Context
Raised in the chain-restructuring review (PR #17, "Think about jev usage for complicated commands detection"). Jev is a "System One" model: unstructured text in → typed structured decisions with calibrated probabilities out, ~70–500 ms, very cheap, schema outputs that cannot type-hallucinate.
Decision recorded in design.md: NOT in v1. The chain-restructuring change ships the deterministic AST-threshold detector only (per-line segment counts, nesting depth, inline-script statement counts). This issue tracks the follow-up.
Why a learned detector fits
The deterministic thresholds are brittle at the margins — "is this command too complex/unreadable to review?" is a fuzzy judgment. A structured-output classifier could:
- score commands where hand-written thresholds disagree with intuition (long pipelines, deeply nested but benign substitutions)
- drive smarter UX: reject only when complexity confidence is high; let borderline commands through to the normal human
ask dialog
Proposed design
Optional, off-by-default detector backend in opencode-bash-guard.jsonc:
"ast" (default): current deterministic path — remains the source of truth and the fallback whenever the classifier errors or times out
"jev": call the TypeSafe API with the command string, receive a structured decision ({ complex: boolean, confidence: number }-shaped schema), reject with the same actionable guidance when the decision is confidently "complex" and the chain resolves to ask
Constraints
- Privacy: commands leave the machine → strictly opt-in, documented in README
- Availability: on API failure/timeout → silent fallback to
"ast" (never block, never throw)
- Determinism of the steering guarantee must not depend on the service
- Gated on Jev early-access availability and a stable API contract
Tasks
/cc PR #17 discussion.
Context
Raised in the
chain-restructuringreview (PR #17, "Think about jev usage for complicated commands detection"). Jev is a "System One" model: unstructured text in → typed structured decisions with calibrated probabilities out, ~70–500 ms, very cheap, schema outputs that cannot type-hallucinate.Decision recorded in
design.md: NOT in v1. Thechain-restructuringchange ships the deterministic AST-threshold detector only (per-line segment counts, nesting depth, inline-script statement counts). This issue tracks the follow-up.Why a learned detector fits
The deterministic thresholds are brittle at the margins — "is this command too complex/unreadable to review?" is a fuzzy judgment. A structured-output classifier could:
askdialogProposed design
Optional, off-by-default detector backend in
opencode-bash-guard.jsonc:{ "restructure": { "enabled": true, "detector": "jev" // default "ast" } }"ast"(default): current deterministic path — remains the source of truth and the fallback whenever the classifier errors or times out"jev": call the TypeSafe API with the command string, receive a structured decision ({ complex: boolean, confidence: number }-shaped schema), reject with the same actionable guidance when the decision is confidently "complex" and the chain resolves toaskConstraints
"ast"(never block, never throw)Tasks
detectorfield (unknown values → warn +"ast")/cc PR #17 discussion.