How to use Jev with Codex, OpenCode, Cursor and Hermes Agent (TypeSafe AI)
This page answers one question for each Jev plugin, hook and MCP server for coding agents: when the Jev call fails, does the agent's tool call still run? When the pool checked search suggestions on , Google suggested "how to use jev with codex" and "how to use jev with opencode", and "jev hermes" appeared on Google, Bing and DuckDuckGo. A suggestion shows that people search for a phrase, not how many do.
Of 18 Jev coding-agent integrations read in source, 1 is vendor-published and none comes from TypeSafe; 8 act on Jev's answer, and 4 of those let the tool call run when Jev errors.
Picked from the plan's list, the Hermes Agent catalog, three GitHub searches and the pool's daily scan; not a survey. The vendor-published one is OpenClaw's plugin. The pool installed and ran nothing: no agent, hook, plugin or MCP server was started and no Jev call was made. npm tarballs were downloaded and read, not executed. The 4 that hold or block the tool call when Jev errors are jev-kit, bloudhood's Codex approval hook, jev-approvals and jev-curator.
2 of the 8 (jev-approvals, jev-curator) do nothing until you switch them on. jev-approvals is off after install: Hermes core's default approval mode is manual, so you must set approvals.mode: smart. jev-curator runs in observe by default: Jev does not block anything until you change the mode to guard or apply. Two more start in a softer mode: jev-judge only logs (shadow) until you switch on enforce, and osuki uses Jev only if you pick TypeSafe as its decision provider.
Does the tool call still run when Jev fails? The 8 integrations that act on Jev's answer
One row per implementation that acts on Jev's answer itself: 8 rows. By host: Codex 3 (jev-kit, bloudhood, rh-guard), Cursor 1 (rh-guard), OpenCode 2 (opencode-tool-gate, osuki) and Hermes Agent 3 (jev-approvals, jev-curator, jev-judge). rh-guard is one row that covers both Codex and Cursor, so the host numbers add up to 9 for 8 rows. 4 of the 5 hosts have a counted row; OpenClaw has none. Columns (a) to (e) are the five failure cases: (a) no API key, (b) the Jev call times out, (c) Jev returns an HTTP error, (d) the answer is malformed, (e) Jev is unsure (below the integration's threshold). Cells use the pool's shared failure vocabulary. Unread cells say not recorded. Documented source at the pins in Sources. 6 rows read 6 Oct 2026, 05:14–05:29 UTC; jev-approvals and jev-curator settled and the rh-guard, opencode-tool-gate and osuki cells rechecked 7 Oct 2026, 05:17–05:27 UTC. Spot-checked by the runner against the raw files: bloudhood, rh-guard, jev-judge (6 Oct) and Hermes core approval.py, approval_smart.py and OpenCode agent.ts (7 Oct). jev-kit and opencode-tool-gate were read by the runner; osuki and jev-curator were read by a helper and not spot-checked
| Integration (pin) | Hosts and hook point | Publisher | Mode after install | (a) No key | (b) Timeout | (c) HTTP error | (d) Malformed | (e) Low confidence | Bypass | Tool call still runs on a Jev failure? |
|---|---|---|---|---|---|---|---|---|---|---|
keiffff/jev-kit jev-agent-review3d74b05 (5 Oct 2026, 19:00 UTC); npm @jev-kit/cli 0.3.1 | Codex and Claude Code; PermissionRequest command hook (4 s hook timeout in both examples) | Community (keiffff); MIT | Enforcing once the hook is configured, approve-only: it auto-approves or defers to the host's own prompt and never denies | fail-closedHeld for the host's own prompt | fail-closedSDK default 10 s, no retries; held for the host's prompt | fail-closedHeld (defer) | fail-closedHeld (defer) | heldAllow only if policy-compliant ≥ 0.7, instruction-aligned ≥ 0.7 and high-risk ≤ 0.15 (example policy), else defer | Only permission requests reach it; secret-like input is deferred without a Jev call | NoThe host asks you (a–d) |
