Jev (TypeSafe AI) in Claude Code and MCP: which server, hook or plugin fails open?
Claude Code hooks, plugins and MCP servers exist that ask Jev whether an agent's next step is safe. This page compares what eight of them do when Jev has no key, times out, returns an error, returns something malformed or is unsure. It also shows what each one sends to Jev and which mode it uses after installation. Every cell comes from the integration's source code at a stated commit.
We read seven Jev guardrails in their source code. Only one of them stops the agent when Jev fails: LangChain AutoModeMiddleware. One, madisonrickert/jev-permission-gate, falls back to Claude Code's built-in classifier. Two ship in a shadow or log-only mode, one is advisory by design and one fails open. One, gulbaki/jev-llm-guard, only returns a verdict: it is not counted as a decision. The official TypeSafe plugin makes no Jev calls at all. Before you rely on any of them, check three things: its default mode, what it sends to Jev, and its timeout. Documented source at pinned commits, checked 29 Sep 2026; the two guard rows read 4 Oct and rechecked 6 Oct 2026
jev-kit (Codex and Claude Code), NiazMorshed2007/jev-review and pedroknigge/mcp_jev also target Claude Code; they are compared on coding agents.
Version checks, 2–7 Oct 2026
Two new releases, not yet read (7 Oct 2026, 05:21 UTC). oh-my-claudecode v5.6.2 is now a GitHub release (published 6 Oct 2026, 06:15 UTC). @jkudish/jev-mcp 0.14.1 was published on npm on 6 Oct 2026 (21:41 UTC; 0.14.0 at 20:54 UTC), a 0.x minor release after the 0.13.0 checked below. For both: targeted diff due in the next run; failure path not re-read. The rows below still give the failure paths checked at oh-my-claudecode v5.6.0 and jev-mcp 0.13.0. Documented (release v5.6.2, R10-S49; npm: @jkudish/jev-mcp 0.14.1, R10-S48)
oh-my-claudecode tag v5.6.2 (6 Oct). A git tag v5.6.2 exists with no GitHub release; the latest release is still v5.6.1 (checked 6 Oct 2026, 05:20 UTC). Its failure path was not re-read: the rows below still give the failure path checked at v5.6.0. Documented (tag and release listing)
oh-my-claudecode v5.6.1 (4 Oct). A patch release, v5.6.1, appeared on 3 Oct 2026 at 06:44 UTC. Its source was not re-read: the rows below give the failure path checked at v5.6.0. No other integration on this page had a new release when checked on 4 Oct 2026. Documented (release listing)
oh-my-claudecode v5.6.0 (3 Oct). oh-my-claudecode's latest release is v5.6.0 (1 Oct 2026). Checked at v5.6.0 (commit e74b22c) on 3 Oct 2026: failure path unchanged; default timeout now 2,000 ms. On a timeout, HTTP error or invalid response the heuristic twin still decides and "the resolver never throws" (resolver.ts L10–12); a point still stops calling Jev after 3 failures in a row; nothing is sent unless OMC_JEV lists points; excerpts are still cut to 200 characters; points still run in shadow by default. New in v5.6.0: OMC_JEV=<point>:active or OMC_JEV=all:active makes Jev decide (a warning is printed), and a script-side judgment channel follows the same degrade-never-block rule. The 250 ms default that made every call fall back (round trips of 465–605 ms reported by the maintainers, #4091, Reported) was raised to 2,000 ms in v5.6.0 (config.ts L36). If you run v5.5.0 or earlier, set OMC_JEV_TIMEOUT_MS=2000. Documented (source at commit e74b22cd, read 3 Oct 2026, 05:21 UTC).
jkudish/jev-mcp (2 Oct).
@jkudish/jev-mcp 0.12.0 (1 Oct) and 0.13.0 (2 Oct, 03:50 UTC) were compared with the audited 0.11.0 at their tagged commits: failure path unchanged. The server still only advises; malformed answers still come back as "review", and from 0.12.0 rate-limit and outage results come back as tool errors. 0.13.0 adds a repository example hook (not in the npm package) that denies a tool call at a block probability of 0.85 or more and, if Jev fails, defers to Claude Code's normal permission prompt. Documented (source diff), checked 2 Oct 2026, 05:22 UTC.
The other four are unchanged: langchain-typesafe is still 0.0.1a3; danna-zhou/jev-mcp was last pushed 23 Sep, brunopivetta88/jev-claude 25 Sep and typesafe-ai/skills 12 Sep (checked 2 Oct, 05:14 UTC). Sources: 0.11.0 to 0.12.0, 0.12.0 to 0.13.0, example hook. Plugins that pick which model answers, rather than allow or deny a tool call, are compared on Jev Router or your own model router?
