JevMade Sign in
← Back to guides

JevMade field notes / Written guide

Review an AI assistant's tools before running them

Jev Security Scan reads tool instructions, connection settings, and code before installation. It combines local checks with optional Jev review and reports evidence and blind spots rather than promising a security certificate.

Original by win4rGuardrails

Listen to this guide

JevMade’s plain-English explanation

0:00 /

Our summary

Before installation, Jev Security Scan reads agent instructions, source code, and MCP settings—the configuration that connects AI software to outside tools. It reports suspicious credential access, hidden changes that survive restarts, downloaded code that runs immediately, and parts it could not inspect.

Offline checks use fixed rules and do not install dependencies, meaning extra software the target relies on. Optional Jev review sends snippets after redaction, which means replacing recognized secrets. It still may expose source text, while offline mode keeps the inspected material local.

A clean report is not a security certificate. Disguised code, unsupported files, missing context, and new attacks can escape both methods. Redaction can miss secrets, so sensitive projects should start offline and inspect exactly what optional review sends.

Key takeaways

  1. Inspect untrusted tools before installing extra software or running them.
  2. Use local-only checks when material must not leave the computer.
  3. Keep evidence and unscanned areas visible beside findings.

The source explicitly describes this as review assistance, not certification.

GitHub project documentation

Read the original guide Opens the author’s site in a new tab.

Keep this for later

Sign in to bookmark experiments, guides and videos, and keep notes only you can see.

Continue to sign in

We’ll bring you back to this listing.