bloudhood/codex-jev-approval-hookb6242c9 (pushed 29 Sep 2026) | Codex; PermissionRequest hook for Bash, apply_patch and mcp__ tools; 12 s host timeout; PowerShell | Community (bloudhood); MIT | Enforcing for allow and deny; otherwise Codex's own approval | fail-closedHeld for Codex's own approval | fail-closedDefault 5 s (1–5 allowed), 9 s budget; held | fail-closedHeld | fail-closedHeld | heldAllow needs ≥ 0.98 with deny ≤ 0.01; deny needs ≥ 0.80 (author's constants) | Only Bash, apply_patch and mcp__; stops deciding after 3 denials in a row or 20 per session | NoCodex asks you (a–d) |
anpicasso/hermes-jev-approvals jev-approvals v0.3.0Plugin 28be98a (catalog commit) with Hermes Agent core v2026.9.24 = f97608f (24 Sep 2026, latest release on 7 Oct) | Hermes Agent; answers Hermes core's smart-approval question for commands Hermes flags as dangerous | Community (anpicasso); MIT | Off after install. Hermes core's default approval mode is manual; it acts only with approvals.mode: smart. Then an APPROVE runs the command without a person (core tools/approval.py L774–777) | fail-closedThe plugin raises; Hermes core escalates to a person | fail-closedPlugin deadline 25 s (core default 30 s); held for a person | fail-closedCore turns any error into escalate (approval_smart.py L126–131) | fail-closedAn empty or unknown answer escalates (L115–125) | heldAn APPROVE below confidence 0.55 becomes ESCALATE (plugin jev_policy.py L13, L54–59) | Mode off or yolo; permanent allowlist; commands with no dangerous or tirith warning never reach it; non-interactive contexts skip the smart step | NoA person decides; with no answer the gateway or CLI denies (a–d) |
anpicasso/hermes-jev-curator jev-curator v0.1.04e8626c (catalog commit; its own repository) | Hermes Agent; pre_tool_call guard on skill_manage calls from Hermes's background review, plus a skill lifecycle hook that starts a dry-run scan | Community (anpicasso); MIT | Observe by default: Jev judges skills, but nothing is blocked until you set mode guard or apply. In those modes, plans built from Jev's judgments decide which background skill deletes or patches may go ahead, with no person involved. The deletes come from Hermes core's background review; the plugin does not start them | not recordedtransport.py not read | fail-closed25 s; that pair gets no judgment, so a background delete or patch it would cover is blocked | fail-closedNo judgment, no plan: blocked | not recorded | not recordedThresholds in graph.py not read | Modes off and observe leave the guard inert; foreground skill operations are never gated; creates and unknown actions pass; other tools are ignored; an exception in the outer hook lets the call through | NoIn guard mode, background deletes and patches not covered by a plan are blocked (b–c); other skill operations are unaffected |
24601/rh-guardc2e682e (pushed 28 Sep 2026) | Codex (PreToolUse) and Cursor (preToolUse, beforeShellExecution) | Community (24601); MIT | Shadow, review or enforce (RH_GUARD_MODE). Default enforce: unset, empty or unknown values give enforce (kinds.ts L176–189), so a default install can block | fallback-lexical detectors | fallback-lexical detectors1,200 ms | fallback-lexical detectors | fallback-lexical detectorsUnparseable answers dropped | acts-anywaySteer message only, below 0.5 on a mutating step (hard-coded) | Codex matcher omits MCP tools; a structural deny skips Jev; shadow mode (opt-in) returns "ok" | ConditionalIn the default enforce mode the call runs on a Jev error, with a steer message on mutating steps, unless the structural or lexical detectors alone reach a block threshold (0.70–0.88 by kind); then it is denied (score.ts L98–109, L174–181) |
justmytwospence/opencode-tool-gate 0.1.0bdf1ef8 (6 Oct 2026, 02:59 UTC) | OpenCode; tool.execute.before plugin hook | Community (justmytwospence); MIT | Enforcing by default (enabled: true) | fallback-opencode permission rulesThe gate allows the call; OpenCode's own rules apply | fallback-opencode permission rules3,000 ms default | fallback-opencode permission rules | fallback-opencode permission rulesMissing fields lead to allow | acts-anywayHeld only above set cuts (for example irreversible ≥ 0.9, exfiltration ≥ 0.8); user-configurable | Read-only tools and allowTools skip Jev; an always-held list (sudo, force-push main, curl | sh and others) is held without Jev | YesOpenCode's default rules allow every tool ("*": "allow"); they ask only for paths outside the project, repeated identical calls and .env reads. Your own permission config can change thisOpenCode v1.18.35 = 53d1eab, packages/opencode/src/agent/agent.ts L119–136 |
