Coverage contract
HOL Guard harness coverage
Every row is derived from the current commit-pinned support manifest. “Supported” is not shorthand for every action in a harness; event surfaces, fail behavior, limitations, release channel, verification date, expiry, and evidence remain visible together.
| Channel/version | Harness | State | Event surfaces | Approval/fallback/resume | Fail behavior | Limitations | Verified / expires |
|---|---|---|---|---|---|---|---|
stable commit evidence3.0.1 | Codex | supported commit evidence | shell, prompt, mcp_tool, file_read, tool_result commit evidence | native approval: yes commit evidencebrowser fallback: yes resume: yes | surface specific commit evidence | Inline file edits applied directly by the model without a tool call are not visible to Guard. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
stable commit evidence3.0.1 | Claude Code | supported commit evidence | shell, prompt, mcp_tool, file_read, tool_result commit evidence | native approval: yes commit evidencebrowser fallback: yes resume: yes | surface specific commit evidence | Background agent sessions that run without an active terminal do not surface hook events to Guard. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
stable commit evidence3.0.1 | OpenCode | supported commit evidence | shell, mcp_tool commit evidence | native approval: no commit evidencebrowser fallback: yes resume: no | surface specific commit evidence | Prompt content is not currently surfaced through hooks. File read/write events bypass Guard unless OpenCode permission rules block them. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
stable commit evidence3.0.1 | GitHub Copilot CLI | partial commit evidence | shell, prompt commit evidence | native approval: yes commit evidencebrowser fallback: yes resume: yes | surface specific commit evidence | MCP tool calls routed through the VS Code extension are not visible to the CLI-level Guard hook. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
stable commit evidence3.0.1 | Cursor | supported commit evidence | shell, mcp_tool, file_read commit evidence | native approval: no commit evidencebrowser fallback: yes resume: no | surface specific commit evidence | Shell commands issued through Cursor's built-in terminal bypass Guard unless the terminal runs inside an agent session. Prompt submission is not surfaced through native Cursor hooks. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
stable commit evidence3.0.1 | Cline | supported commit evidence | shell, prompt, mcp_tool, file_read, file_write, tool_result, network_request commit evidence | native approval: no commit evidencebrowser fallback: yes resume: no | surface specific commit evidence | Native Cline PostToolUse hooks are observation-only; full output mediation requires the Guard-managed Cline plugin transport. JetBrains protection is reported as unverified until a live pre-tool deny proof is observed. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
stable commit evidence3.0.1 | Gemini CLI | partial commit evidence | shell, mcp_tool commit evidence | native approval: no commit evidencebrowser fallback: yes resume: no | surface specific commit evidence | Prompt submission events and file read/write operations are not currently observable through the Gemini hook surface. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
stable commit evidence3.0.1 | Hermes | partial commit evidence | shell, mcp_tool, prompt commit evidence | native approval: no commit evidencebrowser fallback: yes resume: no | surface specific commit evidence | Hermes desktop and ACP entry paths may not register shell hooks; CLI and gateway honor hooks.pre_tool_call. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
stable commit evidence3.0.1 | OpenClaw | partial commit evidence | mcp_tool commit evidence | native approval: no commit evidencebrowser fallback: yes resume: no | surface specific commit evidence | Shell commands and prompt events are not currently observable. Guard only intercepts MCP tool calls via the proxy layer. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
stable commit evidence3.0.1 | Antigravity | partial commit evidence | mcp_tool, prompt commit evidence | native approval: no commit evidencebrowser fallback: yes resume: no | surface specific commit evidence | Shell commands are not currently observable through the Antigravity hook surface; Guard intercepts extensions and MCP registrations via scan at launch time. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
