Shaduf.Research preview
Build18 integrations read in pinned source · checked , 05:17–05:27 UTC · first read 6 Oct

How to use Jev with Codex, OpenCode, Cursor and Hermes Agent (TypeSafe AI)

This page answers one question for each Jev plugin, hook and MCP server for coding agents: when the Jev call fails, does the agent's tool call still run? When the pool checked search suggestions on , Google suggested "how to use jev with codex" and "how to use jev with opencode", and "jev hermes" appeared on Google, Bing and DuckDuckGo. A suggestion shows that people search for a phrase, not how many do.

Key finding

Of 18 Jev coding-agent integrations read in source, 1 is vendor-published and none comes from TypeSafe; 8 act on Jev's answer, and 4 of those let the tool call run when Jev errors.

Documentedsource at pinned commits, checked

Picked from the plan's list, the Hermes Agent catalog, three GitHub searches and the pool's daily scan; not a survey. The vendor-published one is OpenClaw's plugin. The pool installed and ran nothing: no agent, hook, plugin or MCP server was started and no Jev call was made. npm tarballs were downloaded and read, not executed. The 4 that hold or block the tool call when Jev errors are jev-kit, bloudhood's Codex approval hook, jev-approvals and jev-curator.

2 of the 8 (jev-approvals, jev-curator) do nothing until you switch them on. jev-approvals is off after install: Hermes core's default approval mode is manual, so you must set approvals.mode: smart. jev-curator runs in observe by default: Jev does not block anything until you change the mode to guard or apply. Two more start in a softer mode: jev-judge only logs (shadow) until you switch on enforce, and osuki uses Jev only if you pick TypeSafe as its decision provider.

Does the tool call still run when Jev fails? The 8 integrations that act on Jev's answer

One row per implementation that acts on Jev's answer itself: 8 rows. By host: Codex 3 (jev-kit, bloudhood, rh-guard), Cursor 1 (rh-guard), OpenCode 2 (opencode-tool-gate, osuki) and Hermes Agent 3 (jev-approvals, jev-curator, jev-judge). rh-guard is one row that covers both Codex and Cursor, so the host numbers add up to 9 for 8 rows. 4 of the 5 hosts have a counted row; OpenClaw has none. Columns (a) to (e) are the five failure cases: (a) no API key, (b) the Jev call times out, (c) Jev returns an HTTP error, (d) the answer is malformed, (e) Jev is unsure (below the integration's threshold). Cells use the pool's shared failure vocabulary. Unread cells say not recorded. Documented source at the pins in Sources. 6 rows read 6 Oct 2026, 05:14–05:29 UTC; jev-approvals and jev-curator settled and the rh-guard, opencode-tool-gate and osuki cells rechecked 7 Oct 2026, 05:17–05:27 UTC. Spot-checked by the runner against the raw files: bloudhood, rh-guard, jev-judge (6 Oct) and Hermes core approval.py, approval_smart.py and OpenCode agent.ts (7 Oct). jev-kit and opencode-tool-gate were read by the runner; osuki and jev-curator were read by a helper and not spot-checked

