Evidence CodeMarine can inspect
- Workspace changes and resulting source files
- Dependencies, lockfiles, rules and skills
- CodeMarine-mediated MCP tool activity
Continuous workspace security for Claude-written code, plus provider-specific hook and MCP paths.
Workspace observation and pre-execution control are shown separately.
Keep provider permissions and sandboxes. Add one deterministic policy around the workspace and the rest of your stack.
Controls the surfaces and execution modes owned by the provider.
Secures resulting code, software supply chain and supported actions under one control model.
Effective protection needs the right adapter, current configuration, healthy decision path and matching host proof.
No live proof means Setup needed or Beta.
InstallPlace the supported adapter and configuration.
VerifyCheck version, integrity and workspace binding.
ProveRun a harmless nonce-bound canary through the real host.
MaintainExpire proof when the host, policy or configuration changes.
Map the current workspace, provider paths and limits before deciding which controls to rely on.