Claude integration

Independent security around Claude.

Continuous workspace security for Claude-written code, plus provider-specific hook and MCP paths.

Coverage is stated per surface. Native provider security remains a complementary layer.
Claude coverage Current assessment
INTEGRATION PROFILE Beta
Provider
Claude Code and Claude Desktop
Primary transport
Workspace watcher, Claude Code hooks and CodeMarine MCP
Workspace scanning
Available
Blanket runtime protection
Not claimed

Provider versions, host configuration and remote execution mode can change effective coverage.

Coverage detail

What the integration can see and where it stops.

This profile distinguishes workspace observation from pre-execution control. An observed effect is not evidence that the original action was prevented.

OBSERVE

Evidence CodeMarine can inspect

  • Workspace changes and resulting source files
  • Dependencies, lockfiles, rules and skills
  • CodeMarine-mediated MCP tool activity
PREVENTIVE PATH

Defined blocking potential

  • Supported Claude Code shell and write operations after setup
  • Defined catastrophic command classes through the local guard
LIMITS

What you should not assume

  • Live host proof is not available yet, so hook surfaces remain Setup needed
  • Claude Desktop native connectors and UI actions are not covered
  • Cowork and computer-use actions are not intercepted by local hooks
Use both layers

Native controls protect Claude. CodeMarine protects the shared environment.

Provider permissions, sandboxes and security review remain useful. CodeMarine adds one deterministic policy and evidence model around the workspace used by this provider and the rest of your stack.

NATIVE LAYERProvider permissions and containment

Controls the surfaces and execution modes owned by the provider.

CODEMARINE LAYERCross-provider workspace policy

Secures resulting code, software supply chain and supported actions under one control model.

Effective protection

A configured adapter is only the start.

The target product state requires the right adapter, current configuration, workspace identity, healthy decision path and a matching live-host proof.

The live canary does not exist yet. Current adapters must remain Setup needed or Beta until host invocation can be proven.

  1. 01

    InstallPlace the supported adapter and configuration.

  2. 02

    VerifyCheck version, integrity and workspace binding.

  3. 03

    ProveRun a harmless nonce-bound canary through the real host.

  4. 04

    MaintainExpire proof when the host, policy or configuration changes.

Early access

Evaluate CodeMarine with Claude.

Map the current workspace, provider paths and limits before deciding which controls to rely on.

Sarge, the CodeMarine guardian