Fast probabilistic judgments inside coding-agent workflows
A plugin collection powered by TypeSafe's System One model.
The permissions plugin auto-approves harmless shell permission requests. Anything uncertain continues through your agent's normal permission flow.
In this isolated demo, a test reviewer requests the nonmatching OpenCode approvals.
Claude checks readable ask settings; managed, command-line, and session-only rules are not visible to its hook.
Node.js 22.19 or newer is required.
npx @jevvy/permissions initopencode plugin add @jevvy/permissions/plugin marketplace add PanAchy/jevvy
/plugin install jevvy-permissions@jevvy
Each coding agent evaluates its own permission policy first. Existing allow and deny decisions stay final. Visible configured ask rules remain human prompts. Jevvy Permissions reviews other unresolved shell approval requests as complete commands. It approves only the current action when every inquiry passes. Otherwise it abstains, leaving the agent's remaining permission flow unchanged.
flowchart TD
rules[Coding agent permission policy]
rules -->|Allow| run[Run the command]
rules -->|Deny| block[Block the command]
rules -->|Configured ask| remaining[Continue the remaining permission flow]
rules -->|Other approval request| review[Jevvy Permissions reviews]
review -->|Every inquiry passes| approve[Approve this action]
review -->|Anything else| remaining
approve --> proceed[Coding agent continues]
proceed -->|No further check| run
proceed -->|Prompt or check required| remaining
Jevvy Permissions reads one global file at ~/.config/jevvy/jevvy.jsonc. Project repositories cannot override it. JSONC comments and trailing commas are supported. Keep $schema for editor validation and autocomplete.
| Provider | provider |
Credential sources |
|---|---|---|
| OpenCode Zen | zen |
providers.zen.apiKey or OPENCODE_API_KEY |
| TypeSafe AI | typesafe |
providers.typesafe.apiKey or TYPESAFE_API_KEY |
| OpenRouter | openrouter |
providers.openrouter.apiKey or OPENROUTER_API_KEY |
| Vercel AI Gateway | vercel |
providers.vercel.apiKey or AI_GATEWAY_API_KEY |
| Custom endpoint | custom |
Optional providers.custom.apiKey |
The plugin uses only the selected provider and never falls back to another one.
Select custom to use any HTTP endpoint that accepts the System One request shape and returns typed System One answers:
{
"$schema": "https://raw.githubusercontent.com/PanAchy/jevvy/main/config.schema.json",
"provider": "custom",
"providers": {
"custom": {
"endpoint": "https://system-one.example.com/v1/decisions",
"model": "your-model",
"apiKey": "your-api-key",
},
},
}Custom endpoints use the shipped approval policy unless you replace it. The shipped calibration evidence applies only when the route is verified to serve the calibrated Jev model.
By default, Jevvy Permissions requires all four shipped questions to pass:
| Question | What it checks | Pass condition |
|---|---|---|
| Harmful | Could the command cause meaningful harm that deserves review? | Noul ≤ 0.35 |
| Sensitive | Does the command risk exposing credentials, private data, or security-sensitive material? | Noul ≤ 0.50 |
| Untrusted | Does the command execute newly obtained, installed, generated, or concealed code? | Noul ≤ 0.50 |
| Obscured | Is the command's consequential behavior hidden, indirect, or materially uncertain? | Noul ≤ 0.50 |
The four shipped questions, thresholds, and model identities were calibrated together against eval/commands.json. The set includes harmless controls and commands that must remain prompts; any must-ask auto-approval disqualifies a calibration run. Custom policies are not covered by this evidence.
Custom policies replace all shipped questions. Define a non-empty map of risk-oriented System One Nouls, each with a permission threshold:
{
"permissions": {
"questions": {
"harmful": {
"type": "noul",
"instructions": "Could this command cause meaningful harm that deserves human review?",
"criteria": {
"false": "Routine or harmless",
"true": "Potentially harmful",
},
"threshold": 0.35,
},
},
},
}A Noul answer is the probability that the answer is yes. Each Inquiry passes only when its answer is no greater than its threshold. See TypeSafe's Noul documentation.
Install the optional calibrate-permissions skill when you want an agent to design or validate a custom policy:
npx skills add PanAchy/jevvy --skill calibrate-permissionsThe skill runs jevvy-calibrate against the plugin's bundled baseline. Focused command corpora are optional for risks the baseline does not represent. Calibration produces one append-safe JSONL artifact containing metadata, every raw score, and a final summary.


{ "$schema": "https://raw.githubusercontent.com/PanAchy/jevvy/main/config.schema.json", "provider": "typesafe", }