madisonrickert

Jev Permission Gate — Development skill for Claude Code

Development community

A Claude Code mod that uses TypeSafe's Jev to decide auto mode tool calls.

How to install Jev Permission Gate

This entry records only its repository, not the path inside it, so there is no exact command to give. Open madisonrickert/jev-permission-gate and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Jev Permission Gate does

A Claude Code mod that uses TypeSafe's Jev to decide auto mode tool calls. 2x faster than the built-in classifier on the calls it decides.

Alternatives in Development

  • 12 Yolo Auto Mode Classifier — YOLO/Auto-Mode Classifier System 2.3k ★
  • Claude Code Rust — 🚀 Rust 全量重构的 Claude Code - 性能提升 2.5x,体积减少 97% High-performance Rust implementation of Claude Code with 2.5x f 1.4k ★
  • Quick Eval — Quick job evaluation 473 ★

README

jev-permission-gate

A [Claude Code](https://code.claude.com) mod that puts [TypeSafe's Jev](https://docs.typesafe.ai/) in front of the auto mode classifier. In auto mode, for each tool call Claude Code would otherwise send to its built-in classifier, Jev answers eight yes/no questions in one request and the mod decides:

  • allow when Jev is at least 85% sure the call serves your request and every risk check is at or below 25%. The built-in classifier doesn't run.
  • deny when the call is both risky and unrequested: some risk check at or above 80% and "serves your request" at or below 30%. Claude sees the reason.
  • defer everything else to the built-in classifier, unchanged.

Results

Measured head to head against Claude Code's built-in classifier in a live session, on identical tool calls (details below):

  • 2× faster where Jev decides. The permission wait drops from a median of 329ms to 164ms.
  • Matching judgment. Jev's verdicts agreed with the built-in classifier's on every call it would have decided.
  • No unsafe allows in testing. Across 93 labeled cases, including a fresh held-out set with manipulation attempts and non-English requests, it made zero unsafe allows and zero wrong denials. With 35 risky cases, that bounds the unsafe-allow rate below about 9% (95% confidence); more cases will tighten it. Anything Jev isn't sure about goes to the built-in classifier.
  • Resists steering. An eighth question flags text inside a call that claims approval or argues for itself, and a pattern check keeps obvious cases from reaching Jev at all.
  • Cheap to defer. The classifier's work overlaps Jev's request, so calls Jev hands off cost almost nothing extra at the median.

Today Jev decides about half of the calls in a typical workload, which cut the average permission wait by 16% overall. Every point of decision rate raises that: at the 84% Jev reached on the eval set, the projected saving is about 40%. Raising that rate is the main lever