Start here MVP2 / foundation

Meet TraceRook

An independent review layer for supported local coding-agent actions.

Development previewMVP2 foundation complete. Live hooks, enforcement, and Anthropic BYOK are pending. Planned behavior is labeled separately from working features.

A second look before execution

Coding agents can edit files, execute commands, contact services, and read instructions from sources you did not author. TraceRook is designed to add an independent review layer that relates a proposed action to the task you actually asked the agent to perform.

The MVP2 architecture extends the native preview and combines deterministic local policy with Anthropic Claude for contextual analysis. It focuses on supported local Claude Code and Codex sessions on one Mac. A native menu bar companion keeps status visible; a SwiftUI dashboard explains findings and presents one-time reviews.

What you can try today

The current development milestone includes the native interface, deterministic Cloud Demo fixtures, sample incident evidence, and a sample approval experience. MVP2.0 adds strict IPC v2 contracts, exact invocation bindings, and helper codec self-tests while preserving v1 compatibility. The local suite has 43 passing tests.

Live hook ingestion, the background service transport, safe hook installation, actual enforcement, SQLite persistence, and direct Anthropic BYOK are pending. The app does not claim verified real protection. A polished sample screen is a demonstration of the interaction, not proof of interception.

Start with the native preview, then read the implementation status.

The intended decision model

RiskMVP1 responseAuthority
CriticalImmediate denial with concrete local evidenceEnabled catastrophic deterministic rule
HighPause for human review; expiry deniesLocal evidence or contextual recommendation
MediumAllow with warning and findingDeduplicated advisory decision
LowAllow with minimal event recordNo TraceRook override of host permissions

Claude can recommend review and identify drift. It cannot grant permissions or erase a deterministic critical denial. TraceRook Allow Once only releases its own gate; the coding agent’s native permissions still apply.

Know the boundary

TraceRook is a hook-based guardrail. It is not a system-wide sandbox or an endpoint detection platform. A hook that never runs cannot enforce a denial. An intercepted shell call can start nested processes that TraceRook does not separately mediate.

Remote sessions, hosted tool paths without local callbacks, arbitrary commands outside an integrated agent, and tampering by another process with the same user privileges are outside the complete guarantee. See coverage and failure behavior.

Platform and product scope

  • Apple Silicon Mac with macOS 26 or later.
  • Swift 6, SwiftUI, and the macOS 27 SDK for development.
  • Individual developer, local hook-capable Claude Code and Codex sessions.
  • Developer ID signed and notarized distribution is a release gate; the current source build is a development preview.

OpenCode, enterprise management, a real TraceRook Cloud backend, billing, and vulnerability scanning are deferred beyond MVP1.

Based on the MVP1 specification, the additive MVP2 specification, and the acceptance matrix · October 8, 2026.