What you get by default
Installing a Jev guardrail can mean anything from no runtime effect to a guard that halts the agent whenever Jev is unavailable. The figure places each audited integration by what it does as installed. Dashed entries are modes you have to switch on yourself.
Effect on the agent as installed, from none (top) to strongest (bottom)
- No Jev callText instructions for your agent only
- Official
typesafe@typesafe-aiplugin
- Official
- Records onlyShadow or display mode; nothing is blocked
- jev-claude (default
shadow) - oh-my-claudecode Jev points (shadow; its built-in heuristic decides)
- danna-zhou Stop hook
- jev-claude (default
- Advises the agentReturns a recommendation; the agent may ignore it
- jkudish/jev-mcp
- danna-zhou MCP tools
- Gates, but lets the call through if Jev failsCan deny or ask; fails open
- danna-zhou PreToolUse hook
- jev-claude
enforce(defaultfailOpen)
- Gates, and stops or asks if Jev failsFails closed
- LangChain
AutoModeMiddleware(stops the run) - jev-claude
enforcewithJEV_GUARD_FAIL_OPEN=false(asks a person)
- LangChain
Failure matrix: what happens to the tool call
Each cell says what happens to the agent's action in one failure class. "Normal permission flow" means the hook emits no decision, so Claude Code's own permission rules apply. It is not an approval. Use the filter to compare default modes with the opt-in ones.
| Integration and mode after install | (a) No key | (b) Timeout (default) | (c) HTTP 4xx / 5xx | (d) Malformed response | (e) Low confidence |
|---|---|---|---|---|---|
| Official TypeSafe plugin (typesafe@typesafe-ai)Mode: Instructions only | n/aNo runtime path | n/a | n/a | n/a | n/a |
danna-zhou/jev-mcp: PreToolUse hookMode: Enforcing (deny or ask) once added to settings.json | Proceeds anyway (fail-open)Sends Bearer local; any failure → normal permission flow Tested offline | Proceeds anyway (fail-open)8,000 ms | Proceeds anyway (fail-open) | Proceeds anyway (fail-open) | Holds for a person (held)"dangerous" below 0.6 confidence, or "moderate" → ask. "safe" proceeds unless needs_human ≥ 0.6 |
| danna-zhou/jev-mcp: Stop hookMode: Display only | Flags only (advisory)The turn ends normally | Flags only (advisory)8,000 ms | Flags only (advisory) | Flags only (advisory) | Flags only (advisory)Scores are displayed only |
| danna-zhou/jev-mcp: MCP toolsMode: Advisory | Flags only (advisory)Error returned to the agent | No timeout in codeBehaviour on a hang not tested | Flags only (advisory)Error to the agent | Flags only (advisory)JSON parse error to the agent | Flags only (advisory)Raw answer returned; the agent decides |
| jev-claude ("jev-guard" 0.1.0), as installedMode: Shadow (log and note) | Flags only (advisory) | Flags only (advisory) | Flags only (advisory) | Flags only (advisory) | Flags only (advisory)Every decision becomes "allow" plus a note |
| jev-claude, enforce mode with the default fail-openMode: Opt-in | Proceeds anyway (fail-open)Its own deterministic rules still apply | Proceeds anyway (fail-open)1,500 ms; hard deadline 8,000 ms → allow | Proceeds anyway (fail-open)Rules still apply | Proceeds anyway (fail-open)A 200 without usable answers counts as a failure, not an all-clear | Allow, warn, ask or block (conditional)Per-signal thresholds, e.g. destructive: block 0.85, ask 0.6, warn 0.35 |
| jev-claude, enforce mode with fail-open switched offMode: Opt-in | Holds for a person (fail-closed) | Holds for a person (fail-closed) | Holds for a person (fail-closed) | Holds for a person (fail-closed) | Allow, warn, ask or block (conditional)As above |
| jkudish/jev-mcp v0.11.0 (12 tools)Mode: Advisory: "The server never blocks on its own". Checked at 0.13.0: failure path unchanged | Flags only (advisory)The tool call returns an error | Flags only (advisory)60 s over all attempts (OpenRouter, Cloudflare, compatible endpoints). TypeSafe direct and Vercel: unknown | Flags only (advisory)3 attempts on 408/409/429/5xx (fetch transports) | Flags only (advisory)invalid_response with a "review" recommendation, not "pass" | Flags only (advisory)pass / review / block / skip advice; jev_screen blocks at ≥ 0.75, reviews at ≥ 0.25 |
