{"_id":"sovr-ai","_rev":"32-f1060dff63862710e9e3e7cd9eb7567e","name":"sovr-ai","dist-tags":{"latest":"3.0.4"},"versions":{"3.0.3":{"name":"sovr-ai","version":"3.0.3","keywords":["sovr","ai-safety","ai-agent","responsibility-layer","mcp","audit","policy","guard","codex","claude-code","cursor","vscode"],"author":{"name":"SOVR Team"},"license":"BUSL-1.1","_id":"sovr-ai@3.0.3","maintainers":[{"name":"sovr","email":"yuhang@sovr.inc"}],"homepage":"https://github.com/xie38388/sovr#readme","bugs":{"url":"https://github.com/xie38388/sovr/issues"},"bin":{"sovr":"dist/cli.mjs"},"dist":{"shasum":"d0e2d048b22947ba31aab9715da669948f3f5533","tarball":"https://registry.npmjs.org/sovr-ai/-/sovr-ai-3.0.3.tgz","fileCount":245,"integrity":"sha512-I8R+UD26ArYbJIt8xiiwlzThyZ0dUcnhbvqOMRFy4OepJfYyGjTnx3T24bPZjsIn9c7hN2Tti85N7B6sLLSLsw==","signatures":[{"sig":"MEYCIQCiYjjHgxaefT6XK9D+n4eaTkETAMOkyxLdomg4lzL8ggIhALWyQmMdSISHv4X+QRsQL2qQFjLa0FMFBn8Ofm5AOzxk","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":45658624},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./claw":{"types":"./dist/claw/index.d.ts","import":"./dist/claw/index.js","require":"./dist/claw/index.cjs"},"./queue":{"types":"./dist/queue/index.d.ts","import":"./dist/queue/index.js"},"./trust":{"types":"./dist/trust/index.d.ts","import":"./dist/trust/index.js"},"./decision":{"types":"./dist/decision/index.d.ts","import":"./dist/decision/index.js"},"./identity":{"types":"./dist/identity/index.d.ts","import":"./dist/identity/index.js"},"./security":{"types":"./dist/security/index.d.ts","import":"./dist/security/index.js"},"./vectordb":{"types":"./dist/vectordb/index.d.ts","import":"./dist/vectordb/index.js"},"./exec-proxy":{"types":"./dist/exec-proxy/index.d.ts","import":"./dist/exec-proxy/index.js"},"./governance":{"types":"./dist/governance/index.d.ts","import":"./dist/governance/index.js"},"./cost-budget":{"types":"./dist/cost-budget/index.d.ts","import":"./dist/cost-budget/index.js"},"./degradation":{"types":"./dist/degradation/index.d.ts","import":"./dist/degradation/index.js"},"./compensation":{"types":"./dist/compensation/index.d.ts","import":"./dist/compensation/index.js"},"./verification":{"types":"./dist/verification/index.d.ts","import":"./dist/verification/index.js"},"./observability":{"types":"./dist/observability/index.d.ts","import":"./dist/observability/index.js"},"./audit-evidence":{"types":"./dist/audit-evidence/index.d.ts","import":"./dist/audit-evidence/index.js"},"./memory-context":{"types":"./dist/memory-context/index.d.ts","import":"./dist/memory-context/index.js"},"./claw/adapters/mcp":{"types":"./dist/claw/adapters/mcp.d.ts","import":"./dist/claw/adapters/mcp.js","require":"./dist/claw/adapters/mcp.cjs"},"./claw/adapters/crewai":{"types":"./dist/claw/adapters/crewai.d.ts","import":"./dist/claw/adapters/crewai.js","require":"./dist/claw/adapters/crewai.cjs"},"./claw/adapters/autogpt":{"types":"./dist/claw/adapters/autogpt.d.ts","import":"./dist/claw/adapters/autogpt.js","require":"./dist/claw/adapters/autogpt.cjs"},"./claw/adapters/express":{"types":"./dist/claw/adapters/express.d.ts","import":"./dist/claw/adapters/express.js","require":"./dist/claw/adapters/express.cjs"},"./claw/adapters/openclaw":{"types":"./dist/claw/adapters/openclaw.d.ts","import":"./dist/claw/adapters/openclaw.js","require":"./dist/claw/adapters/openclaw.cjs"},"./claw/adapters/langchain":{"types":"./dist/claw/adapters/langchain.d.ts","import":"./dist/claw/adapters/langchain.js","require":"./dist/claw/adapters/langchain.cjs"},"./claw/adapters/vercel-ai":{"types":"./dist/claw/adapters/vercel-ai.d.ts","import":"./dist/claw/adapters/vercel-ai.js","require":"./dist/claw/adapters/vercel-ai.cjs"}},"gitHead":"603dbcdab3e249acfd79d11f2c59615a329a969b","scripts":{"dev":"tsx