src / route.ts
import { HAZARDS, type Assessment, type Hazard, type Settings, type Verdict } from "./types";
export const MANUAL = "Ask the user to run it manually if intended.";
const HAZARD_PHRASES: Record<Hazard, string> = {
destroys_data: "may delete or overwrite data",
touches_system: "may modify the system or files outside the working directory",
network_exfil: "may send data to, or run content from, a remote host",
privilege_or_persistence: "may escalate privileges or install persistent behavior",
obfuscated: "hides its true effect",
};
/** Turns jev's raw probabilities into pass / uncertain / block using the user's thresholds. */
export function route(assessment: Assessment, settings: Settings): Verdict {
let hazard: Hazard = HAZARDS[0];
for (const h of HAZARDS) {
if (assessment.hazards[h] > assessment.hazards[hazard]) hazard = h;
}
const probability = assessment.hazards[hazard];
const details = { hazard, probability, severity: assessment.severity };
if (assessment.severity >= settings.severityBlock || probability >= settings.blockThreshold) {
return { kind: "block", ...details };
}
if (probability >= settings.reviewThreshold) return { kind: "uncertain", ...details };
return { kind: "pass" };
}
export function refusalMessage(verdict: Exclude<Verdict, { kind: "pass" }>): string {
const what = verdict.kind === "block" ? "judged unsafe" : "could not be confirmed safe";
return (
`Blocked: this command was ${what} (${HAZARD_PHRASES[verdict.hazard]}; ` +
`p=${verdict.probability.toFixed(2)}, severity ${verdict.severity.toFixed(1)}). ${MANUAL}`
);
}
src / route.ts
import { HAZARDS, type Assessment, type Hazard, type Settings, type Verdict } from "./types";
export const MANUAL = "Ask the user to run it manually if intended.";
const HAZARD_PHRASES: Record<Hazard, string> = {
destroys_data: "may delete or overwrite data",
touches_system: "may modify the system or files outside the working directory",
network_exfil: "may send data to, or run content from, a remote host",
privilege_or_persistence: "may escalate privileges or install persistent behavior",
obfuscated: "hides its true effect",
};
/** Turns jev's raw probabilities into pass / uncertain / block using the user's thresholds. */
export function route(assessment: Assessment, settings: Settings): Verdict {
let hazard: Hazard = HAZARDS[0];
for (const h of HAZARDS) {
if (assessment.hazards[h] > assessment.hazards[hazard]) hazard = h;
}
const probability = assessment.hazards[hazard];
const details = { hazard, probability, severity: assessment.severity };
if (assessment.severity >= settings.severityBlock || probability >= settings.blockThreshold) {
return { kind: "block", ...details };
}
if (probability >= settings.reviewThreshold) return { kind: "uncertain", ...details };
return { kind: "pass" };
}
export function refusalMessage(verdict: Exclude<Verdict, { kind: "pass" }>): string {
const what = verdict.kind === "block" ? "judged unsafe" : "could not be confirmed safe";
return (
`Blocked: this command was ${what} (${HAZARD_PHRASES[verdict.hazard]}; ` +
`p=${verdict.probability.toFixed(2)}, severity ${verdict.severity.toFixed(1)}). ${MANUAL}`
);
}