by leepokai
Auto mode for every coding agent, built on Jev: risk-scores every tool call with session context (deny / ask / allow), flags prompt injection in results, checks skills and plugins. Claude Code, Codex, Copilot, Gemini, Cursor, pi, OpenCode, ACP.
# Add to your Claude Code skills
git clone https://github.com/leepokai/jev-guardSee how jev-guard compares with popular alternatives.
jev-guard is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by leepokai. Auto mode for every coding agent, built on Jev: risk-scores every tool call with session context (deny / ask / allow), flags prompt injection in results, checks skills and plugins. Claude Code, Codex, Copilot, Gemini, Cursor, pi, OpenCode, ACP. It has 50 GitHub stars.
jev-guard's catalog security scan is still queued. You can run an instant dependency and prompt-injection check now with the "Scan for vulnerabilities" button above.
Clone the repository with "git clone https://github.com/leepokai/jev-guard" and add it to your Claude Code skills directory (see the Installation section above).
jev-guard is primarily written in JavaScript. It is open-source under leepokai on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh jev-guard against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
The deep catalog scan for this skill is still queued. Run an instant dependency check now instead.
Claude Code's auto mode is described as: "A separate classifier model reviews actions before they run, blocking anything that escalates beyond your request, targets unrecognized infrastructure, or appears driven by hostile content Claude read." That is exactly the job jev-guard does — as three typed questions to Jev (risk, user_requested, from_untrusted) instead of a proprietary classifier — and it does it for Codex, Copilot, Gemini, Cursor, pi, OpenCode and ACP editors too, with the same policy and the same session memory everywhere. If you want auto mode outside Claude Code, or a second opinion inside it, this is the build.
| Figure | Source | |
|---|---|---|
| Price | $0.042 per 1M input tokens, $0 output — a typical jev-guard call is ~1k tokens, so ≈ $0.00004 per tool call; a 1,000-call session is about 4 cents | Vercel AI Gateway model card typesafe-ai/jev (GET https://ai-gateway.vercel.sh/v1/models → pricing.input: 0.000000042) |
| Price, relative | "100x cheaper" than running an LLM for the same judgment | TypeSafe docs, example use cases |
| Speed, claimed | "real-time speeds (150 ms)" | TypeSafe docs, example use cases |
| Speed, measured | direct API: ~0.75 s wall per call from Taiwan, TLS and process start-up included; via the AI Gateway: p50 ~580 ms over the 21-call calibration run below | this repo, 2026-09-17/18 |
| Output | calibrated probabilities plus a confidence per answer, not prose to parse | TypeSafe docs, Confidence |
Those two numbers are the whole reason this design works: cheap enough to run on every tool call and every tool result, fast enough that the agent doesn't notice, and typed so the policy lives in twenty lines of code you can read.
Three checks, with the session's context:
CLAUDE.md/AGENTS.md: the things an agent should obey. Every file loaded or installed is checked for behavior its installer would not expect (exfiltration, covert execution, overriding other instructions, canaries, unrelated side effects), at session start, when it's loaded, when a Skill runs, and on demand with jev-guard scan-skills.Works with Claude Code, Codex, GitHub Copilot CLI, Gemini CLI, Cursor, pi, OpenCode, and any ACP client/agent pair (Zed, JetBrains, …). One core, thin adapters. No build step, no dependencies.
Pick your agent; every row is one command, then give it a key.