src/cli.ts","test":"vitest run","build":"tsup && python3 scripts/gen_all_dts.py","postinstall":"node dist/postinstall.mjs || true"},"_npmUser":{"name":"sovr","email":"yuhang@sovr.inc"},"repository":{"url":"git+https://github.com/xie38388/sovr.git","type":"git"},"_npmVersion":"10.9.2","description":"SOVR — The Unified Responsibility Layer for AI Agents. Policy engine, gate check, audit trail, MCP proxy, SQL/HTTP/Exec proxy, trust scoring, and all subsystems in one package.","directories":{},"sideEffects":["./dist/index.js","./dist/index.cjs"],"_nodeVersion":"22.13.0","dependencies":{"uuid":"^13.0.0","yaml":"^2.8.0","chokidar":"^4.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.0.0","tsup":"^8.0.0","uuid":"^13.0.0","yaml":"^2.8.2","vitest":"^2.0.0","express":"^5.2.1","supertest":"^7.2.2","fast-check":"^4.5.3","typescript":"^5.5.0","@types/node":"^22.0.0","@types/express":"^5.0.6","@types/supertest":"^7.2.0"},"_npmOperationalInternal":{"tmp":"tmp/sovr-ai_3.0.3_1772295825204_0.48516189614560634","host":"s3://npm-registry-packages-npm-production"}},"3.0.4":{"name":"sovr-ai","version":"3.0.4","description":"SOVR — The Unified Responsibility Layer for AI Agents. Policy engine, gate check, audit trail, MCP proxy, SQL/HTTP/Exec proxy, trust scoring, and all subsystems in one package.","type":"module","bin":{"sovr":"dist/cli.mjs"},"main":"./dist/index.cjs","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./security":{"types":"./dist/security/index.d.ts","import":"./dist/security/index.js"},"./governance":{"types":"./dist/governance/index.d.ts","import":"./dist/governance/index.js"},"./audit-evidence":{"types":"./dist/audit-evidence/index.d.ts","import":"./dist/audit-evidence/index.js"},"./trust":{"types":"./dist/trust/index.d.ts","import":"./dist/trust/index.js"},"./degradation":{"types":"./dist/degradation/index.d.ts","import":"./dist/degradation/index.js"},"./memory-context":{"types":"./dist/memory-context/index.d.ts","import":"./dist/memory-context/index.js"},"./cost-budget":{"types":"./dist/cost-budget/index.d.ts","import":"./dist/cost-budget/index.js"},"./identity":{"types":"./dist/identity/index.d.ts","import":"./dist/identity/index.js"},"./observability":{"types":"./dist/observability/index.d.ts","import":"./dist/observability/index.js"},"./queue":{"types":"./dist/queue/index.d.ts","import":"./dist/queue/index.js"},"./decision":{"types":"./dist/decision/index.d.ts","import":"./dist/decision/index.js"},"./compensation":{"types":"./dist/compensation/index.d.ts","import":"./dist/compensation/index.js"},"./vectordb":{"types":"./dist/vectordb/index.d.ts","import":"./dist/vectordb/index.js"},"./verification":{"types":"./dist/verification/index.d.ts","import":"./dist/verification/index.js"},"./exec-proxy":{"types":"./dist/exec-proxy/index.d.ts","import":"./dist/exec-proxy/index.js"},"./claw":{"types":"./dist/claw/index.d.ts","import":"./dist/claw/index.js","require":"./dist/claw/index.cjs"},"./claw/adapters/langchain":{"types":"./dist/claw/adapters/langchain.d.ts","import":"./dist/claw/adapters/langchain.js","require":"./dist/claw/adapters/langchain.cjs"},"./claw/adapters/autogpt":{"types":"./dist/claw/adapters/autogpt.d.ts","import":"./dist/claw/adapters/autogpt.js","require":"./dist/claw/adapters/autogpt.cjs"},"./claw/adapters/crewai":{"types":"./dist/claw/adapters/crewai.d.ts","import":"./dist/claw/adapters/crewai.js","require":"./dist/claw/adapters/crewai.cjs"},"./claw/adapters/openclaw":{"types":"./dist/claw/adapters/openclaw.d.ts","import":"./dist/claw/adapters/openclaw.js","require