Agent skill

Hol Guard

by aiskillstore in aiskillstore/marketplace

A skill your agent uses when setting up HOL Guard, protecting local AI harnesses, reviewing Guard approvals or receipts, scanning Codex plugins, skills, MCP servers, marketplace packages, or running…

Apache-2.0Auto-check: notesAgent Workflows

Install Hol Guard

skills CLI
$ npx skills add aiskillstore/marketplace --skill hol-guard -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aiskillstore/marketplace hol-guard --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hashgraph-online/hol-guard .claude/skills/hol-guard && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hol-guard
GitHub stars
433
Used in
1 other repo
Token cost
~1.4k tokens
SKILL.md length
547 words
Files
2
Skills in repo
1,044
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when setting up HOL Guard, protecting local AI harnesses, reviewing Guard approvals or receipts, scanning Codex plugins, skills, MCP servers, marketplace packages, or running…

  • Setting up HOL Guard
  • SKILL.md covers Hard Rules, Install Check, Protect A Local Harness and Approval Work, plus 4 more sections
  • Calls pipx and git
  • Protecting local AI harnesses

What it does

Hol Guard is an agent skill from aiskillstore/marketplace. Use when setting up HOL Guard, protecting local AI harnesses, reviewing Guard approvals or receipts, scanning Codex plugins, skills, MCP servers, marketplace packages, or running plugin-scanner verification before release.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `skill-report.json`).

It sits in Agent Workflows, covering MCP servers. It works with Model Context Protocol. The repository describes itself as: Security-audited skills for Claude, Codex & Claude Code. One-click install, quality verified. The licence is Apache-2.0.

When your agent uses it

  • Setting up HOL Guard
  • Protecting local AI harnesses
  • Reviewing Guard approvals
  • Scanning Codex plugins

Example prompts

  • “/hol-guard”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 44923f3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pipx
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pipx and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hol Guard loads about 1.4k tokens when it runs. Until then it costs about 58 tokens; SKILL.md has 547 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:13
    - Never read `.env` files.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aiskillstore/marketplace at commit 44923f3, republished under its Apache-2.0 licence (© aiskillstore). 547 words, ~1,443 tokens.

Download SKILL.mdSave it as .claude/skills/hol-guard/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
hol-guard
description
Use when setting up HOL Guard, protecting local AI harnesses, reviewing Guard approvals or receipts, scanning Codex plugins, skills, MCP servers, marketplace packages, or running plugin-scanner verification before release.
license
Apache-2.0

HOL Guard

HOL Guard protects local AI harnesses before tools run. Use this skill when the user wants AI antivirus behavior, local approval review, Codex protection, Claude Code protection, MCP safety checks, skill/package verification, or release gates from hol-guard and plugin-scanner.

Hard Rules

  • Never read .env files.
  • Never bypass Guard approvals.
  • Do not mark a workspace protected until a Guard command proves status.
  • Prefer reversible Guard commands over direct harness config edits.
  • Do not mutate user-level harness config unless the hol-guard command owns that mutation.
  • Treat scanner failures as real until inspected.
  • Preserve existing user changes and inspect git status --short before edits in a repo.

Install Check

Check both CLIs independently:

bash
command -v hol-guard
command -v plugin-scanner

If hol-guard is missing and the user asked for runtime setup, prefer:

bash
pipx install hol-guard

If plugin-scanner is missing and the user asked for scanning, install the separate scanner distribution:

bash
pipx install plugin-scanner

Do not assume the hol-guard distribution provides the plugin-scanner command. If pipx is unavailable, explain that isolated CLI installation is recommended rather than silently changing the user's Python environment.

After runtime installation:

bash
hol-guard status
hol-guard detect --json

Protect A Local Harness

Use this flow for Codex, Claude Code, Copilot CLI, Cursor, Gemini, Hermes, OpenClaw, OpenCode, or Antigravity.

bash
hol-guard bootstrap
hol-guard install <harness>
hol-guard run <harness> --dry-run
hol-guard run <harness>
hol-guard status

Harness names:

  • codex
  • claude-code
  • copilot
  • cursor
  • gemini
  • hermes
  • openclaw
  • opencode
  • antigravity

Harness aliases:

  • claude maps to claude-code
  • gemini-cli maps to gemini
  • open-code maps to opencode
  • open-claw maps to openclaw
  • copilot-cli maps to copilot

Use harness-specific bootstrap when available:

bash
hol-guard hermes bootstrap
Claude Code

Use this when the workspace has .claude/settings.local.json, .claude/agents, Claude hooks, .mcp.json, or Claude-managed tool approval surfaces.

bash
hol-guard install claude-code
hol-guard run claude-code --dry-run
hol-guard run claude-code
hol-guard doctor claude-code --json

Claude Code is a first-class Guard target. Prefer Guard-owned Claude hooks over direct manual edits to Claude config.

