HOL Guard
HOL Guard is a local-first runtime security layer for AI agents that watches what an AI assistant is about to do and stops risky actions before they happen. It sits between the agent and the computer, evaluating supported tool calls and local artifacts for threats such as secret and credential exposure, destructive commands, prompt-injection-driven actions, malicious or changed packages, risky MCP configuration, and unsafe plugins, skills, hooks, and settings. Known threats can be blocked automatically, while ambiguous actions are paused for user approval so people remain in control. Guard runs entirely on the developer’s machine, works offline, and does not upload files, prompts, or passwords. Local checks typically complete in under 50 milliseconds and require no changes to existing code or routines. It supports coding agents including Claude Code, Cursor, Codex, Gemini CLI, OpenCode, Hermes, and OpenClaw, with tailored integrations that inspect actions before execution.
Learn more
port22
port22 puts your coding agents in your pocket. Run the agent, pair your iPhone, and drive Claude Code, Codex, or OpenCode from anywhere while reading the live transcript and approving actions as the agent works. It attaches to the session already running in your terminal rather than starting or forking a new one, so you can continue working with the same live process you began at your desk. Every token is streamed to your phone as the agent thinks, edits, and runs, while push notifications arrive when it finishes or needs your approval. Live status remains visible through the Dynamic Island and lock screen, so you can follow every active session without repeatedly opening the app. port22 works over your local network at your desk and automatically switches to an end-to-end encrypted relay when you leave Wi-Fi, keeping the same session over cellular.
Learn more
SuperBased
SuperBased is a local-first control plane for AI coding agents that lets developers see, control, and right-size agent activity from one binary running on their own machine. It reads native session data from 40 coding tools without requiring a proxy, SDK rewrite, or special configuration, supporting agents such as Claude Code, Codex, Cursor, GitHub Copilot, OpenCode, Gemini CLI, Kilo Code, Qwen Code, Aider, Devin, and others. The dashboard tracks provider-reported token usage, cache reads and writes, costs, sessions, and projected next-message spend across tools that normally keep their data separate. Developers can also launch more than 20 CLI agents as terminal sessions, monitor several repositories from one screen, attach to a running agent, take over the keyboard, and hand control back when needed. Model routing helps teams match tasks to appropriate models, while egress gates can hold commands before execution so users can stop or redirect costly or risky actions.
Learn more
Preloop
Preloop is the open source AI agent control plane for agents that take real actions. It combines an MCP firewall for tool access, an AI model gateway for cost, safety, and attribution, policy-as-code with human approvals, runtime session observability, and audit trails in a single self-hostable platform. AI agents can deploy code, change infrastructure, move money, touch production data, and burn model spend in seconds, so Preloop helps teams control what agents can do, how much they spend, and which actions require human approval. It works with OpenClaw, Hermes, Claude Code, Codex CLI, Cursor, Gemini CLI, Windsurf, Cline, OpenCode, and any MCP-compatible agent or managed runtime. Access rules can inspect arguments and context, not just tool names, with CEL expressions for fine-grained conditions. Teams can start with observability, then layer in approvals and deny rules without SDKs or invasive app changes.
Learn more