stable commit evidence3.0.1 | Kimi Code | supported commit evidence | shell, prompt commit evidence | native approval: no commit evidencebrowser fallback: yes resume: no | fail open commit evidence | Tool output post-processing and inline edits applied without a tool call are not visible to Guard. Hooks run in parallel, so separate requests may be reviewed concurrently. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
stable commit evidence3.0.1 | Grok Build | supported commit evidence | shell, prompt, mcp_tool, file_read, file_write commit evidence | native approval: no commit evidencebrowser fallback: yes resume: yes | fail open commit evidence | Grok UserPromptSubmit hooks are observe-only, so prompt screening cannot block the model from seeing the prompt. Enforcement is the catch-all PreToolUse hook, including subagent and MCP tools. --always-approve and bypassPermissions weaken Grok's own prompt policy, but the Guard hook still returns a native deny when policy blocks a tool call. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
stable commit evidence3.0.1 | Pi | supported commit evidence | shell, prompt, mcp_tool, file_read, tool_result commit evidence | native approval: yes commit evidencebrowser fallback: yes resume: yes | surface specific commit evidence | Package install and update flows happen outside the runtime extension bridge; Guard observes the configured package surfaces plus the prompt and tool events forwarded by the managed extension. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
stable commit evidence3.0.1 | Oh My Pi | supported commit evidence | shell, prompt, mcp_tool, file_read, tool_result commit evidence | native approval: yes commit evidencebrowser fallback: yes resume: yes | surface specific commit evidence | Package install and update flows happen outside the runtime extension bridge; Guard observes the configured package surfaces plus the prompt and tool events forwarded by the managed extension. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
stable commit evidence3.0.1 | ZCode | supported commit evidence | shell, prompt, mcp_tool, file_read commit evidence | native approval: no commit evidencebrowser fallback: yes resume: no | fail open commit evidence | Inline edits applied directly by the model without a tool call are not visible to Guard. Background sessions that run without an active terminal do not surface hook events. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
alpha commit evidence3.0.1 | Codex | supported commit evidence | shell, prompt, mcp_tool, file_read, tool_result commit evidence | native approval: yes commit evidencebrowser fallback: yes resume: yes | surface specific commit evidence | Inline file edits applied directly by the model without a tool call are not visible to Guard. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
alpha commit evidence3.0.1 | Claude Code | supported commit evidence | shell, prompt, mcp_tool, file_read, tool_result commit evidence | native approval: yes commit evidencebrowser fallback: yes resume: yes | surface specific commit evidence | Background agent sessions that run without an active terminal do not surface hook events to Guard. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
alpha commit evidence3.0.1 | OpenCode | supported commit evidence | shell, mcp_tool commit evidence | native approval: no commit evidencebrowser fallback: yes resume: no | surface specific commit evidence | Prompt content is not currently surfaced through hooks. File read/write events bypass Guard unless OpenCode permission rules block them. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
alpha commit evidence3.0.1 | GitHub Copilot CLI | partial commit evidence | shell, prompt commit evidence | native approval: yes commit evidencebrowser fallback: yes resume: yes | surface specific commit evidence | MCP tool calls routed through the VS Code extension are not visible to the CLI-level Guard hook. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
alpha commit evidence3.0.1 | Cursor | supported commit evidence | shell, mcp_tool, file_read commit evidence | native approval: no commit evidencebrowser fallback: yes resume: no | surface specific commit evidence | Shell commands issued through Cursor's built-in terminal bypass Guard unless the terminal runs inside an agent session. Prompt submission is not surfaced through native Cursor hooks. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
alpha commit evidence3.0.1 | Cline | supported commit evidence | shell, prompt, mcp_tool, file_read, file_write, tool_result, network_request commit evidence | native approval: no commit evidencebrowser fallback: yes resume: no | surface specific commit evidence | Native Cline PostToolUse hooks are observation-only; full output mediation requires the Guard-managed Cline plugin transport. JetBrains protection is reported as unverified until a live pre-tool deny proof is observed. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
alpha commit evidence3.0.1 | Gemini CLI | partial commit evidence | shell, mcp_tool commit evidence | native approval: no commit evidencebrowser fallback: yes resume: no | surface specific commit evidence | Prompt submission events and file read/write operations are not currently observable through the Gemini hook surface. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
alpha commit evidence3.0.1 | Hermes | partial commit evidence | shell, mcp_tool, prompt commit evidence | native approval: no commit evidencebrowser fallback: yes resume: no | surface specific commit evidence | Hermes is an early-access harness; some event surface coverage depends on the Hermes version installed. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
alpha commit evidence3.0.1 | OpenClaw | partial commit evidence | mcp_tool commit evidence | native approval: no commit evidencebrowser fallback: yes resume: no | surface specific commit evidence | Shell commands and prompt events are not currently observable. Guard only intercepts MCP tool calls via the proxy layer. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
alpha commit evidence3.0.1 | Antigravity | partial commit evidence | mcp_tool, prompt commit evidence | native approval: no commit evidencebrowser fallback: yes resume: no | surface specific commit evidence | Shell commands are not currently observable through the Antigravity hook surface; Guard intercepts extensions and MCP registrations via scan at launch time. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
alpha commit evidence3.0.1 | Kimi Code | supported commit evidence | shell, prompt commit evidence | native approval: no commit evidencebrowser fallback: yes resume: no | fail open commit evidence | Tool output post-processing and inline edits applied without a tool call are not visible to Guard. Hooks run in parallel, so separate requests may be reviewed concurrently. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
alpha commit evidence3.0.1 | Grok Build | supported commit evidence | shell, prompt, mcp_tool, file_read, file_write commit evidence | native approval: no commit evidencebrowser fallback: yes resume: yes | fail open commit evidence | Grok UserPromptSubmit hooks are observe-only, so prompt screening cannot block the model from seeing the prompt. Enforcement is the catch-all PreToolUse hook, including subagent and MCP tools. --always-approve and bypassPermissions weaken Grok's own prompt policy, but the Guard hook still returns a native deny when policy blocks a tool call. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
alpha commit evidence3.0.1 | Pi | supported commit evidence | shell, prompt, mcp_tool, file_read, tool_result commit evidence | native approval: yes commit evidencebrowser fallback: yes resume: yes | surface specific commit evidence | Package install and update flows happen outside the runtime extension bridge; Guard observes the configured package surfaces plus the prompt and tool events forwarded by the managed extension. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
alpha commit evidence3.0.1 | Oh My Pi | supported commit evidence | shell, prompt, mcp_tool, file_read, tool_result commit evidence | native approval: yes commit evidencebrowser fallback: yes resume: yes | surface specific commit evidence | Package install and update flows happen outside the runtime extension bridge; Guard observes the configured package surfaces plus the prompt and tool events forwarded by the managed extension. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
alpha commit evidence3.0.1 | ZCode | supported commit evidence | shell, prompt, mcp_tool, file_read commit evidence | native approval: no commit evidencebrowser fallback: yes resume: no | fail open commit evidence | Inline edits applied directly by the model without a tool call are not visible to Guard. Background sessions that run without an active terminal do not surface hook events. commit evidence | 2026-09-09 commit evidenceexpires 2026-10-09 |
Coverage change history
2026-09-09
stable 3.0.1 support contract reviewed
15 harness assertions reviewed from main@829b607556c9e96094f5029849048c4fd658c56c; expires 2026-10-09.
source commit2026-09-09
alpha 3.0.1 support contract reviewed
15 harness assertions reviewed from release/3.0@e1211e9a3651807a98812b70084b4c7e7ee53845; expires 2026-10-09.
source commit2026-09-09
Windsurf → Devin claim review
historical-name/product migration supplied by HOL product owner. Guard support status: unverified. No Devin harness contract exists in current stable or release/3.0 source. Public Guard surfaces must not claim Windsurf or Devin support until a Devin adapter and proof are added.