Codex

Use this when the workspace has Codex config, .codex/hooks.json, Codex MCP servers, or Codex App/CLI tool flows.

bash
hol-guard install codex
hol-guard run codex --dry-run
hol-guard run codex
hol-guard doctor codex --json

Codex supports Guard-owned PreToolUse Bash hooks and same-chat MCP elicitation where available.

Other Harnesses

Use the same Guard flow for:

  • Copilot CLI: hol-guard install copilot
  • Cursor: hol-guard install cursor
  • Gemini CLI: hol-guard install gemini
  • Hermes: hol-guard hermes bootstrap
  • OpenClaw: hol-guard install openclaw
  • OpenCode: hol-guard install opencode
  • Antigravity: hol-guard install antigravity
Show full SKILL.md (214 more words)Show less

Approval Work

If Guard blocks or queues work:

bash
hol-guard approvals
hol-guard approvals open
hol-guard receipts
hol-guard diff <harness>

For terminal-only resolution:

bash
hol-guard approvals approve <request-id>
hol-guard approvals deny <request-id>

Only approve after reading the risk reason and understanding the requested scope.

Evidence Work

Use evidence commands when user needs proof, audit trail, or handoff artifacts:

bash
hol-guard receipts
hol-guard inventory
hol-guard abom --format json
hol-guard events
hol-guard explain <artifact-id>

For cloud sync, keep it optional and user-directed:

bash
hol-guard connect
hol-guard connect status
hol-guard connect repair
hol-guard sync

Scan A Plugin Or Skill Package

Use scanner mode for Codex plugins, Claude Code project surfaces, .agents marketplaces, skills, MCP server configs, and release gates.

bash
plugin-scanner lint .
plugin-scanner verify .

If scanning a specific package:

bash
plugin-scanner lint <path>
plugin-scanner verify <path>

If the target is a Codex marketplace root with .agents/plugins/marketplace.json, scan the repo root so local plugin entries can be discovered.

Scanner target guidance:

  • Codex plugin: scan the repo root or plugin folder containing .codex-plugin/plugin.json.
  • Codex marketplace: scan the repo root containing .agents/plugins/marketplace.json.
  • Claude Code project: scan the workspace root containing .claude/, .mcp.json, hooks, or agent folders.
  • MCP server package: scan the package root containing server config and package metadata.
  • Skill package: scan the folder containing SKILL.md.
  • Mixed agent workspace: scan the repo root so local plugin, skill, MCP, and harness config surfaces are discovered together.

Common Debug Commands

bash
hol-guard doctor
hol-guard doctor <harness> --json
hol-guard detect --json
hol-guard settings show
hol-guard explain install-connect
plugin-scanner verify . --json

Response Pattern

When using Guard, report:

  • What command ran.
  • What Guard found.
  • What remains blocked or risky.
  • What proof exists.
  • Exact next command if user must act.

Do not claim protection, approval, or release readiness without command output proving it.

© aiskillstore, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/hashgraph-online/hol-guard of aiskillstore/marketplace.

  • SKILL.md
  • skill-report.json

Open the folder on GitHubat commit 44923f3

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in aiskillstore/marketplace, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Hol Guard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hol Guard compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hol Guard this skillaiskillstore/marketplace4331 repos~1.4kAutomated safety check: NotesApache-2.0
MCP Server Builderanthropics/skills180k63 repos~2.3kAutomated safety check: PassApache-2.0
MCP Server BuildershareAI-lab/learn-claude-code78k4 repos~1.2kAutomated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official38k11 repos~3.1kAutomated safety check: PassApache-2.0
Crush Configurationcharmbracelet/crush29k—~3.7kAutomated safety check: PassCustom licence
Context Mode Output Sandboxmksglu/context-mode26k—~4.1kAutomated safety check: PassCustom licence

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 63 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 4 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    38k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Crush Configuration

    charmbracelet/crush

    Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.

