Capability matrix

Per-connector breakdown of block capability, native ask events, fail-closed support, subprocess policy, OpenShell sandbox tier, and HITL behaviour. The single source of truth for "can this connector do X?"

This page answers "can this connector do X?" for every connector. The table is checked against the connector code on every change. Use it to pick the connector that fits your safety needs, or to find the gaps you need to cover another way.

Looking for what works on your OS?

This matrix describes each connector's hook or proxy contract, not where it runs. Which agents and features work on Linux, macOS and Windows, in the open-source and enterprise editions, and what live tests verified in this release, is on the support matrix. OS-specific setup and limits are on each connector page. The Windows package doesn't provide the proxy or subprocess-shim wiring some connectors use elsewhere.

Yes the connector supports itNoit doesn'tScroll the table sideways on a narrow screen.

ConnectorFamilyTool inspectionSubprocess policyBlockNative askFail-closedOpenShell sandbox
Claude Code
claudecode
hookspre-execution + response-scannoneYesYes
PreToolUse
Yesmanaged tier
verified end to end
HITL: Claude Code supports native PreToolUse ask prompts. CRITICAL findings still block; HIGH findings can pause for approval.
Codex
codex
hookspre-execution + response-scannoneYesNoYesmanaged tier
verified end to end
HITL: Codex has no native ask surface here; confirm becomes an alert/systemMessage with raw_action preserved. The TUI can review the event but cannot resume it.
OpenClaw
openclaw
proxypre-execution + response-scanshimsYesYes
before_tool_call
Yespending
HITL: OpenClaw supports DefenseClaw approval prompts for tool actions. Approvals reach chat-origin sessions via the bundled plugin.
Cursor
cursor
hookspre-execution + response-scannoneYesNoYesmanaged tier
unverified: cannot run yet
HITL: DefenseClaw does not enable Cursor native human approval. Confirm verdicts remain attributed alerts and cannot resume the original hook call.
Hermes
hermes
hookspre-execution + response-scannoneYesNoNouser tier
verified end to end
HITL: Hermes has no native human-approval surface; confirm verdicts are recorded and alerted but cannot pause or resume the hook.
OpenCode
opencode
hookspre-execution + response-scannoneYesNoYesuser tier
verified end to end
HITL: No native human-approval surface; blocks by throwing in the bridge plugin's tool.execute.before. confirm verdicts fall back to allow.
Amp
amp
hookspre-execution + response-scannoneYesYes
tool.call, tool.result
Yesuser tier
unverified: cannot run yet
HITL: Amp can ask in the active foreground thread during tool.call and before a tool.result reaches the model. Denial, a background thread, or unavailable plugin UI rejects the call or withholds the result rather than silently allowing it.
OmniGent
omnigent
hookspre-execution + response-scannoneYesYes
UserPromptSubmit, PreToolUse, BeforeModel
Yesmanaged tier
verified end to end
HITL: OmniGent parks request, tool_call, and llm_request for native ASK approval. Post-phase confirm findings are audited and continue without a pause; DENY may suppress onward-visible content but cannot roll back completed work.
GitHub Copilot CLI
copilot
hookspre-execution + response-scannoneYesYes
preToolUse
Nomanaged tier
verified end to end
HITL: Copilot CLI supports native ask on documented preToolUse hooks.
OpenHands
openhands
hookspre-execution + response-scannoneYesNoYesuser tier
verified end to end
HITL: OpenHands has no native ask surface in the documented hook contract; confirm verdicts are downgraded with raw_action preserved and optional additionalContext returned to the agent.
Antigravity
antigravity
hookspre-executionnoneYesYes
PreToolUse
Nouser tier
verified end to end
HITL: Antigravity documents native ask on PreToolUse only. DefenseClaw does not claim that this response overrides permission-bypass flags without persisted official-client evidence; force_ask is retained only as internal raw_action telemetry.
Devin
devin
hookspre-execution + response-scannoneYesNoYesuser tier
unverified: cannot run yet
HITL: Can block documented events but has no native resumable human-approval surface; confirm verdicts fall back explicitly.
Kiro
kiro
hookspre-execution + response-scannoneYesNoYesuser tier
verified end to end
HITL: Kiro has no native ask verdict; policy confirms are recorded and downgraded to alerts. ACP permission requests stay native client interactions and may be denied before the client displays them.
ZeptoClaw
zeptoclaw
proxypre-execution + response-scanshimsYesNoYespending
HITL: ZeptoClaw has no native ask surface; confirm uses its explicit fallback with raw_action preserved for TUI/audit review. There is no resumable approval.

Reading the matrix

Family

proxy = DefenseClaw sits in the LLM data path. hooks = DefenseClaw hooks into the agent's lifecycle; the agent talks directly to its upstream.

Tool inspection

When DefenseClaw can see the tool call. pre-execution + response-scan means we score before the call fires and after it returns.

Subprocess policy

shims = connector setup installs DefenseClaw's PATH shims for curl, wget, ssh, nc, pip, and npm, which ask the gateway to inspect each invocation before it runs; shims do not isolate the process. none = the agent's own runtime executes commands; DefenseClaw observes or blocks only through the connector's hook/proxy surface.

Block

Whether the hooks the connector exposes can return a block decision at all.

Native ask

Whether the connector's hooks can prompt the operator inside the agent UI for approval. Without native ask, confirm uses a connector-specific alert/allow/context fallback; the TUI can review the event but cannot resume it.

Fail-closed

Whether the hook surface supports a fail-closed response — i.e. block on transport failure to the gateway. It does not cover a hook process the user kills or stops. Connectors marked false require operator-managed timeouts.

OpenShell sandbox

The tamper tier of the connector's hooks in a DefenseClaw OpenShell sandbox image, and whether the harness is verified. managed tier = a root-owned policy file that user and project settings can't switch off. user tier = a file the agent can edit, or code the agent or a repository adds runs beside the hooks. verified = the harness ran end to end in a sandbox; unverified = its image never passes the hook check, so it can't run yet; pending = DefenseClaw builds no sandbox image for this connector. The image pin and hook file are in the sandbox table below.

HITL

The line under each connector: how human-in-the-loop approvals reach you on that connector.

Antigravity asks and blocks only before a tool runs

Antigravity can show its approval prompt and hard-block only on PreToolUse. PreInvocation and PostInvocation can only change the context the agent sees, PostToolUse only observes, and DefenseClaw always allows Stop. DefenseClaw doesn't claim it can override Antigravity's own permission bypass, because no recorded test with the official client has shown that.

Common patterns

"I want maximum safety on a single connector"

Pick a row with Block: Yes, Native ask: Yes and Fail-closed: Yes, and a managed tier sandbox that is verified end to end: Claude Code and OmniGent. Both ask for approval inside the agent, and in a sandbox their hooks sit in a root-owned policy file the agent can't switch off.

"I want my agent's own hooks to enforce"

Direct-to-upstream hook enforcement is supported on Claude Code, Codex, Cursor, Hermes, Devin, Copilot CLI, OpenHands, Antigravity, OpenCode, Kiro, and OmniGent. Amp uses a direct-to-upstream system policy plugin instead. Cursor action uses documented event-native deny from the user hook. Cursor exposes no safe API for detecting an actual higher-priority Enterprise, Team, or Project conflict, so DefenseClaw reports that limitation and does not infer a conflict. The broader constraint is that these connectors cannot block a request the agent has not yet presented to their hook or policy surface.

"I want HITL approvals to surface inside the agent UI"

Pick a row with Native ask: Yes: Claude Code (PreToolUse), GitHub Copilot CLI (preToolUse), Antigravity (PreToolUse only), Amp (tool.call and model-bound tool.result in the active foreground thread), OmniGent (UserPromptSubmit, PreToolUse and BeforeModel, which OmniGent calls its request, tool_call and llm_request policy phases), or OpenClaw. Cursor is not counted because DefenseClaw does not enable its native ask response; confirm verdicts remain attributed alerts and cannot resume the original call. Confirm verdicts on every other connector/event take an immediate connector-specific fallback; there is no TUI approval queue.

"I want to run the agent in an OpenShell sandbox"

defenseclaw sandbox run <harness> runs a coding agent in an NVIDIA OpenShell sandbox that sees only your project folder, on Linux, or on an Apple-silicon Mac in an OpenShell MicroVM that works on a copy of it (how). The sandbox guide covers setup and every sandbox command. DefenseClaw builds sandbox images for twelve harnesses; every other connector is pending in the matrix above.

ConnectorImage pinTamper tierHook config in the imageVerification
Claude Code
claudecode
2.1.156managed/etc/claude-code/managed-settings.d/50-defenseclaw.jsonVerified end to end
Codex
codex
0.146.0managed/etc/codex/requirements.tomlVerified end to end
Cursor
cursor
2026.07.23-e383d2bmanaged/etc/cursor/hooks.jsonUnverified: cannot run yet. The Cursor Agent CLI needs a Cursor account (CURSOR_API_KEY or cursor-agent login) before any agent turn.
Not tested live: defenseclaw-cursor, in-sandbox login
Hermes
hermes
0.19.0user/etc/hermes/config.yamlVerified end to end
Not tested live: defenseclaw-openai, defenseclaw-anthropic
OpenCode
opencode
1.18.31user/etc/opencode/opencode.jsonVerified end to end
Amp
amp
0.0.1785334225-g9abe75user/sandbox/.config/amp/plugins/defenseclaw.tsUnverified: cannot run yet. Amp needs an Amp account API key (AMP_API_KEY) for every run.
Not tested live: defenseclaw-amp
OmniGent
omnigent
0.13.0managed/etc/omnigent/config.yamlVerified end to end
Not tested live: defenseclaw-openai, defenseclaw-anthropic
GitHub Copilot CLI
copilot
1.0.88managed/etc/github-copilot/policy.d/50-defenseclaw.jsonVerified end to end
Not tested live: defenseclaw-copilot-github
OpenHands
openhands
1.16.0user/sandbox/.openhands/hooks.jsonVerified end to end
Not tested live: defenseclaw-openai, defenseclaw-anthropic
Antigravity
antigravity
1.2.12user/sandbox/.gemini/config/hooks.jsonVerified end to end
Not tested live: defenseclaw-gemini
Devin
devin
3000.4.25user/sandbox/.config/devin/config.jsonUnverified: cannot run yet. The Devin CLI needs a Devin account login (devin auth login, a browser or pasted-token flow) before any agent turn.
Not tested live: in-sandbox login
Kiro
kiro
2.24.1user/usr/local/lib/defenseclaw/kiro/defenseclaw.jsonVerified end to end
Not tested live: defenseclaw-kiro, in-sandbox login
  • Tamper tier. In the managed tier the hooks are in a root-owned system or managed policy file that user and project settings cannot switch off. In the user tier the agent can edit its own hook file, or code the agent or a repository adds runs beside the hooks (Hermes, for example, loads .env files and plugins from its home, which its launcher checks before every start). DefenseClaw reports a sandbox whose hooks go silent while the harness is active, and OpenShell's network policy holds either way. defenseclaw sandbox status <name> shows the tier.
  • Verification. Before DefenseClaw starts a sandbox from an image, the image must pass a hook check against a built-in mock model (for Kiro CLI, Kiro's own scripted-response mode): the hooks fire, a blocked tool call has no effect, and an allowed one runs. Verified end to end also means the harness ran in a live OpenShell sandbox with the DefenseClaw daemon, where a blocked command stayed blocked and the egress block list held.
  • Unverified. These harnesses send every request, the account check included, to their vendor's service and need an account before the first turn, so no mock model can drive them. Their images build but never pass the hook check: sandbox run builds the image (several GB), then refuses it until a check with a vendor account passes, and the unverified image stays until you remove it (see the connector page).
  • Not tested live. A sign-in path whose endpoints or login no live run exercised, because no account was available. The connector page says which sign-ins defenseclaw sandbox run shares.
  • Setup defaults. The openshell.harnesses setting (Claude Code and Codex when empty) decides which images defenseclaw sandbox setup and a bare defenseclaw sandbox image build build and which ones defenseclaw sandbox doctor checks. sandbox setup writes that list: its --harness (repeatable) replaces it, so name every harness you want. sandbox image build <harness>... builds the harnesses you name without changing it, and sandbox run builds a missing image on the first run. The macOS app's setup wizard lists only Claude Code and Codex, and a wizard run replaces openshell.harnesses with the ones you tick.

Every sandbox hook fails closed.

"I want fail-closed on transport failures"

Fail-closed here means the hook blocks when it cannot reach the gateway (a transport failure). It does not cover a hook process that the user kills, stops or starves: the agent then decides, and Claude Code, Codex, OpenHands and Devin treat a hook that dies or times out as non-blocking and run the call (see the enterprise threat model).

Pick a row with Fail-closed: Yes: OpenClaw, ZeptoClaw, Claude Code, Codex, Cursor, Devin, OpenCode, Amp, OpenHands, Kiro, and OmniGent. GitHub Copilot CLI, Hermes, and Antigravity do not expose a generic DefenseClaw-controlled fail-closed transport response. Cursor's support is mode-matched: action writes failClosed: true, while observe writes failClosed: false. Devin can map DefenseClaw availability failures to vendor exit 2 only on its four declared block-capable events.