Guardrails reduce risk; they don't remove it. A determined attacker
can write text a classifier scores low.
No published defaults. A judgment compares a score with your
threshold. jes does not guarantee that the score is right.
One decision-model protocol. Judgments go to a decision model on the
TypeSafe API, such as Jev or Laya (directly or through
OpenRouter), or to tev1 on Ollama, through
TypeSafeClassifier. An outage of the endpoint you chose fails judgments
(see on_backend_error).
A beta client.TypeSafeClassifier is marked beta in
langchain-typesafe, so its constructor may change.
A byte cap, not a token window. jes caps each request it sends at
max_request_bytes (1 MiB by default). TypeSafe may still reject a request
that exceeds the model's own token limits.
Fail-open is still incomplete.on_backend_error="allow" leaves ok
false. See Failures and limits.
Complete replies only. Output judgments and restoration run on one
complete reply. jes does not check or restore a stream.
Tools are checked, not authorized. jes does not restore values into
tool-call arguments, and it does not decide that your application may run
a tool. See Tool calls and agents.
Plain-text restoration. Escape restored values before Markdown, HTML,
JSON, or a shell.
Text only. jes does not moderate images or audio.
One turn at a time. jes does not detect an attack spread across turns,
and does not decode obfuscated payloads.
English and US-centric PII.PERSON uses a spaCy English model, and
the phone number and SSN patterns follow North American and US formats.
Hooks can't undo a tool. A tool result is checked after the tool ran.
Blocking it keeps the model from reading it, but a command or file write
stays done. Only a tool_call check stops a tool.
Hooks depend on the host. What a block does varies by agent. Hermes and
Pi can't reject a prompt, and several hosts can't rewrite the reply. Each
agent page lists its limits.
Hooks can't add a custom question. The agent config picks the built-in
guards and the model, jev-latest by default, but not your own judge().
No URL fetching. URLReachability is not implemented. jes never requests
a host chosen by model output.