":"./dist/claw/adapters/openclaw.cjs"},"./claw/adapters/vercel-ai":{"types":"./dist/claw/adapters/vercel-ai.d.ts","import":"./dist/claw/adapters/vercel-ai.js","require":"./dist/claw/adapters/vercel-ai.cjs"},"./claw/adapters/mcp":{"types":"./dist/claw/adapters/mcp.d.ts","import":"./dist/claw/adapters/mcp.js","require":"./dist/claw/adapters/mcp.cjs"},"./claw/adapters/express":{"types":"./dist/claw/adapters/express.d.ts","import":"./dist/claw/adapters/express.js","require":"./dist/claw/adapters/express.cjs"}},"sideEffects":["./dist/index.js","./dist/index.cjs"],"scripts":{"postinstall":"node dist/postinstall.mjs || true","build":"tsup && python3 scripts/gen_all_dts.py","test":"vitest run","dev":"tsx src/cli.ts"},"keywords":["sovr","ai-safety","ai-agent","responsibility-layer","mcp","audit","policy","guard","codex","claude-code","cursor","vscode"],"author":{"name":"SOVR Team"},"license":"BUSL-1.1","repository":{"type":"git","url":"git+https://github.com/xie38388/sovr.git"},"engines":{"node":">=18.0.0"},"dependencies":{"chokidar":"^4.0.0","uuid":"^13.0.0","yaml":"^2.8.0"},"devDependencies":{"@types/express":"^5.0.6","@types/node":"^22.0.0","@types/supertest":"^7.2.0","express":"^5.2.1","fast-check":"^4.5.3","supertest":"^7.2.2","tsup":"^8.0.0","tsx":"^4.0.0","typescript":"^5.5.0","uuid":"^13.0.0","vitest":"^2.0.0","yaml":"^2.8.2"},"_id":"sovr-ai@3.0.4","gitHead":"155c9bc7951632b1547c8fd50b42cc0f94fd4251","bugs":{"url":"https://github.com/xie38388/sovr/issues"},"homepage":"https://github.com/xie38388/sovr#readme","_nodeVersion":"22.13.0","_npmVersion":"10.9.2","dist":{"integrity":"sha512-NLxK3u2k8WaUsv2aoL/KhzylFkjwQc1rcpPhNq1ylBocSoIPIHyr4S5ptLN8WQKM+zoI7AQZoPrPpoSbtqG3tQ==","shasum":"56e34d17467430f0944b1706391890eef66339ff","tarball":"https://registry.npmjs.org/sovr-ai/-/sovr-ai-3.0.4.tgz","fileCount":245,"unpackedSize":45691910,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDJ9lrb8T8aaF113faSCJB7CJ07uu17i23+QNn2Zv2j7AIgei7EnaNa3sASbxzUzmN7vZSeNS6JRWdN//6zEVL/XeE="}]},"_npmUser":{"name":"sovr","email":"yuhang@sovr.inc"},"directories":{},"maintainers":[{"name":"sovr","email":"yuhang@sovr.inc"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sovr-ai_3.0.4_1772298148005_0.2826576492818158"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-28T11:33:18.987Z","modified":"2026-02-28T17:02:28.598Z","2.2.0":"2026-02-28T11:33:19.394Z","2.2.1":"2026-02-28T11:38:35.483Z","2.2.2":"2026-02-28T11:45:07.538Z","2.2.3":"2026-02-28T11:57:11.882Z","2.3.0":"2026-02-28T12:11:45.644Z","2.4.0":"2026-02-28T13:50:29.937Z","2.4.1":"2026-02-28T14:32:27.609Z","3.0.0":"2026-02-28T15:18:33.319Z","3.0.1":"2026-02-28T15:27:38.803Z","3.0.2":"2026-02-28T16:07:49.174Z","3.0.3":"2026-02-28T16:23:45.662Z","3.0.4":"2026-02-28T17:02:28.483Z"},"bugs":{"url":"https://github.com/xie38388/sovr/issues"},"author":{"name":"SOVR Team"},"license":"BUSL-1.1","homepage":"https://github.com/xie38388/sovr#readme","keywords":["sovr","ai-safety","ai-agent","responsibility-layer","mcp","audit","policy","guard","codex","claude-code","cursor","vscode"],"repository":{"type":"git","url":"git+https://github.com/xie38388/sovr.git"},"description":"SOVR — The Unified Responsibility Layer for AI Agents. Policy engine, gate check, audit trail, MCP proxy, SQL/HTTP/Exec proxy, trust scoring, and all subsystems in one package.","maintainers":[{"name":"sovr","email":"yuhang@sovr.inc"}],"readme":"<p align=\"center\">\n  <img src=\"https://sovr.inc/images/sovr-icon.svg\" width=\"80\" alt=\"SOVR\" />\n</p>\n\n<h1 align=\"center\">sovr-ai</h1>\n\n<p align=\"center\">\n  <strong>The Responsibility Layer for AI Agents</strong><br/>\n  Sovereign gate checks · Immutable audit trails · Trust scoring · Policy engine\n</p>\n\n<p align=\"center\">\n  <a href=\"https://www.npmjs.com/package/sovr-ai\"><img src=\"https://img.shields.io/npm/v/sovr-ai?color=00FF94&label=npm\" alt=\"npm\" /></a>\n  <a href=\"https://github.com/xie38388/sovr\"><img src=\"https://img.shields.io/github/stars/xie38388/sovr?style=social\" alt=\"GitHub\" /></a>\n  <a href=\"./LICENSE\"><img src=\"https://img.shields.io/badge/License-BSL--1.1-blue.svg\" alt=\"License\" /></a>\n</p>\n\n---\n\n> *\"Claude is AI and can make mistakes. Please double-check responses.\"*\n> — Every AI company says this. **SOVR does the double-checking for you.**\n\n## The Problem\n\nAI agents are powerful but unreliable. Every time you delegate a task to an AI, you spend more time verifying the output than it took to generate. This is the **double-check dilemma** — the hidden cost that breaks the promise of AI automation.\n\nSOVR solves this by placing a **sovereign verification layer** between AI intent and execution. One daemon. Every AI agent on your machine — audited, judged, governed.\n\n```\n┌─────────────────────────────────────────────────────┐\n│                   Your Computer                      │\n│                                                      │\n│  ┌──────────┐ ┌──────────┐ ┌──────────┐            │\n│  │  Codex   │ │  Claude  │ │  Cursor  │  ...        │\n│  │   CLI    │ │   Code   │ │   IDE    │             │\n│  └────┬─────┘ └────┬─────┘ └────┬─────┘            │\n│       │             │             │                   │\n│  ═════╪═════════════╪═════════════╪══════════════    │\n│       │       SOVR DAEMON        │                   │\n│       ▼             ▼             ▼                   │\n│  ┌──────────────────────────────────────────┐        │\n│  │  Agent Detector → File Watcher           │        │\n│  │  Shell Hook     → MCP Proxy              │        │\n│  │  Policy Engine  → Judgment Engine         │        │\n│  │  Audit Logger   → Cloud Connector         │        │\n│  └──────────────────────────────────────────┘        │\n│                      │                                │\n│  ════════════════════╪════════════════════════════    │\n│                      ▼                                │\n│              ┌──────────────┐                         │\n│              │  SOVR Cloud  │  Billing & Compliance   │\n│              └──────────────┘                         │\n└─────────────────────────────────────────────────────┘\n```\n\n## Installation\n\n### Option A — Global Install (Recommended)\n\nGlobal install registers the `sovr` command in your PATH so you can use it directly:\n\n```bash\nnpm i -g sovr-ai\n```\n\nAfter global install, all commands work directly:\n\n```bash\nsovr init                              # Initialize SOVR\nsovr start                             # Start the daemon\nsovr check delete_file /etc/passwd     # Gate check\nsovr status                            # Daemon status\nsovr setup claude-code                 # Hook into Claude Code\n```\n\n### Option B — Local Install + npx\n\nIf you prefer not to install globally, use `npx` to run commands:\n\n```bash\nnpm i sovr-ai\n```\n\nThen prefix all commands with `npx`:\n\n```bash\nnpx sovr init\nnpx sovr start\nnpx sovr check delete_file /etc/passwd\nnpx sovr status\nnpx sovr setup claude-code\n```\n\n### Option C — One-shot with npx (No Install)\n\nRun SOVR without installing at all:\n\n```bash\nnpx sovr-ai                           # Shows banner + onboarding guide\nnpx sovr-ai init                      # Initialize directly\n```\n\n> **Note**: `npx sovr` works after local/global install. For one-shot without install, use `npx sovr-ai` (the full package name).\n\n## Quick Start\n\n```bash\n# Step 1 — Install globally\nnpm i -g sovr-ai\n\n# Step 2 — See the onboarding guide\nsovr\n#  ███████╗  ██████╗  ██╗   ██╗ ██████╗\n#  ██╔════╝ ██╔═══██╗ ██║   ██║ ██╔══██╗\n#  ███████╗ ██║   ██║ ██║   ██║ ██████╔╝\n#  ╚════██║ ██║   ██║ ╚██╗ ██╔╝ ██╔══██╗\n#  ███████║ ╚██████╔╝  ╚████╔╝  ██║  ██║\n#  ╚══════╝  ╚═════╝    ╚═══╝   ╚═╝  ╚═╝\n#  🛡️ SOVR v2.2.2 — The Responsibility Layer for AI Agents\n\n# Step 3 — Initialize (creates ~/.sovr/ config, detects agents, installs hooks)\nsovr init\n\n# Step 4 — (Optional) Add your API key for cloud features\nsovr init --api-key sovr_live_xxx\n\n# Step 5 — Start the daemon\nsovr start\n# ✅ SOVR daemon running on port 19876\n#    Agents detected: 5\n#    Policy rules: 7\n#    Cloud: connected\n\n# Step 6 — Hook into your AI agent\nsovr setup claude-code\nsovr setup codex\nsovr setup openclaw\n\n# Step 7 — Test gate checks\nsovr check delete_file /etc/passwd\n# → 🔐 REQUIRE_APPROVAL\n\nsovr check read_file /tmp/test.txt\n# → ✅ ALLOW\n\nsovr check execute_command . 'rm -rf /tmp'\n# → 🚫 BLOCK\n```\n\n## What Gets Installed\n\nSOVR is a single unified package that provides a complete AI governance stack:\n\n| Capability | Description |\n|:-----------|:------------|\n| **Gate Engine** | Policy-based gate checks with 30+ built-in danger patterns |\n| **Agent Detector** | Auto-discovers Codex, Claude Code, Cursor, Copilot, Windsurf, Aider, OpenClaw, Manus |\n| **File Watcher** | Monitors project directories, attributes changes to responsible AI agents |\n| **Shell Hook** | Intercepts shell commands via bash/zsh preexec hooks |\n| **MCP Proxy** | Transparent proxy for MCP tool calls with policy filtering |\n| **Audit Chain** | HMAC-signed, tamper-proof, chain-linked audit log |\n| **Kill-Switch** | Emergency stop with 5-level severity escalation |\n| **Trust Scoring** | Quantified trust assessment per agent and per action |\n| **Policy Engine** | Flexible rule-based system with custom JSON/YAML policies |\n| **Cloud Billing** | API key-based usage tracking with quota management |\n\n## CLI Reference\n\n| Command | Description |\n|:--------|:------------|\n| `sovr` | Show banner + onboarding guide (or quick reference if already initialized) |\n| `sovr init [--api-key KEY]` | Interactive onboarding — creates `~/.sovr/` config, detects agents, installs hooks |\n| `sovr start [-f]` | Start the daemon (`-f` for foreground mode) |\n| `sovr stop` | Stop the daemon |\n| `sovr status` | Show daemon status + detected agents + version info |\n| `sovr check <action> <resource> [detail]` | Check if an action is allowed by policy |\n| `sovr agents` | List detected AI agents on this machine |\n| `sovr setup <agent>` | Hook SOVR into an AI agent (claude-code, codex, cline, openclaw, cursor, windsurf) |\n| `sovr audit [limit]` | Show recent audit entries from the chain |\n| `sovr doctor` | Run system health diagnostics |\n| `sovr install-hooks` | Install shell hooks for bash/zsh |\n| `sovr config [show\\|set KEY VALUE]` | View or modify configuration |\n| `sovr version` | Show current version |\n| `sovr help` | Show full command reference |\n\n## SDK Usage\n\n```typescript\nimport { gateCheck, getDefaultPolicy, SovrDaemon } from 'sovr-ai';\n\n// --- Stateless gate check (no daemon needed) ---\nconst policy = getDefaultPolicy();\nconst result = gateCheck(\n  { action: 'execute_command', resource: '.', command: 'rm -rf /' },\n  policy\n);\n\nif (result.verdict === 'BLOCK') {\n  console.error(`Blocked: ${result.reason}`);\n}\n\n// --- Full daemon with file watcher + MCP proxy ---\nconst daemon = new SovrDaemon({\n  port: 19876,\n  watchPaths: ['/home/user/projects'],\n  apiKey: 'sovr_live_xxx',\n});\nawait daemon.start();\n```\n\n## Sub-path Imports\n\nSOVR exposes 15 sub-system modules for tree-shaking. Import only what you need:\n\n```typescript\nimport { ... } from 'sovr-ai/security';        // KillSwitch, Honeypot, Crypto\nimport { ... } from 'sovr-ai/governance';       // Policy engine, approval workflows\nimport { ... } from 'sovr-ai/audit-evidence';   // Immutable audit chain, trust bundles\nimport { ... } from 'sovr-ai/trust';            // Trust score calculation\nimport { ... } from 'sovr-ai/degradation';      // Circuit breaker, graceful fallback\nimport { ... } from 'sovr-ai/memory-context';   // Session memory, context assembly\nimport { ... } from 'sovr-ai/cost-budget';      // Usage metering, budget alerts\nimport { ... } from 'sovr-ai/identity';         // API key management, tenant isolation\nimport { ... } from 'sovr-ai/observability';    // Metrics, logging, tracing\nimport { ... } from 'sovr-ai/queue';            // Async job processing\nimport { ... } from 'sovr-ai/decision';         // Decision execution engine\nimport { ... } from 'sovr-ai/compensation';     // Rollback and compensation logic\nimport { ... } from 'sovr-ai/vectordb';         // Embedding storage helpers\nimport { ... } from 'sovr-ai/verification';     // Result verification router\nimport { ... } from 'sovr-ai/exec-proxy';       // Sandboxed command execution\n```\n\n## REST API\n\nWhen the daemon is running (default port `19876`):\n\n```bash\n# Health check\ncurl http://localhost:19876/health\n\n# Gate check\ncurl -X POST http://localhost:19876/api/check \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"action\":\"execute_command\",\"resource\":\".\",\"command\":\"rm -rf /\"}'\n\n# Status\ncurl http://localhost:19876/api/status\n\n# Detected agents\ncurl http://localhost:19876/api/agents\n\n# Audit log\ncurl http://localhost:19876/api/audit\n\n# Current policy\ncurl http://localhost:19876/api/policy\n```\n\n## Agent Detection\n\nSOVR automatically discovers AI agents running on your machine:\n\n| Agent | Detection Method |\n|:------|:----------------|\n| Claude Code | Process scanning + `~/.claude` config |\n| Codex CLI | Process scanning + `~/.codex` config |\n| Cursor | Process scanning + Application Support |\n| VS Code + Copilot | Process scanning + extension detection |\n| Windsurf | Process scanning + Codeium config |\n| Aider | Process scanning + config detection |\n| Continue.dev | Config directory detection |\n| OpenClaw | Process scanning |\n| Manus | Environment variable detection |\n\n## Built-in Danger Patterns\n\nThe default policy includes 30+ patterns across 5 risk levels:\n\n| Risk Level | Examples |\n|:-----------|:---------|\n| **Critical** | `rm -rf /`, `DROP DATABASE`, `curl \\| bash`, fork bombs |\n| **High** | `chmod 777`, `iptables -F`, write to `/etc/passwd` |\n| **Medium** | `npm publish`, `git push --force`, `docker rm` |\n| **Low** | Large file writes, bulk operations |\n| **None** | Read operations, status checks |\n\n## Configuration\n\nConfig file: `~/.sovr/config.json`\n\n```json\n{\n  \"port\": 19876,\n  \"apiKey\": \"sovr_live_xxx\",\n  \"watchPaths\": [\"/home/user/projects\"],\n  \"excludePatterns\": [\"**/node_modules/**\", \"**/.git/**\"],\n  \"mcpProxy\": true,\n  \"mcpProxyPort\": 19877,\n  \"shellHook\": true,\n  \"fileWatcher\": true,\n  \"cloudSync\": true,\n  \"logLevel\": \"info\"\n}\n```\n\n## Custom Policies\n\nCreate `~/.sovr/policy.json`:\n\n```json\n{\n  \"name\": \"my-team-policy\",\n  \"version\": \"1.0.0\",\n  \"rules\": [\n    {\n      \"id\": \"block-production-db\",\n      \"name\": \"Block production database access\",\n      \"match\": {\n        \"commands\": [\"psql.