
Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
![]() | Stop risky AI actions before they compromise your machine. HOL Guard is a local-first security layer for AI agents, tools, plugins, skills, MCP servers, and package installs. Install HOL Guard Read the documentation PyPI Package ( hol-guard)Report an Issue |
|---|
HOL Guard reviews agent actions before they run: shell commands, file access, package installs, and MCP tool calls. It detects secret exposure, destructive operations, prompt injection, and supply-chain risks, then allows, blocks, or requests approval according to your policy.
Run it locally without an account. Use the CLI and local dashboard to manage protection, resolve approvals, and inspect decision history. Optional Guard Cloud adds shared history, team policy, and fleet management.
Get started · Supported agents · Plugin scanner · Documentation · Contribute an extension · Development
Requires Python 3.10 or newer and pipx.
pipx install hol-guard
hol-guard init
The first-run wizard discovers supported agents and walks you through protection setup. It asks before each setup change, including opening the dashboard, installing agent integrations, and connecting optional cloud services.
Check your installation:
hol-guard --version
hol-guard status
To update an existing installation:
hol-guard update
For manual setup, see the installation guide. Annotated release notes with upgrade context live at hol.org/guard/releases; raw releases and prereleases are on the GitHub releases page.
| Surface | Protection |
|---|---|
| Shell commands and file access | Reviews destructive operations, sensitive file access, credential exposure, and suspicious outbound commands. |
| Package installs | Evaluates supported package-manager operations against supply-chain intelligence before installation. |
| Plugins, skills, and agent configuration | Inventories local artifacts and reviews new or changed tools before launch. |
| MCP servers and tools | Inspects server configuration and reviews tool calls through supported hooks and managed proxies. |
| Prompts and tool results | Screens supported events for prompt injection and sensitive content. |
| Approvals and evidence | Routes decisions to native prompts or the approval center, and records local receipts for review. |
Guard connects through native agent hooks, managed MCP proxies, and launch integrations. Coverage depends on the events each agent exposes; the support matrix documents enforcement, approval delivery, and failure behavior per integration.
Codex, Claude Code, GitHub Copilot CLI, Cursor, Cline, Gemini CLI, Grok, Hermes, Kimi Code, Pi, oh-my-pi, OpenClaw, OpenCode, Antigravity, ZCode, and Devin. Paseo is supported through these native provider integrations, with per-provider coverage.
For example, to set up Codex explicitly:
hol-guard install codex
hol-guard run codex --dry-run
hol-guard run codex
The dry run records the current artifact state before launch. For Codex, Guard installs native pre-tool hooks and refuses a managed launch if those hooks are missing or disabled.
Agent support matrix · Troubleshooting
| Task | Command |
|---|---|
| Check protection status | hol-guard status |
| Diagnose an agent integration | hol-guard doctor codex |
| Inspect changes before launch | hol-guard diff codex |
| Review pending approvals | hol-guard approvals |
| Approve or deny a request | hol-guard approvals approve <request-id> / hol-guard approvals deny <request-id> |
| Read decision history | hol-guard receipts |
| List tracked artifacts | hol-guard inventory |
| Export an AI bill of materials | hol-guard abom --format json |
| Scan workspace dependencies | hol-guard supply-chain scan |
| Connect optional cloud sync | hol-guard connect |
Inspect the command's classification and matching rules:
hol-guard command test 'rm -rf ./build'
hol-guard command explain 'git clean -ndx'
hol-guard command extensions command.git --json
command test and command explain inspect the command without executing it or creating an approval. Use hol-guard approvals to resolve a pending request and hol-guard receipts to review the recorded decision.