run:6c40bcd4-3b75-4bfc-bc54-b254713e0f95 · checks , 05:13–05:36 UTCRun 9 research report: coding agents beyond Claude Code, and Jev versions and aliases (6 Oct 2026)
This dated report records the evidence behind release regular-2026-10-06-coding-agents-versions of 6 October 2026. It covers 18 Jev integrations for coding agents (Codex, OpenCode, Cursor, OpenClaw and Hermes Agent), the Jev model IDs and aliases on 6 routes, a new provider for Jev on Vercel, and the failure checklist, which grows from 51 to 58 rows. The page titles it feeds use phrases that search suggestions offered on 6 Oct 2026, 05:19 UTC (a demand signal, not a volume). The pool ran nothing: no agent, hook, plugin or MCP server was installed or run, and no account, key or Jev call was used.
Of 18 Jev coding-agent integrations read in source, 1 is vendor-published (OpenClaw) and none comes from TypeSafe; 6 act on Jev's answer, and 4 of those let the tool call run when Jev errors.
Rows picked by the runner from the projects it found and read in source this run (the selection is described in the research notes); not a survey. The pool ran no agent and made no Jev call.
Run 9 at a glance (counts with their denominators)
All counts are Documented from source read at pinned commits, from route pages, or from the published pages, 6 Oct 2026. Nothing was run. Bar length is the share of the group's n.
Run: run:6c40bcd4-3b75-4bfc-bc54-b254713e0f95 (scheduled regular research run 9, on the v0.2 harness) · Pool: pool_jev_catalog · Runner: one runner plus two helper agents (A: the Hermes Agent catalog and OpenClaw; B: Codex, OpenCode and Cursor, then the LiteLLM diff). GitHub search calls: 5 of 10 · Checks: 6 Oct 2026; runner started 05:13:45 UTC; home status written 05:18:34 UTC (minute 5); research notes finished about 05:36 UTC (minute 23).
The run's research notes and its source ledger (80 records, IDs R9-S01 to R9-S120) are held in the pool's private record. Key sources are linked below and on the pages each finding feeds.
Rules kept: nothing was installed or run. No agent, hook, plugin or MCP server was installed or run, and no account, key or inference request was used, so no Jev call was made. Failure cells come only from source at pinned commits. Nothing in this run is Tested. Every finding below is Documented, Reported (a named third party's own claim) or Unverified (a lead only).
Previous report: browser and computer use, framework integrations, Jev on Bedrock or Azure (5 Oct). All dated reports: Research.
1. Summary answer, as of 6 October 2026
- Access is unchanged (checked 6 Oct 2026, 05:15 UTC). Signups are open with no new-user credit since 27 Sep, 22:33:25 UTC. The API has been operational since 29 Sep, 22:05 UTC (90-day uptime 99.826%). Limits are 100K tokens per second and 80 requests per second; the price is $0.042 per million input tokens.
jev-latestandjev-previewboth point tojev-1.13.0. Documented - One route change: Vercel AI Gateway now lists TypeSafe itself (zero data retention) as a second provider for
typesafe-ai/jev, beside DigitalOcean (no zero data retention). Vercel picks between them by uptime and latency unless the caller sets the order. Documented build/coding-agentsships. 18 integrations were read at pinned commits. 6/18 act on Jev's answer, covering Codex, Cursor, OpenCode and Hermes Agent. When Jev errors or there is no key, 4/6 let the tool call run and 2/6 hold it for the user. 1/18 is vendor-published: OpenClaw's own@openclaw/typesafe, which only returns Jev's answer to the agent. 0/18 come from TypeSafe. Documentedwhere-to-use/versions-and-aliasesships. 6/6 routes were read with dates. 4/6 accept a versioned ID: TypeSafe, Netlify and Opper takejev-1.13.0; OpenRouter takestypesafe/jev-1.13. Vercel and Cloudflare accept only an unversioned ID. Documented- Guard rows: both are still at their run-7 pins. jev-permission-gate counts on
when-jev-fails. jev-llm-guard does not count: its command-line tool exits 0 whatever the verdict. Documented when-jev-fails: n = 58 in 10 domains (adds a new "Coding agents" domain). 32/58 stop or hold the action on a Jev error; 7/58 let it through unchecked. Documented- Products: 92 rows (A 75, B 16, C 1); 0/92 independently verified in production.