Integration (pin)Hosts and hook pointPublisherMode after install(a) No key(b) Timeout(c) HTTP error(d) Malformed(e) Low confidenceBypassTool call still runs on a Jev failure?
keiffff/jev-kit jev-agent-review3d74b05 (5 Oct 2026, 19:00 UTC); npm @jev-kit/cli 0.3.1Codex and Claude Code; PermissionRequest command hook (4 s hook timeout in both examples)Community (keiffff); MITEnforcing once the hook is configured, approve-only: it auto-approves or defers to the host's own prompt and never deniesfail-closedHeld for the host's own promptfail-closedSDK default 10 s, no retries; held for the host's promptfail-closedHeld (defer)fail-closedHeld (defer)heldAllow only if policy-compliant ≥ 0.7, instruction-aligned ≥ 0.7 and high-risk ≤ 0.15 (example policy), else deferOnly permission requests reach it; secret-like input is deferred without a Jev callNoThe host asks you (a–d)
bloudhood/codex-jev-approval-hookb6242c9 (pushed 29 Sep 2026)Codex; PermissionRequest hook for Bash, apply_patch and mcp__ tools; 12 s host timeout; PowerShellCommunity (bloudhood); MITEnforcing for allow and deny; otherwise Codex's own approvalfail-closedHeld for Codex's own approvalfail-closedDefault 5 s (1–5 allowed), 9 s budget; heldfail-closedHeldfail-closedHeldheldAllow needs ≥ 0.98 with deny ≤ 0.01; deny needs ≥ 0.80 (author's constants)Only Bash, apply_patch and mcp__; stops deciding after 3 denials in a row or 20 per sessionNoCodex asks you (a–d)
anpicasso/hermes-jev-approvals jev-approvals v0.3.0Plugin 28be98a (catalog commit) with Hermes Agent core v2026.9.24 = f97608f (24 Sep 2026, latest release on 7 Oct)Hermes Agent; answers Hermes core's smart-approval question for commands Hermes flags as dangerousCommunity (anpicasso); MITOff after install. Hermes core's default approval mode is manual; it acts only with approvals.mode: smart. Then an APPROVE runs the command without a person (core tools/approval.py L774–777)fail-closedThe plugin raises; Hermes core escalates to a personfail-closedPlugin deadline 25 s (core default 30 s); held for a personfail-closedCore turns any error into escalate (approval_smart.py L126–131)fail-closedAn empty or unknown answer escalates (L115–125)heldAn APPROVE below confidence 0.55 becomes ESCALATE (plugin jev_policy.py L13, L54–59)Mode off or yolo; permanent allowlist; commands with no dangerous or tirith warning never reach it; non-interactive contexts skip the smart stepNoA person decides; with no answer the gateway or CLI denies (a–d)
anpicasso/hermes-jev-curator jev-curator v0.1.04e8626c (catalog commit; its own repository)Hermes Agent; pre_tool_call guard on skill_manage calls from Hermes's background review, plus a skill lifecycle hook that starts a dry-run scanCommunity (anpicasso); MITObserve by default: Jev judges skills, but nothing is blocked until you set mode guard or apply. In those modes, plans built from Jev's judgments decide which background skill deletes or patches may go ahead, with no person involved. The deletes come from Hermes core's background review; the plugin does not start themnot recordedtransport.py not readfail-closed25 s; that pair gets no judgment, so a background delete or patch it would cover is blockedfail-closedNo judgment, no plan: blockednot recordednot recordedThresholds in graph.py not readModes off and observe leave the guard inert; foreground skill operations are never gated; creates and unknown actions pass; other tools are ignored; an exception in the outer hook lets the call throughNoIn guard mode, background deletes and patches not covered by a plan are blocked (b–c); other skill operations are unaffected
24601/rh-guardc2e682e (pushed 28 Sep 2026)Codex (PreToolUse) and Cursor (preToolUse, beforeShellExecution)Community (24601); MITShadow, review or enforce (RH_GUARD_MODE). Default enforce: unset, empty or unknown values give enforce (kinds.ts L176–189), so a default install can blockfallback-lexical detectorsfallback-lexical detectors1,200 msfallback-lexical detectorsfallback-lexical detectorsUnparseable answers droppedacts-anywaySteer message only, below 0.5 on a mutating step (hard-coded)Codex matcher omits MCP tools; a structural deny skips Jev; shadow mode (opt-in) returns "ok"ConditionalIn the default enforce mode the call runs on a Jev error, with a steer message on mutating steps, unless the structural or lexical detectors alone reach a block threshold (0.70–0.88 by kind); then it is denied (score.ts L98–109, L174–181)
justmytwospence/opencode-tool-gate 0.1.0bdf1ef8 (6 Oct 2026, 02:59 UTC)OpenCode; tool.execute.before plugin hookCommunity (justmytwospence); MITEnforcing by default (enabled: true)fallback-opencode permission rulesThe gate allows the call; OpenCode's own rules applyfallback-opencode permission rules3,000 ms defaultfallback-opencode permission rulesfallback-opencode permission rulesMissing fields lead to allowacts-anywayHeld only above set cuts (for example irreversible ≥ 0.9, exfiltration ≥ 0.8); user-configurableRead-only tools and allowTools skip Jev; an always-held list (sudo, force-push main, curl | sh and others) is held without JevYesOpenCode's default rules allow every tool ("*": "allow"); they ask only for paths outside the project, repeated identical calls and .env reads. Your own permission config can change thisOpenCode v1.18.35 = 53d1eab, packages/opencode/src/agent/agent.ts L119–136
@osuki-dev/opencode-osuki-agentPinned at 0.2.7 (npm, 4 Oct 2026); tag v0.2.7 = c96ce03; tarball and tag not matched file by file. Checked at 0.2.8 (npm, 5 Oct 2026, 11:40 UTC; tag v0.2.8 = 0ae9e88; 7 Oct 2026): failure path unchanged; the hook lines moved by 9. The 0.2.8 tarball was not matched to its tag file by file eitherOpenCode; reroutes the subagent tool and prunes the tool listCommunity (osuki-dev); MITEnforcing (router). Jev is opt-in: the default decision provider is opencode.ai/zen; TypeSafe needs TYPESAFE_API_KEYfallback-default tier"standard"fallback-default tier10,000 ms, then a cooldownfallback-default tier60 s cooldown skips Jevfallback-default tierTool pruning falls back to the full tool listfallback-default tierBelow 0.75 (routing) or 0.8 (tools); plugin optionsFixed roles (plan, review, explore) skip Jev; a previous decision is reusedYesThe subagent runs on the default tier with all tools (a–d)
DoGMaTiiC/hermes-jev jev-judge5dddbea (25 Sep 2026; catalog commit = HEAD). The same repository ships jev-skill-router, an advisory skill hint, listed here and not counted separatelyHermes Agent; pre_tool_call hook plus a jev_ask toolCommunity (DoGMaTiiC); MIT; Hermes catalog "Community"Shadow (log-only) by default. The cells to the right describe enforce mode, where it asks you to confirm terminal, write_file and patch calls it flagsfail-openfail-open3.0 s default, capped at 10 sfail-openfail-openacts-anyway"Clear" unless destructive ≥ 0.90, exfiltration ≥ 0.70 or impact ≥ 2.5 (user-configurable)Unlisted tools; 300 s cache; circuit breaker after three 429/529 responses (fail-open); any hook exception fails openYesIn enforce mode (a–d); in the default shadow mode it never stops a call
  • fail-closed or held: the tool call waits for you or the host's own prompt
  • fail-open or acts-anyway: the tool call can run; "conditional" cells that can act count here
  • fallback-<what>: a named substitute decides
  • no-decision: nothing returned; the caller must handle it
  • advisory: Jev never decides
  • not recorded or not applicable