@osuki-dev/opencode-osuki-agentPinned at 0.2.7 (npm, 4 Oct 2026); tag v0.2.7 = c96ce03; tarball and tag not matched file by file. Checked at 0.2.8 (npm, 5 Oct 2026, 11:40 UTC; tag v0.2.8 = 0ae9e88; 7 Oct 2026): failure path unchanged; the hook lines moved by 9. The 0.2.8 tarball was not matched to its tag file by file either | OpenCode; reroutes the subagent tool and prunes the tool list | Community (osuki-dev); MIT | Enforcing (router). Jev is opt-in: the default decision provider is opencode.ai/zen; TypeSafe needs TYPESAFE_API_KEY | fallback-default tier"standard" | fallback-default tier10,000 ms, then a cooldown | fallback-default tier60 s cooldown skips Jev | fallback-default tierTool pruning falls back to the full tool list | fallback-default tierBelow 0.75 (routing) or 0.8 (tools); plugin options | Fixed roles (plan, review, explore) skip Jev; a previous decision is reused | YesThe subagent runs on the default tier with all tools (a–d) |
DoGMaTiiC/hermes-jev jev-judge5dddbea (25 Sep 2026; catalog commit = HEAD). The same repository ships jev-skill-router, an advisory skill hint, listed here and not counted separately | Hermes Agent; pre_tool_call hook plus a jev_ask tool | Community (DoGMaTiiC); MIT; Hermes catalog "Community" | Shadow (log-only) by default. The cells to the right describe enforce mode, where it asks you to confirm terminal, write_file and patch calls it flags | fail-open | fail-open3.0 s default, capped at 10 s | fail-open | fail-open | acts-anyway"Clear" unless destructive ≥ 0.90, exfiltration ≥ 0.70 or impact ≥ 2.5 (user-configurable) | Unlisted tools; 300 s cache; circuit breaker after three 429/529 responses (fail-open); any hook exception fails open | YesIn enforce mode (a–d); in the default shadow mode it never stops a call |
- fail-closed or held: the tool call waits for you or the host's own prompt
- fail-open or acts-anyway: the tool call can run; "conditional" cells that can act count here
- fallback-<what>: a named substitute decides
- no-decision: nothing returned; the caller must handle it
- advisory: Jev never decides
- not recorded or not applicable
jev-judge starts in shadow mode. After install it only logs what it would do. Its row describes enforce mode, which you switch on yourself. It is counted because the enforcing path is in the same repository.
The 8 integrations that act: who holds the tool call when Jev fails, and where the 18 come from
- Jev errors (timeout or HTTP error)4/8 hold or block the call, 4/8 let it run
- Heldjev-kit
- Heldbloudhood
- Heldjev-approvals
- Blockedjev-curator (guard mode)
- Runs, conditionalrh-guard
- Runsopencode-tool-gate
- Runsosuki
- Runsjev-judge (enforce)
- No API key, or a malformed answer3/8 hold, 4/8 run, 1/8 not recorded
- Heldjev-kit
- Heldbloudhood
- Heldjev-approvals
- Runs, conditionalrh-guard
- Runsopencode-tool-gate
- Runsosuki
- Runsjev-judge (enforce)
- Not recordedjev-curator
- Jev is unsure (below threshold)counted apart from errors: 3/8 held, 3/8 acts-anyway, 1/8 fallback, 1/8 not recorded
- Heldjev-kit
- Heldbloudhood
- Heldjev-approvals
- Acts anywayrh-guard (steer only)
- Acts anywayopencode-tool-gate
- Fallbackosuki (default tier)
- Acts anywayjev-judge (enforce)
- Not recordedjev-curator
- Who publishes the 18by publisher
- Host vendor: 1/18OpenClaw
- TypeSafe: 0/18none found
- Community: 17/18personal repositories
The 10 not counted: they do not act on Jev's answer themselves
