Runtime governor for AI coding agents

AI agents repeat work that changed nothing.MARGINAL catches it.

MARGINAL watches tool actions, outcomes and workspace evidence. When the same successful action repeats with no observable progress, it can identify the loop — without assuming every retry is waste.

Observe first. Prove waste. Earn enforcement.

  • Open source
  • Local first
  • Provider neutral
  • Zero mandatory runtime dependencies
agent trace / workspace
01
Read config.pynew evidence acquired
RUN
02
Read config.pyverification; outcome successful
RUN
03
Read config.pysame workspace state · no new evidence
OBSERVE
04
Read config.pyexact eligible no-progress repetition
STOP*
*Only after local Earned Enforcement. Otherwise MARGINAL stays advisory.Fails open on ambiguity.

10-second mechanism demo

Activity is not the same thing as progress.

Same action. Same state. No new evidence. That is the signal MARGINAL cares about. This deterministic visual is a mechanism demonstration, not a production benchmark.

Without a governorLOOP
01Read config.pyRUN
02Read config.pyRUN
03Read config.pyRUN
04Read config.pyRUN
05Read config.pyRUN
With MARGINALEVIDENCE
01Read config.pyNEW EVIDENCE
02Read config.pyVERIFY
03Read config.pySAME STATE
04Read config.pySTOP CANDIDATE
05Earned authority?BLOCK / ALLOW
Open shareable demo ↗No API credits required. No provider telemetry claimed.

How it works

A governor that has to earn the right to govern.

Installation does not equal authority. MARGINAL separates observation, proof and enforcement so an efficiency tool cannot casually become a correctness risk.

01 / OBSERVE

Watch

Collect derived action, outcome, coverage, workspace-state and evidence signals locally.

02 / PROVE

Compare

Look for repeated successful actions where observable state and useful evidence did not change.

03 / EARN

Build trust

Require representative local evidence, clean coverage and explicit promotion before blocking.

04 / INTERVENE

Stop narrowly

Only eligible action families can be denied, and only under the exact proven no-progress condition.

05 / RECOVER

Fail open

Unknown outcomes, drift, integrity failures or changed evidence remove pressure and restore allowance.

Works alongside coding agents

One governance core. Conservative engine boundaries.

MARGINAL is not another coding agent. It sits beside supported runtimes and turns native lifecycle signals into the same provider-neutral evidence model.

Observe-only

Claude Code

Native hooks record engine-declared success and failure without changing the next model action.

Observe-only

OpenCode

In-process JavaScript plugin with a persistent stdio bridge to the provider-neutral runtime.

Observe-only

PrivacyCode

OpenCode-compatible target with its own engine identity, ledger root and trust evidence.

Designed to be falsifiable

MARGINAL has to justify its own overhead, too.

The project treats governance cost, harmful interventions and preserved quality as first-class measurements — not footnotes.

01

Shadow first

New installations observe before blocking. Lack of evidence is not permission.

02

Decision ledger

Canonical records are hash chained so decisions can be reproduced and integrity drift detected.

03

Local-first privacy

Raw prompts, source, commands, outputs, transcripts and credentials are not evidence fields.

04

Fail open

Ambiguous or unsupported outcomes do not become evidence for blocking.

05

Explicit boundaries

Tool Enforcement is not presented as Full Compute Enforcement. Capabilities stay adapter-specific.

06

Graceful irrelevance

If a future agent is already efficient, MARGINAL should measure that and get out of the way.

Public evidence, without marketing math

The first smoke validated the integration — not the savings claim.

We keep negative and inconclusive results public because MARGINAL's credibility depends on separating observation from causation.

Exploratory SWE-bench Lite smoke

Exploratory 3-task smoke, one paired run per task. Both lanes resolved 0/3. No deny was applied in these three agent trajectories. A 24.93% token difference was observed, so the difference is not attributed to MARGINAL and is not a support claim.

The full report, raw JSON, protocol and evidence bundle remain public in the repository.

Resolved0/3 → 0/3
Effective tokens24.93% fewer
Tool calls3.03% fewer
Governance latency7.06 s
Applied denies0
Evaluatorpass_through

Install

Start in Shadow Mode.

The Codex marketplace install is one command. Enforcement still has to be earned locally.

codex plugin marketplace add SignalLayerLabs/Marginal --ref main && codex plugin add marginal@marginal

Remove cleanly with codex plugin remove marginal@marginal.

Research & Engineering

Ideas that have to survive contact with evidence.

Long-form technical notes on no-progress detection, runtime governance, privacy boundaries and the cases that could prove MARGINAL wrong.

Technical guides

Search the problem. Inspect the mechanism.

Evidence-first guides for developers dealing with repeated reads, tool calls and no-progress loops in coding agents.

01

No-progress loops

Detect successful activity that repeats without observable progress.

03

Codex

Shadow-first native plugin with narrow evidence-earned Tool Enforcement.

04

Claude Code

Observe-only hooks with engine-declared outcomes and no blocking.

FAQ

Fast answers before you clone.

What does MARGINAL actually stop?

Today, Codex Tool Enforcement is deliberately narrow. Exact eligible workspace-local reads can become denyable after verified repeated success with no state or evidence change. Generic shell, tests, search, writes, network and unknown MCP paths remain observe/recommend only.

Is MARGINAL a security product?

No. It is an efficiency governor, not a security boundary against software running as the same OS user.

Does it work with Claude Code?

Yes in Observe-only mode. Claude Code hooks can record engine-declared success/failure and feed the same evidence model, but the integration does not block actions today.

Why not just cap tokens?

A fixed cap cannot distinguish useful verification from repeated no-progress work. MARGINAL focuses on the marginal value of the next action and on observable evidence, not only the size of a budget.

Open source · Apache-2.0

If your coding agent loops, make the loop prove it is useful.

Clone it, inspect the hooks, run Shadow Mode, challenge the evidence model — and star the repo if you want this idea to keep moving.