HOL Guard is an open-source security layer designed to protect AI agents and their local tool ecosystems at runtime. It evaluates supported actions for secret exposure, prompt injection, unsafe commands, malicious packages, and risky MCP interactions. Safe operations can proceed automatically, while known threats are blocked and ambiguous actions can require human approval. The platform also examines plugins, skills, hooks, package installs, and agent configurations before they are trusted. It integrates with major coding agents including Claude Code, Codex, Cursor, Gemini CLI, OpenCode, and GitHub Copilot CLI. Local operation requires no cloud account, while optional cloud services add synchronized evidence, shared policies, fleet visibility, and team approvals.
Features
- Runtime AI agent protection
- Prompt injection detection
- Secret and credential exposure monitoring
- Plugin, skill, and MCP security scanning
- Human approval for ambiguous actions
- Local security receipts and audit evidence