- Drift: the LiteLLM 1.104.0 failure path is unchanged. No new release of the six framework pins.
ai7.0.128 and@ai-sdk/typesafe-ai3.0.13 are patches (drift note only).
2. Publication
This release shipped both planned pages and the follow-on edits:
- How to use Jev with Codex, OpenCode, Cursor and Hermes Agent (new page).
- Jev 1.13 and jev-latest: model IDs and aliases by route (new page).
- Refreshed: Claude Code and MCP guardrails (the two guard rows); When Jev fails (51 → 58 rows, new "Coding agents" domain); Products (92 rows).
- Refreshed: where to use, Vercel two-provider note; data privacy; model routing (LiteLLM 1.104.0 check); frameworks (recheck line); TypeScript (drift note).
- Status refresh on Home and access status.
- Release 3: 9 of 9 (closed). Release 4: 1 of 4.
- Failure colours aligned across pages (see Research for the list).
3. Corrections to plan facts and pool pages
- Run 8 spare-time table:
jev-curatoris in its own repository (anpicasso/hermes-jev-curator,4e8626c), not in anpicasso/hermes-jev-approvals. Documented - Hermes catalog pins: three catalog entries install a commit other than the run-8 HEAD pin:
jev(28a4ea3),typesafe-skill-router(e6cdac2) andjev-approvals(28be98a). The catalog says "Every entry installs exactly the commit above". The page cites the catalog-installed commits. Documented - Vercel row on
where-to-use: "DigitalOcean only (5 Oct)" is no longer current (see section 4).
Editorial correction to the runner's draft. The runner's draft key finding said "12 only advise the agent". That is not accurate for all 12 rows that are not counted. Of the 12: 8 return Jev's answer to the agent, 2 give advisory hints, and 2 are not settled (one sends its verdict to Hermes core, which was not read; one was only partly read). The published key finding was rewritten to say what the 6 counted rows do.
4. Access status and home notices
- Checked 6 Oct 2026, 05:15:34 UTC. Signups
open_with_conditions; serviceoperational. The headline is unchanged: "Available to new users: signups open, but new accounts get no free credit. API operational." Changed since the last run: no. Documented - New field in the home status record: the alias read.
jev-latestandjev-previewboth point tojev-1.13.0; TypeSafe's models page is undated (read 05:15:34 UTC). - Notices shown, unchanged:
new-user-credit-disabled(rank 1);lookalike-resellers(rank 2; all three sites return HTTP 200, and the Eye Security report is online);rate-limits-changed-2026-10-03(rank 3);subprocessors-added-2026-10-02(rank 4). - New notice, hidden at rank 5 by manager decision:
vercel-typesafe-provider-added-2026-10-06(route change, Documented). It is not shown on Home. It retires on 13 Oct 2026, 05:15 UTC, or earlier if superseded. typesafe-workflow-evals-codestays hidden, now at rank 6. It retires at the 7 Oct run. Retired: none. Timeline additions: none.- Vercel note for
where-to-useanddata-privacy: "Vercel lists two providers for Jev (checked 6 Oct 2026, 05:15 UTC): TypeSafe AI (zero data retention) and DigitalOcean (no zero data retention). Vercel picks a provider by uptime and latency unless you set the provider order." Vercel's docs say that by default it "dynamically chooses the default providers … based on a combination of recent uptime and latency". So zero data retention on one provider does not say where a given request goes. - The
typesafe-aiGitHub organisation has 12 repositories. The new one,typesafe-public-examples, holds only a README, so it is not a release. - TypeSafe's docs file
legal.mdis 6 bytes larger; the legal "Last updated" dates are unchanged. Not compared line by line; recheck next run.