| LangChain AutoModeMiddleware (langchain-typesafe 0.0.1a3)Mode: Enforcing for listed tools only; other tools bypass it | Stops (fail-closed)The middleware cannot be constructed (ValueError), so the agent is not built | Stops (fail-closed)30 s; the exception ends the agent run and the tool is not executed | Stops (fail-closed)The run raises; tests assert the tool did not run | Stops (fail-closed)Exception | Tool runs below 0.5 (acts-anyway)Noul "is_risky" below 0.5 → the tool runs; at 0.5 or above → error message to the agent, which continues. Threshold fixed at 0.5 |
oh-my-claudecode Jev judgment points, as installed (default shadow) (audited v5.5.0 at 9fd35ec; rechecked at v5.6.0, 3 Oct: failure path unchanged)Mode: Shadow by default: Jev never decides, so the points are advisory; the built-in heuristic decides whether or not Jev answers. A key alone sends nothing: no point runs unless OMC_JEV lists it. After 3 failures in a row a point stops calling for the process | Heuristic decides (advisory)The point is off; nothing is sent | Heuristic decides (advisory)2,000 ms default from v5.6.0; 250 ms up to v5.5.0 | Heuristic decides (advisory)Jev's answer is only logged in shadow mode | Heuristic decides (advisory)The response is validated | No gate (advisory)Jev never decides at default settings |
oh-my-claudecode, active modeMode: Opt-in from v5.6.0: OMC_JEV=<point>:active or all:active makes Jev decide (a warning is printed). On any Jev failure the heuristic decides | Heuristic decides (fallback-heuristic)The point is off; nothing is sent | Heuristic decides (fallback-heuristic)2,000 ms default from v5.6.0 | Heuristic decides (fallback-heuristic) | Heuristic decides (fallback-heuristic)The response is validated | No confidence gateJev's first answer is used |
madisonrickert/jev-permission-gate (7349bc9)Mode: Enforcing by default (gate_mode "enforce"); acts only when Claude Code's own engine says "ask" in auto mode. Bypassed when the engine already decided or not in auto mode, for tools other than Bash, WebFetch and WebSearch, for input with secrets or too long, in measure mode and on cache hits | Built-in classifier decides (fallback)Claude Code's built-in classifier decides (register.ts L333–341) | Built-in classifier decides (fallback)1,500 ms (policy.ts L37; register.ts L360–365, L377–381) | Built-in classifier decides (fallback)Error caught (register.ts L377–381) | Built-in classifier decides (fallback)hooks/typesafe.ts L54–74; register.ts L198, L377–381 | Built-in classifier decides (fallback)Defers unless allow (serves_request ≥ 0.5, every risk ≤ 0.1) or deny (a risk ≥ 0.8, serves_request ≤ 0.3) (policy.ts L27–42, L423–445) |
gulbaki/jev-llm-guard (7c7b1b5)Mode: Returns verdict; not a decision. The jev-guard CLI exits 0 for allow, review and block; the demo server enforces nothing. Not a Claude Code hook; not counted | Returns verdict; not a decision (no-decision)Throws "TYPESAFE_API_KEY is required" (guard.js L50); the CLI exits 1 | Returns verdict; not a decision (no-decision)30,000 ms (guard.js L51); throws, the CLI exits 1 | Returns verdict; not a decision (no-decision)Rethrown (guard.js L61–63); the CLI exits 1 | Returns verdict; not a decision (no-decision)Strict validators throw (guard.js L27–40, L67–71); the CLI exits 1 | Returns verdict; not a decision (no-decision)Signal below 0.4 → allow; 0.4 or above → review; 0.8 or above → block, except LLM07 (policy.js L32, L42–45). Nothing enforces it: the CLI exits 0 for all three |
- fail-closed: stops the call or run, or holds it for a person (held)
- fail-open or acts-anyway: the tool call goes ahead
- advisory: flags only, Jev never decides; conditional: thresholds you set decide
- fallback: a built-in heuristic or classifier decides
- no-decision: an error, and no verdict
- Not applicable or not set
Colours follow the shared legend used on when Jev fails and framework integrations. Changed 6 Oct 2026: until then this page coloured "Stops" red and "Proceeds anyway" green. The cells themselves did not change, except that the AutoModeMiddleware low-confidence cell now leads with what happens below 0.5 (the tool runs), as on when Jev fails.
