Coverage is per surface
An agent can have guarded shell actions and uncovered native browser actions at the same time.
See the agent, surface, mechanism and operational state behind every preventive claim.
Workspace code changesDeterministic scan path
CurrentDestructive shell commandsHook capable, no live proof
SETUP NEEDEDNative web actionsNo local interception path
NOT COVEREDCodeMarine MCPMediated tool path
BetaScanning, prevention, detection and recovery are different capabilities.
An agent can have guarded shell actions and uncovered native browser actions at the same time.
A hook file can exist while the host never invokes it. Guarded requires a current live-host canary.
A mechanism may support blocking but still be disabled, stale or disconnected in one workspace.
Each state comes from capability, configuration and health data.
A supported blocking mechanism is active and has current matching proof.
CodeMarine can observe or warn but cannot authoritatively block this protection.
A capable path exists but installation, permission or proof is incomplete.
A previously configured mechanism is stale, unreachable or failing.
The protection has been disabled by an authorized setting.
CodeMarine has no structural interception path for this action.
Proof binds the host, adapter, build, policy and workspace. Any relevant change invalidates it.
No live proof means no Guarded status.
Signed record includes build revision and canary identity.
Keep reason codes and fingerprints. Keep raw commands and secrets out of routine telemetry.
Current, beta and planned capability are separated below.
| Area | Claim boundary | Status |
|---|---|---|
| Deterministic code scanning | Unified local-first scan path with structural confirmation in supported languages | Current |
| Supply-chain and AI artifact scanning | Multiple package ecosystems plus selected MCP, rule and skill artifacts | Current |
| Destructive action evaluator | Deterministic command evaluation with sanitized verdicts | Current |
| Provider action adapters | Defined shell or write paths. Setup and provider limits apply | Beta |
| Proof-backed Protection Center | Per-surface status, live canaries, event history and critical alerts | Planned |
| MCP and API authority gateway | Structured remote tool policy and scoped credentials | Planned |
| Frontier investigation loop | Bounded context, provider routing and deterministic patch gate | Planned |
| Enterprise governance | SSO, SCIM, organization RBAC and compliance reporting | Planned |
Include the affected version, reproduction details and a safe way to contact you.
Report a security issueUse a minimal reproduction and avoid accessing data that is not yours.
Publish active exploit details before the team has had a reasonable chance to respond.
An acknowledgement and a request for any missing details. A formal response SLA is not claimed yet.
See what is current, what needs setup and where no preventive path exists.