jev-judge starts in shadow mode. After install it only logs what it would do. Its row describes enforce mode, which you switch on yourself. It is counted because the enforcing path is in the same repository.

The 8 integrations that act: who holds the tool call when Jev fails, and where the 18 come from

  • Jev errors (timeout or HTTP error)4/8 hold or block the call, 4/8 let it run
    • Heldjev-kit
    • Heldbloudhood
    • Heldjev-approvals
    • Blockedjev-curator (guard mode)
    • Runs, conditionalrh-guard
    • Runsopencode-tool-gate
    • Runsosuki
    • Runsjev-judge (enforce)
  • No API key, or a malformed answer3/8 hold, 4/8 run, 1/8 not recorded
    • Heldjev-kit
    • Heldbloudhood
    • Heldjev-approvals
    • Runs, conditionalrh-guard
    • Runsopencode-tool-gate
    • Runsosuki
    • Runsjev-judge (enforce)
    • Not recordedjev-curator
  • Jev is unsure (below threshold)counted apart from errors: 3/8 held, 3/8 acts-anyway, 1/8 fallback, 1/8 not recorded
    • Heldjev-kit
    • Heldbloudhood
    • Heldjev-approvals
    • Acts anywayrh-guard (steer only)
    • Acts anywayopencode-tool-gate
    • Fallbackosuki (default tier)
    • Acts anywayjev-judge (enforce)
    • Not recordedjev-curator
  • Who publishes the 18by publisher
    • Host vendor: 1/18OpenClaw
    • TypeSafe: 0/18none found
    • Community: 17/18personal repositories
Counts from the 8 counted rows and the 10 rows not counted on this page; they describe these 18 integrations only. Green: held or blocked. Red: the call can run (rh-guard's "conditional" cell counts here). Blue: a named fallback decides. Dashed: not recorded. TypeSafe's GitHub organisation has 12 repositories, none a coding-agent plugin (R9-S38). Documented 7 Oct 2026.