Owner, version, data sent and grade
| Integration | Owner and type | Sends to Jev | Pinned version or commit (date) | Grade and label |
|---|---|---|---|---|
typesafe-ai/skills: plugin typesafe@typesafe-ai | Official (TypeSafe AI). Claude Code plugin with one skill; no hook, no MCP server, no script | Nothing. The skill tells your agent to read docs.typesafe.ai | v0.5.7, 65a39f3 (12 Sep) | A · Documented all contents read · checked 29 Sep |
| danna-zhou/jev-mcp | Community. Two Claude Code hook scripts (PreToolUse on Bash, Stop) added by hand to settings.json, plus an MCP server | PreToolUse: the full Bash command, only if it matches a "high-stakes" pattern (git push, publish, kubectl delete, terraform apply, DROP TABLE…); no redaction. Stop: the agent's full final message | 436469a (23 Sep); no tags | A · Documented; no-key cell also Tested offline · 29 Sep |
| brunopivetta88/jev-claude ("jev-guard") | Community. Claude Code hook plugin (SessionStart, UserPromptSubmit, PreToolUse, PostToolUse, Stop); Codex adapter not audited | User goal (≤ 1,500 characters), tool name and full tool input (regex-redacted; strings ≤ 4,000 characters), last 8 action summaries, working directory. Read-only tools with a clean rule check are not sent | 0.1.0, 7d7e876; PR #1 merged 25 Sep | A · Documented · 29 Sep |
jkudish/jev-mcp (@jkudish/jev-mcp) | Community. MCP server with 12 judgment tools (verify, screen, noul, find, classify, decide, rerank, compare, extract, audit, review, gate); no hook | Only what the agent passes to a tool (for example jev_screen: the text and an optional purpose) | Checked at 0.13.0: failure path unchanged (audited 0.11.0, 53fe575, 29 Sep, 05:30 UTC) | A for the tool layer and fetch transports; TypeSafe-direct timeout unknown (dependency not read) · Documented; README "never blocks on its own" Reported · 29 Sep |
langchain-typesafe AutoModeMiddleware | LangChain (framework vendor, not TypeSafe). Python agent middleware that guards the tools you list; experimental alpha | The proposed tool call (id, name, full arguments), the tool description and the last 30 messages of the agent state, all roles, full text. No redaction | 0.0.1a3 (released 20 Sep): tag langchain-typesafe==0.0.1a3 = 4af7ab8; sdist sha256 d77647a7…3272 | A · Documented released package read · 29 Sep |
| oh-my-claudecode Jev judgment points | Community. A Jev layer inside the plugin's own hooks | Nothing unless OMC_JEV lists points ("a key alone sends nothing anywhere"); then per-point text, each string cut to 200 characters | v5.5.0 = main = 9fd35ec (22 Sep); dev differs | A · Documented · 29 Sep |
| madisonrickert/jev-permission-gate | Community. Claude Code plugin on tool.check (hooks/hooks.json L3; hooks/register.ts L293–382); shadow and measure modes optional | Last 3 user and 3 peer messages (each cut to 1,500 characters head and tail), the Bash command (≤ 2,000 characters) and description (cut to 300), WebFetch URL and prompt, WebSearch query, project directory (policy.ts L348–414). Calls carrying a secret are never sent (L279–320) | 7349bc9 (3 Oct). HEAD 7349bc9 = run-7 pin on 6 Oct; failure files unchanged | A candidate (code read; not verified in production) · Documented · read 4 Oct, rechecked 6 Oct. README "1 unsafe allow in 3,664 risky calls" Reported |
| gulbaki/jev-llm-guard | Community. Node library (evaluateGuardrail), jev-guard CLI and demo web server; not a Claude Code hook. Returns verdict; not a decision (not counted) | Untrusted text (≤ 20,000 characters; longer input is rejected, not cut; context.js L2, L15), context, optional trusted task and app context; 13 questions (guard.js L18–25); up to 2 more calls for quotations | 7c7b1b5 (1 Oct). HEAD 7c7b1b5 = run-7 pin on 6 Oct; failure files unchanged | A candidate (code read; not verified in production) · Documented · read 4 Oct, rechecked 6 Oct |
Grades use the same scale as Products and projects: A means the pool read the code that calls Jev. It does not mean the integration works well or has users. Star counts are not adoption.
What leaves your machine
Data sent to Jev per guarded action, audited range
- Official plugin; oh-my-claudecode unless enabledNothing
- oh-my-claudecode with points enabledPer-point text, each string cut to 200 characters
- danna-zhou PreToolUse hookOne full shell command, only if it matches the high-stakes pattern; not redacted
- jev-claudeGoal, full tool input and 8 action summaries, with regex redaction of keys and tokens
- LangChain
AutoModeMiddlewareThe last 30 messages in full, including tool outputs, plus the full tool call; not redacted
A timeout shorter than the round trip turns the guard off
If the timeout is shorter than the time Jev takes to answer, every call fails. The integration then takes its failure path on every call, which is "proceed" or "heuristic" for most of the integrations above. oh-my-claudecode defaulted to 250 ms up to v5.5.0, below the 465–605 ms round trips its maintainers measured; v5.6.0 (1 Oct 2026) defaults to 2,000 ms.