These integrations were read in source but do not decide the tool call. Of the 10, 8 return Jev's answer to the agent, 2 give advisory hints, and 0 are not settled. jev-approvals and jev-curator, not settled on 6 Oct, were settled on 7 Oct and moved to the counted table. Documented source at the pins in Sources, 6 Oct 2026; OpenClaw spot-checked by the runner; the other 9 are helper reads, not spot-checked
| Group | Integration (pin) | Hosts and hook point | Publisher | Why not counted | (a) No key | (b) Timeout | (c) HTTP error | Tool call still runs? |
|---|---|---|---|---|---|---|---|---|
| Returns to the agent | @openclaw/typesafe 2026.9.8npm (3 Oct 2026); provenance commit aa6008a | OpenClaw; decision provider; disabled by default | Host vendor (OpenClaw). npm provenance from the openclaw/openclaw repository; LICENSE "OpenClaw Foundation"; README "Official external plugin" Reported | Gives Jev to the agent's model through OpenClaw core's decision_evaluate tool (core not read) | no-decision"credentials-unavailable" | no-decision30,000 ms default (1,000–60,000) | no-decision | not applicableGates nothing; the agent sees "unavailable" |
| Returns to the agent | ourines/hermes-jev jev v0.1.2Catalog commit 28a4ea3 | Hermes Agent; jev_evaluate tool | Community (ourines); MIT | Tool only; catalog card: "advisory judgments, no automatic tool gating" | not recorded | not recorded30 s | Error returned to the agent | not applicable |
| Returns to the agent | ajensenwaud/hermes-jev-plugin jev-typesafe v0.1.0b3d29f7 (= catalog commit) | Hermes Agent; 4 plugin tools | Community (ajensenwaud); MIT | Tool only | no-decisionRaises | not recorded30 s | no-decisionError JSON to the agent | not applicable |
| Returns to the agent | ydmw74/jev-skill-router jev-skill-router-mcp76ee09e (= catalog commit) | Hermes Agent; MCP tool skill_select | Community (ydmw74); MIT per plugin.json, no LICENSE file | Tool only | no-decision | not recorded60 s | no-decision | not applicable |
| Returns to the agent | NiazMorshed2007/jev-review57690af | Codex, Cursor, OpenCode (also Claude Code); MCP tool jev_review | Community; MIT | Quality scores returned to the agent | no-decision | not recorded30,000 ms, up to 2 retries | no-decision | not applicable |
| Returns to the agent | burnigtm/jev-mcp v0.1.09448f61 | Codex, Cursor; MCP tools including gate | Community; MIT | gate returns auto, review or escalate; the CLI exits non-zero only on errors, so nothing is enforced | no-decision | not recorded30,000 ms | no-decision | not applicable |
| Returns to the agent | minhgv/jev-mcp v0.3.01a1f0a5 | Cursor, Codex; MCP tools plus a ci-shadow CLI | Community; MIT | ci-shadow prints would_block but always exits 0 | no-decision | not recordedNo explicit timeout; SDK default | no-decision | not applicable |
| Returns to the agent | pedroknigge/mcp_jev v0.0.1132377f8 | Cursor, Codex, Claude, Grok, Antigravity; MCP server | Community; MIT | "The MCP returns signals only — harness allowlist and sandbox still required" | no-decision | not recorded20,000 ms | no-decision | not applicable |
| Advisory hint | DECRUX9812/typesafe-skill-routerCatalog commit e6cdac2 | Hermes Agent; pre_llm_call hook | Community (DECRUX9812); MIT | advisoryAdds a skill hint; the agent's model still picks. Off by default | no-decisionSilent | no-decision10 s | no-decision | not applicable |
| Advisory hint | wellkilo/codex-jev-preflight633ddef | Codex; UserPromptSubmit hook adding context | Community; MIT | advisoryAdds a task-complexity note; gates no tool | not recorded | not recorded15 s | fail-openAdds an "unavailable" note and continues | not applicable |
How the 10 split: 8 return Jev's answer to the agent (@openclaw/typesafe, ourines jev, jev-typesafe, jev-skill-router-mcp, jev-review, burnigtm/jev-mcp, minhgv/jev-mcp, mcp_jev), so the agent's model decides what to do with it. 2 give advisory hints (typesafe-skill-router, codex-jev-preflight). 0 are not settled. 8 + 2 + 0 = 10 not counted; with the 8 counted rows, 18 read. DoGMaTiiC's jev-skill-router shares jev-judge's repository and is listed with it, not as a 19th integration.