5. Scan (S1) highlights
- Window: 5 Oct 2026, 05:14 UTC to 6 Oct 2026, 05:14 UTC. Gap 0, overlap 0.
- Window counts: Hacker News "jev" 11 stories and 33 comments; 192 new GitHub "jev" repositories (9 with the topic); npm 14 "jev" and 7 "typesafe" packages published; 22 Hugging Face models modified; 1 DEV.to article. These are search-index counts, not verified integrations or adoption.
- Not readable: Reddit (HTTP 403) and X (login wall). Both are unknown, not zero.
- "jev vision" stays unexplained. It is suggested on all three endpoints. There is no Hacker News hit, no npm package and no TypeSafe vision model (TypeSafe docs say "Text only"). Bing and DuckDuckGo also suggest "jev vlm" and "jev vla".
- Coding-agent leads found and read this run: opencode-tool-gate (created 6 Oct, 03:14 UTC) and jev-kit (npm releases 5 Oct, 19:02 UTC).
- Leads not read (Unverified): abaljeu/jev-mcp ("for thejevai.com"; not a TypeSafe domain, so a possible lookalike watch item); Dotpals (Hacker News); jev-browser-wingman (Hacker News; browser page); n8n-nodes-system-one (n8n); kfchow-llm-value-router (routing); "Pseudo-Relevances with Jev" (reranking).
- No candidate home notice besides the Vercel change.
6. Findings per page and ship verdicts
6.1 build/coding-agents (new; closes release 3): ships
Of 18 Jev coding-agent integrations read in source, 1 is vendor-published (OpenClaw) and none comes from TypeSafe; 6 act on Jev's answer, and 4 of those let the tool call run when Jev errors.
- Page: How to use Jev with Codex, OpenCode, Cursor and Hermes Agent (TypeSafe AI). Not claimed: that coding-agent plugins are unsafe, or anything about hosts or plugins that have no row. Short form: "Of 6 Jev coding-agent integrations that act on Jev's answer, 4 let the tool call run when Jev errors and 2 hold it for you."
- Editorial correction: the runner's draft said "12 only advise the agent". Of the 12 not counted, 8 return Jev's answer to the agent, 2 give advisory hints and 2 are not settled.
- Title query source: search suggestions checked 6 Oct 2026, 05:19:23–05:19:30 UTC. Google (
client=firefox) suggests "how to use jev with codex" and "how to use jev with opencode" exactly, plus "jev in cursor" and "jev openclaw". "jev hermes" and "jev codex" appear on Google, Bing and DuckDuckGo. Every host named in the title has a counted row. - Ship rule: 4 or more implementations at pinned commits, covering at least 3 of 5 hosts, with the required columns from source. Met: 18 implementations; the 6 counted rows cover 4 hosts.
- Spot-checks: 4 rows checked against the raw files (the failure cell and the "still runs" cell): bloudhood and rh-guard (helper B), jev-judge and OpenClaw (helper A). All matched.
| Row | Hosts | Mode | Jev error or timeout | No key | Low confidence | Tool call still runs? |
|---|---|---|---|---|---|---|
keiffff/jev-kit jev-agent-review (3d74b05) | Codex, Claude Code | approve-only PermissionRequest hook | fail-closed (held for the host prompt; SDK 10 s, no retry) | fail-closed (held) | held (0.7 / 0.7 / 0.15) | No |
bloudhood/codex-jev-approval-hook (b6242c9) | Codex | PermissionRequest hook | fail-closed (held for Codex approval; 5 s) | fail-closed (held) | held (allow at 0.98 or more, deny at 0.80 or more) | No |
24601/rh-guard (c2e682e) | Codex, Cursor | pre-tool hook | fallback-lexical detectors (1.2 s) | fallback-lexical detectors | acts-anyway (steer) | Conditional |
justmytwospence/opencode-tool-gate (bdf1ef8) | OpenCode | tool.execute.before, enforcing | fallback-OpenCode permission rules (3 s) | same | acts-anyway | Yes (unless OpenCode's own rules hold it) |
@osuki-dev/opencode-osuki-agent 0.2.7 (tag c96ce03) | OpenCode | router (subagent and tool pruning) | fallback-default tier (10 s) | same | fallback-default tier | Yes |
DoGMaTiiC/hermes-jev jev-judge (5dddbea) | Hermes Agent | pre_tool_call; shadow mode by default | fail-open (3 s) | fail-open | acts-anyway | Yes (in enforce mode) |
Not counted (12 of 18):
- Return Jev's answer to the agent (8):
@openclaw/typesafe(vendor-published), jev-typesafe, jev-skill-router-mcp, ourinesjevv0.1.2, NiazMorshed2007/jev-review, burnigtm/jev-mcp, minhgv/jev-mcp and pedroknigge/mcp_jev. - Advisory hints (2): typesafe-skill-router and wellkilo/codex-jev-preflight.