Default timeouts against one project's measured round trips (shaded band)
OMC_JEV_TIMEOUT_MS (or the equivalent) above it. Documented timeouts from source, 29 Sep 2026; oh-my-claudecode v5.6.0 read 3 Oct 2026.Caveats before you rely on this table
- "Normal permission flow" means Claude Code's own rules apply. It is not an approval. Documented 29 Sep
- LangChain
AutoModeMiddleware0.0.1a3 sends no risk criteria unless you passcriteria=NoulCriteria(...). The constructor'scriteria=Nonedefault replaces the documented default criteria (auto_mode.pyL66–71, L147, L164), and a unit test assertscriteria is None. Documented 29 Sep - danna-zhou hooks: set
JEV_MODEL=jev-1.13.0when you point them at TypeSafe. The defaultkev-latestis meant for a local Kev server. Whether TypeSafe rejectskev-latestwas not tested. Earlier third-party reports say unknown models return 400, and this hook would treat that as "skip review". Documented defaults; the consequence is the pool's inference 29 Sep - oh-my-claudecode: defaulted to 250 ms up to v5.5.0, while the maintainers measured 465–605 ms round trips (Reported, #4091, 22 Sep); v5.6.0 defaults to 2,000 ms. On v5.5.0 or earlier, set
OMC_JEV_TIMEOUT_MSabove your round trip. From v5.6.0,OMC_JEV=<point>:activelets Jev decide, so check your environment for it. Documented 29 Sep; v5.6.0 on 3 Oct - jev-claude's own tests run in
enforcemode; the shipped default isshadow. Passing tests do not show that the installed plugin blocks anything. Documented 29 Sep - No integration was run against the live Jev API, and star counts are not adoption.
Worked example: the danna-zhou hook with no key
Tested (offline, no Jev call) Node v24.20.0, 29 Sep 2026, about 07:12 UTC. The hook (86 lines) and its helper (62 lines) use only Node built-ins and were read in full before running. They were fetched at commit 436469a2 into a temporary directory, then deleted. Nothing was installed.
The pool piped four PreToolUse events into the hook with an empty environment (no key). The endpoint pointed at ports on 127.0.0.1 that were confirmed closed.
| Case | Command in the event | Endpoint | Exit | Output | Sent to Jev? |
|---|---|---|---|---|---|
| A | git push origin main | default 127.0.0.1:8009 (closed) | 0 (159 ms) | "jev guardrail unreachable, skipping review: fetch failed" | Attempted; failed → proceeds |
| B | git push origin main | 127.0.0.1:9 (closed) | 0 (152 ms) | Same message | Attempted; failed → proceeds |
| C | ls -la | 127.0.0.1:9 (closed) | 0 (83 ms) | None | No: not in the high-stakes pattern |
| D | rm -rf / --no-preserve-root | 127.0.0.1:9 (closed) | 0 (73 ms) | None | No: not in the high-stakes pattern |
Reading. Exit 0 with no permissionDecision means Claude Code's normal permission flow applies, so the Jev layer fails open. Case D shows that the pattern list, not Jev, decides what this guard checks: a destructive command outside the list is never sent. The run does not show the behaviour against the real API with a missing or invalid key (the 401/403 path). The code sends that path to the same fail-open helper.
Runner script and raw output
# bash, pool-authored; run in a temporary directory with the two hook files
run(){ echo "--- case: $1"; shift; start=$(date +%s%N)
out=$(echo "$PAYLOAD" | env -i PATH=$PATH "$@" node hooks/pretooluse-guardrail.mjs 2>err.txt); code=$?
