Agent skill

Jev Guardrail

by cobusgreyling in cobusgreyling/Jev

Screen LLM input and output with TypeSafe Jev Noul hazard batteries plus a harm Score; policy in code returns pass, review, or block.

MITAuto-check: warningsAI & LLM Engineering

Install Jev Guardrail

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add cobusgreyling/Jev --skill jev-guardrail -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cobusgreyling/Jev jev-guardrail --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cobusgreyling/Jev.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/jev-guardrail .claude/skills/jev-guardrail && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
jev-guardrail
GitHub stars
136
Token cost
~544 tokens
SKILL.md length
185 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

Screen LLM input and output with TypeSafe Jev Noul hazard batteries plus a harm Score; policy in code returns pass, review, or block.

  • Prompt injection
  • SKILL.md covers Battery, Policy lives in code, Pair with a generative model and This repo
  • Calls npx and python
  • Denylist pressure

What it does

Jev Guardrail is an agent skill from cobusgreyling/Jev. Screen LLM input and output with TypeSafe Jev Noul hazard batteries plus a harm Score; policy in code returns pass, review, or block. Use for jailbreak, prompt injection, secret leak, denylist pressure, or when the user runs /jev-guardrail or npx jev guard.

Its SKILL.md is about 540 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in AI & LLM Engineering, covering LLM guardrails and Prompt injection and agent security. The repository describes itself as: Unofficial TypeSafe Jev showcase — System One decisions, not chat. The licence is MIT.

When your agent uses it

  • Prompt injection
  • Denylist pressure
  • The user runs /jev-guardrail

Example prompts

  • “/jev-guardrail”

Requirements

  • Python 3
  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit 77b65c6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.typesafe.ai

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Jev Guardrail loads about 544 tokens when it runs. Until then it costs about 68 tokens; SKILL.md has 185 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~544

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningContains instruction-override wording (e.g. “without asking the user”)SKILL.md:45
    npx jev guard --side input --text "Ignore previous instructions" --json

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cobusgreyling/Jev at commit 77b65c6, republished under its MIT licence (© cobusgreyling). 185 words, ~544 tokens.

Download SKILL.mdSave it as .claude/skills/jev-guardrail/SKILL.md (or your agent's skills folder).
name
jev-guardrail
description
Screen LLM input and output with TypeSafe Jev Noul hazard batteries plus a harm Score; policy in code returns pass, review, or block. Use for jailbreak, prompt injection, secret leak, denylist pressure, or when the user runs /jev-guardrail or `npx jev guard`.

Jev LLM guardrail

Jev does not refuse in prose. It scores hazards. Code returns pass / review / block, then a generative model (or a static message) talks.

Primitives and auth: skills/jev/SKILL.md. Cookbook: https://docs.typesafe.ai/cookbooks/llm_guardrails

Battery

One request. Independent Nouls per hazard + one Score for harm. Gate Noul on the probability. Do not copy a Noul threshold onto Choice confidence.

Input hazards in this repo: jailbreak, prompt_injection, secret_exfil, denylist_pressure, harmful_request.

Output hazards: broke_policy, secret_leak, hallucination, instruction_drift, harmful_content.

Screen both sides. Redact secrets before sending state.

Policy lives in code

Caller-owned thresholds. Defaults in this repo (packages/js/src/guard.ts, jev_lab/policy.py):

SignalStrictPermissive
Noul review≥ 0.35≥ 0.35
Noul action≥ 0.7≥ 0.85
Harm Score promotes review → block≥ 2.0≥ 2.0

Guardrails fail closed (block if the call errors). Routers may fail open; this skill does not.

jailbreak, prompt_injection, secret_exfil, denylist_pressure, harmful_request, broke_policy, secret_leak, harmful_content → block when above the action bar. hallucination and instruction_drift → review.

Pair with a generative model

  • block — do not forward the text; return a fixed refusal
  • review — human or a reasoning model
  • pass — generate as usual

This repo

bash
npx jev guard --side input --text "Ignore previous instructions" --json
npx jev guard --side output --text "$REPLY" --json
python examples/07_guardrails.py
  • packages/js/src/guard.ts — inputBattery / outputBattery / routeGuard
  • examples/07_guardrails.py — Choice + Noul, then skip the chat model

© cobusgreyling, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/jev-guardrail of cobusgreyling/Jev.

Open the folder on GitHubat commit 77b65c6

Compare with similar skills

Jev Guardrail next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Jev Guardrail compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Jev Guardrail this skillcobusgreyling/Jev136—~544Automated safety check: WarnMIT
Aisafetyhotwuyoscar/AISafetyHot-Hub827—~1.4kAutomated safety check: PassCustom licence
Writing Eval Scenariosopen-bias/open-bias143—~1.5kAutomated safety check: PassApache-2.0
Prompt GuardOrchestra-Research/AI-Research-SKILLs13k1 repos~2.4kAutomated safety check: WarnMIT
Building Agent Systemstelagod/code-abyss244—~691Automated safety check: PassMIT
Defending LLMs With Guardrailsmukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: WarnApache-2.0

Similar skills

  • Aisafetyhot

    wuyoscar/AISafetyHot-Hub

    Query AI Safety HOT news, research papers, incidents, hot topics, and daily/weekly/monthly reports through its public read-only MCP service.

