Runtime governor for AI coding agents
AI agents repeat work that changed nothing.MARGINAL catches it.
MARGINAL watches tool actions, outcomes and workspace evidence. When the same successful action repeats with no observable progress, it can identify the loop — without assuming every retry is waste.
Observe first. Prove waste. Earn enforcement.
- Open source
- Local first
- Provider neutral
- Zero mandatory runtime dependencies
10-second mechanism demo
Activity is not the same thing as progress.
Same action. Same state. No new evidence. That is the signal MARGINAL cares about. This deterministic visual is a mechanism demonstration, not a production benchmark.
How it works
A governor that has to earn the right to govern.
Installation does not equal authority. MARGINAL separates observation, proof and enforcement so an efficiency tool cannot casually become a correctness risk.
Watch
Collect derived action, outcome, coverage, workspace-state and evidence signals locally.
Compare
Look for repeated successful actions where observable state and useful evidence did not change.
Build trust
Require representative local evidence, clean coverage and explicit promotion before blocking.
Stop narrowly
Only eligible action families can be denied, and only under the exact proven no-progress condition.
Fail open
Unknown outcomes, drift, integrity failures or changed evidence remove pressure and restore allowance.
Works alongside coding agents
One governance core. Conservative engine boundaries.
MARGINAL is not another coding agent. It sits beside supported runtimes and turns native lifecycle signals into the same provider-neutral evidence model.
Codex
Native plugin. Shadow Mode by default; repository-local Earned Enforcement is intentionally narrow.
Claude Code
Native hooks record engine-declared success and failure without changing the next model action.
OpenCode
In-process JavaScript plugin with a persistent stdio bridge to the provider-neutral runtime.
PrivacyCode
OpenCode-compatible target with its own engine identity, ledger root and trust evidence.
Designed to be falsifiable
MARGINAL has to justify its own overhead, too.
The project treats governance cost, harmful interventions and preserved quality as first-class measurements — not footnotes.
Shadow first
New installations observe before blocking. Lack of evidence is not permission.
Decision ledger
Canonical records are hash chained so decisions can be reproduced and integrity drift detected.
Local-first privacy
Raw prompts, source, commands, outputs, transcripts and credentials are not evidence fields.
Fail open
Ambiguous or unsupported outcomes do not become evidence for blocking.
Explicit boundaries
Tool Enforcement is not presented as Full Compute Enforcement. Capabilities stay adapter-specific.
Graceful irrelevance
If a future agent is already efficient, MARGINAL should measure that and get out of the way.
Public evidence, without marketing math
The first smoke validated the integration — not the savings claim.
We keep negative and inconclusive results public because MARGINAL's credibility depends on separating observation from causation.
Exploratory SWE-bench Lite smoke
Exploratory 3-task smoke, one paired run per task. Both lanes resolved 0/3. No deny was applied in these three agent trajectories. A 24.93% token difference was observed, so the difference is not attributed to MARGINAL and is not a support claim.
The full report, raw JSON, protocol and evidence bundle remain public in the repository.
Install
Start in Shadow Mode.
The Codex marketplace install is one command. Enforcement still has to be earned locally.
codex plugin marketplace add SignalLayerLabs/Marginal --ref main && codex plugin add marginal@marginalRemove cleanly with codex plugin remove marginal@marginal.
Research & Engineering
Ideas that have to survive contact with evidence.
Long-form technical notes on no-progress detection, runtime governance, privacy boundaries and the cases that could prove MARGINAL wrong.
Detecting no-progress without reading prompts
Use action identity, outcomes, observable state and evidence without turning every repeated call into waste.
Why an AI agent governor should start powerless
Installation is not evidence. Observe first, earn narrow authority, and demote when assumptions drift.
Technical guides
Search the problem. Inspect the mechanism.
Evidence-first guides for developers dealing with repeated reads, tool calls and no-progress loops in coding agents.
No-progress loops
Detect successful activity that repeats without observable progress.
Repeated tool calls
Separate useful verification from same-state repetition.
Codex
Shadow-first native plugin with narrow evidence-earned Tool Enforcement.
Claude Code
Observe-only hooks with engine-declared outcomes and no blocking.
FAQ
Fast answers before you clone.
What does MARGINAL actually stop?
Today, Codex Tool Enforcement is deliberately narrow. Exact eligible workspace-local reads can become denyable after verified repeated success with no state or evidence change. Generic shell, tests, search, writes, network and unknown MCP paths remain observe/recommend only.
Is MARGINAL a security product?
No. It is an efficiency governor, not a security boundary against software running as the same OS user.
Does it work with Claude Code?
Yes in Observe-only mode. Claude Code hooks can record engine-declared success/failure and feed the same evidence model, but the integration does not block actions today.
Why not just cap tokens?
A fixed cap cannot distinguish useful verification from repeated no-progress work. MARGINAL focuses on the marginal value of the next action and on observable evidence, not only the size of a budget.
Open source · Apache-2.0
If your coding agent loops, make the loop prove it is useful.
Clone it, inspect the hooks, run Shadow Mode, challenge the evidence model — and star the repo if you want this idea to keep moving.