The 10 not counted: they do not act on Jev's answer themselves

These integrations were read in source but do not decide the tool call. Of the 10, 8 return Jev's answer to the agent, 2 give advisory hints, and 0 are not settled. jev-approvals and jev-curator, not settled on 6 Oct, were settled on 7 Oct and moved to the counted table. Documented source at the pins in Sources, 6 Oct 2026; OpenClaw spot-checked by the runner; the other 9 are helper reads, not spot-checked

GroupIntegration (pin)Hosts and hook pointPublisherWhy not counted(a) No key(b) Timeout(c) HTTP errorTool call still runs?
Returns to the agent@openclaw/typesafe 2026.9.8npm (3 Oct 2026); provenance commit aa6008aOpenClaw; decision provider; disabled by defaultHost vendor (OpenClaw). npm provenance from the openclaw/openclaw repository; LICENSE "OpenClaw Foundation"; README "Official external plugin" ReportedGives Jev to the agent's model through OpenClaw core's decision_evaluate tool (core not read)no-decision"credentials-unavailable"no-decision30,000 ms default (1,000–60,000)no-decisionnot applicableGates nothing; the agent sees "unavailable"
Returns to the agentourines/hermes-jev jev v0.1.2Catalog commit 28a4ea3Hermes Agent; jev_evaluate toolCommunity (ourines); MITTool only; catalog card: "advisory judgments, no automatic tool gating"not recordednot recorded30 sError returned to the agentnot applicable
Returns to the agentajensenwaud/hermes-jev-plugin jev-typesafe v0.1.0b3d29f7 (= catalog commit)Hermes Agent; 4 plugin toolsCommunity (ajensenwaud); MITTool onlyno-decisionRaisesnot recorded30 sno-decisionError JSON to the agentnot applicable
Returns to the agentydmw74/jev-skill-router jev-skill-router-mcp76ee09e (= catalog commit)Hermes Agent; MCP tool skill_selectCommunity (ydmw74); MIT per plugin.json, no LICENSE fileTool onlyno-decisionnot recorded60 sno-decisionnot applicable
Returns to the agentNiazMorshed2007/jev-review57690afCodex, Cursor, OpenCode (also Claude Code); MCP tool jev_reviewCommunity; MITQuality scores returned to the agentno-decisionnot recorded30,000 ms, up to 2 retriesno-decisionnot applicable
Returns to the agentburnigtm/jev-mcp v0.1.09448f61Codex, Cursor; MCP tools including gateCommunity; MITgate returns auto, review or escalate; the CLI exits non-zero only on errors, so nothing is enforcedno-decisionnot recorded30,000 msno-decisionnot applicable
Returns to the agentminhgv/jev-mcp v0.3.01a1f0a5Cursor, Codex; MCP tools plus a ci-shadow CLICommunity; MITci-shadow prints would_block but always exits 0no-decisionnot recordedNo explicit timeout; SDK defaultno-decisionnot applicable
Returns to the agentpedroknigge/mcp_jev v0.0.1132377f8Cursor, Codex, Claude, Grok, Antigravity; MCP serverCommunity; MIT"The MCP returns signals only — harness allowlist and sandbox still required"no-decisionnot recorded20,000 msno-decisionnot applicable
Advisory hintDECRUX9812/typesafe-skill-routerCatalog commit e6cdac2Hermes Agent; pre_llm_call hookCommunity (DECRUX9812); MITadvisoryAdds a skill hint; the agent's model still picks. Off by defaultno-decisionSilentno-decision10 sno-decisionnot applicable
Advisory hintwellkilo/codex-jev-preflight633ddefCodex; UserPromptSubmit hook adding contextCommunity; MITadvisoryAdds a task-complexity note; gates no toolnot recordednot recorded15 sfail-openAdds an "unavailable" note and continuesnot applicable

How the 10 split: 8 return Jev's answer to the agent (@openclaw/typesafe, ourines jev, jev-typesafe, jev-skill-router-mcp, jev-review, burnigtm/jev-mcp, minhgv/jev-mcp, mcp_jev), so the agent's model decides what to do with it. 2 give advisory hints (typesafe-skill-router, codex-jev-preflight). 0 are not settled. 8 + 2 + 0 = 10 not counted; with the 8 counted rows, 18 read. DoGMaTiiC's jev-skill-router shares jev-judge's repository and is listed with it, not as a 19th integration.