Install-and-check list
Six questions to answer before you rely on any of these. Documented from the rows above, 7 Oct 2026; 18 integrations, 8 counted, 10 not counted. Cells still not recorded in the counted table: 3 of 40 (jev-curator: no key, malformed, low confidence)
- Who publishes it? 1 of 18 comes from the host vendor (OpenClaw's plugin). The other 17 are personal repositories. None comes from TypeSafe.
- Which mode does it start in? jev-approvals is off after install (Hermes core default
manual; setapprovals.mode: smart); jev-curator starts in observe and blocks nothing until you setguardorapply; jev-judge starts in shadow (log-only); typesafe-skill-router starts off. rh-guard starts in enforce, so a default install can block. - What happens with no key? Unset the key and try a risky call. jev-kit, bloudhood and jev-approvals ask you; rh-guard, opencode-tool-gate, osuki and jev-judge (enforce mode) let it through or fall back; jev-curator's no-key path was not recorded. Test procedure: testing without a key.
- Which tools never reach Jev? Read the matcher. bloudhood covers Bash, apply_patch and
mcp__only; rh-guard's Codex matcher has no MCP tools; jev-approvals sees only commands Hermes flags as dangerous; jev-curator sees only background skill deletes and patches. - Is the catalog commit the one you read? Three Hermes catalog entries install a commit other than the repository's HEAD, and jev-curator is in a different repository from the one recorded on 5 Oct (pins below).
- What leaves your machine? See the next section.
What leaves your machine
- Can send file contents
opencode-tool-gate (tool arguments up to 6,000 characters, so content being written), jev-judge (up to 12 arguments, each redacted and cut to 600 characters), jev-review (task, diff, full file contents and repository context, no cap or redaction) and osuki (tool results up to 900 characters, regex redaction only).
4 integrations - Defers secret-like input instead of sending it
jev-kit and bloudhood do not send requests that look like they contain secrets; they hand them to your own prompt instead. bloudhood's endpoint and model are set by you in
settings.json(HTTPS only); no TypeSafe URL is hard-wired.2 integrations
Route data terms are on data privacy.
Hermes Agent catalog: which commit gets installed
The Hermes Agent plugin catalog says: "Every entry installs exactly the commit above" (R9-S64). The rows on this page cite the catalog-installed commit. At least 15 catalog entries mention Jev; 8 were read. Documented catalog pages read 6 Oct 2026, 05:17 UTC; HEADs by git ls-remote, 05:14 UTC
| Catalog entry | Catalog installs | Repository HEAD | Note |
|---|---|---|---|
jev (ourines/hermes-jev) | 28a4ea3 (v0.1.2) | cdf59e4 (v0.2.0) | v0.2.0 is not in the catalog; it adds model routing, off by default |
typesafe-skill-router | e6cdac2 | 94fe114 | Page cites the catalog commit |
jev-approvals | 28be98a | 530fdb0 | The two files read are identical at both commits. Read with Hermes core v2026.9.24 (f97608f) on 7 Oct |
jev-curator | 4e8626c | Not compared | Correction: its own repository, anpicasso/hermes-jev-curator. The 5 Oct research put it in the jev-approvals repository |
jev-judge, jev-typesafe, jev-skill-router-mcp | 5dddbea, b3d29f7, 76ee09e | Same as the catalog commit | DoGMaTiiC's jev-skill-router was read at 5dddbea; its catalog source repository was not verified |
Catalog entries seen by name only, not read: jev-agent-router, jev-cron-gate, jev-effort-router, jev-mcp-router, jev-memory-selector, jev-model-router, jev-skill-router; and cards that mention Jev: hermes-slash-router, tool-slimmer, hermes-switchyard, nerve, protean-ordaprompt, local-system-one-hermes, hermes-structured-aux-models.
