Capability Matrix
Per-connector breakdown of block capability, native ask events, fail-closed support, subprocess policy, OpenShell sandbox tier, and HITL behaviour. The single source of truth for "can this connector do X?"
This page is the single source of truth for "can this connector do X?". Every row is hand-derived from the Go connector files in internal/gateway/connector/ and re-verified on every change. Use it to pick the connector that fits your safety posture, or to find the gaps you need to compensate for.
Connector capability is not platform certification
This matrix describes each connector's product-level hook or proxy contract. Platform availability, setup, and operating-system-specific limits live in the connector platform table and on each connector page. A supported native Windows path does not fabricate official-client validation evidence, and the Windows package does not provide the proxy or subprocess-shim wiring used by some connectors elsewhere.
| Connector | Family | Tool inspection | Subprocess policy | Block | Native ask | Fail-closed | OpenShell sandbox | HITL behavior |
|---|---|---|---|---|---|---|---|---|
| Claude Code claudecode | hooks | pre-execution + response-scan | none | ✓ | ✓ PreToolUse | ✓ | managed tier /etc/claude-code/managed-settings.d/50-defenseclaw.json image pin 2.1.156 verified end to end | Claude Code supports native PreToolUse ask prompts. CRITICAL findings still block; HIGH findings can pause for approval. |
| Codex codex | hooks | pre-execution + response-scan | none | ✓ | · | ✓ | managed tier /etc/codex/requirements.toml image pin 0.146.0 verified end to end | Codex has no native ask surface here; confirm becomes an alert/systemMessage with raw_action preserved. The TUI can review the event but cannot resume it. |
| OpenClaw openclaw | proxy | pre-execution + response-scan | shims | ✓ | ✓ before_tool_call | ✓ | pending | OpenClaw supports DefenseClaw approval prompts for tool actions. Approvals reach chat-origin sessions via the bundled plugin. |
| Cursor cursor | hooks | pre-execution + response-scan | none | ✓ | · | ✓ | managed tier /etc/cursor/hooks.json image pin 2026.07.23-e383d2b unverified: cannot run yet | DefenseClaw does not enable Cursor native human approval. Confirm verdicts remain attributed alerts and cannot resume the original hook call. |
| Hermes hermes | hooks | pre-execution + response-scan | none | ✓ | · | · | user tier /etc/hermes/config.yaml image pin 0.19.0 verified end to end | Hermes has no native human-approval surface; confirm verdicts are recorded and alerted but cannot pause or resume the hook. |
| OpenCode opencode | hooks | pre-execution + response-scan | none | ✓ | · | ✓ | user tier /etc/opencode/opencode.json image pin 1.18.31 verified end to end | No native human-approval surface; blocks by throwing in the bridge plugin's tool.execute.before. confirm verdicts fall back to allow. |
| Amp amp | hooks | pre-execution + response-scan | none | ✓ | ✓ tool.call, tool.result | ✓ | user tier /sandbox/.config/amp/plugins/defenseclaw.ts image pin 0.0.1785334225-g9abe75 unverified: cannot run yet | Amp can ask in the active foreground thread during tool.call and before a tool.result reaches the model. Denial, a background thread, or unavailable plugin UI rejects the call or withholds the result rather than silently allowing it. |
| OmniGent omnigent | hooks | pre-execution + response-scan | none | ✓ | ✓ UserPromptSubmit, PreToolUse, BeforeModel | ✓ | managed tier /etc/omnigent/config.yaml image pin 0.13.0 verified end to end | OmniGent parks request, tool_call, and llm_request for native ASK approval. Post-phase confirm findings are audited and continue without a pause; DENY may suppress onward-visible content but cannot roll back completed work. |
| GitHub Copilot CLI copilot | hooks | pre-execution + response-scan | none | ✓ | ✓ preToolUse | · | managed tier /etc/github-copilot/policy.d/50-defenseclaw.json image pin 1.0.88 verified end to end | Copilot CLI supports native ask on documented preToolUse hooks. |
| OpenHands openhands | hooks | pre-execution + response-scan | none | ✓ | · | ✓ | user tier /sandbox/.openhands/hooks.json image pin 1.16.0 verified end to end | OpenHands has no native ask surface in the documented hook contract; confirm verdicts are downgraded with raw_action preserved and optional additionalContext returned to the agent. |
