Jev in production › Agent guardrails and approvals
OpenCode and Claude Code plugin that sends unresolved shell permission requests to Jev as four Noul questions (harmful, sensitive, untrusted, obscured) and auto-approves only when all pass calibrated thresholds; otherwise the normal prompt runs.

The permissions plugin auto-approves harmless shell permission requests. Anything uncertain continues through your agent's normal permission flow.
In this isolated demo, a test reviewer requests the nonmatching OpenCode approvals.
Claude checks readable ask settings; managed, command-line, and session-only rules are not visible to its hook.
Each coding agent evaluates its own permission policy first. Existing allow and deny decisions stay final. Visible configured ask rules remain human prompts. Jevvy Permissions reviews other unresolved shell approval requests as complete commands. It approves only the current action when every inquiry passes. Otherwise it abstains, leaving the agent's remaining permission flow unchanged.
For the project's own README, linking back here: