---
title: "hol-guard"
description: "Local-first AI agent security with Guard status, security receipts, approvals, MCP visibility, and pre-trust scanning for skills, plugins, and MCP servers."
canonical: https://agentpluginsdirectory.com/plugins/hol-guard--hashgraph-online
last-updated: 2026-09-28
---

# hol-guard
Local-first AI agent security with Guard status, security receipts, approvals, MCP visibility, and pre-trust scanning for skills, plugins, and MCP servers.
- Slug: hol-guard--hashgraph-online
- Publisher: Hashgraph Online
- Repository: https://github.com/hashgraph-online/hol-guard-plugin
- Manifest: plugin.json
- Version: 0.1.1
- License: Apache-2.0
- Category (editorial): security
- Skills: 2 (hol-guard, plugin-scanner)
- MCP servers: 1 (hol-guard)
- Stars: 3
- Repository created: 2026-05-16
- Repository last pushed: 2026-09-20
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/hol-guard--hashgraph-online
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## What hol-guard does, in the publisher's words

Codex and DeepSeek Harness plugin for HOL Guard, the local AI security layer from hol-guard.

HOL Guard protects local AI harnesses before tools run. It can inspect Codex, Claude Code, Copilot CLI, Cursor, DeepSeek Harness, Gemini, Hermes, OpenClaw, OpenCode, and Antigravity surfaces, then route risky changes through local approvals and receipts.

Install HOL Guard first:

- tools/pre-execute performs the bounded asynchronous HOL Guard review.
- Guard ask, review, and require-reapproval outcomes use DSH's native one-time approval service when it is mounted.
- The resolved decision is latched onto the exact DSH execution.
- ctx.tools.guard() enforces the latch as a monotonic final denial boundary before dispatch.
- A native DSH bundle with asynchronous Guard review, native one-time approval, and a monotonic pre-dispatch denial guard.
- A public Codex skill at skills/hol-guard/SKILL.md.

From the project README, punctuation lightly normalized. Full text: https://raw.githubusercontent.com/hashgraph-online/hol-guard-plugin/HEAD/README.md

## Skills

- hol-guard: Use when setting up HOL Guard, protecting local AI harnesses, reviewing Guard approvals or receipts, scanning Codex plugins, skills, MCP servers, marketplace packages, or running plugin-scanner verification before release.
- plugin-scanner: Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.

## MCP servers

- hol-guard: transport: stdio; command: hol-guard mcp serve --stdio

Read from the plugin's own mcp.json. Environment variable names only, never values.
