You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
CLAI currently asks the main generative LLM to do several different jobs at once: understand the user's intent, generate a command, explain it, classify risk, and decide whether it is safe enough for risk_appetite auto-run behavior. That works, but intent routing and risk classification are not really generation problems. They are small, repeated judgments where we want typed answers, probabilities, speed, and predictable control flow.
This PR adds optional System One support for those judgments. When configured, CLAI can use TypeSafe / Jev-style APIs for fast typed decisions while keeping the existing LLM provider responsible for command generation and explanations.
The goal is not to replace the LLM. It is to make the surrounding control plane sharper:
Speed: small intent/risk judgments can be handled by a focused System One model instead of another broad generative prompt.
Cost: cheap typed judgments can avoid overusing the main LLM for routing and safety decisions.
Accuracy/control: risk and intent become explicit typed classifications with confidence, instead of buried inside prompt-following JSON generation.
Safer auto-run:risk_appetite no longer has to trust only the command-generating model's self-assessed risk.
What changed
Add optional System One-compatible config:
system_one_key
system_one_api
system_one_model
Add an internal /v1/systemone HTTP client for TypeSafe-compatible Choice judgments.
Use System One intent routing when configured, replacing the local ? heuristic for normal requests.
Use System One risk auditing after command generation:
A higher System One risk label overrides the LLM-provided risk.
Low-confidence risk audits force a confirmation prompt before execution.
The main LLM still generates the command and explanation.
Integrates routing and risk auditing. Critical (1 vote): validate confidence bounds. Moderate (1 vote): route clear-history requests through System One when configured.
Relax probability-sum tolerance for two-decimal Choice responses
internal/systemone/client.go:243
TypeSafe reports Choice probabilities rounded to two decimal places, so a valid three-option distribution can be 0.33 + 0.33 + 0.33 = 0.99. The current 1e-6 tolerance rejects that normal API response, causing both intent routing and risk auditing to fail. Allow half a unit in the last reported decimal per option (while retaining the strict base tolerance).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why this matters
CLAI currently asks the main generative LLM to do several different jobs at once: understand the user's intent, generate a command, explain it, classify risk, and decide whether it is safe enough for
risk_appetiteauto-run behavior. That works, but intent routing and risk classification are not really generation problems. They are small, repeated judgments where we want typed answers, probabilities, speed, and predictable control flow.This PR adds optional System One support for those judgments. When configured, CLAI can use TypeSafe / Jev-style APIs for fast typed decisions while keeping the existing LLM provider responsible for command generation and explanations.
The goal is not to replace the LLM. It is to make the surrounding control plane sharper:
risk_appetiteno longer has to trust only the command-generating model's self-assessed risk.What changed
system_one_keysystem_one_apisystem_one_model/v1/systemoneHTTP client for TypeSafe-compatible Choice judgments.?heuristic for normal requests.Example config
If any of those settings are missing, CLAI keeps the existing behavior.
Testing
env GOCACHE=/tmp/clai-go-cache make check