail-closed claim about them.

Routing and context-compaction plugins (effort-router, Jevgrep, fast-jev-compaction) are not covered here because they do not guard tool calls.

What was not verified

  • No integration was run against the real Jev API. The offline run covered unreachable endpoints only; the 401/403 no-key path of the danna-zhou hook is read from code.
  • jkudish/jev-mcp's timeout and retries for TypeSafe direct and Vercel live in @jkudish/jev-agent-tools, which was not read.
  • The danna-zhou MCP server sets no timeout; what happens on a hanging endpoint depends on Node and the MCP client and was not tested.
  • jev-claude's deterministic rule list and its Codex adapter were not read line by line; oh-my-claudecode's per-point hook events were not read, and its npm package name was not verified.
  • Whether TypeSafe accepts model: "kev-latest" is unknown.

Search published pools, pages, reports, and evidence.