A typed decision model that reads each target's response and settles eight decisions the scanner used to make from fixed lists.
The whole idea in one line: at eight points in the pipeline, Jev reads the target's response and decides, then hands control straight back to the scan.
FFuf has one extension list. Nuclei has default tags. Crawlers run A to Z, smart fuzz picks directories at random, and every page is just another URL. They were set once — but targets aren't frozen.
A chat model writes text, and your code has to parse it into a decision.
Jev takes facts plus typed questions and returns one typed answer per question.
The answer space is fixed in advance — so it cannot hallucinate: no invented option, no JSON to repair, no retry loop.
“Is this statement true?”
A calibrated probability from 0 to 1. At 0.5 or above, RedAmon reads it as yes.
“Which one of these?”
Exactly one option from a list you define — never anything outside it.
“How much, on this rubric?”
One ordered level, from a rubric of 2 to 10 concrete steps.
“Is this page only a login or single-sign-on wall?” Then the same for parked, default page, placeholder and error.
State given: status, sizes, word and line counts, title, Server, headers and the first 4 KB of the body. Identical pages are asked once; at most 300 distinct pages a scan, within 60 seconds.
“Is this host likely to have a rich web application surface (many pages, forms, APIs or an admin area) rather than a thin or static site?”
State given: status, size, word and line counts of the host's root page, its title and Server, and its seed count. Up to 400 hosts are scored. Every seed stays in the list; a partial recon keeps A to Z.
“Is this directory likely to hold sensitive, administrative or application content, rather than static assets?”
State given: the directory names from the crawl, up to 400. It runs only when the crawl found more directories than the cap; under it, every directory is fuzzed.
“Is .x likely to find real files on this server, given its headers and URL?”
State given: the target URL and the response headers of one HEAD request. Cached per header fingerprint — 100 hosts on one stack cost one call.
“The tool's error output describes a transient failure (a timeout, a network or rate-limit error, a crashed or killed container) rather than a permanent one.”
State given: tool name, exit code, elapsed time, seed count and the error output, with header values, session headers and credential-shaped text redacted. At most 20 questions a run.
“Should the Nuclei tag x run against a host with this detected tech stack?”
State given: the detected technologies and Server headers. Runs once per scan, so no cache is needed.
“A WAF or CDN edge produced this response.” Then, if yes: “which vendor, of these 14?”
State given: URL, status, response time, headers and a body sample. Cached per response fingerprint.
“This response is a WAF or edge block page, not the unclaimed-site page of the claimed provider.”
State given: hostname, claimed provider, status, headers, response sample. Skipped when a vendor token (Heroku-Request-Id, …) settles it.
One TypeSafe key, saved once on your account.
Create it at console.typesafe.ai, then add it under Global Settings → LLM Providers → TypeSafe AI (Jev). The model is pinned to jev-1.13.0, and Test Connection is free.
The master switch for every AI hook.
In the project's Target & Modules tab, turn on Enable AI in Pipeline. Each hook gets its own card, and the Jev engine panel shows whether your account has a key.
LLM or Jev, hook by hook.
FFuf extensions, Nuclei tags, WAF and takeover show an Engine row: LLM | Jev. The four Jev-only hooks show Off | Jev. Both controls of a hook write the same field.
Jev reads each target's response and answers what static lists can't: what a page is, what to crawl first, what to fuzz, what to run, whether a tool really failed, whether a WAF is in the way, and whether a takeover is real. Typed answers, in under a second.
Full guide: the “TypeSafe Jev” page in the RedAmon wiki