CodeMarine Dev

Let AI build. Secure everything that follows.

CodeMarine Dev is the independent security layer across coding agents, editors and pipelines. It continuously checks code, new trust and supported high-impact actions, then works with frontier models on the hard cases.

CodeMarine Dev security dashboard

One policy across every tool your team adopts.

Choose the best model for the job. CodeMarine keeps watching the code, supply chain and supported actions when the provider changes.

ClaudeCoding agent

Protect Claude-written code

Continuously check the workspace, new dependencies and supported local actions.

  • Code
  • Packages
  • Hooks

CodexCoding agent

Secure every Codex change

Inspect resulting code, agent configuration and supported write paths under one policy.

  • Code
  • Config
  • Writes

CursorAI editor

Keep agent edits in policy

Watch local and background-agent output, dependencies and exposed hook events.

  • Workspace
  • Supply chain
  • Hooks

GrokFrontier model

Scan what Grok brings in

Check resulting source, dependencies and agent artifacts while adapter coverage expands.

  • Code
  • Artifacts
  • Provenance

DevinAI coding agent

Guard the repository handoff

Inspect synchronized changes and reinforce remote work through repository and CI policy.

  • Repository
  • Dependencies
  • CI
One independent policy Code integrity · Supply-chain trust · Runtime decisions · Security evidence Compare every integration

Frontier intelligence, with an independent safety layer.

Claude, Codex, Cursor and other frontier tools do the creative work. CodeMarine watches the shared result, checks what enters the workspace and applies deterministic policy wherever a supported control point exists.

Works with your frontier stackUse the right intelligence for every job

01FRONTIER INTELLIGENCE

Build, reason and investigate.

Frontier tools bring deep context, novel vulnerability discovery and contextual remediation.

  • BuildWrite code and operate tools
  • InvestigateReason about ambiguous or novel risk
  • FixPropose a patch with repository context
Focused evidence Proposed fixes
CODEMARINE CONTROL

Watch, verify and enforce.

CodeMarine stays on the continuous path with deterministic checks, cross-provider policy and evidence that survives the model session.

  • Secure the codeScan every resulting change
  • Verify new trustCheck packages, MCP, skills and rules
  • Control actionsEvaluate supported high-impact operations
  1. 1

    AI createsCode, tools and hypotheses

  2. 2

    CodeMarine checksCode, supply chain and supported actions

  3. 3

    AI investigatesFocused evidence for the hard cases

  4. 4

    CodeMarine validatesRescan, policy and durable evidence

Frontier intelligence. Deterministic control.

The model does the reasoning. CodeMarine keeps the result continuous, repeatable and governed.

See the governed model workflow

One security contract around the shared codebase.

Provider controls still matter. CodeMarine adds continuous checks around the repository, software supply chain and supported agent actions. The policy remains when the model changes.

01

Deterministic decisionsThe same revision, rules and policy produce the same result.

02

Continuous coverageProtection keeps running after one agent session ends.

03

Visible limitsEvery surface is marked by its actual mechanism and health.

Your AI development stack

ClaudeCoding agent

CodexCoding agent

CursorAI editor

GrokFrontier model

DevinAI coding agent

INDEPENDENT SECURITY LAYER
CodeMarine Dev

Continuously watches the shared workspace and applies one deterministic policy.

  • CodeIntegrity
  • SupplyProvenance
  • ActionsRuntime policy
  • EvidenceDecision record
WorkspaceAgent toolsCIInfrastructure

Let AI move fast without letting one bad command wreck everything.

Developers allow shell access because the agent needs it. CodeMarine checks the exact command before it runs on supported paths.

Explore Runtime Safety
CodeMarine Runtime Protection showing agent coverage and destructive command policy
Protect your machine and codeCatch commands that can wipe folders, overwrite protected files or destroy Git history.
Protect production dataCheck database drops, truncation and broad deletes that can erase records.
Protect infrastructureCheck attempts to remove cloud resources, Kubernetes environments or Terraform-managed systems.
Protect credentialsDetect shell-visible attempts to collect secrets and send them somewhere else.

Coverage stays explicit. Supported local hooks can stop an action before execution. Remote services need a governed control path before CodeMarine claims prevention.

Trust is added one package and tool at a time.

Agents extend the system while they work. CodeMarine inspects the dependencies, MCP servers, skills and instructions entering that trust boundary.

  • Stop slopsquattingCatch invented package names before a plausible dependency is installed.
  • Check package identityDetect typosquatting, known-malicious packages and suspicious sources.
  • Inspect install behaviorReview manifests, lockfiles, install scripts and source changes.
  • Secure agent extensionsCheck MCP descriptions, plugins, skills, rules and persistent instructions.
Explore Supply Chain Security
Sarge stopping a malicious software bug before it enters the system
Dependency review
package.jsonMODIFIED BY CURSOR
12"dependencies": {13"fastify": "^5.2.0" KNOWN14"auth-flow-utils": "^1.0.4" VERIFY15}
PACKAGE TRUST SIGNALDo not install yet

The name is plausible but expected ownership and source are not established.

Registry UnconfirmedInstall script InspectLockfile Changed

Models investigate. CodeMarine remembers.

Routine checks stay fast and local. Ambiguous or novel cases can move to an approved frontier model with focused evidence, then return through an independent validation gate.

01

Detect locally

Continuous deterministic checks find known risks without a model call.

02

Package context

Graph paths, evidence and revision data focus the investigation.

03

Investigate

An approved frontier model reasons about ambiguous or novel risk.

04

Validate

CodeMarine rescans the patch and checks policy before acceptance.

05

Retain the lesson

A verified discovery becomes a fixture and can graduate into a durable control.

FRONTIER MODELSReason about new and context-dependent risk.
+
CODEMARINECheck continuously and enforce on proven paths.
See the complete governed workflow

Know what is watching. Know what can stop.

Code scanning, hook installation and live prevention are different claims. CodeMarine keeps capability, setup health and current proof separate.

A green status has to describe a real mechanism, not marketing confidence.

Read the coverage contract

Code and configuration scanningContinuous deterministic workspace checks

Current

Supply-chain and agent artifactsDependencies, MCP, rules and skills

Current

Supported local action adaptersSetup and host limitations remain visible

Beta

Frontier investigation workflowFocused escalation and independent validation

Planned

Built for developers. Legible to security.

Run quietly during normal work. Surface clear evidence when something needs intervention.

Local-first speed

Run high-frequency checks without paying for a model call on every save.

Deterministic decisions

The same revision, rules and policy produce the same security result.

Visible coverage

Separate observation, blocking capability, setup health and live proof.

Durable learning

Turn verified model discoveries into regression fixtures and future controls.

Put one security contract around AI development.

Install CodeMarine Dev, connect the tools your team uses and keep one independent watch over every change.

Sarge, the CodeMarine guardian