- Not settled (2): jev-approvals sends its verdict to Hermes core, which was not read; jev-curator was only partly read, so counting is deferred.
6.2 Guard rows and build/claude-code-mcp
- gulbaki/jev-llm-guard: HEAD
7c7b1b5on 6 Oct; failure files unchanged. Not counted. Itsjev-guardcommand-line tool returns 0 for allow, review and block (src/cli.jsL31–40) and exits 1 only on errors (L41). The demo server only displays the result. Written as "returns verdict; not a decision". Documented - madisonrickert/jev-permission-gate: HEAD
7349bc9on 6 Oct; failure files unchanged. Counted in "Claude Code / MCP guards" with fallback-built-in classifier on error, malformed answer, below threshold and no key; bypass recorded. Documented - Both rows go on Claude Code and MCP guardrails, using the run-7 cells. If the page counts the guardrails it read, the count sentence ("We read five Jev guardrails …") becomes seven.
- A one-line pointer on that page leads to coding agents for jev-kit, jev-review and mcp_jev, which also target Claude Code.
6.3 build/when-jev-fails: recount (n = 58, 10 domains, each with 3 or more rows)
Of 58 Jev implementations read in source, 32 stop or hold the action when Jev errors and 7 let it through unchecked: 4 content-moderation bots, 2 agent hooks and one Spring AI passage filter.
- The base is the published 51-row map, read at 05:25:44 UTC. This run adds 1 guard row and 6 coding-agent rows. No existing row changes. Totals were recomputed by a script that checks every row and that each total sums to n = 58. Below-threshold totals are kept apart from error totals.
- New page meta: "58 Jev implementations in 10 use cases, read in source: what each does on a Jev error, a bad answer, an unsure answer, a missing key or a bypass."
| Condition | fail-closed | fail-open | advisory | fallback | no-decision | not recorded |
|---|---|---|---|---|---|---|
| Jev error or timeout | 32/58 | 7/58 | 3/58 | 13/58 | 3/58 | 0/58 |
| Malformed answer | 26/58 | 10/58 | 3/58 | 15/58 | 3/58 | 1/58 |
| No key | 25/58 | 4/58 | 3/58 | 9/58 | 0/58 | 17/58 |
| Condition | Counts | Not recorded |
|---|---|---|
| Below threshold (separate) | held 12, acts-anyway 12, fallback 7, no-decision 4, advisory 4, no-threshold 14 | 5/58 |
| Bypass | recorded 29 | 29/58 |
| Action goes ahead on a Jev error | 12/58 (was 8/51); adds jev-judge, jev-permission-gate, rh-guard and opencode-tool-gate. osuki is excluded under the routing-fallback convention. | — |
6.4 products: row changes
- 20 new A rows: the 2 guard rows and 18 coding-agent projects.
- The existing B rows "jev-review" (devagrawal09) and "openclaw-typesafe-ai" (Olli0103) are different projects from the new rows, so both stay.
- New total: 92 rows (A 75/92, B 16/92, C 1/92), was 72 rows (A 55/72, B 16/72, C 1/72). Independently verified in production: 0/92.
6.5 where-to-use/versions-and-aliases (new; first release-4 page): ships
On 4 of 6 routes read on 6 Oct 2026 you can write a versioned Jev ID; Vercel and Cloudflare take only an unversioned one. jev-latest points to jev-1.13.0 on TypeSafe's models page.
- Page: Jev 1.13 and jev-latest (TypeSafe AI): model IDs and aliases by route. Not claimed: that
jev-latestis safe, or anything about the next version. - Title query source: "jev 1.13" and "jev-latest" appear on all three endpoints (checked 05:19:23–05:19:30 UTC); Google now suggests "jev-latest" too. "jev 1.14", "jev versions" and "jev model version" got no supporting suggestion.
- Ship rule: at least 4 routes with IDs, aliases and dates read this run, plus TypeSafe's own alias statement. Met: 6/6 routes read 05:15–05:24 UTC. 4/6 show a date of their own; TypeSafe's page and Cloudflare are marked "undated; read at …".
| Route | IDs | Aliases (target) | Pin a version? | Date |
|---|---|---|---|---|
| TypeSafe direct | jev-1.13.0 | jev-latest and jev-preview both → jev-1.13.0 | Yes | undated; read 05:15:34 UTC |
| OpenRouter | typesafe/jev-1.13 | ~typesafe/jev-latest ("always redirects to the latest model in the Jev family"; page shows "Latest Jev 1.13") | Yes, minor version only | Released Sep 18, 2026 |
| Vercel | typesafe-ai/jev | none; version not stated | No | Release date 09/15/2026 |
| Cloudflare | typesafe/jev | none; example response shows jev-1.13.0 | No | undated; read 05:15:34 UTC |
| Netlify | jev-1.13.0, jev-latest, jev-preview | targets not stated by Netlify | Yes | Last updated Sep 17, 2026 |
| Opper | typesafe/jev-1.13.0 | typesafe/jev-latest and typesafe/jev-preview → it | Yes | Verified by Opper 2026-09-18 |
7. Drift (S5)
- LiteLLM 1.104.0 (tag commit
79645770fedc7ec2627e6468d31062f20f82aecc): the Jev classifier's failure path is unchanged from8d28e8d. The runner compared the whole caller block by script and found it identical. Line for model routing: "Checked at LiteLLM 1.104.0 (tag commit7964577, 6 Oct 2026): the Jev classifier's failure path is unchanged from8d28e8d." Caveat: the tag may predate8d28e8d; their order was not verified. Documented - Framework pins: no new release of any of the six. Line for frameworks: "Rechecked 6 Oct 2026, 05:20 UTC: no new release of any of the six packages; LiteLLM 1.104.0 failure path unchanged."
- Drift notes only:
ai7.0.128 and@ai-sdk/typesafe-ai3.0.13 (TypeScript), and the oh-my-claudecode tag v5.6.2 (no release; Claude Code and MCP guardrails). - New this run:
@osuki-dev/opencode-osuki-agent0.2.8 is already out (the row is pinned at 0.2.7). Its page note says "0.2.8 not read".
8. Spare time
- The LiteLLM TypeSafe proxy guardrail at v1.104.0 is a context-compaction guardrail, not a safety block. It blanks tool results that Jev judges no longer relevant (below 0.2). Its default model is
jev-latest. On a Jev error it forwards the request uncompacted by default; it can be set to return HTTP 502 instead. With no key it fails at start-up. It is a candidate decision row for the next frameworks or routing refresh. Documented - Item 2 (reranking studies) and item 3 (database error behaviour) were not reached.
9. Evidence gaps and uncertainties
- Host behaviour after a hook decision: Codex, Cursor, Hermes core and OpenClaw core were not read.
- OpenCode's default permission configuration.
- rh-guard's default mode and its thresholds.
- osuki 0.2.8, and whether the 0.2.7 package matches its tag.
- How jev-approvals errors are handled in Hermes core.
- jev-curator's plan path.
- The contents of all test files.
- Commit dates for 4 MCP repositories.
- What each route actually serves (no request was sent).