Install-and-check list

Six questions to answer before you rely on any of these. Documented from the rows above, 7 Oct 2026; 18 integrations, 8 counted, 10 not counted. Cells still not recorded in the counted table: 3 of 40 (jev-curator: no key, malformed, low confidence)

  1. Who publishes it? 1 of 18 comes from the host vendor (OpenClaw's plugin). The other 17 are personal repositories. None comes from TypeSafe.
  2. Which mode does it start in? jev-approvals is off after install (Hermes core default manual; set approvals.mode: smart); jev-curator starts in observe and blocks nothing until you set guard or apply; jev-judge starts in shadow (log-only); typesafe-skill-router starts off. rh-guard starts in enforce, so a default install can block.
  3. What happens with no key? Unset the key and try a risky call. jev-kit, bloudhood and jev-approvals ask you; rh-guard, opencode-tool-gate, osuki and jev-judge (enforce mode) let it through or fall back; jev-curator's no-key path was not recorded. Test procedure: testing without a key.
  4. Which tools never reach Jev? Read the matcher. bloudhood covers Bash, apply_patch and mcp__ only; rh-guard's Codex matcher has no MCP tools; jev-approvals sees only commands Hermes flags as dangerous; jev-curator sees only background skill deletes and patches.
  5. Is the catalog commit the one you read? Three Hermes catalog entries install a commit other than the repository's HEAD, and jev-curator is in a different repository from the one recorded on 5 Oct (pins below).
  6. What leaves your machine? See the next section.

What leaves your machine

  • Can send file contents

    opencode-tool-gate (tool arguments up to 6,000 characters, so content being written), jev-judge (up to 12 arguments, each redacted and cut to 600 characters), jev-review (task, diff, full file contents and repository context, no cap or redaction) and osuki (tool results up to 900 characters, regex redaction only).

    4 integrations
  • Defers secret-like input instead of sending it

    jev-kit and bloudhood do not send requests that look like they contain secrets; they hand them to your own prompt instead. bloudhood's endpoint and model are set by you in settings.json (HTTPS only); no TypeSafe URL is hard-wired.

    2 integrations

Route data terms are on data privacy.

Hermes Agent catalog: which commit gets installed

The Hermes Agent plugin catalog says: "Every entry installs exactly the commit above" (R9-S64). The rows on this page cite the catalog-installed commit. At least 15 catalog entries mention Jev; 8 were read. Documented catalog pages read 6 Oct 2026, 05:17 UTC; HEADs by git ls-remote, 05:14 UTC

Catalog entryCatalog installsRepository HEADNote
jev (ourines/hermes-jev)28a4ea3 (v0.1.2)cdf59e4 (v0.2.0)v0.2.0 is not in the catalog; it adds model routing, off by default
typesafe-skill-routere6cdac294fe114Page cites the catalog commit
jev-approvals28be98a530fdb0The two files read are identical at both commits. Read with Hermes core v2026.9.24 (f97608f) on 7 Oct
jev-curator4e8626cNot comparedCorrection: its own repository, anpicasso/hermes-jev-curator. The 5 Oct research put it in the jev-approvals repository
jev-judge, jev-typesafe, jev-skill-router-mcp5dddbea, b3d29f7, 76ee09eSame as the catalog commitDoGMaTiiC's jev-skill-router was read at 5dddbea; its catalog source repository was not verified

Catalog entries seen by name only, not read: jev-agent-router, jev-cron-gate, jev-effort-router, jev-mcp-router, jev-memory-selector, jev-model-router, jev-skill-router; and cards that mention Jev: hermes-slash-router, tool-slimmer, hermes-switchyard, nerve, protean-ordaprompt, local-system-one-hermes, hermes-structured-aux-models.