end=$(date +%s%N); echo "exit=$code ms=$(( (end-start)/1000000 ))"; echo "stdout=$out"; echo "stderr=$(cat err.txt)"; }
PAYLOAD='{"hook_event_name":"PreToolUse","tool_name":"Bash","tool_input":{"command":"git push origin main"}}'
run "A no key, no env (default base 127.0.0.1:8009, closed)"
run "B no key, JEV_BASE_URL=http://127.0.0.1:9 (closed)" JEV_BASE_URL=http://127.0.0.1:9
PAYLOAD='{"hook_event_name":"PreToolUse","tool_name":"Bash","tool_input":{"command":"ls -la"}}'
run "C non-high-stakes command, closed port" JEV_BASE_URL=http://127.0.0.1:9
PAYLOAD='{"hook_event_name":"PreToolUse","tool_name":"Bash","tool_input":{"command":"rm -rf / --no-preserve-root"}}'
run "D rm -rf / (not in high-stakes regex), closed port" JEV_BASE_URL=http://127.0.0.1:9
--- case: A no key, no env (default base 127.0.0.1:8009, closed)
exit=0 ms=159
stdout={"hookSpecificOutput":{"hookEventName":"PreToolUse","additionalContext":"jev guardrail: could not reach http://127.0.0.1:8009 (fetch failed); skipping review."},"systemMessage":"jev guardrail unreachable, skipping review: fetch failed"}
--- case: B no key, JEV_BASE_URL=http://127.0.0.1:9 (closed)
exit=0 ms=152
stdout={"hookSpecificOutput":{"hookEventName":"PreToolUse","additionalContext":"jev guardrail: could not reach http://127.0.0.1:9 (fetch failed); skipping review."},"systemMessage":"jev guardrail unreachable, skipping review: fetch failed"}
--- case: C non-high-stakes command, closed port
exit=0 ms=83
--- case: D rm -rf / (not in high-stakes regex), closed port
exit=0 ms=73
File hashes: lib.mjs sha256 2064e808…089e; pretooluse-guardrail.mjs sha256 d6890148…d079. Empty stderr lines are omitted from the output above.
Before you install: eight checks
- Owner. Official means
github.com/typesafe-aionly. Every other server, hook or plugin is community code. (Thegithub.com/TypeSafeAIorganisation is an unofficial community organisation.) - What it installs. A skill is instructions only. An MCP server is advisory, because the agent can ignore it. Only hooks can deny or ask. Look for
hooks/hooks.json,.claude-plugin/plugin.jsonorsettings.jsonsnippets in the README. - Default mode. Two of the seven audited guardrails ship in a shadow or log-only mode (jev-claude
shadow; oh-my-claudecode shadow points). Installing them gates nothing until you change the mode. - What leaves your machine. Find where the
stateis built. The audited range runs from nothing to the last 30 messages in full (see the figure above). - Failure branch. Find the
catch, the timeout constant and the no-key check (see the next section). Decide whether that behaviour is acceptable for the action being guarded. The general choice between failing closed, holding for review and failing open is on Errors and rate limits. - Timeout against round trip. A guard whose timeout is shorter than the real round trip fails on every call. oh-my-claudecode defaulted to 250 ms up to v5.5.0 and to 2,000 ms from v5.6.0.
- Model ID. Check the model string the integration sends on your route:
jev-1.13.0direct,typesafe/jev-1.13on OpenRouter,typesafe-ai/jevon Vercel (route matrix). A local-model default such askev-latestsent to TypeSafe is a likely silent failure. - Key scope. Prefer a plugin's sensitive
userConfigfield or an environment variable over a key in a projectsettings.jsonthat may be committed.
Documented method derived from the six audits, 29 Sep 2026; it makes no claim about live behaviour
How to check an integration yourself
- Pin a commit. Open the repository and press
yon a file view, or use the tags page, to get a permanent URL. - Search the source for
fetch(,systemone,evaluate(andsystem_one(to find the one call site. - From the call site, read four things: the timeout constant (
timeout,AbortController,timeoutMs), thecatchblock, the check for a missing key, and what the code does when the response lacks the expected field. - Map each branch to one of four outcomes: stops, asks a person, proceeds, or only flags.
- Search the tests for "fail", "timeout", "unreachable" and "invalid". Note whether they use a fake server and which mode they set.
- If the hook is a small standard-library script, run it with no key and the endpoint pointed at a closed local port, as in the worked example, and read the exit code and output. Testing without a key covers mocks for your own code.
Source notes per integration
Official plugin typesafe@typesafe-ai
- Install:
claude plugin marketplace add typesafe-ai/skills, thenclaude plugin install typesafe@typesafe-ai. Other agents:npx skills add typesafe-ai/skills --skill typesafe-ai("project-local by default; add-gto install globally"). Source: docs.typesafe.ai/agent-skill. Documented - The tree at the tag has 9 entries: marketplace and plugin manifests, README, licences and one
SKILL.md(about 150 lines). The skill says "The live TypeSafe docs are the source of truth" and "Keep API credentials server-side in web apps" (SKILL.md). Any Jev call you see after installing it is made by your agent, not by the plugin. Licence MIT. - The skill links a v1 migration guide that returns 404. This is open issue #13, and the pool confirmed the 404 on 29 Sep. Issue #2 asks that the skill stop triggering on "TypeScript" requests. Reported
- Whether
claude plugin installinstalls for the user or the project is not stated in TypeSafe's docs and was not tested.
danna-zhou/jev-mcp (hooks and MCP server)
- Fail-open helper: every exception (no key, unreachable, 8,000 ms abort, non-2xx, invalid JSON, missing fields) prints a warning and exits 0 (lib.mjs L46–61; pretooluse-guardrail.mjs L24–85).
