Practical security for AI-assisted development.

Detailed guides for the people giving coding agents access to real repositories, terminals and infrastructure.

Practical guides

Answers you can use.

Threat models, checklists and operating guidance grounded in how current agent tools actually work.

Checklist12 min read

MCP security checklist: 12 checks before you connect a server

MCP turns useful context into executable authority. This checklist covers server trust, tool permissions, authentication, prompt injection, secrets and ongoing monitoring.

Treat every MCP server as privileged software. Verify what it is, limit what it can do and monitor the configuration after installation.

MCP security
Guide11 min read

How to stop AI agents running destructive commands

Permission fatigue makes broad approval inevitable. Here is how to keep agents useful while protecting files, Git history, databases, containers and cloud infrastructure.

Runtime safety
Explainer10 min read

What is slopsquatting? How AI package hallucinations become attacks

A coding model invents a plausible package name. An attacker publishes it. A developer installs it. Learn how the attack works and how to stop it before installation.

Supply chain
Guide12 min read

Claude Code security: permissions, hooks and the gaps around them

Claude Code has strong native controls. Learn what its permission system, sandbox and hooks do well, when teams bypass them and where an independent layer still matters.

Claude Code
Comparison13 min read

Claude Security, Codex Security and deterministic scanners

Frontier security agents and deterministic scanners solve different problems. This comparison shows where each is strongest and how to combine them without paying to scan everything twice.

Security architecture
Analysis

The architecture behind the controls.

Shorter essays on deterministic security, agent authority and the software supply chain.

Need a direct answer?

The FAQ covers deployment, provider compatibility, runtime limits and how CodeMarine works with frontier security tools.

Open the full FAQ

Build with the frontier. Keep an independent watch.

See how CodeMarine fits around the tools your team already uses.

Sarge, the CodeMarine guardian