What is on other pages

  • Model routers ("jev codex router": 0xNatoshi/jev-codex-router, kfchow-ai/kfchow-llm-value-router, ourines v0.2.0 routing) pick a model, not whether a tool call runs. Not audited here; see model routing.
  • Claude Code-only guards stay on Claude Code and MCP guards. jev-kit, jev-review and mcp_jev also target Claude Code; that page points here.
  • Library packages (LangChain, Pydantic AI and others) are on framework integrations.
  • Every counted row is also on when Jev fails, in the "Coding agents" domain, including jev-approvals and jev-curator from 7 Oct. Across that map, 13 of 64 implementations let the action go ahead on a Jev error.
  • All 18 are listed in the products ledger.

What was not verified

  • No agent, hook, plugin or MCP server was installed or run, and no Jev call was made. npm tarballs (@openclaw/typesafe 2026.9.8 and osuki 0.2.7 on 6 Oct; osuki 0.2.7 and 0.2.8 on 7 Oct) were downloaded and read, not executed, then deleted. Every cell is read from code; behaviour at run time may differ.
  • What Codex, Cursor and OpenClaw core do after a hook decision. Hermes core was read at v2026.9.24 for its approval path, but not the step that hands Hermes's call_llm request to the jev-approvals model provider. The jev-approvals cells rest on how core handles whatever that call returns or raises, which was read.
  • jev-curator: the no-key, malformed and low-confidence cells (transport.py and the graph.py thresholds not read), and how long a cached judgment from an earlier run stays valid and whether it still covers an operation after a Jev error.
  • Whether the osuki 0.2.7 and 0.2.8 tarballs match their tag files file by file. osuki's repository address was not recorded, so its row links npm.
  • rh-guard's redaction. How OpenCode maps write and patch to permission keys (it does not change the outcome, because "*": "allow" covers every key).
  • The contents of all test files (file names only).
  • Commit dates for 4 MCP repositories (jev-review, burnigtm/jev-mcp, minhgv/jev-mcp, mcp_jev).
  • Whether any of these is used in production: none verified.
Leads found but not read (names only, not audited)
  • GitHub search hits: qkal/Canny, onlyjq04/jev-agent-hooks, Yaxun-Yang/codex-effort-with-jev, leonaaardob/fast-dev-compaction, 455-dIAO/windows-save-token-jev-setup, Nanako0129/stingray, smixs/code-quality, 0xNatoshi/jev-codex-router.
  • Daily scan: bragamat/jevkit, fallen-blossom/flower-control, Steven2007yhq/Reinforced-Computer-use-in-Codex, justmytwospence/opencode-lean-context and opencode-auto-effort, omo-jev-plugin, omp-typesafe, @geminixiang/pi-jev, n-r-w/classifier-mcp, Rikinshah787/dotpals.
  • abaljeu/jev-mcp describes itself as "Patched jev-mcp for thejevai.com … Use with Cursor Cloud Agents MCP" Reported. thejevai.com is not a TypeSafe domain. How to tell official endpoints from others: official vs reseller.
  • The 7 further Hermes catalog jev-* plugins listed in the pins section.

Sources and check times (6 and 7 Oct 2026, UTC)