What is on other pages
- Model routers ("jev codex router": 0xNatoshi/jev-codex-router, kfchow-ai/kfchow-llm-value-router, ourines v0.2.0 routing) pick a model, not whether a tool call runs. Not audited here; see model routing.
- Claude Code-only guards stay on Claude Code and MCP guards. jev-kit, jev-review and mcp_jev also target Claude Code; that page points here.
- Library packages (LangChain, Pydantic AI and others) are on framework integrations.
- Every counted row is also on when Jev fails, in the "Coding agents" domain, including jev-approvals and jev-curator from 7 Oct. Across that map, 13 of 64 implementations let the action go ahead on a Jev error.
- All 18 are listed in the products ledger.
What was not verified
- No agent, hook, plugin or MCP server was installed or run, and no Jev call was made. npm tarballs (
@openclaw/typesafe2026.9.8 and osuki 0.2.7 on 6 Oct; osuki 0.2.7 and 0.2.8 on 7 Oct) were downloaded and read, not executed, then deleted. Every cell is read from code; behaviour at run time may differ. - What Codex, Cursor and OpenClaw core do after a hook decision. Hermes core was read at
v2026.9.24for its approval path, but not the step that hands Hermes'scall_llmrequest to the jev-approvals model provider. The jev-approvals cells rest on how core handles whatever that call returns or raises, which was read. - jev-curator: the no-key, malformed and low-confidence cells (
transport.pyand thegraph.pythresholds not read), and how long a cached judgment from an earlier run stays valid and whether it still covers an operation after a Jev error. - Whether the osuki 0.2.7 and 0.2.8 tarballs match their tag files file by file. osuki's repository address was not recorded, so its row links npm.
- rh-guard's redaction. How OpenCode maps
writeandpatchto permission keys (it does not change the outcome, because"*": "allow"covers every key). - The contents of all test files (file names only).
- Commit dates for 4 MCP repositories (jev-review, burnigtm/jev-mcp, minhgv/jev-mcp, mcp_jev).
- Whether any of these is used in production: none verified.
Leads found but not read (names only, not audited)
- GitHub search hits: qkal/Canny, onlyjq04/jev-agent-hooks, Yaxun-Yang/codex-effort-with-jev, leonaaardob/fast-dev-compaction, 455-dIAO/windows-save-token-jev-setup, Nanako0129/stingray, smixs/code-quality, 0xNatoshi/jev-codex-router.
- Daily scan: bragamat/jevkit, fallen-blossom/flower-control, Steven2007yhq/Reinforced-Computer-use-in-Codex, justmytwospence/opencode-lean-context and opencode-auto-effort,
omo-jev-plugin,omp-typesafe,@geminixiang/pi-jev, n-r-w/classifier-mcp, Rikinshah787/dotpals. - abaljeu/jev-mcp describes itself as "Patched jev-mcp for thejevai.com … Use with Cursor Cloud Agents MCP" Reported. thejevai.com is not a TypeSafe domain. How to tell official endpoints from others: official vs reseller.
- The 7 further Hermes catalog
jev-*plugins listed in the pins section.
Sources and check times (6 and 7 Oct 2026, UTC)
Per-row sources: pinned commits and file paths
- jev-kit: R9-S72, R9-S73, R9-S75, R9-S85, R9-S86. keiffff/jev-kit at 3d74b05f85c1344ce4ae4b3f07b2eaaa6f957b07 (read 05:20; runner read).
packages/hook-adapters/src/index.tsL24–31, L73–90;packages/agent-review/src/index.tsL112–123, L134–140, L151–158, L162–164, L238–283, L295–308;packages/decision-contract/src/index.tsL142, L153–156, L160, L214, L217, L223;packages/cli/src/cli.tsL76–81, L189–192;examples/codex-config.toml,examples/claude-settings.json. SDK@typesafe-ai/sdk0.6.0dist/index.mjsdocstring (R9-S75). - bloudhood/codex-jev-approval-hook: R9-S81. at b6242c9802724550b54eb346d1df40adf997253d.
hook.ps1L13–24, L318–322, L334, L373, L451, L458–460, L581–595, L597, L598–601. Spot-checked by the runner (05:22). - 24601/rh-guard: R9-S82; 7 Oct: R10-S117, R10-S118. at c2e682ef0e838cc0538a7c2062e8a96d262dbd14.
