2 Downloads
2 Downloads
Gives local models a shell_run tool. Every command is safety-checked before it runs, using
TypeSafe's jev model plus a small deterministic deny list. Pipes, redirects, && and $(...) work
because commands run through /bin/sh -c.
npm installnpm run dev (runs lms dev) to try it in LM Studio, or npm run push to install it.Either of these works; the plugin setting wins if both are set:
JEV_API_KEY for the LM Studio process. LM Studio started from the Dock
or Finder, or a plugin process started by an already-running LM Studio background service, may not
inherit variables from ~/.zshrc or from launchctl setenv. If commands are refused with "no jev API
key", use the plugin setting instead.If no key is found, every command is refused with a message saying so; nothing runs unchecked. The key is
removed from the environment of the commands the tool runs, so a model cannot read it back with env.
Refusals come back to the model as Blocked: ... text that tells it to hand off to you.
xargs -I{} rm -rf {}); jev is the second line of defense.npm run calibrate.echo hello > notes.txt, ). Raise the thresholds if that is too strict.npm test runs the offline unit tests. npm run calibrate calls the real jev API (needs JEV_API_KEY).
Gives local models a shell_run tool. Every command is safety-checked before it runs, using
TypeSafe's jev model plus a small deterministic deny list. Pipes, redirects, && and $(...) work
because commands run through /bin/sh -c.
npm installnpm run dev (runs lms dev) to try it in LM Studio, or npm run push to install it.Either of these works; the plugin setting wins if both are set:
JEV_API_KEY for the LM Studio process. LM Studio started from the Dock
or Finder, or a plugin process started by an already-running LM Studio background service, may not
inherit variables from ~/.zshrc or from launchctl setenv. If commands are refused with "no jev API
key", use the plugin setting instead.If no key is found, every command is refused with a message saying so; nothing runs unchecked. The key is
removed from the environment of the commands the tool runs, so a model cannot read it back with env.
Refusals come back to the model as Blocked: ... text that tells it to hand off to you.
xargs -I{} rm -rf {}); jev is the second line of defense.npm run calibrate.echo hello > notes.txt, ). Raise the thresholds if that is too strict.npm test runs the offline unit tests. npm run calibrate calls the real jev API (needs JEV_API_KEY).
/, ~ or *,
writes to system paths or ~/.ssh, mkfs, dd to devices, fork bombs, and piping downloads into a
shell. It looks inside pipelines, $(...), backticks, sh -c, eval and wrappers like env/nohup.cp config.example.json config.json/bin/sh and process groups)./, ~ or *,
writes to system paths or ~/.ssh, mkfs, dd to devices, fork bombs, and piping downloads into a
shell. It looks inside pipelines, $(...), backticks, sh -c, eval and wrappers like env/nohup.cp config.example.json config.json/bin/sh and process groups).