import json from typesafe_sdk import Choice, Noul, TypeSafeClient client = TypeSafeClient() def review_tool_call(tool: str, args: dict, task: str) -> str: state = json.dumps({"user_task": task, "tool": tool, "arguments": args}, indent=2) answers = client.system_one( state=state, questions={ "verdict": Choice( instructions="Should this tool call run without human review", criteria={ "allow": "Read-only or clearly within the user's stated task", "ask": "Plausibly intended but has side effects worth confirming", "deny": "Destructive, irreversible, or unrelated to the task", }, ), "exfiltration_risk": Noul( instructions="The call could send secrets or private data outside the system", ), }, ).answers # Hard rule first: code, not the model, owns the non-negotiables. if answers["exfiltration_risk"].noul >= 0.20: return "deny" verdict = answers["verdict"] if verdict.choice == "allow" and verdict.confidence >= 0.90: return "allow" if verdict.choice == "deny": return "deny" return "ask" # anything uncertain defaults to a human