Trust and Coverage

Security claims should be inspectable.

See the agent, surface, mechanism and operational state behind every preventive claim.

Surface coverage
CLAUDE CODE · PAYMENTS-API4 SURFACES

Workspace code changesDeterministic scan path

Current

Destructive shell commandsHook capable, no live proof

SETUP NEEDED

Native web actionsNo local interception path

NOT COVERED

CodeMarine MCPMediated tool path

Beta

Say exactly what the control can prove.

Scanning, prevention, detection and recovery are different capabilities.

01 · Specificity

Coverage is per surface

An agent can have guarded shell actions and uncovered native browser actions at the same time.

02 · Proof

Installation is not enforcement

A hook file can exist while the host never invokes it. Guarded requires a current live-host canary.

03 · Separation

Health is not capability

A mechanism may support blocking but still be disabled, stale or disconnected in one workspace.

Six states with distinct meanings.

Each state comes from capability, configuration and health data.

Guarded Planned

A supported blocking mechanism is active and has current matching proof.

Alerts only Planned

CodeMarine can observe or warn but cannot authoritatively block this protection.

Setup needed Beta

A capable path exists but installation, permission or proof is incomplete.

Problem Planned

A previously configured mechanism is stale, unreachable or failing.

Off Planned

The protection has been disabled by an authorized setting.

Not covered Current

CodeMarine has no structural interception path for this action.

Guarded should expire when reality changes.

Proof binds the host, adapter, build, policy and workspace. Any relevant change invalidates it.

No live proof means no Guarded status.

Proof record
PROTECTIONdestructive_shell_commands
Host + protocol
Bound
Adapter hash
Bound
Policy revision
Bound
Workspace
Bound
Harmless canary
Passed
Expires
23h 14m

Signed record includes build revision and canary identity.

Keep evidence useful without turning it into a leak.

Keep reason codes and fingerprints. Keep raw commands and secrets out of routine telemetry.

RETAIN
  • Stable reason and category codes
  • Decision fingerprint and severity
  • Agent, tool and workspace attribution hashes
  • Mechanism and policy revisions
  • Outcome and timestamps
DO NOT RETAIN
  • Raw commands by default
  • Environment variable values
  • Secret or credential content
  • Database connection strings
  • Unbounded tool payloads

What exists now and what is being built.

Current, beta and planned capability are separated below.

AreaClaim boundaryStatus
Deterministic code scanningUnified local-first scan path with structural confirmation in supported languages Current
Supply-chain and AI artifact scanningMultiple package ecosystems plus selected MCP, rule and skill artifacts Current
Destructive action evaluatorDeterministic command evaluation with sanitized verdicts Current
Provider action adaptersDefined shell or write paths. Setup and provider limits apply Beta
Proof-backed Protection CenterPer-surface status, live canaries, event history and critical alerts Planned
MCP and API authority gatewayStructured remote tool policy and scoped credentials Planned
Frontier investigation loopBounded context, provider routing and deterministic patch gate Planned
Enterprise governanceSSO, SCIM, organization RBAC and compliance reporting Planned

Found something we should know?

Include the affected version, reproduction details and a safe way to contact you.

Report a security issue
Do

Use a minimal reproduction and avoid accessing data that is not yours.

Do not

Publish active exploit details before the team has had a reasonable chance to respond.

Expect

An acknowledgement and a request for any missing details. A formal response SLA is not claimed yet.

Verify the boundary before you trust it.

See what is current, what needs setup and where no preventive path exists.

Sarge, the CodeMarine guardian