A safety floor your AI agents can't get under: one policy for Claude Code, Codex, Gemini CLI, Cursor, Windsurf and MCP, judged by what each call will run, backstopped by the kernel, with a signed, tamper-evident ledger.
rust security mcp sandbox audit policy provenance audit-log ai-safety ai-agents rust-cli model-context-protocol agent-security claude-code-plugin gemini-cli-extension provio
-
Updated
Oct 6, 2026 - Rust