What it does
Separate checks try to distinguish quoted attacks from active requests. The author's quotation tests still report many false alarms; the scores are not calibrated attack probabilities or an application security audit.
Agent tooling
Route user messages, retrieved text and tool output toward allow, review or block using Jev risk signals and a local policy.
Only you can see your notes.
Screenshot unavailable. Open the experiment ↗
Separate checks try to distinguish quoted attacks from active requests. The author's quotation tests still report many false alarms; the scores are not calibrated attack probabilities or an application security audit.
If your assistant reads outside documents, tell it where the text came from. Supply its real task separately. Jev Guard asks AI about warning signs, then code chooses whether to allow, review or block. Keep permission checks in your app; an allow result is not proof of safety.
A developer can start with the example that asks for a document summary. Running it needs an access key for the outside Jev service. Test harmless quotations as well as attacks. Extra quotation checks can add two AI requests, and the author's tests still found many false alarms.