Jev in production › Agent guardrails and approvals

pi-system-one-auto (lunaroute)

Jev answers one question per safety rule to allow, block, or ask before each tool call the Pi coding agent executes, with safety behavior benchmarked using DSPy.

Open on GitHub ↗

The source publishes no measured number.
Use
Agent guardrails and approvals
Industry
Developer tools
Form
Open-source tool
Stage
Beta
Plugs into
Pi coding agent
Listed
2026-10-06
Found via
github
Repository
dbreunig/lunaroute-systemone-auto
Stars
4
Forks
0
Last push
2026-10-05
Language
HTML
License
none stated

The README opens with

An auto-mode safety monitor for the Pi coding agent. Every tool call Pi is about to run is judged by a program that asks a System One classifier one question per rule, then decides allow, block, or ask in code. The program is written and benchmarked in DSPy 3.4 against TypeSafe's Jev (jevauto/), then exported to a TypeScript Pi extension (pi-extension/, package pi-system-one-auto) that calls lunaroute/djev by default.

The rules come from autoprompt.md, a monolithic LLM classifier prompt. Following the Jev skill, the prompt is decomposed rather than sent whole:

Badge

For the project's own README, linking back here:

Listed in Jev in production

Also used for agent guardrails and approvals