src/lib/risk/score.tsL91–106, L110–116, L136–146, L171–181, L239–250;src/lib/risk/jev.tsL75–78, L240, L245–247, L265–279, L335–338;hooks.tsL161–167;hosts.tsL194–195;hooks/run.tsL41–46. Spot-checked by the runner (05:22). 7 Oct (helper read, 05:20):src/lib/risk/kinds.tsL36, L39–61 (block thresholds), L176–189 (default mode enforce);score.tsL98–109, L125–146, L171–199, L236–241. Same commit, still HEAD on 7 Oct. - justmytwospence/opencode-tool-gate: R9-S74, R9-S85. at bdf1ef8d132a16db73814e94b23f8396b3976cac (read 05:20; runner read).
src/index.tsL42–43, L240–265, L288, L313, L328–349, L352–380;src/jev.tsL33–36, L47, L51–60;src/judge.tsL147–182. 7 Oct: R10-S114, R10-S115, R10-S116. OpenCodev1.18.35(latest release, published 6 Oct 2026, 20:18 UTC) at anomalyco/opencode 53d1eabb61e21162157817bf677da0a4ad3332e3 (sst/opencoderesolves to the same repository):packages/opencode/src/agent/agent.tsL119–151 (default"*": "allow"; user config merged last);packages/opencode/src/permission/index.tsL28–38 (last matching rule wins). Runner spot-checkedagent.ts. @osuki-dev/opencode-osuki-agent0.2.7: R9-S80. npm 0.2.7 (4 Oct 2026, 10:52 UTC); tagv0.2.7=c96ce03c1c7dfc5c6fdf9d966691549101c68080. Tarballdist/index.jsL59–68, L335–337, L343–394, L415–420, L969–1036, L1668–1737, L1751, L1764, L1829–1832. Helper read; not spot-checked. 7 Oct: R10-S112, R10-S113. npm 0.2.8 (5 Oct 2026, 11:40:53 UTC; npm sha1dc959c68bd27836f9ece153b023e947efe948404; tagv0.2.8=0ae9e884a97a5539fef3f0772318a628c1f75e00), latest on npm on 7 Oct.dist/index.jsdiff against 0.2.7: the Jev call, timeout and fallback lines (L63, L343–394, L969–972) are identical; hook lines now L1677–1746, L1760, L1838–1841 (0.2.7 L1668–1737, L1751, L1829–1832). Non-failure changes: read-only roles always go to the explore agent (L993–994); newrequireDispatchchecks inosuki_route. Tarball not matched to the tag file by file.- DoGMaTiiC/hermes-jev
jev-judge: R9-S63, R9-S64. at 5dddbeaac5be08281e6c3b372eeaba3639971f0a.plugins/jev-judge/__init__.pyL43–58, L64–73, L77–91, L93–96;jev.pyL44, L52, L281–283, L349–388, L397–401, L468–473, L480–482;gate.pyL277–284, L345–357, L362–368;plugin.yaml.plugins/jev-skill-routerL194–200, L224–226 (helper read, partial). jev-judge spot-checked by the runner (05:23). @openclaw/typesafe2026.9.8: R9-S69. openclaw/openclaw at aa6008ad198ef99c43f9d89dbd01694708712974 (npm provenance commit).extensions/typesafe/src/decisions.tsL28–30, L80–82; tarballdist/index.jsL96–104,dist/.setup/errors-BdIwQubl.mjsL26–30, L45,client-CRLm45hB.mjsL244–256. Spot-checked by the runner (05:23).extensions/typesafe/package.jsonat that commit says 2026.9.7; the published version is 2026.9.8.- ourines/hermes-jev: R9-S66, R9-S60. at 28a4ea390f80d97fcdc8c20d6b630dfe2de645de.
service.pyL45, L73–80 (HEAD: L95–101, L149–177);client.pyL132–148. Helper read; not spot-checked. - ajensenwaud/hermes-jev-plugin: R9-S67. at b3d29f71770a3447ad0b3db00658f64a8edc7dd3.
