Coverage, without hand-waving

Know exactly where Leash can step in.

Installable protection means Leash has a supported hook, plugin, or adapter for that agent. It does not mean every possible action or unofficial extension is intercepted.

Installable action-time protection Detection only
Available now

Installable protection

The desktop setup can install a documented protection contract. Exact coverage still depends on agent version, enabled surfaces, and the action path.

Protectable

Claude Code

Hooks + automatic proxyClaude CLI and Claude Code for VS Code

Leash installs Claude-compatible command hooks and can automatically route supported provider traffic through the bundled local proxy.

Protectable

OpenAI Codex

Hooks + automatic proxyCodex CLI and Codex for VS Code

Leash installs Codex hooks and approval handoff, then configures its supported Responses API provider path through the local proxy.

Protectable

Cursor

Hooks + guided proxyCursor editor and CLI

Leash installs Cursor hooks. Full-conversation proxy setup is guided because Cursor keeps provider overrides in settings the user controls.

Protectable

Gemini CLI

HooksGemini CLI

Leash installs supported Gemini hook events for action-time evaluation. A persistent full-conversation proxy adapter is not claimed.

Protectable

GitHub Copilot

HooksCopilot CLI and VS Code

Leash installs user-level Copilot hooks for supported local events. Copilot provider routing is launch-environment scoped and is not persisted by Leash.

Protectable

OpenCode

Plugin + proxyOpenCode CLI and desktop

Leash installs its OpenCode plugin. Proxy setup is automatic for strict JSON and guided for JSONC so unrelated configuration is not rewritten.

Protectable

NanoClaw

Hooks + automatic proxyNanoClaw

Leash installs Claude-compatible hooks and can apply the supported Claude-compatible provider base URL.

Protectable

OpenClaw

Hook packOpenClaw

Leash installs its managed OpenClaw hook pack. Full provider proxying requires an OpenClaw runtime extension because resolved URLs live in memory.

Visible, not yet protectable

Detection-only agents

These agents may appear when Leash detects them locally, but the setup wizard keeps protection disabled until a native, testable action contract exists.

Follow or request coverage
ClineDetection only
ContinueDetection only
WindsurfDetection only
How to read this page

Supported integration is not universal interception.

Action-time enforcement applies only where the installed agent emits a supported event or uses a configured provider-traffic path. Agent updates, alternate binaries, cloud-only execution, custom extensions, or manual configuration changes can alter coverage. The Leash desktop reports installation and protection state so teams can verify what is active.

Read the Trust Center