Coverage is per surface
An agent can have guarded shell actions and uncovered native browser actions at the same time.
CodeMarine is building a proof-backed coverage model that names the agent, surface, mechanism and operational state behind every preventive claim.
This page is a public product contract. It distinguishes current foundations from beta adapters and planned proof systems.Workspace code changesDeterministic scan path
CurrentDestructive shell commandsHook capable, no live proof
SETUP NEEDEDNative web actionsNo local interception path
NOT COVEREDCodeMarine MCPMediated tool path
BetaThis view is illustrative. The typed status authority and live proof registry are planned.
Code scanning, runtime prevention, after-effect detection and recovery are different capabilities. CodeMarine will not collapse them into one protected badge.
An agent can have guarded shell actions and uncovered native browser actions at the same time.
A hook file can exist while the host never invokes it. Guarded requires a current live-host canary.
A mechanism may support blocking but still be disabled, stale or disconnected in one workspace.
The planned UI derives these labels from typed capability, mechanism and health data. Screen copy must not mint them independently.
A supported blocking mechanism is active and has current matching proof.
CodeMarine can observe or warn but cannot authoritatively block this protection.
A capable path exists but installation, permission or proof is incomplete.
A previously configured mechanism is stale, unreachable or failing.
The protection has been disabled by an authorized setting.
CodeMarine has no structural interception path for this action.
A valid proof must bind the host and protocol, adapter configuration, CodeMarine build, policy revision, workspace and adversarial test. A host update or configuration change invalidates stale proof.
The live canary and proof registry do not exist yet. Current hook surfaces must not be presented as Guarded.
Example only. A real proof also records build revision and the successful test identity.
The action guard is designed around classifications, reason codes and fingerprints. Raw commands and secret contents should not become routine telemetry.
This ledger avoids fixed pattern counts and universal enforcement claims. It should become machine-generated from owned product evidence.
| Area | Claim boundary | Status |
|---|---|---|
| Deterministic code scanning | Unified local-first scan path with structural confirmation in supported languages | Current |
| Supply-chain and AI artifact scanning | Multiple package ecosystems plus selected MCP, rule and skill artifacts | Current |
| Destructive action evaluator | Deterministic command evaluation with sanitized verdicts | Current |
| Provider action adapters | Defined shell or write paths. Setup and provider limits apply | Beta |
| Proof-backed Protection Center | Per-surface status, live canaries, event history and critical alerts | Planned |
| MCP and API authority gateway | Structured remote tool policy and scoped credentials | Planned |
| Frontier investigation loop | Bounded context, provider routing and deterministic patch gate | Planned |
| Enterprise governance | SSO, SCIM, organization RBAC and compliance reporting | Planned |
Send security reports to the CodeMarine team. Include the affected version, reproduction details and a safe way to contact you.
Report a security issueUse a minimal reproduction and avoid accessing data that is not yours.
Publish active exploit details before the team has had a reasonable chance to respond.
An acknowledgement and a request for any missing details. A formal response SLA is not claimed yet.
We will show what is current, what needs setup and where no preventive path exists.