$npx skillfedfor your agent

hol-guard

Open-source antivirus and runtime protection for AI agents, tools, MCP servers, plugins, skills, and package installs.

Worth itPyPI SecurityReleased Aug 2026252.0K downloads / moApache-2.0Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — hol_guard-2.2.87-py3-none-any.whl
v2.2.87 · released 2026-08-14 · Python >=3.10 · 10 runtime deps: cisco-ai-skill-scanner, cryptography, keyring, litellm, mcp, packaging, pyyaml, requests

Yes. HOL Guard addresses a real gap in AI agent security: most tools see only one part of the attack surface (code scanners, sandboxes, or MCP gateways alone), but agents interact with shells, files, packages, and credentials all at once. The package is actively maintained, has no known vulnerabilities, uses a permissive license, and installs with low friction. It works locally by default and scales to team workflows optionally. Install it if you run AI agents on your machine and want runtime visibility and control over their actions.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later.
  • Designed for pipx installation to isolate the tool environment; direct pip install is supported but pipx is recommended for CLI use.
  • Low friction: pure Python wheel with no compiled dependencies.

License · maintenance · safety

Apache-2.0 (permissive) — Apache-2.0 permissive license allows commercial and private use without restriction. You can integrate this into proprietary workflows or modify it for your needs.

last release 2026-08-14 (0 days) · last repo commit 2026-08-14 · 434 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 252,014 downloads/mo, #8,561 on PyPI

Verify before relying

pipx install hol-guard
hol-guard init

from hol_guard import Guard
# Guard integrates via hooks into supported agents; init discovers and configures them
  • Exact scope of 'supported' agent integrations and whether all listed agents (Codex, Claude Code, Cursor, Gemini CLI, etc.) have equal enforcement depth
  • Whether local-only mode (without Guard Cloud) provides full protection or if some threat detection requires cloud sync
  • Performance overhead of runtime evaluation on typical AI agent workloads
  • Whether approval workflows work with headless/non-interactive environments
Same gist for agents: .md · .json

What it is and what it does

HOL Guard is a runtime security layer that sits between AI agents and their local tools, evaluating actions in real time before they execute. It detects and blocks risky patterns: secrets leaking in file access or command output, prompt injection attempts, unsafe shell or Git commands, malicious package installs, and MCP server misconfigurations. The package works entirely locally without requiring a cloud account, though it can optionally sync to Guard Cloud for team policies and shared approval workflows.

The tool integrates with supported AI agents (Codex, Claude Code, GitHub Copilot CLI, Cursor, Gemini CLI, and others) through native hooks or reversible overlays, depending on what each agent exposes. When it encounters an ambiguous action, it routes it to a local approval center or native prompt rather than blocking blindly. All decisions are recorded as security receipts for later review. Setup is guided: `hol-guard init` discovers compatible agents on your machine, explains each change before applying it, and walks you through your first protected action.

Use it for

  • Prevent AI agents from accidentally exfiltrating secrets or credentials during code generation or tool use
  • Block malicious or suspicious package installs before they run, protecting your supply chain from compromised dependencies
  • Review and approve risky shell commands, Git operations, or file access before an agent executes them
  • Detect and stop prompt injection attempts that try to trick agents into exposing sensitive data or bypassing security controls
  • Maintain an audit trail of all agent actions and security decisions for compliance or forensic review

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

HOL Guard addresses a real gap in AI agent security: most tools see only one part of the attack surface (code scanners, sandboxes, or MCP gateways alone), but agents interact with shells, files, packages, and credentials all at once. The package is actively maintained, has no known vulnerabilities, uses a permissive license, and installs with low friction. It works locally by default and scales to team workflows optionally. Install it if you run AI agents on your machine and want runtime visibility and control over their actions.

Install

hol-guard on PyPI

Before you install

Low friction: pure Python wheel with no compiled dependencies. Active maintenance as of 2026-08-14 with recent release. Requires Python 3.10 or later. Ten runtime dependencies including cryptography, keyring, and litellm suggest mature integration with AI tooling and credential handling.

Requires Python 3.10 or later. Designed for pipx installation to isolate the tool environment; direct pip install is supported but pipx is recommended for CLI use.

License in practice

Apache-2.0 permissive license allows commercial and private use without restriction. You can integrate this into proprietary workflows or modify it for your needs.

Quickstart

pipx install hol-guard
hol-guard init

from hol_guard import Guard
# Guard integrates via hooks into supported agents; init discovers and configures them

Verify before relying

  • Exact scope of 'supported' agent integrations and whether all listed agents (Codex, Claude Code, Cursor, Gemini CLI, etc.) have equal enforcement depth
  • Whether local-only mode (without Guard Cloud) provides full protection or if some threat detection requires cloud sync
  • Performance overhead of runtime evaluation on typical AI agent workloads
  • Whether approval workflows work with headless/non-interactive environments

Package facts

LicenseApache-2.0 permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
10 packages
cisco-ai-skill-scannercryptographykeyringlitellmmcppackagingpyyamlrequestsrichtomli
MaintenanceActively maintained 0 days since the last release
Last repo commit
First released
Downloads252,014 / month, #8,561 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: SecurityTopic :: Software Development :: Quality Assurance

Evidence: hol_guard-2.2.87-py3-none-any.whl

Tags

Capabilities
ai agent security runtime protectionantivirus for ai agentsprompt injection detectionsecrets detection ai toolsmcp server securityai supply chain securityagent action approval workflow
Topics
ai-agent-securityruntime-protectionsupply-chain-security
PyPI keywords
ai agent securityai agentsai antivirusclaudeclicodexcursorgeminimcp securityopencodeplugin securityprompt injectionruntime securitysecrets detectionsupply chain security

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “ai agent security runtime protection”

  • hol-guardHOL Guard is a local-first antivirus and runtime protection layer for…
  • plugin-scannerLints, verifies, and gates plugins, skills, MCP servers, and packages…
  • apm-cliAPM is a dependency manager and configuration tool for AI agents that…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also plugin-scanner · llm-guard · omnigent · pydantic-ai-shields · ouroboros-ai · baml-py · echo-agent · apm-cli · agentrust-trace · deepagents

Further reading