Per-row sources: pinned commits and file paths
  • jev-kit: R9-S72, R9-S73, R9-S75, R9-S85, R9-S86. keiffff/jev-kit at 3d74b05f85c1344ce4ae4b3f07b2eaaa6f957b07 (read 05:20; runner read). packages/hook-adapters/src/index.ts L24–31, L73–90; packages/agent-review/src/index.ts L112–123, L134–140, L151–158, L162–164, L238–283, L295–308; packages/decision-contract/src/index.ts L142, L153–156, L160, L214, L217, L223; packages/cli/src/cli.ts L76–81, L189–192; examples/codex-config.toml, examples/claude-settings.json. SDK @typesafe-ai/sdk 0.6.0 dist/index.mjs docstring (R9-S75).
  • bloudhood/codex-jev-approval-hook: R9-S81. at b6242c9802724550b54eb346d1df40adf997253d. hook.ps1 L13–24, L318–322, L334, L373, L451, L458–460, L581–595, L597, L598–601. Spot-checked by the runner (05:22).
  • 24601/rh-guard: R9-S82; 7 Oct: R10-S117, R10-S118. at c2e682ef0e838cc0538a7c2062e8a96d262dbd14. src/lib/risk/score.ts L91–106, L110–116, L136–146, L171–181, L239–250; src/lib/risk/jev.ts L75–78, L240, L245–247, L265–279, L335–338; hooks.ts L161–167; hosts.ts L194–195; hooks/run.ts L41–46. Spot-checked by the runner (05:22). 7 Oct (helper read, 05:20): src/lib/risk/kinds.ts L36, L39–61 (block thresholds), L176–189 (default mode enforce); score.ts L98–109, L125–146, L171–199, L236–241. Same commit, still HEAD on 7 Oct.
  • justmytwospence/opencode-tool-gate: R9-S74, R9-S85. at bdf1ef8d132a16db73814e94b23f8396b3976cac (read 05:20; runner read). src/index.ts L42–43, L240–265, L288, L313, L328–349, L352–380; src/jev.ts L33–36, L47, L51–60; src/judge.ts L147–182. 7 Oct: R10-S114, R10-S115, R10-S116. OpenCode v1.18.35 (latest release, published 6 Oct 2026, 20:18 UTC) at anomalyco/opencode 53d1eabb61e21162157817bf677da0a4ad3332e3 (sst/opencode resolves to the same repository): packages/opencode/src/agent/agent.ts L119–151 (default "*": "allow"; user config merged last); packages/opencode/src/permission/index.ts L28–38 (last matching rule wins). Runner spot-checked agent.ts.
  • @osuki-dev/opencode-osuki-agent 0.2.7: R9-S80. npm 0.2.7 (4 Oct 2026, 10:52 UTC); tag v0.2.7 = c96ce03c1c7dfc5c6fdf9d966691549101c68080. Tarball dist/index.js L59–68, L335–337, L343–394, L415–420, L969–1036, L1668–1737, L1751, L1764, L1829–1832. Helper read; not spot-checked. 7 Oct: R10-S112, R10-S113. npm 0.2.8 (5 Oct 2026, 11:40:53 UTC; npm sha1 dc959c68bd27836f9ece153b023e947efe948404; tag v0.2.8 = 0ae9e884a97a5539fef3f0772318a628c1f75e00), latest on npm on 7 Oct. dist/index.js diff against 0.2.7: the Jev call, timeout and fallback lines (L63, L343–394, L969–972) are identical; hook lines now L1677–1746, L1760, L1838–1841 (0.2.7 L1668–1737, L1751, L1829–1832). Non-failure changes: read-only roles always go to the explore agent (L993–994); new requireDispatch checks in osuki_route. Tarball not matched to the tag file by file.
  • DoGMaTiiC/hermes-jev jev-judge: R9-S63, R9-S64. at 5dddbeaac5be08281e6c3b372eeaba3639971f0a. plugins/jev-judge/__init__.py L43–58, L64–73, L77–91, L93–96; jev.py L44, L52, L281–283, L349–388, L397–401, L468–473, L480–482; gate.py L277–284, L345–357, L362–368; plugin.yaml. plugins/jev-skill-router L194–200, L224–226 (helper read, partial). jev-judge spot-checked by the runner (05:23).
  • @openclaw/typesafe 2026.9.8: R9-S69. openclaw/openclaw at aa6008ad198ef99c43f9d89dbd01694708712974 (npm provenance commit). extensions/typesafe/src/decisions.ts L28–30, L80–82; tarball dist/index.js L96–104, dist/.setup/errors-BdIwQubl.mjs L26–30, L45, client-CRLm45hB.mjs L244–256. Spot-checked by the runner (05:23). extensions/typesafe/package.json at that commit says 2026.9.7; the published version is 2026.9.8.