client.pyL22, L31–34, L132–158;tools.pyL43–44, L59–64. Helper read; not spot-checked. - ydmw74/jev-skill-router: R9-S68. at 76ee09e049dbc10c76f98cfefc6ca16b42cfad38.
src/jev_skill_router/mcp_server.pyL150–158, L167, L169–173, L346–349. Helper read; not spot-checked. - NiazMorshed2007/jev-review: R9-S76. at 57690af54ef7d862c2483342c1e61c14dffcf727.
src/mcp/server.tsL43–58;src/evaluation/input.tsL5–37;src/config/environment.tsL3–8;src/jev/client.tsL42, L71–81, L92–118. Helper read; not spot-checked. - burnigtm/jev-mcp: R9-S77. at 9448f6120015f2f6c6dad7137c7f234545209918.
src/cli.tsL37–39;src/typesafe.tsL124–128;src/config.tsL214–222;src/errors.tsL53. Helper read; not spot-checked. - minhgv/jev-mcp: R9-S78. at 1a1f0a5b599e3c9f00a126bb247536a624aa265e.
src/ci-shadow.tsL6–31;src/typesafe.tsL47–51;src/server.tsL236–244. Helper read; not spot-checked. - pedroknigge/mcp_jev: R9-S79. at 32377f8e4d5a63a76d4efbe9abf0b2fbf3f98a0d.
src/packs/command-risk.tsL7–8;src/typesafe.tsL33–35;src/config.tsL9, L48;src/server.tsL21–27. Helper read; not spot-checked. - DECRUX9812/typesafe-skill-router: R9-S65. at e6cdac26f9ed588b4a94b8a2f7f9f026e1b9faf3.
__init__.pyL49, L55, L180–190, L242–247, L284–289;typesafe_router/client.pyL292–306. Helper read; not spot-checked. - wellkilo/codex-jev-preflight: R9-S83. at 633ddefe6596aa5d7c6b00767c08d07edea61096.
jev_user_prompt_hook.pyL25, L175–196. Helper read (partial); not spot-checked. - anpicasso/hermes-jev-approvals (row): R9-S61, R9-S60, R10-S41. Plugin at 28be98a19539b29768398fb400f4c62f41337c26:
plugin/__init__.pyL100–105, L336–341, L495, L520–527, L543, L851, L911–931, L966–974 (6 Oct helper read);plugin/jev_policy.pyL13, L54–59 (confidence 0.55; read 7 Oct, 05:25). Hermes Agent core (7 Oct, helper A, 05:18–05:20): R10-S101 releasev2026.9.24= NousResearch/hermes-agent f97608f178d1ffeca59860195ab7da295f7c8e5f; R10-S103tools/approval.pyL774–791, L808–815, L884–887, L918–919, L1178–1192, L1208–1209; R10-S102tools/approval_smart.pyL80–131; R10-S104agent/auxiliary_client.pyL6097, L6222–6230 (30 s default); R10-S105tools/approval_context.pyL228–241 (modemanual, approval wait 300 s). The runner spot-checkedapproval.py,approval_smart.pyand the tag SHA. - anpicasso/hermes-jev-curator (row): R9-S62; 7 Oct: R10-S106 to R10-S111. at 4e8626c7d394a9cbef8594993ec4b208ffb3395f.
plugin/plugin.yamlL24–29 (default observe), L50–53 (25 s);plugin/guard.pyL35, L43, L57–74, L143–160, L376–396;plugin/service.pyL79–104;plugin/debounce.pyL88–96, L107;plugin/engine.pyL80–95, L157–166;plugin/commands.pyL102–104, L120–124. Helper read; not spot-checked.
- R9-S11: search suggestions from Google (
suggestqueries,client=firefox), Bing (osjson) and DuckDuckGo (ac), 05:19:23–05:19:30. A demand signal, not a volume. - R9-S38: TypeSafe's GitHub organisation repository list (12 repositories), 05:15:34.
- R9-S60:
git ls-remoteHEAD for 6 Hermes plugin repositories, 05:14:50. - R9-S64: Hermes Agent plugin catalog pages (7 entries) and the rendered index, 05:17:40.
- R9-S84: GitHub repository searches "jev codex hook" (26 results), "typesafe cursor hooks" (1) and "jev codex router" (96), 05:17:45.