• The current release is unsigned and unnotarized; qualification is limited to the documented macOS Apple Silicon release path.
  • Only macOS on Apple Silicon is supported. The minimum accepted versions are Codex CLI 0.147.0 and Claude Code CLI 2.1.223; independent current-release qualification is limited to Codex 0.154.0 and Claude Code 2.1.272.
  • The unreleased v0.4 whole-plugin selector is qualified only for Claude Code 2.1.273 on macOS Apple Silicon and admits exactly one already-installed provider-native plugin per launch. Other provider tuples fail closed for this activation path. The published v0.3.1 release remains qualified against Claude Code 2.1.272 for its documented clean-launch path.
  • The initial v0.4 whole-plugin qualification accepts only bundles whose observed effective surface is skill-only. Bundles exposing hooks, MCP servers, agents, LSP servers, background monitors, plugin executables, or plugin settings fail closed. This avoids reopening ambient ~/.claude state that those components may depend on.
  • Component-level filtering, Codex plugin activation, standalone MCP resource selection, presets, and --with=all are not qualified by this slice.
  • The protection is a narrow macOS filesystem denylist, not a VM, container, network sandbox or complete home-directory isolation.
  • A provider may visibly warn that reading a blocked global instruction is not permitted. This is expected and does not mean the provider itself failed.
  • User arguments are intentionally last. Explicit overrides can re-enable apps, hooks or plugins and therefore reduce the clean defaults.
  • The project directory and other host paths remain available unless macOS or the selected provider applies an additional restriction.
  • Ordinary project, user, or other ambient MCP configurations are not loaded by default in the current Claude launch. CLROOM passes --strict-mcp-config and does not synthesize an --mcp-config; MCP servers are considered only when you explicitly supply Claude’s own --mcp-config argument for that launch.
  • CLROOM controls each top-level launch. Provider-owned Claude Code teammates and subagents follow Claude’s own inheritance and scoping rules.
  • Claude Code -p reached the provider and exited successfully in the current release qualification canary, but response-output semantics are not independently qualified by this release.
  • The launcher depends on the undocumented longevity of macOS sandbox-exec; it fails closed if the protection cannot be created.
  • No bounty program exists.
  • Claude cleanup preserves live, unknown, corrupt, and legacy projection state; only a recognized session whose recorded owner is proven dead is reaped.
  • Linux and Windows are NOT_QUALIFIED. Intel macOS, Homebrew, crates.io, signing and notarization are not claimed.