    29k GitHub stars~3.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Context Mode Output Sandbox

    mksglu/context-mode

    Routes large command, file, API and browser output through context-mode tools so only the needed result enters the agent's context, instead of dumping it via Bash.

    26k GitHub stars~4.1k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Migrates the compatible subset of settings and global file-based MCP servers from the Warp desktop app into Warp Agent CLI without exposing credentials or state.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    Agent WorkflowsAuto-check passed

More from aiskillstore/marketplace

All 1,044 skills in this repo
  • Code Stats

    aiskillstore/marketplace

    Analyze codebase with tokei (fast line counts by language) and difft (semantic AST-aware diffs).

    433 GitHub starsUsed in 1 repo~697 tokens
    Auto-check: notes
  • Data Processing

    aiskillstore/marketplace

    Process JSON with jq and YAML/TOML with yq. An agent skill from aiskillstore/marketplace.

    433 GitHub starsUsed in 1 repo~720 tokens
    Auto-check: notes
  • Doc Scanner

    aiskillstore/marketplace

    Scans for project documentation files (AGENTS.md, CLAUDE.md, GEMINI.md, COPILOT.md, CURSOR.md, WARP.md, and 15+ other formats) and synthesizes guidance.

    433 GitHub starsUsed in 1 repo~644 tokens
    Auto-check: notes
  • File Search

    aiskillstore/marketplace

    Modern file and content search using fd, ripgrep (rg), and fzf.

    433 GitHub starsUsed in 1 repo~598 tokens
    Auto-check: notes
  • Find Replace

    aiskillstore/marketplace

    Modern find-and-replace using sd (simpler than sed) and batch replacement patterns.

    433 GitHub starsUsed in 1 repo~527 tokens
    Auto-check: notes
  • Project Planner

    aiskillstore/marketplace

    Detects stale project plans and suggests session commands. An agent skill from aiskillstore/marketplace.

    433 GitHub starsUsed in 1 repo~504 tokens
    Auto-check passed

Categories

Questions about Hol Guard

What does Hol Guard do?

A skill your agent uses when setting up HOL Guard, protecting local AI harnesses, reviewing Guard approvals or receipts, scanning Codex plugins, skills, MCP servers, marketplace packages, or running…. Hol Guard is an agent skill from aiskillstore/marketplace. Use when setting up HOL Guard, protecting local AI harnesses, reviewing Guard approvals or receipts, scanning Codex plugins, skills, MCP servers, marketplace packages, or running plugin-scanner verification before release.

When should I use Hol Guard?

Hol Guard fits situations like: setting up HOL Guard; protecting local AI harnesses; reviewing Guard approvals; scanning Codex plugins.

How do I install Hol Guard in Claude Code?

Run `npx skills add aiskillstore/marketplace --skill hol-guard -a claude-code`. Or copy the skill folder (skills/hashgraph-online/hol-guard in aiskillstore/marketplace) into .claude/skills/hol-guard in your project. Claude Code loads it when a task matches its description.

How do I install Hol Guard in Codex?

Run `npx skills add aiskillstore/marketplace --skill hol-guard -a codex`. Or copy the skill folder (skills/hashgraph-online/hol-guard in aiskillstore/marketplace) into .agents/skills/hol-guard in your project. Codex loads it when a task matches its description.

Can I use Hol Guard in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aiskillstore/marketplace --skill hol-guard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hol-guard, .gemini/skills/hol-guard, .github/skills/hol-guard and .opencode/skills/hol-guard in your project.

What does Hol Guard need to run?

Going by SKILL.md and its folder, Hol Guard needs the command-line tools its instructions call (pipx and git). Our summary lists: Python 3.

Does Hol Guard access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Hol Guard safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Hol Guard use?

Hol Guard is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hol Guard use?

About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hol Guard?

Skills that share tags, products or a category with Hol Guard: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), MCP Integration for Plugins (anthropics/claude-plugins-official, 38k stars) and Crush Configuration (charmbracelet/crush, 29k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hol Guard?

aiskillstore (a GitHub organization) maintains it in aiskillstore/marketplace, which has 433 GitHub stars. The repository holds 1,044 skills in this directory. The repository was last updated on October 10, 2026.

Source: aiskillstore/marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.