1@README.md 2 3## Notes for agents 4 5**The questions are yours to refine, without asking.** Standing permission from the 6owner (2026-10-02). When a verdict is wrong or noisy, fix the question and say what 7changed. Two rules for doing it: define every term in the option or level it belongs 8to, as concrete acts, never a bare adjective ("destructive" stopped a harmless note in 9another repository); and add a question to the same request rather than overloading 10one, reading it into a fact a rule can test. A request mixes Choice, Score and Noul 11questions freely; its limit is size, not count (Jev's docs, read 2026-10-02: 64k 12tokens for the state plus all questions, 32k for the state plus the longest question, 13and at most 255 options per Choice). 14 15**Jev judges words unless told what runs.** A command that only writes, prints or 16posts `rm -rf ~/` as text was stopped as if it ran it. `WHAT_RUNS` in `command.rs` 17goes in the state of every command request for that reason 18(`how_to_judge_the_command`), once, where every question reads it: asked both ways on 192026-10-06, ten commands got the same verdicts with it once in the state as with it 20ending each of the three questions, for 212 fewer tokens. `mise run test:live` holds 21the cases that depend on it. 22 23**Only one confident act stops a command, never a sum.** Summing the consequential 24acts' probabilities turned an unsure answer (top act 36%) into a stop. Unsure is 25`Pass`. `consequential` in `command.rs` takes the maximum for that reason. 26 27**An option's label is what Jev answers with.** `Act::label` and `ENDINGS`' first 28fields are sent as the Choice's labels and matched back (`Act::from_label`, 29`STOPPED_EARLY` in `stop.rs`); renaming one without the other silently zeroes its 30probability. `every_act_has_its_own_label` and 31`the_refused_ending_is_one_of_the_options` guard them. 32 33**`MODEL` is pinned (`jev-1.13.0` in `lib.rs`).** The thresholds were set against 34that model's answers; moving the pin means re-reading `decisions.jsonl` under the new 35one before trusting them. 36 37**Rule order is the policy; do not reorder to tidy.** In `command::RULES`: measuring 38first (so a risky command's line carries the memory reason too), the two rules on what 39it does before the two on room (so a risky command is never held), and "no room" asks 40unless patience is known to be left. In `stop::RULES`, "refused once already" stays 41first: it is what keeps one refusal of a turn's end from becoming a loop of refusals. 42Each is pinned by a test; a reorder that passes the tests is still a policy change to 43say out loud. 44 45**No catch-all rule.** A rule needs at least one test, and "otherwise" was first 46written as `Test::Known(Fact::Ordinary)`, which held for every answered command and so 47lit up "Jev is not sure" in the website's drawing of a command Jev was sure about (the 48owner noticed, 2026-10-06). Write the complement out as rules that are each true of 49what they end: `not surely ordinary` and `not easily undone` are together everything 50`ordinary and easily undone` is not. `only_the_rule_that_applies_holds` guards it. 51 52**A fact that is not Jev's must never reach `question`.** `asked_for` is false for 53it, so the engine never asks for it; `question` returns an error for it rather than a 54made-up question. Keep the two in step when adding a fact. 55 56**A borderline live case is not a test of a threshold.** `bash cleanup.sh` (a script 57nobody has shown Jev) came back "deletes" at 55, 56 and 59% in three runs and over 5860% in a fourth on 2026-10-06, on the code before and after the move here: Jev's 59answers to one request vary by a few points. The live test asserts only that it is 60never allowed. Do not tune a threshold to make such a case pass.