MCP
File scope is free. Folder and workspace scope require Iris Code Pro. Both native and SDK MCP servers enforce the current agent governance policy before planning or verification. Agent-supplied before-source content is refused.
CLI scanning
Finish verification
The hook verifies only a baseline ID already found in the current agent transcript and matched to a live MCP server for the same workspace. Source snapshots remain in server memory; the local registry contains connection metadata and IDs. Missing, null or compacted transcripts leave the hook inactive, with no guessed baseline or HEAD fallback.
Only
regressed requests a correction turn. not-improved is a warning, never a block. The shared counter permits at most maxCorrections blocks for a baseline, then asks the agent to stop and show the verdict and diff. Host loop signals provide a second backstop. Cursor warnings use stderr because its stop JSON has no advisory field. The hook does not call a model or change push/build enforcement.
Codex also needs hooks enabled in its local configuration and project-hook approval. Vendor transcript formats are best-effort interfaces; explicit verification remains available when automatic matching is inactive.