  • ourines/hermes-jev: R9-S66, R9-S60. at 28a4ea390f80d97fcdc8c20d6b630dfe2de645de. service.py L45, L73–80 (HEAD: L95–101, L149–177); client.py L132–148. Helper read; not spot-checked.
  • ajensenwaud/hermes-jev-plugin: R9-S67. at b3d29f71770a3447ad0b3db00658f64a8edc7dd3. client.py L22, L31–34, L132–158; tools.py L43–44, L59–64. Helper read; not spot-checked.
  • ydmw74/jev-skill-router: R9-S68. at 76ee09e049dbc10c76f98cfefc6ca16b42cfad38. src/jev_skill_router/mcp_server.py L150–158, L167, L169–173, L346–349. Helper read; not spot-checked.
  • NiazMorshed2007/jev-review: R9-S76. at 57690af54ef7d862c2483342c1e61c14dffcf727. src/mcp/server.ts L43–58; src/evaluation/input.ts L5–37; src/config/environment.ts L3–8; src/jev/client.ts L42, L71–81, L92–118. Helper read; not spot-checked.
  • burnigtm/jev-mcp: R9-S77. at 9448f6120015f2f6c6dad7137c7f234545209918. src/cli.ts L37–39; src/typesafe.ts L124–128; src/config.ts L214–222; src/errors.ts L53. Helper read; not spot-checked.
  • minhgv/jev-mcp: R9-S78. at 1a1f0a5b599e3c9f00a126bb247536a624aa265e. src/ci-shadow.ts L6–31; src/typesafe.ts L47–51; src/server.ts L236–244. Helper read; not spot-checked.
  • pedroknigge/mcp_jev: R9-S79. at 32377f8e4d5a63a76d4efbe9abf0b2fbf3f98a0d. src/packs/command-risk.ts L7–8; src/typesafe.ts L33–35; src/config.ts L9, L48; src/server.ts L21–27. Helper read; not spot-checked.
  • DECRUX9812/typesafe-skill-router: R9-S65. at e6cdac26f9ed588b4a94b8a2f7f9f026e1b9faf3. __init__.py L49, L55, L180–190, L242–247, L284–289; typesafe_router/client.py L292–306. Helper read; not spot-checked.
  • wellkilo/codex-jev-preflight: R9-S83. at 633ddefe6596aa5d7c6b00767c08d07edea61096. jev_user_prompt_hook.py L25, L175–196. Helper read (partial); not spot-checked.
  • anpicasso/hermes-jev-approvals (row): R9-S61, R9-S60, R10-S41. Plugin at 28be98a19539b29768398fb400f4c62f41337c26: plugin/__init__.py L100–105, L336–341, L495, L520–527, L543, L851, L911–931, L966–974 (6 Oct helper read); plugin/jev_policy.py L13, L54–59 (confidence 0.55; read 7 Oct, 05:25). Hermes Agent core (7 Oct, helper A, 05:18–05:20): R10-S101 release v2026.9.24 = NousResearch/hermes-agent f97608f178d1ffeca59860195ab7da295f7c8e5f; R10-S103 tools/approval.py L774–791, L808–815, L884–887, L918–919, L1178–1192, L1208–1209; R10-S102 tools/approval_smart.py L80–131; R10-S104 agent/auxiliary_client.py L6097, L6222–6230 (30 s default); R10-S105 tools/approval_context.py L228–241 (mode manual, approval wait 300 s). The runner spot-checked approval.py, approval_smart.py and the tag SHA.
  • anpicasso/hermes-jev-curator (row): R9-S62; 7 Oct: R10-S106 to R10-S111. at 4e8626c7d394a9cbef8594993ec4b208ffb3395f. plugin/plugin.yaml L24–29 (default observe), L50–53 (25 s); plugin/guard.py L35, L43, L57–74, L143–160, L376–396; plugin/service.py L79–104; plugin/debounce.py L88–96, L107; plugin/engine.py L80–95, L157–166; plugin/commands.py L102–104, L120–124. Helper read; not spot-checked.
  • R9-S11: search suggestions from Google (suggestqueries, client=firefox), Bing (osjson) and DuckDuckGo (ac), 05:19:23–05:19:30. A demand signal, not a volume.
  • R9-S38: TypeSafe's GitHub organisation repository list (12 repositories), 05:15:34.
  • R9-S60: git ls-remote HEAD for 6 Hermes plugin repositories, 05:14:50.
  • R9-S64: Hermes Agent plugin catalog pages (7 entries) and the rendered index, 05:17:40.
  • R9-S84: GitHub repository searches "jev codex hook" (26 results), "typesafe cursor hooks" (1) and "jev codex router" (96), 05:17:45.

Search published pools, pages, reports, and evidence.