Product questions
Is TraceRook ready to protect my real sessions?
The current build includes the native UI, Cloud Demo, and tested MVP2.0 IPC contracts. Live hooks, enforcement, Anthropic BYOK, and signed beta distribution are pending. Real activity remains Not integrated.
Why use Claude to review Claude Code or Codex?
The coding agent and security analysis are separate roles. TraceRook uses local rules first and is designed to use Anthropic Claude to assess task relevance and suspicious context. The model is advisory; human review and deterministic policy retain authority.
Does TraceRook replace native agent permissions?
No. Allow once only releases TraceRook’s gate for one pending action. Native host permissions remain independently applicable.
Is this a macOS-wide sandbox?
No. Local hooks can only mediate supported paths where the callback actually runs and the host honors its result. Nested processes, arbitrary manual commands, and hosted or remote paths have limitations.
Claude and privacy questions
Where will my API key go?
The planned BYOK flow stores it in macOS Keychain and sends requests directly to Anthropic. No TraceRook proxy or website key form exists. The current preview does not collect keys.
Will entire transcripts or source trees be uploaded?
The design uses a task anchor, a proposed action summary, selected sanitized events, and evidence. Additional code excerpts are off by default. The final privacy check must reject unsafe or uninspectable remote payloads.
Can Claude overrule a critical local rule?
No. Deterministic catastrophic evidence has precedence. A model-only critical verdict is capped at human review; it does not independently authorize execution or grant permission.
Does Cloud Demo call Claude?
No. Bundled fixtures provide the sample experience without analysis network requests. A real session must never be passed off as a cloud-analyzed fixture.
Operation questions
What happens if I miss a high-risk review?
In the intended live flow, the default 45-second deadline expires and denies the waiting high-risk call. Notification suppression does not extend the deadline. The sample flow demonstrates expiry, but real-host behavior remains a gate.
Can a lost hook fail closed?
Only a callback that runs and returns in time can deny. The bridge can apply local catastrophic fallback when a dependency is unavailable, but a skipped or timed-out hook cannot be forced to block by an app preference.
Why does Codex need a trust step?
Nonmanaged Codex hooks require review and trust of their definition. A configured hook may be skipped until trusted. TraceRook must guide the human review and verify actual execution.
What Mac does the preview require?
Apple Silicon, macOS 26 or later, Swift 6, and the macOS 27 SDK to build from source. Developer ID signing and notarization are required before the beta release.
Glossary
| Term | Meaning |
|---|---|
| BYOK | Bring your own Anthropic API key; direct provider analysis |
| Task anchor | Redacted concise statement of user intent, updated by explicit user instructions |
| Pre-tool | Host lifecycle callback before a supported tool executes |
| Post-tool | Observation after a tool has executed |
| Action fingerprint | Digest of canonical original action identity for exact pending-call binding |
| Deterministic critical | Concrete catastrophic local policy evidence; not a model severity label |
| Local rules only | No contextual remote analysis; deterministic policy remains available in a live build |
| Verified coverage | Evidence that a compatible trusted callback and blocking tool path work |
| Execution unknown | Available events do not establish whether the host executed the action |
| Cloud Demo | Bundled synthetic account, analysis, and activity fixtures |