| Antigravity antigravity | hooks | pre-execution | none | ✓ | ✓ PreToolUse | · | user tier /sandbox/.gemini/config/hooks.json image pin 1.2.12 verified end to end | Antigravity documents native ask on PreToolUse only. DefenseClaw does not claim that this response overrides permission-bypass flags without persisted official-client evidence; force_ask is retained only as internal raw_action telemetry. |
| Devin devin | hooks | pre-execution + response-scan | none | ✓ | · | ✓ | user tier /sandbox/.config/devin/config.json image pin 3000.4.25 unverified: cannot run yet | Can block documented events but has no native resumable human-approval surface; confirm verdicts fall back explicitly. |
| Kiro kiro | hooks | pre-execution + response-scan | none | ✓ | · | ✓ | user tier /usr/local/lib/defenseclaw/kiro/defenseclaw.json image pin 2.24.1 verified end to end | Kiro has no native ask verdict; policy confirms are recorded and downgraded to alerts. ACP permission requests stay native client interactions and may be denied before the client displays them. |
| ZeptoClaw zeptoclaw | proxy | pre-execution + response-scan | shims | ✓ | · | ✓ | pending | ZeptoClaw has no native ask surface; confirm uses its explicit fallback with raw_action preserved for TUI/audit review. There is no resumable approval. |
Reading the matrix
Family
proxy = DefenseClaw sits in the LLM data path. hooks = DefenseClaw hooks into the agent's lifecycle; the agent talks directly to its upstream.
Tool inspection
When DefenseClaw can see the tool call. pre-execution + response-scan means we score before the call fires and after it returns.
Subprocess policy
shims = connector setup installs DefenseClaw's PATH shims for curl, wget, ssh, nc, pip, and npm, which ask the gateway to inspect each invocation before it runs; shims do not isolate the process. none = the agent's own runtime executes commands; DefenseClaw observes or blocks only through the connector's hook/proxy surface.
Block
Whether the hooks the connector exposes can return a block decision at all.
Native ask
Whether the connector's hooks can prompt the operator inside the agent UI for approval. Without native ask, confirm uses a connector-specific alert/allow/context fallback; the TUI can review the event but cannot resume it.
Fail-closed
Whether the hook surface supports a fail-closed response — i.e. block on transport failure to the gateway. It does not cover a hook process the user kills or stops. Connectors marked false require operator-managed timeouts.
OpenShell sandbox
Where the connector's hooks live in a DefenseClaw OpenShell sandbox image: the tamper tier, then the hook config file. managed tier = a root-owned system policy file that user and project settings cannot switch off. user tier = a file in the image home the agent can edit (some launchers restore it from a root-owned copy before every start), or code the agent or a repository adds runs beside the hooks. The image pin is the harness version the image installs by default. verified = the harness ran end to end in a sandbox; unverified = its image never passes the hook check, so it cannot run yet. pending = DefenseClaw builds no sandbox image for this connector.
HITL behaviour
One-line summary of how human-in-the-loop approvals reach the operator for this connector.
Where the data comes from
| Field | Source |
|---|---|
| Family | internal/gateway/connector/*.go (whether the connector implements RoutingConnector for proxy mode) |
| Tool inspection | _CONNECTOR_META[<id>].tool_mode in cli/defenseclaw/commands/cmd_setup.py |
| Subprocess policy | Effective setup call sites for SetupSubprocessEnforcement in internal/gateway/connector/*.go, cross-checked with _CONNECTOR_META[<id>].subprocess_policy |
| Block / Native ask / Fail-closed | HookCapability{} literals in internal/gateway/connector/hook_only.go and the per-connector files |
| Hook contract versions | cli/defenseclaw/inventory/hook_contracts.json, checked against internal/gateway/connector/hook_contract.go |
| HITL behaviour | _hilt_support_note(<id>) in cli/defenseclaw/commands/cmd_setup.py |
| OpenShell sandbox | SandboxArtifacts() and the <connector>_sandbox.go renderers in internal/gateway/connector/ (tamper tier and hook config file); in internal/openshell/harness/, each harness's DefaultVersion (image pin), Verification() (status, and the reason an unverified harness is unverified), and the credential profiles and in-sandbox login marked unverified (sign-in paths not tested live) |
The component renders from data/capability-matrix.json, which is the single editable copy and is refreshed against the Go source on every connector change. The Go tests in internal/gateway/connector and internal/openshell/harness fail when its sandbox fields disagree with the code.