- Mapping: Choice
risk(safe / moderate / dangerous) and Noulneeds_human. "dangerous" with confidence ≥ 0.6 → deny. - Stop hook:
SHOULD_BLOCK = false. A local log~/.claude/jev-quality-log.jsonlstores scores,cwd, session ID and a 200-character preview (stop-guardrail.mjs). - Defaults:
JEV_BASE_URL=http://127.0.0.1:8009,JEV_API_KEY="local",JEV_MODEL="kev-latest"(index.ts L16–18). No retries, no tests.package.jsonsays MIT, but there is no LICENSE file.
brunopivetta88/jev-claude ("jev-guard")
- Defaults:
mode: 'shadow',timeoutMs: 1500,failOpen: true, redaction on (config.mjs). Shadow mode turns every decision into allow (policy.mjs L81–105). - Missing key, timeout, non-2xx or "no usable answers" all count as failure (jev-client.mjs). An 8 s watchdog exits with "allowing" (entry.mjs).
- Payload built in run.mjs L131–139. Redaction masks private keys, cloud and chat tokens,
sk-…keys, JWTs and*SECRET/TOKEN/PASSWORD/API_KEY=values. Results are cached for 60 s under.jev-guard/in the project directory. - A deterministic rule floor runs first, with or without Jev; a test asserts
rm -rf /is blocked with no key, in enforce mode. The manifests name a different owner (bruno-ship-it); this was not investigated.
jkudish/jev-mcp
- Malformed or missing answers become
status: "invalid_response"withrecommendation: review(index.ts L296–372). Error texts redact the configured key. - Transports: OpenRouter, Cloudflare and compatible endpoints use one 60 s deadline, up to 3 attempts, retrying 408/409/429/5xx with 0.5–4 s jittered backoff (provider.ts L28–49). TypeSafe direct and Vercel go through
@jkudish/jev-agent-tools, which was not read: timeout and retries unknown. - "The server never blocks on its own; enforcement stays with the calling agent" (README L242). Reported
- Node ≥ 22; depends on
@typesafe-ai/sdk ^0.6.0. Extensive mocked tests exist; not run by the pool.
LangChain AutoModeMiddleware
- Class
langchain_typesafe.experimental.middleware.AutoModeMiddleware, installed with the[experimental]extra. It was read from the PyPI source distribution, not installed. The release taglangchain-typesafe==0.0.1a3is commit4af7ab8, read for framework integrations on 5 Oct 2026. - "Classification failures propagate and the tool handler is not called, so failures are fail-closed." "This middleware blocks risky calls; it does not request human approval." (
auto_mode.pyL94–98) - Timeout 30 s; no retry code (
classifier.pyL36–38). This matches the single-attempt row on Errors and rate limits. With no key,TypeSafeClassifier()raises "TypeSafe API key is required" (classifier.pyL255–265). - Payload:
messages[-30:], the tool call id, name and full arguments, and the tool description (auto_mode.pyL170–182). The trace policy hides this payload from LangChain traces only.
oh-my-claudecode Jev judgment points
- Configuration:
OMC_JEV=offor a list of points;OMC_JEV_TIMEOUT_MSdefault 250 (2,000 from v5.6.0);OMC_JEV_EXCERPT_CHARSdefault 200;ACTIVATED_POINTSis empty, so enabled points run in shadow (config.ts L1–31). Modeljev-latestis hard-coded. - On timeout, HTTP error or invalid response the heuristic "twin" decides and the call is logged as degraded (resolver.ts). The project's decision record rejects fail-closed: "blocking the orchestration on an external judgment API would make OMC hostage to one dependency" (ADR 03665).
