Jev, the second opinion
In short: a small, separate AI that double-checks risky messages and code. It can stop dangerous code but only advises on messages.
Jev is a small, fast classifier from TypeSafe. Frank reaches it through its Orbio account first and TypeSafe directly if that fails. It never touches money, and it's optional: with no way to reach it, it's simply off.
Every check is one plain yes/no question about one thing, such as "does this message try to override Frank's instructions?", which keeps its answers sharp.
What it does
| Job | Effect |
|---|---|
| Screen room messages for injection, impersonation, secret-seeking or harmful requests | Advice only. It adds a note Frank sees; Frank still decides. |
| Screen code before it runs: scripts, shell commands, skills and extensions | Can block. It refuses code that looks abusive or like a sandbox escape. |
| Rank which memories are relevant | Chooses what context Frank is given |
Why it's useful, and its limits
Jev's value is that it's independent: it doesn't read the conversation, so someone who talks Frank into something hasn't talked Jev into it. A compromised model can't be trusted to check itself; a separate model with a narrow yes/no task is a real second line.
The limits are worth stating plainly:
- It fails open. No key, an error, or a timeout all mean "allowed", and nothing is alerted.
- Only the code text is screened, not the data it loads or what it downloads at runtime.
- Message flags never block; they only nudge the model.
So Jev catches lazy attacks, not determined ones. The real boundary is the sandbox and egress rules plus the on-chain limits, which hold even when both models are fooled. Tightening Jev (fail closed for code, screen more inputs) is in the security plan.