For agents, on top of README.md, which they read first.
Notes for agents
The questions are yours to refine, without asking. Standing permission from the
owner (2026-10-02). When a verdict is wrong or noisy, fix judge.rs and say what
changed. Two rules for doing it: define every term in the option or level it belongs
to, as concrete acts, never a bare adjective ("destructive" stopped a harmless note in
another repository); and add a question to the same request rather than overloading
one, deriving the verdict from the typed answers in code where a test can pin it. A
request mixes Choice, Score and Noul questions freely; its limit is size, not count
(Jev's docs, read 2026-10-02: 64k tokens for the state plus all questions, 32k for the
state plus the longest question, and at most 255 options per Choice).
Jev judges words unless told what runs. A command that only writes, prints or
posts rm -rf ~/ as text was stopped as if it ran it. WHAT_RUNS in judge.rs is in
every command question for that reason; keep it in any new question about a command.
Only one confident act stops a command, never a sum. Summing the consequential
acts' probabilities turned an unsure answer (top act 36%) into a stop. Unsure is
Pass.
An option's label is what Jev answers with. Act::label and ENDINGS' first
fields are sent as the Choice's labels and matched back (Act::from_label, the
"stopped-early" lookup in stop); renaming one without the other silently zeroes
its probability. every_act_has_its_own_label guards the acts only.
MODEL is pinned (jev-1.13.0 in serve.rs). The thresholds were set against
that model's answers; moving the pin means re-reading decisions.jsonl under the new
one before trusting them.
Never remove the stop_hook_active check. It is what keeps one refusal of a
turn's end from becoming a loop of refusals.
The decision log is evidence, not a guard. DecisionLog::append reports a failed
write and the decision stands; do not make a full disk block a command.
Outcomes are logged only for judged tool calls. Session.judged holds their ids
until PostToolUse, PostToolUseFailure or PermissionDenied removes them; an
outcome record for an unjudged call would join to nothing.
A configured memory command is the only source once set. Headroom never falls
back to MemAvailable when the command fails (a_configured_command_is_the_only_source).