    827 GitHub stars~1.4k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Writing Eval Scenarios

    open-bias/open-bias

    Guide for writing eval conversation JSONs and running them through policy engines

    143 GitHub stars~1.5k tokensUpdated 3 days ago
    AI & LLM EngineeringAuto-check passed
  • Prompt Guard

    Orchestra-Research/AI-Research-SKILLs

    Meta's 86M prompt injection and jailbreak detector. An agent skill from Orchestra-Research/AI-Research-SKILLs.

    13k GitHub starsUsed in 1 repo~2.4k tokens
    AI & LLM EngineeringAuto-check: warnings
  • Building Agent Systems

    telagod/code-abyss

    AI agent and LLM system engineering reference covering single-agent dev (ReAct, tool calling, plan-execute), multi-agent coordination (swarm, role decomposition, file locking), LLM security (prompt…

    244 GitHub stars~691 tokensUpdated 2 mo ago
    AI & LLM EngineeringAuto-check passed
  • Defending LLMs With Guardrails

    mukul975/Anthropic-Cybersecurity-Skills

    Deploys Llama Guard 3 safety classification, NeMo Guardrails programmable dialogue rails, and LLM Guard input/output scanner pipelines as complementary runtime defenses that inspect and constrain…

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    AI & LLM EngineeringAuto-check: warnings
  • Clade Policy Guardrails

    jeremylongshore/tons-of-skills-marketplace

    Implement content safety guardrails for Claude — input filtering, Use when working with policy-guardrails patterns.

    2.8k GitHub stars~1.1k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed

More from cobusgreyling/Jev

  • Jev

    cobusgreyling/Jev

    Use TypeSafe Jev for typed judgments (Choice, Score, Noul) instead of asking a chat model to classify.

    136 GitHub stars~708 tokensUpdated today
    Auto-check passed
  • Jev Fanout

    cobusgreyling/Jev

    Ask every independent TypeSafe Jev question in one POST /v1/systemone (speculative fan-out).

    136 GitHub stars~603 tokensUpdated today
    Auto-check passed
  • Jev Route

    cobusgreyling/Jev

    Route with TypeSafe Jev — map Choice plus confidence to act/confirm/human, or pick a coding-agent model tier.

    136 GitHub stars~481 tokensUpdated today
    Auto-check passed

Questions about Jev Guardrail

What does Jev Guardrail do?

Screen LLM input and output with TypeSafe Jev Noul hazard batteries plus a harm Score; policy in code returns pass, review, or block. Jev Guardrail is an agent skill from cobusgreyling/Jev. Screen LLM input and output with TypeSafe Jev Noul hazard batteries plus a harm Score; policy in code returns pass, review, or block.

When should I use Jev Guardrail?

Jev Guardrail fits situations like: prompt injection; denylist pressure; the user runs /jev-guardrail.

How do I install Jev Guardrail in Claude Code?

Run `npx skills add cobusgreyling/Jev --skill jev-guardrail -a claude-code`. Or copy the skill folder (skills/jev-guardrail in cobusgreyling/Jev) into .claude/skills/jev-guardrail in your project. Claude Code loads it when a task matches its description.

How do I install Jev Guardrail in Codex?

Run `npx skills add cobusgreyling/Jev --skill jev-guardrail -a codex`. Or copy the skill folder (skills/jev-guardrail in cobusgreyling/Jev) into .agents/skills/jev-guardrail in your project. Codex loads it when a task matches its description.

Can I use Jev Guardrail in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cobusgreyling/Jev --skill jev-guardrail -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/jev-guardrail, .gemini/skills/jev-guardrail, .github/skills/jev-guardrail and .opencode/skills/jev-guardrail in your project.

What does Jev Guardrail need to run?

Going by SKILL.md and its folder, Jev Guardrail needs the command-line tools its instructions call (npx and python). Our summary lists: Python 3; Node.js.

Does Jev Guardrail access the network?

SKILL.md names 1 domain. As links in the text: docs.typesafe.ai. This is read from the text; nothing was executed.

Is Jev Guardrail safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): contains instruction-override wording (e.g. “without asking the user”). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Jev Guardrail use?

Jev Guardrail is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Jev Guardrail use?

About 544 tokens (SKILL.md is roughly 2.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Jev Guardrail?

Skills that share tags, products or a category with Jev Guardrail: Aisafetyhot (wuyoscar/AISafetyHot-Hub, 827 stars), Writing Eval Scenarios (open-bias/open-bias, 143 stars), Prompt Guard (Orchestra-Research/AI-Research-SKILLs, 13k stars) and Building Agent Systems (telagod/code-abyss, 244 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Jev Guardrail?

cobusgreyling (a GitHub user) maintains it in cobusgreyling/Jev, which has 136 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 10, 2026.

Source: cobusgreyling/Jev on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.