| Agent | Install | Before a tool runs | After it returns |
|---|---|---|---|
| Claude Code | /plugin marketplace add leepokai/jev-guard then /plugin install jev-guard@jev-guard |
deny · ask prompt | flag |
| Codex | codex plugin marketplace add leepokai/jev-guard, install from the plugin browser, /hooks to trust |
deny · ask → warning (Codex has no ask yet) |
flag |
| Copilot CLI | copilot plugin marketplace add leepokai/jev-guard then copilot plugin install jev-guard@jev-guard |
deny · ask prompt (deny in cloud agent) |
flag |
| Gemini CLI | gemini extensions install https://github.com/leepokai/jev-guard — it asks for the key on install |
deny · ask → warning (no ask in BeforeTool) |
flag |
| Cursor | plugin manifest included for marketplaces; solo users: jev-guard install cursor |
deny · ask for shell and MCP (preToolUse can't ask) |
flag |
| pi | pi install npm:jev-guard (or git:github.com/leepokai/jev-guard) |
block · confirm dialog | flag |
| OpenCode | "plugin": ["jev-guard"] in opencode.json (0.2.1+) |
throw on deny · ask via permission.ask for tools you set to "ask" |
flag |
| ACP | editor runs jev-guard acp -- <agent> |
reject · permission request for terminal/create, fs/write_text_file |
flag fs/read_text_file, terminal/output |
Everything else goes through the npm package:
npm i -g jev-guard
jev-guard key "…" # TypeSafe key from console.typesafe.ai, a vck_… Vercel AI Gateway key, or an sk-or-… OpenRouter key
jev-guard install claude|codex|copilot|gemini|cursor|pi|opencode # writes hooks into that agent's user config
jev-guard check Bash '{"command":"rm -rf ~/"}'
# DENY jev-guard blocked this call (risk 3.0/3, approval p=0.98, confidence 0.99): Bash rm -rf ~/ …
install is idempotent and writes the absolute path of the current node, so hosts launched from a Dock (Cursor, Zed) work too. One hook script serves every host: it recognises the payload it is given (Claude Code, Codex, Copilot, Gemini, Cursor) and answers in that host's format.
jev-guard key writes ~/.jev-guard/config.json (mode 0600). Every adapter reads that file, so it works for GUI hosts that never see your shell profile. Environment variables win when present: JEV_API_KEY, AI_GATEWAY_API_KEY, or VERCEL_OIDC_TOKEN (from vercel env pull, expires in ~12 h). OPENROUTER_API_KEY is used only when no other key is set, env or file, since many other tools export it too. Gemini CLI asks for the key when you install the extension and stores it in its keychain. Each key is sent only to its own provider (api.typesafe.ai, openrouter.ai, or ai-gateway.vercel.sh), never stored anywhere else by jev-guard, and never given to the coding agent.
OpenRouter serves Jev over the same System One request and response (OpenRouter's guide); with OPENROUTER_API_KEY set, jev-guard calls https://openrouter.ai/api/v1/systemone with model jev-1.13 (JEV_MODEL picks another, e.g. jaredpalmer/kev-4b).
JEV_BASE_URL points jev-guard at any other server that speaks POST /v1/systemone, such as a local Kev (JEV_BASE_URL=http://127.0.0.1:8009), and takes precedence over the keys above. It gets only its own optional JEV_BASE_API_KEY; no TypeSafe, OpenRouter or gateway key is ever sent to it. It must be https, or plain http on localhost or a private (RFC 1918) address such as a Docker bridge IP. Plain http is unencrypted and unauthenticated: anyone on that network can read the tool calls and forge Jev's answers (making the guard allow everything), so use it only on this machine or a network you trust, and https for a server on another machine. Thresholds were calibrated on Jev: check the calibration table against another model before relying on it.
{
"agent_servers": {
"Claude (guarded)": {
"command": "node",
"args": ["/Users/you/.jev-guard/src/cli.js", "acp", "--", "claude-agent-acp"],
"env": { "JEV_API_KEY": "…" }
}
}
}
The proxy only sees what passes through the client. Tools an agent runs on its own (a built-in web fetch, say) don't cross the wire and aren't covered — use that agent's native hooks for those.
Jev is asked narrow, typed questions; the policy lives in code (src/guard.js).
Action (PreToolUse / BeforeTool / beforeShellExecution / tool_call / tool.execute.before / terminal/create):
risk — a 4-level Score: read-only → easy to undo → hard to undo or outside the workspace → destructive. Returned as a position 0–3.approval — a Noul: would a careful senior engineer want the human to approve this exact call?deny if risk ≥ 2.5
ask if risk ≥ 1.5 or approval ≥ 0.75
allow otherwise
user_requested — a Noul over the session context: did the user's own recent messages ask for exactly this? A yes turns ask into allow (never lifts a deny).from_untrusted — a Noul: does this call carry out an instruction planted in content the agent read, serving that content's author rather than the user? A yes is a deny on it