Jev reads chat excerpts and each bot’s job description. Ordinary code uses its yes/no probabilities to choose a responder, and a separate program runs that bot through the Pi coding agent. If Jev fails, a person’s message can go to the room owner or first candidate. Bots use file and shell tools as their user; the README explicitly says there is no sandbox.
How you can use it
For a small shared chat, give a few bots clearly different jobs and inspect which messages select each responder. Naming a bot selects it directly; Jev can judge other messages. Ask a developer to test with made-up conversations in a low-risk workspace before connecting useful files or tools.
This is not a sandbox. The local bot runner can read, change and execute files as its user. Native mode also listens beyond the local machine unless restricted. Chat excerpts go to Jev, and pattern-based secret masking is not a privacy guarantee. Limit access independently of the routing probabilities.