1@README.md
2
3## Notes for agents
4
5**The questions are yours to refine, without asking.** Standing permission from the
6owner (2026-10-02). When a verdict is wrong or noisy, fix the question and say what
7changed. Two rules for doing it: define every term in the option or level it belongs
8to, as concrete acts, never a bare adjective ("destructive" stopped a harmless note in
9another repository); and add a question to the same request rather than overloading
10one, reading it into a fact a rule can test. A request mixes Choice, Score and Noul
11questions freely; its limit is size, not count (Jev's docs, read 2026-10-02: 64k
12tokens for the state plus all questions, 32k for the state plus the longest question,
13and at most 255 options per Choice).
14
15**Jev judges words unless told what runs.** A command that only writes, prints or
16posts `rm -rf ~/` as text was stopped as if it ran it. `WHAT_RUNS` in `command.rs`
17goes in the state of every command request for that reason
18(`how_to_judge_the_command`), once, where every question reads it: asked both ways on
192026-10-06, ten commands got the same verdicts with it once in the state as with it
20ending each of the three questions, for 212 fewer tokens. `mise run test:live` holds
21the cases that depend on it.
22
23**Only one confident act stops a command, never a sum.** Summing the consequential
24acts' probabilities turned an unsure answer (top act 36%) into a stop. Unsure is
25`Pass`. `consequential` in `command.rs` takes the maximum for that reason.
26
27**An option's label is what Jev answers with.** `Act::label` and `ENDINGS`' first
28fields are sent as the Choice's labels and matched back (`Act::from_label`,
29`STOPPED_EARLY` in `stop.rs`); renaming one without the other silently zeroes its
30probability. `every_act_has_its_own_label` and
31`the_refused_ending_is_one_of_the_options` guard them.
32
33**`MODEL` is pinned (`jev-1.13.0` in `lib.rs`).** The thresholds were set against
34that model's answers; moving the pin means re-reading `decisions.jsonl` under the new
35one before trusting them.
36
37**Rule order is the policy; do not reorder to tidy.** In `command::RULES`: measuring
38first (so a risky command's line carries the memory reason too), the two rules on what
39it does before the two on room (so a risky command is never held), and "no room" asks
40unless patience is known to be left. In `stop::RULES`, "refused once already" stays
41first: it is what keeps one refusal of a turn's end from becoming a loop of refusals.
42Each is pinned by a test; a reorder that passes the tests is still a policy change to
43say out loud.
44
45**No catch-all rule.** A rule needs at least one test, and "otherwise" was first
46written as `Test::Known(Fact::Ordinary)`, which held for every answered command and so
47lit up "Jev is not sure" in the website's drawing of a command Jev was sure about (the
48owner noticed, 2026-10-06). Write the complement out as rules that are each true of
49what they end: `not surely ordinary` and `not easily undone` are together everything
50`ordinary and easily undone` is not. `only_the_rule_that_applies_holds` guards it.
51
52**A fact that is not Jev's must never reach `question`.** `asked_for` is false for
53it, so the engine never asks for it; `question` returns an error for it rather than a
54made-up question. Keep the two in step when adding a fact.
55
56**A borderline live case is not a test of a threshold.** `bash cleanup.sh` (a script
57nobody has shown Jev) came back "deletes" at 55, 56 and 59% in three runs and over
5860% in a fourth on 2026-10-06, on the code before and after the move here: Jev's
59answers to one request vary by a few points. The live test asserts only that it is
60never allowed. Do not tune a threshold to make such a case pass.