feat: add TypeSafe Jev as HITL audit backend

Let audit_agent approve or reject with one System One call instead of chat JSON, while keeping the OpenAI-compatible backend as an option.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Ed1s0nZ
2026-09-22 21:15:53 +08:00
co-authored by Cursor
parent 3aa9274675
commit 38b96ec67a
30 changed files with 1372 additions and 21 deletions
+3 -1
View File
@@ -103,7 +103,9 @@ Common Web UI operations:
## Fallback Relationships
- `vision.api_key/base_url/provider` can inherit from the resolved default AI channel.
- `hitl.audit_model` can inherit from the resolved default AI channel.
- `hitl.audit_backend` chooses `openai` (default) or `typesafe` (TypeSafe Jev).
- `hitl.audit_model` can inherit from the resolved default AI channel when `audit_backend` is `openai`. TypeSafe keys are never inherited.
- `hitl.audit_agent_prompt` is a chat system prompt on `openai`, and a Jev `operatorPolicy` overlay on `typesafe`. The built-in default prompt is not copied into Jev state.
- `knowledge.embedding.base_url/api_key` can inherit from model settings.
- rerank config can inherit from embedding/openai.
- `database.knowledge_db_path` can be separate or reuse the main DB.
+7 -1
View File
@@ -9,6 +9,7 @@ HITL reviews tool calls before an Agent executes them. Use it to control high-ri
Open **System Settings → Human-in-the-loop** in the web UI. You can configure:
- Global default reviewer: `human` or `audit_agent`
- Approval engine: `hitl.audit_backend` (`openai` or `typesafe`)
- Dedicated Audit Agent model: `hitl.audit_model`
- Resolved audit log retention days
- No-approval tool allowlist: `hitl.tool_whitelist`
@@ -19,6 +20,7 @@ Example `config.yaml`:
```yaml
hitl:
default_reviewer: human
audit_backend: openai
audit_model:
provider: ""
base_url: ""
@@ -28,7 +30,9 @@ hitl:
tool_whitelist: [read_file, ls, glob, grep, tool_search, get_project_fact, list_project_facts, search_project_facts, list_vulnerabilities, get_vulnerability, get_asset, query_assets, list_knowledge_risk_types, get_tool_execution, wait_tool_execution, batch_task_list, batch_task_get, manage_webshell_list, c2_event, c2_file]
```
`audit_model` supports partial configuration. Empty fields inherit from the resolved default AI channel, so the common setup is to fill only `model` and run approvals on a cheaper small model.
`audit_backend` is a choice of `openai` (default, chat-completions JSON from the prompt) or `typesafe` (TypeSafe Jev). Custom audit-strategy text is evaluated as structured `operatorPolicy` questions; built-in destructive rules remain a hard floor. Jev cannot rewrite arguments, including in review-edit mode. The built-in default prompt is already encoded as Jev questions and is not copied into state.
`audit_model` supports partial configuration on the OpenAI backend. Empty fields inherit from the resolved default AI channel. On the TypeSafe backend, `api_key` is required and is **not** inherited from the main model; blank `base_url` uses `https://api.typesafe.ai`, and blank `model` uses `jev-latest`.
## Recommended Approval Strategy
@@ -86,6 +90,8 @@ Reject actions outside the user-authorized target scope.
In review-edit mode, you may narrow paths, targets, or command arguments before approving, but must not expand the attack surface.
```
On the OpenAI backend this text is a chat system prompt. On TypeSafe Jev it becomes an `operatorPolicy` overlay evaluated as structured questions; built-in destructive rules remain a hard floor, and Jev will not rewrite arguments. If the text is empty or identical to the built-in default, Jev uses the built-in questions only and does not copy the long prompt into state.
### 4. Keep The Allowlist Conservative
Allowlisted tools skip approval, so keep the list stable and low-risk. Recommended examples: