Capability matrix
Per-connector breakdown of block capability, native ask events, fail-closed support, subprocess policy, OpenShell sandbox tier, and HITL behaviour. The single source of truth for "can this connector do X?"
This page answers "can this connector do X?" for every connector. The table is checked against the connector code on every change. Use it to pick the connector that fits your safety needs, or to find the gaps you need to cover another way.
Looking for what works on your OS?
This matrix describes each connector's hook or proxy contract, not where it runs. Which agents and features work on Linux, macOS and Windows, in the open-source and enterprise editions, and what live tests verified in this release, is on the support matrix. OS-specific setup and limits are on each connector page. The Windows package doesn't provide the proxy or subprocess-shim wiring some connectors use elsewhere.
Yes the connector supports itNoit doesn'tScroll the table sideways on a narrow screen.
| Connector | Family | Tool inspection | Subprocess policy | Block | Native ask | Fail-closed | OpenShell sandbox |
|---|---|---|---|---|---|---|---|
| Claude Code claudecode | hooks | pre-execution + response-scan | none | Yes | Yes PreToolUse | Yes | managed tier verified end to end |
| HITL: Claude Code supports native PreToolUse ask prompts. CRITICAL findings still block; HIGH findings can pause for approval. | |||||||
| Codex codex | hooks | pre-execution + response-scan | none | Yes | No | Yes | managed tier verified end to end |
| HITL: Codex has no native ask surface here; confirm becomes an alert/systemMessage with raw_action preserved. The TUI can review the event but cannot resume it. | |||||||
| OpenClaw openclaw | proxy | pre-execution + response-scan | shims | Yes | Yes before_tool_call | Yes | pending |
| HITL: OpenClaw supports DefenseClaw approval prompts for tool actions. Approvals reach chat-origin sessions via the bundled plugin. | |||||||
| Cursor cursor | hooks | pre-execution + response-scan | none | Yes | No | Yes | managed tier unverified: cannot run yet |
| HITL: DefenseClaw does not enable Cursor native human approval. Confirm verdicts remain attributed alerts and cannot resume the original hook call. | |||||||
| Hermes hermes | hooks | pre-execution + response-scan | none | Yes | No | No | user tier verified end to end |
| HITL: Hermes has no native human-approval surface; confirm verdicts are recorded and alerted but cannot pause or resume the hook. | |||||||
| OpenCode opencode | hooks | pre-execution + response-scan | none | Yes | No | Yes | user tier verified end to end |
| HITL: No native human-approval surface; blocks by throwing in the bridge plugin's tool.execute.before. confirm verdicts fall back to allow. | |||||||
| Amp amp | hooks | pre-execution + response-scan | none | Yes | Yes tool.call, tool.result | Yes | user tier unverified: cannot run yet |
| HITL: Amp can ask in the active foreground thread during tool.call and before a tool.result reaches the model. Denial, a background thread, or unavailable plugin UI rejects the call or withholds the result rather than silently allowing it. | |||||||
| OmniGent omnigent | hooks | pre-execution + response-scan | none | Yes | Yes UserPromptSubmit, PreToolUse, BeforeModel | Yes | managed tier verified end to end |
| HITL: OmniGent parks request, tool_call, and llm_request for native ASK approval. Post-phase confirm findings are audited and continue without a pause; DENY may suppress onward-visible content but cannot roll back completed work. | |||||||
| GitHub Copilot CLI copilot | hooks | pre-execution + response-scan | none | Yes | Yes preToolUse | No | managed tier verified end to end |
| HITL: Copilot CLI supports native ask on documented preToolUse hooks. | |||||||
| OpenHands openhands | hooks | pre-execution + response-scan | none | Yes | No | Yes | user tier verified end to end |
| HITL: OpenHands has no native ask surface in the documented hook contract; confirm verdicts are downgraded with raw_action preserved and optional additionalContext returned to the agent. | |||||||
| Antigravity antigravity | hooks | pre-execution | none | Yes | Yes PreToolUse | No | user tier verified end to end |
| HITL: Antigravity documents native ask on PreToolUse only. DefenseClaw does not claim that this response overrides permission-bypass flags without persisted official-client evidence; force_ask is retained only as internal raw_action telemetry. | |||||||
| Devin devin | hooks | pre-execution + response-scan | none | Yes | No | Yes | user tier unverified: cannot run yet |
| HITL: Can block documented events but has no native resumable human-approval surface; confirm verdicts fall back explicitly. | |||||||
| Kiro kiro | hooks | pre-execution + response-scan | none | Yes | No | Yes | user tier verified end to end |
| HITL: Kiro has no native ask verdict; policy confirms are recorded and downgraded to alerts. ACP permission requests stay native client interactions and may be denied before the client displays them. | |||||||
| ZeptoClaw zeptoclaw | proxy | pre-execution + response-scan | shims | Yes | No | Yes | pending |
| HITL: ZeptoClaw has no native ask surface; confirm uses its explicit fallback with raw_action preserved for TUI/audit review. There is no resumable approval. | |||||||
Reading the matrix
Family
proxy = DefenseClaw sits in the LLM data path. hooks = DefenseClaw hooks into the agent's lifecycle; the agent talks directly to its upstream.
Tool inspection
When DefenseClaw can see the tool call. pre-execution + response-scan means we score before the call fires and after it returns.
Subprocess policy
shims = connector setup installs DefenseClaw's PATH shims for curl, wget, ssh, nc, pip, and npm, which ask the gateway to inspect each invocation before it runs; shims do not isolate the process. none = the agent's own runtime executes commands; DefenseClaw observes or blocks only through the connector's hook/proxy surface.
Block
Whether the hooks the connector exposes can return a block decision at all.
Native ask
Whether the connector's hooks can prompt the operator inside the agent UI for approval. Without native ask, confirm uses a connector-specific alert/allow/context fallback; the TUI can review the event but cannot resume it.
Fail-closed
Whether the hook surface supports a fail-closed response — i.e. block on transport failure to the gateway. It does not cover a hook process the user kills or stops. Connectors marked false require operator-managed timeouts.
OpenShell sandbox
The tamper tier of the connector's hooks in a DefenseClaw OpenShell sandbox image, and whether the harness is verified. managed tier = a root-owned policy file that user and project settings can't switch off. user tier = a file the agent can edit, or code the agent or a repository adds runs beside the hooks. verified = the harness ran end to end in a sandbox; unverified = its image never passes the hook check, so it can't run yet; pending = DefenseClaw builds no sandbox image for this connector. The image pin and hook file are in the sandbox table below.
HITL
The line under each connector: how human-in-the-loop approvals reach you on that connector.
Antigravity asks and blocks only before a tool runs
Antigravity can show its approval prompt and hard-block only on PreToolUse.
PreInvocation and PostInvocation can only change the context the agent
sees, PostToolUse only observes, and DefenseClaw always allows Stop.
DefenseClaw doesn't claim it can override Antigravity's own permission bypass,
because no recorded test with the official client has shown that.
Common patterns
"I want maximum safety on a single connector"
Pick a row with Block: Yes, Native ask: Yes and Fail-closed: Yes, and a managed tier sandbox that is verified end to end: Claude Code and OmniGent. Both ask for approval inside the agent, and in a sandbox their hooks sit in a root-owned policy file the agent can't switch off.
"I want my agent's own hooks to enforce"
Direct-to-upstream hook enforcement is supported on Claude Code, Codex, Cursor, Hermes, Devin, Copilot CLI, OpenHands, Antigravity, OpenCode, Kiro, and OmniGent. Amp uses a direct-to-upstream system policy plugin instead. Cursor action uses documented event-native deny from the user hook. Cursor exposes no safe API for detecting an actual higher-priority Enterprise, Team, or Project conflict, so DefenseClaw reports that limitation and does not infer a conflict. The broader constraint is that these connectors cannot block a request the agent has not yet presented to their hook or policy surface.
"I want HITL approvals to surface inside the agent UI"
Pick a row with Native ask: Yes: Claude Code (PreToolUse), GitHub Copilot
CLI (preToolUse), Antigravity (PreToolUse only), Amp (tool.call and
model-bound tool.result in the active foreground thread), OmniGent
(UserPromptSubmit, PreToolUse and BeforeModel, which OmniGent calls its
request, tool_call and llm_request policy phases), or OpenClaw.
Cursor is not counted because DefenseClaw does not enable its native ask response;
confirm verdicts remain attributed alerts and cannot resume the original call.
Confirm verdicts on every other connector/event take an immediate
connector-specific fallback; there is no TUI approval queue.
"I want to run the agent in an OpenShell sandbox"
defenseclaw sandbox run <harness> runs a coding agent in an NVIDIA OpenShell
sandbox that sees only your project folder, on Linux, or on an Apple-silicon
Mac in an OpenShell MicroVM that works on a copy of it
(how). The
sandbox guide covers setup and every sandbox command.
DefenseClaw builds sandbox images for twelve harnesses; every other connector is
pending in the matrix above.
| Connector | Image pin | Tamper tier | Hook config in the image | Verification |
|---|---|---|---|---|
| Claude Code claudecode | 2.1.156 | managed | /etc/claude-code/managed-settings.d/50-defenseclaw.json | Verified end to end |
| Codex codex | 0.146.0 | managed | /etc/codex/requirements.toml | Verified end to end |
| Cursor cursor | 2026.07.23-e383d2b | managed | /etc/cursor/hooks.json | Unverified: cannot run yet. The Cursor Agent CLI needs a Cursor account (CURSOR_API_KEY or cursor-agent login) before any agent turn. Not tested live: defenseclaw-cursor, in-sandbox login |
| Hermes hermes | 0.19.0 | user | /etc/hermes/config.yaml | Verified end to end Not tested live: defenseclaw-openai, defenseclaw-anthropic |
| OpenCode opencode | 1.18.31 | user | /etc/opencode/opencode.json | Verified end to end |
| Amp amp | 0.0.1785334225-g9abe75 | user | /sandbox/.config/amp/plugins/defenseclaw.ts | Unverified: cannot run yet. Amp needs an Amp account API key (AMP_API_KEY) for every run. Not tested live: defenseclaw-amp |
| OmniGent omnigent | 0.13.0 | managed | /etc/omnigent/config.yaml | Verified end to end Not tested live: defenseclaw-openai, defenseclaw-anthropic |
| GitHub Copilot CLI copilot | 1.0.88 | managed | /etc/github-copilot/policy.d/50-defenseclaw.json | Verified end to end Not tested live: defenseclaw-copilot-github |
| OpenHands openhands | 1.16.0 | user | /sandbox/.openhands/hooks.json | Verified end to end Not tested live: defenseclaw-openai, defenseclaw-anthropic |
| Antigravity antigravity | 1.2.12 | user | /sandbox/.gemini/config/hooks.json | Verified end to end Not tested live: defenseclaw-gemini |
| Devin devin | 3000.4.25 | user | /sandbox/.config/devin/config.json | Unverified: cannot run yet. The Devin CLI needs a Devin account login (devin auth login, a browser or pasted-token flow) before any agent turn. Not tested live: in-sandbox login |
| Kiro kiro | 2.24.1 | user | /usr/local/lib/defenseclaw/kiro/defenseclaw.json | Verified end to end Not tested live: defenseclaw-kiro, in-sandbox login |
- Tamper tier. In the managed tier the hooks are in a root-owned system or
managed policy file that user and project settings cannot switch off. In the
user tier the agent can edit its own hook file, or code the agent or a
repository adds runs beside the hooks (Hermes, for example, loads
.envfiles and plugins from its home, which its launcher checks before every start). DefenseClaw reports a sandbox whose hooks go silent while the harness is active, and OpenShell's network policy holds either way.defenseclaw sandbox status <name>shows the tier. - Verification. Before DefenseClaw starts a sandbox from an image, the image must pass a hook check against a built-in mock model (for Kiro CLI, Kiro's own scripted-response mode): the hooks fire, a blocked tool call has no effect, and an allowed one runs. Verified end to end also means the harness ran in a live OpenShell sandbox with the DefenseClaw daemon, where a blocked command stayed blocked and the egress block list held.
- Unverified. These harnesses send every request, the account check
included, to their vendor's service and need an account before the first
turn, so no mock model can drive them. Their images build but never pass the
hook check:
sandbox runbuilds the image (several GB), then refuses it until a check with a vendor account passes, and the unverified image stays until you remove it (see the connector page). - Not tested live. A sign-in path whose endpoints or login no live run
exercised, because no account was available. The connector page says which
sign-ins
defenseclaw sandbox runshares. - Setup defaults. The
openshell.harnessessetting (Claude Code and Codex when empty) decides which imagesdefenseclaw sandbox setupand a baredefenseclaw sandbox image buildbuild and which onesdefenseclaw sandbox doctorchecks.sandbox setupwrites that list: its--harness(repeatable) replaces it, so name every harness you want.sandbox image build <harness>...builds the harnesses you name without changing it, andsandbox runbuilds a missing image on the first run. The macOS app's setup wizard lists only Claude Code and Codex, and a wizard run replacesopenshell.harnesseswith the ones you tick.
Every sandbox hook fails closed.
"I want fail-closed on transport failures"
Fail-closed here means the hook blocks when it cannot reach the gateway (a transport failure). It does not cover a hook process that the user kills, stops or starves: the agent then decides, and Claude Code, Codex, OpenHands and Devin treat a hook that dies or times out as non-blocking and run the call (see the enterprise threat model).
Pick a row with Fail-closed: Yes: OpenClaw, ZeptoClaw, Claude Code, Codex, Cursor, Devin, OpenCode, Amp, OpenHands, Kiro, and OmniGent. GitHub Copilot CLI, Hermes, and Antigravity do not expose a generic DefenseClaw-controlled fail-closed transport response. Cursor's support is mode-matched: action writes failClosed: true, while observe writes failClosed: false. Devin can map DefenseClaw availability failures to vendor exit 2 only on its four declared block-capable events.
Connectors
Every DefenseClaw connector shares one adapter interface, and each one exposes only the hook, plugin, policy, ACP, telemetry and approval capabilities its agent offers.
Connector compatibility
Versioned hook contracts, setup-time compatibility checks, and the runtime hook contract lock for DefenseClaw connectors.