*production\", \"mysql.*prod\"],\n        \"actions\": [\"execute_command\"]\n      },\n      \"action\": \"BLOCK\",\n      \"priority\": 100,\n      \"enabled\": true\n    },\n    {\n      \"id\": \"approve-npm-publish\",\n      \"name\": \"Require approval for npm publish\",\n      \"match\": {\n        \"commands\": [\"npm publish\"],\n        \"actions\": [\"execute_command\"]\n      },\n      \"action\": \"REQUIRE_APPROVAL\",\n      \"priority\": 90,\n      \"enabled\": true\n    }\n  ]\n}\n```\n\n## Billing & Quotas\n\nSOVR uses a tiered subscription model. The `SUBSCRIPTION_PLANS` export provides programmatic access:\n\n```typescript\nimport { SUBSCRIPTION_PLANS } from 'sovr-ai';\n\nconst starter = SUBSCRIPTION_PLANS.find(p => p.id === 'starter');\nconsole.log(starter.monthlyPrice);                     // 300\nconsole.log(starter.quota.gateChecksPerMonth);          // 50000\nconsole.log(starter.quota.irreversibleAllowedPerMonth); // 1000\n```\n\n| Plan | Price | Gate Checks/mo | Irreversible/mo | Trust Bundles/mo | Audit Retention |\n|:-----|:------|:--------------|:----------------|:-----------------|:----------------|\n| **Free** | $0 | 5,000 | 0 | 0 | 7 days |\n| **Personal** | $10/mo | 10,000 | 1,000 | 0 | 30 days |\n| **Starter** | $300/mo | 50,000 | 1,000 | 5 | 90 days |\n| **Pro** | $2,000/mo | 500,000 | 20,000 | 50 | 90 days |\n| **Enterprise** | $15,000/mo | 5,000,000 | 200,000 | 200 | 365 days |\n\nOverage pricing (all paid tiers): **$0.40 / 1K gate checks**, **$8.00 / 1K irreversible actions**.\n\n## Architecture\n\nSOVR implements a **three-layer defense model**:\n\n**L0 — Pattern Matching**: 97 built-in OpenGuard rules scan every request for known dangerous patterns (SQL injection, path traversal, prompt injection, etc.).\n\n**L1 — Policy Engine**: Configurable rule-based system evaluates actions against custom policies with priority-based matching and 4-tier approval levels (auto / human / escalate / emergency).\n\n**L2 — Behavioral Analysis**: Trust scoring, anomaly detection, and adaptive thresholds learn from historical patterns to flag suspicious deviations.\n\n## Troubleshooting\n\n### `zsh: command not found: sovr`\n\nThis means SOVR was installed locally (not globally). Fix with:\n\n```bash\n# Option 1: Install globally\nnpm i -g sovr-ai\n\n# Option 2: Use npx prefix\nnpx sovr start\n```\n\n### `sovr-shell-hook.sh: parse error near '*'`\n\nThe shell hook file has a syntax issue. Regenerate it:\n\n```bash\nsovr install-hooks\n```\n\nThen restart your terminal or run `source ~/.zshrc`.\n\n### Daemon won't start\n\n```bash\n# Check if another instance is running\nsovr status\n\n# Force stop and restart\nsovr stop\nsovr start -f    # Foreground mode to see errors\n```\n\n### API Key missing warnings\n\nSOVR works in **offline mode** without an API key. To add one:\n\n```bash\nsovr config set apiKey sovr_live_xxx\n```\n\nOr set the environment variable:\n\n```bash\nexport SOVR_API_KEY='sovr_live_xxx'\n```\n\n## Related Packages\n\n| Package | Description |\n|:--------|:------------|\n| [`sovr-mcp-proxy`](https://www.npmjs.com/package/sovr-mcp-proxy) | Standalone MCP proxy with OpenGuard scanning |\n| `sovr-ai` | This package — the unified responsibility layer |\n\n## License\n\n[BSL-1.1](./LICENSE) — Free for non-production use. Converts to Apache 2.0 on 2030-02-28.\n\n## Links\n\n- [SOVR Cloud Dashboard](https://sovr.inc)\n- [GitHub](https://github.com/xie38388/sovr)\n- [npm](https://www.npmjs.com/package/sovr-ai)\n","readmeFilename":"README.md"}