- Whether OpenRouter accepts patch-level IDs.
- Route changelogs: only TypeSafe's was checked, and it returns 404.
- SDK default models beyond TypeSafe's statement.
- The
legal.mdsize change. - The Internet Archive (connection error).
- Reddit and X (unknown).
10. Not done (for run 10)
- The
reranking-ragcondition check (spare item 2). It decides run 10's page. - The
databases-and-documentserror behaviour (spare item 3). - Unread coding-agent leads: about 20, listed in the research notes, including the 7 further Hermes catalog
jev-*plugins and 0xNatoshi/jev-codex-router. - The per-SDK default-model check.
- The
legal.mdcomparison. - Drift-list additions from run 10:
@openclaw/typesafe,@osuki-dev/opencode-osuki-agentand the three@jev-kitpackages.
11. Timings (UTC, 6 Oct 2026)
| Time (minute) | Step |
|---|---|
| 05:13:45–05:16 (0–2) | Start; helpers launched |
| 05:15:34–05:18:34 (2–5) | S2 fetch and home status record |
| 05:19–05:20 (5–7) | S1 scan and S5b registry check |
| 05:20–05:25 (7–11) | S3 own reads (tool-gate, jev-kit, guard rows) |
| 05:21 and 05:22 (8–9) | Helpers returned (B, then A) |
| 05:22–05:29 (9–15) | Spot-checks, recount, coding-agent notes |
| 05:22–05:31 (9–17) | S4 reads and notes, LiteLLM spot-check, drift note |
| 05:31–05:35 (17–21) | Spare item 1, scan note, sources |
| 05:35–05:36 (21–23) | Report |
| — | GitHub search calls: 5 of 10 |
What was not verified
- How any agent, hook, plugin or MCP server behaves when run: nothing was installed or run, and no Jev call was made.
- What the host does after a hook decision (Codex, Cursor, Hermes core, OpenClaw core); OpenCode's default permissions; rh-guard's default mode and thresholds.
- osuki 0.2.8, and whether the 0.2.7 package matches its tag; jev-approvals error handling in Hermes core; jev-curator's plan path.
- What each route actually serves (no request was sent), and whether OpenRouter accepts patch-level IDs.
- The
legal.mdsize change; the Internet Archive (connection error). - README claims (such as "Official external plugin"): Reported only.
- Reddit and X activity in the scan window: unknown.
Key sources and check times (6 Oct 2026, UTC)
- Counted coding-agent rows (05:20–05:29): jev-kit
3d74b05; codex-jev-approval-hookb6242c9; rh-guardc2e682e; opencode-tool-gatebdf1ef8; @osuki-dev/opencode-osuki-agent 0.2.7 (tag commitc96ce03c1c7dfc5c6fdf9d966691549101c68080); hermes-jev5dddbea. File paths per cell are on the coding agents page. - Not-counted rows: @openclaw/typesafe 2026.9.8 (provenance commit
aa6008ad198ef99c43f9d89dbd01694708712974); jev-typesafeb3d29f7; jev-skill-router-mcp76ee09e; ourines jev28a4ea3; jev-review57690af; burnigtm/jev-mcp9448f61; minhgv/jev-mcp1a1f0a5; mcp_jev32377f8; typesafe-skill-routere6cdac2; codex-jev-preflight633ddef; jev-approvals28be98a; jev-curator4e8626c. - Guard rows: jev-llm-guard
7c7b1b5; jev-permission-gate7349bc9. - Access and aliases (05:15:34): status.typesafe.ai; docs.typesafe.ai/models.md. Route pages for OpenRouter, Vercel, Cloudflare, Netlify and Opper (05:15–05:24) are linked on the versions and aliases page.
- LiteLLM: v1.104.0 tag commit
7964577. - Search suggestions (R9-S11, 05:19:23–05:19:30): Google (
client=firefox), Bing (osjson), DuckDuckGo (ac). - Failure checklist: recomputed from the published 51-row map plus the 7 new rows; rows and links on when Jev fails.