20131 20131
中文

Agents & protocols we integrate with today

Integration depth as of the 2026-09 security-runtime research pass. FULL = structured action events; LIMITED = indirect/process-level observation; PLANNED = not shipped in Early Access yet.

Agent / protocolIntegration surfaceLevel (monitor)Level (enforce)
Claude CodeOfficial hooks (PreToolUse allow/deny/ask, PostToolUse, SessionStart/End, Stop, SubagentStop, PreCompact, Notification)FULLFULL (hook decisions)
OpenClawTool policy, plugins, session JSONLFULLFULL
MCP servers (any agent)Proxy at the MCP transport layer — every tool call across any agent crosses itFULL (tool calls)FULL (allow/deny + task-scoped grants)
OpenAI Codex (CLI)No public hook event surface today; approvals + sandbox are its own controlsLIMITED (process + file audit)LIMITED — adapter research in progress
Cursor / other IDE agentsProcess lineage + file/network observationLIMITEDLIMITED
Unknown / new agentsUniversal Agent Discovery + Known/Observed/Trusted states with workable default policiesFULL (auto-discovered)Policy default, not blanket ban
Skills / MCP ecosystemsSkill and MCP supply-chain analysis (planned layer)PLANNEDPLANNED

Design rule

Universal capabilities first, adapters only when necessary. An agent we cannot hook is not exempt: it still hits the OS observation layer. "The agent we could not integrate with" is precisely why a platform-agnostic layer exists.

Vendor and product names belong to their owners; listings describe integration targets only.