{"categories":[{"label":"Security","url":"https://skillfed.io/packages/category/security/2"},{"label":"Quality Assurance","url":"https://skillfed.io/packages/category/software-development-quality-assurance/3"}],"enrichment":{"capability":"HOL Guard is a local-first antivirus and runtime protection layer for AI agents that evaluates agent actions, tool calls, package installs, and MCP servers for secrets exposure, prompt injection, unsafe commands, and malicious packages before they execute.","skillfed_tags":["ai-agent-security","runtime-protection","supply-chain-security"],"use_cases":["Prevent AI agents from accidentally exfiltrating secrets or credentials during code generation or tool use","Block malicious or suspicious package installs before they run, protecting your supply chain from compromised dependencies","Review and approve risky shell commands, Git operations, or file access before an agent executes them","Detect and stop prompt injection attempts that try to trick agents into exposing sensitive data or bypassing security controls","Maintain an audit trail of all agent actions and security decisions for compliance or forensic review"],"what_it_does":"HOL Guard is a runtime security layer that sits between AI agents and their local tools, evaluating actions in real time before they execute. It detects and blocks risky patterns: secrets leaking in file access or command output, prompt injection attempts, unsafe shell or Git commands, malicious package installs, and MCP server misconfigurations. The package works entirely locally without requiring a cloud account, though it can optionally sync to Guard Cloud for team policies and shared approval workflows.\n\nThe tool integrates with supported AI agents (Codex, Claude Code, GitHub Copilot CLI, Cursor, Gemini CLI, and others) through native hooks or reversible overlays, depending on what each agent exposes. When it encounters an ambiguous action, it routes it to a local approval center or native prompt rather than blocking blindly. All decisions are recorded as security receipts for later review. Setup is guided: `hol-guard init` discovers compatible agents on your machine, explains each change before applying it, and walks you through your first protected action.","worth_installing":"Yes. HOL Guard addresses a real gap in AI agent security: most tools see only one part of the attack surface (code scanners, sandboxes, or MCP gateways alone), but agents interact with shells, files, packages, and credentials all at once. The package is actively maintained, has no known vulnerabilities, uses a permissive license, and installs with low friction. It works locally by default and scales to team workflows optionally. Install it if you run AI agents on your machine and want runtime visibility and control over their actions."},"id":"hol-guard","links":{"html":"https://skillfed.io/packages/hol-guard","md":"https://skillfed.io/packages/hol-guard.md","pypi":"https://pypi.org/project/hol-guard/"},"maintenance":{"status":"active"},"meta":{"latest_release":"2026-08-14","license_spdx":"Apache-2.0","license_treatment":"permissive","name":"hol-guard","python_support":"supports_current","summary":"Open-source antivirus and runtime protection for AI agents, tools, MCP servers, plugins, skills, and package installs."},"popularity":{"monthly_downloads":252014,"position":8561,"tier":"top_15000"},"security":{"n_vulnerabilities":0},"version":"2.2.87"}
