Public-source research
Vendor evidence
Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.
Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6
Operant claims device-layer controls for Claude Code, Cursor, Copilot, Cline, Windsurf, Aider, and custom agents, covering shell commands, files, repositories, credentials, packages, plugins, skills, prompts, Model Context Protocol (MCP) tools, application programming interfaces (APIs), and proprietary code.
Real-time shell command monitoring distinguishes legitimate developer tooling from injection-driven attacks — and blocks before execution.
Related framework references (5)