Integrations

One policy across a mixed agent stack.

CodeMarine watches the shared workspace across tools, then adds provider-specific prevention where a host exposes an authoritative path. Every integration page states the boundary.

Provider behavior changes. Coverage must be re-verified against each host and version.
Integration fleet Illustrative product view
DEVELOPMENT SURFACES6 PROFILES

ClaudeWorkspace watcher, Claude Code hooks and CodeMarine MCP

Beta

CodexWorkspace watcher, plugin and write adapter

Beta

CursorWorkspace watcher and Cursor hooks

Beta

WindsurfWorkspace watcher and Windsurf hooks

Beta

GrokWorkspace watcher and adapter assets

Planned

A provider profile is not a universal protected state. Each action surface has its own mechanism and limit.

Provider profiles

Know what CodeMarine can see before you depend on it.

Workspace scanning is provider-independent. Earlier prevention depends on hooks, MCP routing, a gateway or authority controlled outside the agent.

Claude Beta

Claude Code and Claude Desktop

Continuous workspace security for Claude-written code, plus provider-specific hook and MCP paths.

Workspace watcher, Claude Code hooks and CodeMarine MCPView coverage
Codex Beta

Codex CLI, IDE and desktop surfaces

Independent scanning for Codex changes today, with stronger command and MCP mediation in active development.

Workspace watcher, plugin and write adapterView coverage
Cursor Beta

Cursor local and Background Agents

Code and dependency monitoring across Cursor work, with local edit and shell adapters available for setup.

Workspace watcher and Cursor hooksView coverage
Windsurf Beta

Windsurf

Workspace, dependency and agent-configuration security with local write and shell adapters.

Workspace watcher and Windsurf hooksView coverage
Grok Planned

Grok

A provider adapter exists. Managed installation and verified protection are still being completed.

Workspace watcher and adapter assetsView coverage
Devin Planned

Devin

CodeMarine can inspect the resulting repository today. Preventive remote control requires governed tool and credential paths.

Repository, CI and future gateway controlsView coverage
The shared layer

The integration is more than a plugin.

CodeMarine’s independent value starts with the resulting workspace. A provider adapter can move the decision earlier, but the normalized finding, policy and evidence model stays the same.

WorkspaceWatch code, configuration and generated artifacts across authors
Supply chainInspect dependencies, lockfiles, MCP, rules and skills
Host adapterEvaluate supported operations before execution where the host permits it
DownstreamReinforce gaps through CI, SCM and future governed tool paths
Reading the matrix

Observe, prevent and not covered mean different things.

These terms prevent a common category error: assuming that seeing a resulting file change proves CodeMarine stopped the action that caused it.

Observe

See resulting evidence

The workspace watcher or connected tool reports a change. This can happen after the effect.

Prevent

Deny before execution

An authoritative host hook or governed tool path returns a blocking decision before side effects.

Not covered

No structural path

A native, remote or provider-hosted action sits outside the configured CodeMarine boundary.

Early access

Bring your real agent mix to the evaluation.

CodeMarine will map the workspace, provider surfaces and current protection gaps without painting the whole stack green.

Sarge, the CodeMarine guardian