Skip to content
Back to skills

Hol Guard

ASecurity

Run HOL Guard scanner and guard operations via `uv run hol-guard`. Use when the user asks to scan plugins/MCP/skills for security, quality, or ecosystem compliance, or when they ask to run guard detect/install/protect workflows for local AI harnesses.

  • 791 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added August 31, 2026
ai-agentspythongosecurity

Works with

  • cursor
  • cli
  • mcp

Security analysis

A100/100

Scanned August 31, 2026

npx -y skills add hashgraph-online/hol-guard --skill hol-guard --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Hol Guard?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Hol Guard
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hashgraph-online-hol-guard/badge)](https://www.skillsdirectory.com/skills/hashgraph-online-hol-guard)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: hol-guard
description: Run HOL Guard scanner and guard operations via `uv run hol-guard`. Use when the user asks to scan plugins/MCP/skills for security, quality, or ecosystem compliance, or when they ask to run guard detect/install/protect workflows for local AI harnesses.
---

# HOL Guard

HOL Guard is an AI Antivirus scanner that checks plugins, MCP servers, skills, and local AI harnesses for security, quality, and ecosystem compliance.

## Prerequisites

- Always run from the `hol-guard` project root.
- Use `uv run hol-guard` to invoke the CLI. Never invoke Python modules directly.
- Ensure `uv sync --frozen --extra dev` has been run before invoking.

## Scanner Operations

Scan a plugin or skill directory:

```
uv run hol-guard scan <directory> [--format json|text|markdown|sarif] [--profile default|public-marketplace|strict-security] [--fail-on-severity critical|high|medium|low|info|none]
```

Lint rules:

```
uv run hol-guard lint <directory> [--list-rules] [--explain <rule-id>]
```

Verify runtime:

```
uv run hol-guard verify <directory> [--online]
```

List ecosystems:

```
uv run hol-guard --list-ecosystems
```

## Guard Operations

Detect harnesses:

```
uv run hol-guard detect [codex|claude|cursor|gemini|opencode] [--json]
```

Run guard in dry-run mode:

```
uv run hol-guard run <harness> --dry-run --default-action allow --json
```

Check guard status:

```
uv run hol-guard status [--json]
```

## Common Test Fixtures

Test fixtures live in `tests/fixtures/`:
- `good-plugin/` - clean Codex plugin with all required fields
- `bad-plugin/` - plugin with secrets, missing fields, bad practices
- `malicious-skill-plugin/` - skill with malicious patterns
- `multi-ecosystem-repo/` - repo with Codex, Claude, and Gemini configs
- `claude-plugin-good/` - clean Claude plugin
- `opencode-good/` - clean OpenCode plugin
- `gemini-extension-good/` - clean Gemini extension

## Verification

After each operation, verify:
- Exit code 0 for clean targets
- Exit code non-zero for targets with findings
- Output is valid JSON when `--format json` or `--json` is used
- Scanner reports findings with correct rule IDs and severities

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…