Advertised contract vs empirical verification
The Antigravity contract documents native ask and hard deny only on
PreToolUse. PreInvocation and PostInvocation are context-transform
surfaces, PostToolUse is observation-only, and DefenseClaw returns the
documented allow shape for Stop. No permission-bypass override is claimed
without persisted official-client evidence.
Common patterns
"I want maximum safety on a single connector"
Pick a row with proxy family, block: yes, native ask: yes, fail-closed: yes. That's OpenClaw today.
"I want enforcement on Claude Code without the proxy"
Direct-to-upstream hook enforcement is supported on Claude Code, Codex, Cursor, Hermes, Devin, Copilot CLI, OpenHands, Antigravity, OpenCode, Kiro, and OmniGent. Amp uses a direct-to-upstream system policy plugin instead. Cursor action uses documented event-native deny from the user hook. Cursor exposes no safe API for detecting an actual higher-priority Enterprise, Team, or Project conflict, so DefenseClaw reports that limitation and does not infer a conflict. The broader constraint is that these connectors cannot block a request the agent has not yet presented to their hook or policy surface.
"I want HITL approvals to surface inside the agent UI"
Pick a row with native ask: yes: OpenClaw, Claude Code (PreToolUse), GitHub Copilot CLI (preToolUse),
Antigravity (PreToolUse only), Amp (tool.call and model-bound tool.result
in the active foreground thread), or OmniGent (request, tool_call, llm_request).
Cursor is not counted because DefenseClaw does not enable its native ask response;
confirm verdicts remain attributed alerts and cannot resume the original call.
Confirm verdicts on every other connector/event take an immediate
connector-specific fallback; there is no TUI approval queue.
"I want to run the agent in an OpenShell sandbox"
defenseclaw sandbox run <harness> runs a coding agent in an NVIDIA OpenShell
sandbox that sees only your project folder, on Linux, or on an Apple-silicon
Mac in an OpenShell MicroVM that works on a copy of it
(how). The
sandbox guide covers setup and every sandbox command.
DefenseClaw builds sandbox images for twelve harnesses; every other connector is
pending in the matrix above.
| Connector | Image pin | Tamper tier | Hook config in the image | Verification |
|---|---|---|---|---|
| Claude Code claudecode | 2.1.156 | managed | /etc/claude-code/managed-settings.d/50-defenseclaw.json | Verified end to end |
| Codex codex | 0.146.0 | managed | /etc/codex/requirements.toml | Verified end to end |
| Cursor cursor | 2026.07.23-e383d2b | managed | /etc/cursor/hooks.json | Unverified: cannot run yet. The Cursor Agent CLI needs a Cursor account (CURSOR_API_KEY or cursor-agent login) before any agent turn. Not tested live: defenseclaw-cursor, in-sandbox login |
| Hermes hermes | 0.19.0 | user | /etc/hermes/config.yaml | Verified end to end Not tested live: defenseclaw-openai, defenseclaw-anthropic |
| OpenCode opencode | 1.18.31 | user | /etc/opencode/opencode.json | Verified end to end |
| Amp amp | 0.0.1785334225-g9abe75 | user | /sandbox/.config/amp/plugins/defenseclaw.ts | Unverified: cannot run yet. Amp needs an Amp account API key (AMP_API_KEY) for every run. Not tested live: defenseclaw-amp |
| OmniGent omnigent | 0.13.0 | managed | /etc/omnigent/config.yaml | Verified end to end Not tested live: defenseclaw-openai, defenseclaw-anthropic |
| GitHub Copilot CLI copilot | 1.0.88 | managed | /etc/github-copilot/policy.d/50-defenseclaw.json | Verified end to end Not tested live: defenseclaw-copilot-github |
| OpenHands openhands | 1.16.0 | user | /sandbox/.openhands/hooks.json | Verified end to end Not tested live: defenseclaw-openai, defenseclaw-anthropic |
| Antigravity antigravity | 1.2.12 | user | /sandbox/.gemini/config/hooks.json | Verified end to end Not tested live: defenseclaw-gemini |
| Devin devin | 3000.4.25 | user | /sandbox/.config/devin/config.json | Unverified: cannot run yet. The Devin CLI needs a Devin account login (devin auth login, a browser or pasted-token flow) before any agent turn. Not tested live: in-sandbox login |
| Kiro kiro | 2.24.1 | user | /usr/local/lib/defenseclaw/kiro/defenseclaw.json | Verified end to end Not tested live: defenseclaw-kiro, in-sandbox login |
- Tamper tier. In the managed tier the hooks are in a root-owned system or
managed policy file that user and project settings cannot switch off. In the
user tier the agent can edit its own hook file, or code the agent or a
repository adds runs beside the hooks (Hermes, for example, loads
.envfiles and plugins from its home, which its launcher checks before every start). DefenseClaw reports a sandbox whose hooks go silent while the harness is active, and OpenShell's network policy holds either way.defenseclaw sandbox status <name>shows the tier. - Verification. Before DefenseClaw starts a sandbox from an image, the image must pass a hook check against a built-in mock model (for Kiro CLI, Kiro's own scripted-response mode): the hooks fire, a blocked tool call has no effect, and an allowed one runs. Verified end to end also means the harness ran in a live OpenShell sandbox with the DefenseClaw daemon, where a blocked command stayed blocked and the egress block list held.
- Unverified. These harnesses send every request, the account check
included, to their vendor's service and need an account before the first
turn, so no mock model can drive them. Their images build but never pass the
hook check:
sandbox runbuilds the image (several GB), then refuses it until a check with a vendor account passes, and the unverified image stays until you remove it (see the connector page). - Not tested live. A sign-in path whose endpoints or login no live run
exercised, because no account was available. The connector page says which
sign-ins
defenseclaw sandbox runshares. - Setup defaults. The
openshell.harnessessetting (Claude Code and Codex when empty) decides which imagesdefenseclaw sandbox setupand a baredefenseclaw sandbox image buildbuild and which onesdefenseclaw sandbox doctorchecks.sandbox setupwrites that list: its--harness(repeatable) replaces it, so name every harness you want.sandbox image build <harness>...builds the harnesses you name without changing it, andsandbox runbuilds a missing image on the first run. The TUI and macOS setup wizards list only Claude Code and Codex, and a wizard run replacesopenshell.harnesseswith the ones you tick.
Every sandbox hook fails closed.
"I want fail-closed on transport failures"
Fail-closed here means the hook blocks when it cannot reach the gateway (a transport failure). It does not cover a hook process that the user kills, stops or starves: the agent then decides, and Claude Code, Codex, OpenHands and Devin treat a hook that dies or times out as non-blocking and run the call (see the enterprise threat model).
Pick a row with fail-closed: yes: OpenClaw, ZeptoClaw, Claude Code, Codex, Cursor, Devin, OpenCode, Amp, OpenHands, Kiro, and OmniGent. GitHub Copilot CLI, Hermes, and Antigravity do not expose a generic DefenseClaw-controlled fail-closed transport response. Cursor's support is mode-matched: action writes failClosed: true, while observe writes failClosed: false. Devin can map DefenseClaw availability failures to vendor exit 2 only on its four declared block-capable events.
ACP guard
Put DefenseClaw between an ACP editor client and coding agent to inspect prompts, streaming output, permissions, filesystem, terminal, and extension methods.
Deterministic Detection Benchmarks
Public F1, false-positive, benign-block, YARA, privacy, and bounded-chain results for DefenseClaw's deterministic guardrails.