Jev in production › Agent guardrails and approvals
Risk-scores every coding-agent tool call as deny, ask, or allow with Jev across Claude Code, Codex, Copilot, Gemini and Cursor; vendor claims about $0.00004 per call (leepokai).

jev-guard A security hook for coding agents, powered by Jev .
Claude Code's auto mode is described as: "A separate classifier model reviews actions before they run, blocking anything that escalates beyond your request, targets unrecognized infrastructure, or appears driven by hostile content Claude read." That is exactly the job jev-guard does — as three typed questions to Jev (risk, userrequested, fromuntrusted) instead of a proprietary classifier — and it does it for Codex, Copilot, Gemini, Cursor, pi, OpenCode and ACP editors too, with the same policy and the same session memory everywhere. If you want auto mode outside Claude Code, or a second opinion inside it, this is the build.
For the project's own README, linking back here: