| CodexmacOSLocal history + explicit-scan samplingAction Chain | Verified todayLocal config, automations, install and managed-policy surfaces. | Verified todayCodex automation history supplies source event and session evidence. | Available with limitsExplicit-scan process sampling only; no background lifecycle capture. | Available with limitsgit, gh, aws, kubectl, psql, docker and ssh classifiers during the sampling window. | Available with limitsConfigured MCP surfaces and supported history signals; not universal runtime invocation proof. | Available with limitsCredential references are available separately; per-action lineage is missing. | Available with limitsRepository/project context where the source exposes it; production classification is not universal. | Not in current pilotContracts and synthetic fixtures exist; production external-control adapters remain planned. |
|---|
| Claude CodemacOSLocal history + supported MCP history + explicit-scan samplingCausal fixture | Verified todayLocal config, managed settings and MCP definitions. | Verified todayLocal history supplies session records when readable. | Available with limitsExplicit-scan sampling; ancestry is limited to processes present in one sample. | Available with limitsSupported CLI classifiers during the sampling window only. | Available with limitsRuntime invocation metadata is available for supported Claude history sources. | Available with limitsCredential references can be discovered; session-to-credential lineage is incomplete. | Available with limitsProject and supported target metadata where exposed by the source. | Not in current pilotSource-attributed production adapters are not shipped. |
|---|
| CursormacOSLocal history + explicit-scan samplingCoverage notes | Verified todayRules, hooks, local settings, install and managed-policy surfaces. | Available with limitsComposer history supplies source-dependent session signals. | Available with limitsExplicit-scan sampling; detached or nested execution may be missed. | Available with limitsSupported CLI classifiers during the sampling window only. | Not in current pilotConfigured MCP commands are not runtime invocation proof. | Available with limitsCredential references are separate from the action chain. | Available with limitsProject context where present; production environment is not universally classified. | Not in current pilotSource-attributed production adapters are not shipped. |
|---|
| MCP serversmacOSConfiguration + supported vendor historySource matrix | Verified todayLocal MCP definitions, commands, endpoints and first-seen baselines. | Available with limitsAvailable only where a supported vendor history source exposes a session. | Not applicableMCP configuration is not process ancestry evidence. | Not applicableDirect CLI is evaluated through the process-observation path. | Available with limitsSupported runtime history only; otherwise configuration evidence. | Available with limitsEnvironment credential references are metadata-only; secret values are not collected. | Available with limitsConfigured network endpoints where present; runtime target can remain unknown. | Not in current pilotProduction MCP enforcement-source adapters are not shipped. |
|---|