Risk classification acts as a warning system, not a strict permission check. If the decision layer fails, it defaults to letting the main model decide, making the risk check a best-effort feature. Streaming responses bypass this control entirely. The author notes that live integrations with specific agent frameworks were not verified in automated testing.
How you can use it
A developer can add this layer to software that carries out tasks, suggesting a next action, judging completion and flagging risk. Start with a harmless action such as listing running containers, using action details already approved by your app. Information about the task goes to the external TypeSafe service for these judgments.
Set how certain a suggestion must be before following it, but keep real permissions in your app. Model risk judgments are not permission or proof of completion. Errors leave the main model to decide by default, and streaming bypasses this layer, so it is best-effort rather than an unbroken gate.