Project profile
pi-jev-auto-mode
A fail-closed permission gate for the Pi coding agent. Deterministic rules run first. Hosted Jev judges what those rules escalate.
Last verified: 2026-09-30
Quick facts
| Project | pi-jev-auto-mode |
|---|---|
| Creator | jomatsu |
| Type | Developer Tool |
| Language | TypeScript |
| License | MIT |
| Uses Jev for | Semantic allow or block after deterministic policy |
| Open source | Yes |
| Status | Active |
What it is
Pi has no built-in permission system, so this extension judges bash, write, and edit calls. Hard-deny never reaches the model. The default for an undecidable Jev answer, a timeout, or a missing engine is to block.
Why it matters
It shows a coding-agent gate with the threshold policy written down, including which questions are allowed to abstain and which are not.
Relationship to Jev
| Hosted Jev | Yes. The semantic layer calls TypeSafe's System One API. |
|---|---|
| Order | Hard-deny, user patterns, then Jev only for what the first layer escalates. |
| Failure | README: no engine, timeout, malformed response, or cancellation blocks. |
| Middle band | Default is block. A setting can ask the user or allow the band instead. |
Architecture
- Tool call
- Deterministic policy
- Jev questions
- Allow or block
Key features
- gateScope defaults to all, so commands that match no pattern are still judged.
- Protected paths such as .env, .git, and ~/.ssh are escalated even inside the project.
- The README says 171 tests run without the network, and that docs/calibration.md records the measured probabilities behind the thresholds.
Performance and claims
The README says an unrequested git reset --hard, npm publish, rm -rf, or sudo is blocked, while an unrequested mv, cp, tar, chmod +x, or node -e can be judged and allowed.
Jev AI Hub read the README and the repository record on 2026-09-30. It has not replayed those commands.
The part to copy is the order of checks and the fail-closed default. The part to remeasure is the threshold, which the author fit on their own API calls.
Limitations
- A judged call is a network round trip. The README says eleven ordinary commands measured 193–642 ms.
- The gate is an extension for Pi, not a universal Claude Code or Cursor hook.
- This hub has not installed the extension.
Code and repository
https://github.com/jomatsu/pi-jev-auto-mode
GitHub snapshot captured 2026-09-30: 31 stars, 3 forks, 2 open issues. Last push 2026-09-24. Counts change; this is not a live lookup.
Related Jev concepts
Confidence-gated routingDecision layerCoding-agent gates
Related guides
Related projects
Sources
- pi-jev-auto-mode READMEjomatsu · accessed 2026-09-30 · github
- jomatsu/pi-jev-auto-mode repository metadataGitHub · accessed 2026-09-30 · third-party