Agents & protocols we integrate with today
Integration depth as of the 2026-09 security-runtime research pass. FULL = structured action events; LIMITED = indirect/process-level observation; PLANNED = not shipped in Early Access yet.
| Agent / protocol | Integration surface | Level (monitor) | Level (enforce) |
|---|---|---|---|
| Claude Code | Official hooks (PreToolUse allow/deny/ask, PostToolUse, SessionStart/End, Stop, SubagentStop, PreCompact, Notification) | FULL | FULL (hook decisions) |
| OpenClaw | Tool policy, plugins, session JSONL | FULL | FULL |
| MCP servers (any agent) | Proxy at the MCP transport layer — every tool call across any agent crosses it | FULL (tool calls) | FULL (allow/deny + task-scoped grants) |
| OpenAI Codex (CLI) | No public hook event surface today; approvals + sandbox are its own controls | LIMITED (process + file audit) | LIMITED — adapter research in progress |
| Cursor / other IDE agents | Process lineage + file/network observation | LIMITED | LIMITED |
| Unknown / new agents | Universal Agent Discovery + Known/Observed/Trusted states with workable default policies | FULL (auto-discovered) | Policy default, not blanket ban |
| Skills / MCP ecosystems | Skill and MCP supply-chain analysis (planned layer) | PLANNED | PLANNED |
Design rule
Universal capabilities first, adapters only when necessary. An agent we cannot hook is not exempt: it still hits the OS observation layer. "The agent we could not integrate with" is precisely why a platform-agnostic layer exists.
Vendor and product names belong to their owners; listings describe integration targets only.