Jev end to end: the policy author and publish skills, for failproofai 1.0.9 - #24
Merged
Merged
Conversation
The skill here predated Jev and had drifted from the product's copy. Merge that copy in three ways from this repo's first import (byte-identical to it), with its content corrected for 1.0.9: the npm package ships no Jev checks, reviewedBy counts only for installed checks, publish holds a third-party pack to 9,101 characters, --min-cli-version defaults to 1.0.8-beta.0, and Hermes' native plugin makes instruct block once per model response while user_said stays empty. Kept from this repo: routing to failproofai-policy-publish and fp-cloud-cli, the policy backtest sections, and fleet-tool-coverage's canonicalNames fix. builtins.md and policy-events.json regenerated against 1.0.9. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Folds in what #23 had and this branch did not, rewritten for failproofai 1.0.9, so one PR covers Jev from authoring to publishing. failproofai-policy-publish: - New "Packs that carry Jev checks" section: the 1.0.9 dry-run lines, what publish refuses, the 9,101-character budget, minCliVersion, the rollback reminder, and what policies show / policies add print for a pack's checks. - publishing.md: the refusal messages as 1.0.9 prints them, the budget, reserved and contested names, the FailproofAI/ namespace, minCliVersion, installing a dry run locally, and observe / --cli packs. - Discovery also finds semanticPolicies.add files. failproofai-policy-author: - Consent rules decideV1 checks in code: op_requested clears a shell command only when every target is named, task_step does not soften one the user named only in part, and a command the scan cannot read whole (any $ expansion, globs, brace expansion, heredocs, eval, sh -c) is never cleared or softened. - Reviewable clearing: in 1.0.9 a warning nobody consented to keeps the floor, and one from a deny-mode check cancels every clear on the call (combine.ts, jev-review.ts). The text said a warning counted as a clear. README: both rows mention Jev. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
failproofai-policy-authorhere predates Jev, FailproofAI's semantic evaluator, and has drifted from the copy the product maintains. Anyone installing it today gets no guidance on Jev checks, reviewable blocks, packs as the way to enable builtins, or failproofai guarding the agent's own session. The product copy itself was also out of date for failproofai 1.0.9, which no longer ships Jev's 16 checks in the npm package.failproofai-policy-publishhas no Jev guidance at all, although a pack is the only way a Jev check reaches a machine.This PR covers Jev end to end, from writing a check to publishing the pack that carries it, all corrected for 1.0.9. It replaces #23, which did the same for 1.0.8-beta.0. Everything this repo changed on its own is kept.
What changed
Jev in 1.0.9: no pack, no policy
FailproofAI/jev-policiespack, not built into the CLI.reviewedBycounts only for checks installed on the machine. A policy naming a check the machine doesn't have stays hard.publishlimits a pack from anyone other than FailproofAI to 9,101 characters of questions, and the dry run fails if it's over. The old text said the limit was the whole 27,591.--min-cli-versiondefaults to1.0.8-beta.0for packs with checks;publishwith no repository is a dry run.--cli <agent>scopes a pack to one agent; re-adding with a new version upgrades it;policies removeuninstalls it.Reviewable clearing and consent, as 1.0.9 decides them
combine.ts,jev-review.ts). The product copy said a warning counted as a clear.decideV1checks in code:op_requestedclears a shell command only when every target it names appears in what the user typed;task_stepdoes not soften a command the user named only in part;$expansion, globs, brace expansion, heredocs,evalandsh -c, so no request clearsrm -rf build/*.Publishing Jev packs (
failproofai-policy-publish, from #23, rewritten for 1.0.9)publishrefuses;minCliVersion;policies showandpolicies addprint for a pack's checks.references/publishing.mdcovers:FailproofAI/namespace;minCliVersion;--clipacks.semanticPolicies.add.Hermes
instructon the native plugin blocks the first attempt in each model response and lets the retry through. The old text said it was only a stderr note.user_saidis always empty on Hermes, so Jev probes must judge the command itself.Brought in from the product copy
policy-drafts/and hand the operator the commands.enabledPoliciesstops counting once any pack is installed.Kept from this repo
failproofai-policy-publishandfp-cloud-cli. The product copy routes to afailproofai-policy-deployskill that doesn't exist here.SKILL.mdandreferences/cloud.md. The feature is still live in the dashboard.canonicalNamesfix infleet-tool-coverage.mjs.Generator
sync-builtins.mjsreads the Jev checks from thejev-policiesreference copy. Before this, on 1.0.9 it silently dropped the whole section.authorityandreviewedByinpolicy-events.json.README: both policy rows mention Jev.
How it was merged
This repo's first import of the skill (
acad059) is byte-identical to the product copy at the time. Each file was merged three ways from that base: this repo'smainon one side, the product copy corrected for 1.0.9 on the other. The 25 conflicts were resolved by hand, following the rules above. The generated files were regenerated rather than merged.The publish-side content comes from #23. #23 was written against 1.0.8-beta.0, so every message and number in it was re-checked against the 1.0.9 tag and rewritten where it had changed. The dry-run line, the
policies addoutput, the list of commands consent can't clear, and the "built-in checks" framing had all changed.Verification
python3 scripts/validate-skills.py: 6 skills, 0 errors, 0 warnings.sync-builtins.mjs --checkandsync-harnesses.mjs --checkboth pass against the failproofai 1.0.9 source. The second commit changes no generated file.node --checkpasses on every script.Every claim about 1.0.9 was checked against the released source at tag
1.0.9(ee5dc022):pack-cli.ts,pack-manifest.tsandpack-store.ts;effective-reviewers.tsandprecondition-names.ts;semantic/pack-policies.ts,semantic/decide.ts,semantic/facts.ts,semantic/combine.tsandsemantic/jev-review.ts;semantic/intent.tsandhermes-plugin/ledger.py.The Jev workflow was run end to end on 1.0.9 with real Hermes agents:
publish --dry-run;--cli hermes;That run predates the second commit, which only adds text checked against source.
Supersedes #23.
🤖 Generated with Claude Code