- Timeout history: PR #4092 raised it to 2,000 ms and was merged on 22 Sep, 22:21 UTC, into the
devbranch. On 29 Sep, v5.5.0 andmainstill set 250 ms (L27); onlydevset 2,000 ms (L36). The change was released in v5.6.0 on 1 Oct 2026 (config.ts L36 at e74b22c, read 3 Oct). v5.6.0 also adds environment activation (OMC_JEV=<point>:active, commit3681dcb3, #4093) and fixes the request shape (lowercase types; Score criteria sent as a list). Documented - No retries ("the interactive path degrades instead"). Tests use injected fetch stubs; not run by the pool. Which hook events each point runs in (
points.ts) was not read.
madisonrickert/jev-permission-gate
- Pin
7349bc9(3 Oct). HEAD checked bygit ls-remoteon 6 Oct 2026, 05:20:19 UTC (R9-S70): HEAD 7349bc9 = run-7 pin; failure files unchanged. Cells from the run-7 read of the source, 4 Oct 2026 (R7-S85). Documented - Default
gate_mode"enforce" (register.ts L88, L222). Timeout 1,500 ms (policy.ts L37). No key (register.ts L333–341), timeout (L360–365) and errors (L377–381) fall back to Claude Code's built-in classifier. Malformed answers: typesafe.ts L54–74; register.ts L198. Thresholds and defer: policy.ts L27–42, L423–445. - Bypass: engine already decided or not auto mode (register.ts L305–316); tools other than Bash, WebFetch and WebSearch; secrets, too-long or empty input (policy.ts L28, L348–383); measure mode; cache hits reuse a stored verdict. Opt-in logs in enforce mode; a write failure never affects the decision (register.ts L47–70). 4 test files; not read.
gulbaki/jev-llm-guard
- Pin
7c7b1b5(1 Oct; Show HN 49919953, 1 Oct). HEAD checked bygit ls-remoteon 6 Oct 2026, 05:20:19 UTC (R9-S70): HEAD 7c7b1b5 = run-7 pin; failure files unchanged. Cells from the run-7 read of the source, 4 Oct 2026 (R7-S84). Documented - Returns verdict; not a decision: the
jev-guardCLI printsDecision: <ACTION>and exits 0 for allow, review and block (cli.js L31–41); it exits 1 only when evaluation throws (L41) or input is over 20,000 characters (L28). The demo server returns the analysis as JSON and enforces nothing (web-server.js L76–100). A CI step that runsjev-guardfails only on an error, not on a "block" verdict. - No key, 30,000 ms timeout, HTTP errors and malformed answers all throw (guard.js L50–71). Thresholds 0.4 and 0.8 are set in code (policy.js L32, L42–45). No audit log; tests stubbed, not run.
Seen, not audited
These are one-line self-descriptions by their authors, recorded on 29 Sep 2026 (Reported). The pool did not read their failure paths, so this page makes no fail-open or fail-closed claim about them.
- codaaiteam/jev-mcp (MIT, pushed 22 Sep): "MCP server for Jev … give any agent typed, calibrated decisions". Flag: the same owner's
jev-aiandjev-typesafe-airepositories say "Try it free: jevtypesafeai.com". Eye Security (25 Sep) names jevtypesafeai.com as a lookalike reseller storefront; see official vs reseller. This is a link, not evidence of wrongdoing. - AutoJev jev-mcp: not found (GitHub search "autojev mcp" returned 0 results); owner unknown.
- npm
mcp-jev2.0.1 (28 Sep): "Two tools: jev_decide (noul/choice/score) and jev_list_models." - Afloat16/jev-mcp (created 28 Sep): "Unofficial conservative MCP server for TypeSafe AI Jev".
- jkudish/jev-agent-tools: "multi-provider transport layer that supports fail-closed validation"; the dependency of jkudish/jev-mcp.
- Created 28–29 Sep, 0–1 stars each: jev-scope-control, jev-gate, cc-jev-teacher, drift-guard, jevis, jev-harness, jev-linter, and qualixar/jev-decision-layer (Show HN, 29 Sep).
- Older, not audited: toolgate ("calibrated tool-call firewall"), jev-kit, jev-pruner, jev-judge-mcp, burnigtm/jev-mcp, permit-mcp.
Routing and context-compaction plugins (effort-router, Jevgrep, fast-jev-compaction) are not covered here because they do not guard tool calls.
What was not verified
- No integration was run against the real Jev API. The offline run covered unreachable endpoints only; the 401/403 no-key path of the danna-zhou hook is read from code.
- jkudish/jev-mcp's timeout and retries for TypeSafe direct and Vercel live in
@jkudish/jev-agent-tools, which was not read. - The danna-zhou MCP server sets no timeout; what happens on a hanging endpoint depends on Node and the MCP client and was not tested.
- jev-claude's deterministic rule list and its Codex adapter were not read line by line; oh-my-claudecode's per-point hook events were not read, and its npm package name was not verified.
- Whether TypeSafe accepts
model: "kev-latest"is unknown.