Run HOL Guard scanner and guard operations via uv run hol-guard.

Apache-2.0Auto-check passedSecurity

Install Hol Guard

skills CLI
$ npx skills add hashgraph-online/hol-guard --skill hol-guard -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hashgraph-online/hol-guard hol-guard --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hashgraph-online/hol-guard.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.factory/skills/hol-guard .claude/skills/hol-guard && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hol-guard
GitHub stars
827
Token cost
~542 tokens
SKILL.md length
170 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
Apache-2.0

At a glance

Run HOL Guard scanner and guard operations via uv run hol-guard.

  • The user asks to scan plugins/MCP/skills for security
  • SKILL.md covers Prerequisites, Scanner Operations, Guard Operations and Common Test Fixtures, plus 1 more section
  • Calls uv, claude and cursor
  • Ecosystem compliance

What it does

Hol Guard is an agent skill from hashgraph-online/hol-guard. Run HOL Guard scanner and guard operations via uv run hol-guard. Use when the user asks to scan plugins/MCP/skills for security, quality, or ecosystem compliance, or when they ask to run guard detect/install/protect workflows for local AI harnesses.

Its SKILL.md is about 540 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Prompt injection and agent security and MCP servers. It works with Model Context Protocol. The repository describes itself as: Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime. The licence is Apache-2.0.

When your agent uses it

  • The user asks to scan plugins/MCP/skills for security
  • Ecosystem compliance
  • They ask to run guard detect/install/protect workflows for local AI harnesses

Example prompts

  • “/hol-guard”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 4736564. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv
    • claude
    • cursor
    • gemini

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hol Guard loads about 542 tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 170 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~542

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hashgraph-online/hol-guard at commit 4736564, republished under its Apache-2.0 licence (© hashgraph-online). 170 words, ~542 tokens.

Download SKILL.mdSave it as .claude/skills/hol-guard/SKILL.md (or your agent's skills folder).
name
hol-guard
description
Run HOL Guard scanner and guard operations via `uv run hol-guard`. Use when the user asks to scan plugins/MCP/skills for security, quality, or ecosystem compliance, or when they ask to run guard detect/install/protect workflows for local AI harnesses.

HOL Guard

HOL Guard is an AI Antivirus scanner that checks plugins, MCP servers, skills, and local AI harnesses for security, quality, and ecosystem compliance.

Prerequisites

  • Always run from the hol-guard project root.
  • Use uv run hol-guard to invoke the CLI. Never invoke Python modules directly.
  • Ensure uv sync --frozen --extra dev has been run before invoking.

Scanner Operations

Scan a plugin or skill directory:

uv run hol-guard scan <directory> [--format json|text|markdown|sarif] [--profile default|public-marketplace|strict-security] [--fail-on-severity critical|high|medium|low|info|none]

Lint rules:

uv run hol-guard lint <directory> [--list-rules] [--explain <rule-id>]

Verify runtime:

uv run hol-guard verify <directory> [--online]

List ecosystems:

uv run hol-guard --list-ecosystems

Guard Operations

Detect harnesses:

uv run hol-guard detect [codex|claude|cursor|gemini|opencode] [--json]

Run guard in dry-run mode:

uv run hol-guard run <harness> --dry-run --default-action allow --json

Check guard status:

uv run hol-guard status [--json]

Common Test Fixtures

Test fixtures live in tests/fixtures/:

  • good-plugin/ - clean Codex plugin with all required fields
  • bad-plugin/ - plugin with secrets, missing fields, bad practices
  • malicious-skill-plugin/ - skill with malicious patterns
  • multi-ecosystem-repo/ - repo with Codex, Claude, and Gemini configs
  • claude-plugin-good/ - clean Claude plugin
  • opencode-good/ - clean OpenCode plugin
  • gemini-extension-good/ - clean Gemini extension

Verification

After each operation, verify:

  • Exit code 0 for clean targets
  • Exit code non-zero for targets with findings
  • Output is valid JSON when --format json or --json is used
  • Scanner reports findings with correct rule IDs and severities

© hashgraph-online, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .factory/skills/hol-guard of hashgraph-online/hol-guard.

Open the folder on GitHubat commit 4736564

Compare with similar skills

Hol Guard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hol Guard compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hol Guard this skillhashgraph-online/hol-guard827—~542Automated safety check: PassApache-2.0
Forensifyalexgreensh/repo-forensics188—~2.5kAutomated safety check: NotesCustom licence
Plugin Scanneriflytek/skillhub5.2k2 repos~1.1kAutomated safety check: NotesApache-2.0
Hunt MCPEncod3d-Sec/TORCH329—~1.4kAutomated safety check: PassMIT
MCP Server Security Auditawarexone/Agentic-Bug-Hunter5.3k—~1.9kAutomated safety check: WarnMIT
Securing AI Systemstrilwu/secskills157—~2.9kAutomated safety check: PassMIT

Similar skills

  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    188 GitHub stars~2.5k tokensUpdated 12 days ago
    SecurityAuto-check: notes
  • Plugin Scanner

    iflytek/skillhub

    Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.

    5.2k GitHub starsUsed in 2 repos~1.1k tokens
    SecurityAuto-check: notes
  • Hunt MCP

    Encod3d-Sec/TORCH

    MCP server attack hunting - tool poisoning, indirect prompt injection via tool output, rug-pull updates, cross-tool shadowing, over-permissioned/excessive-agency tools, lethal trifecta.

    329 GitHub stars~1.4k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • MCP Server Security Audit

    awarexone/Agentic-Bug-Hunter

    Audits MCP servers and their client configs for tool poisoning, prompt injection, over-privileged tools, injection bugs, secret leaks and missing approval gates.

    5.3k GitHub stars~1.9k tokensUpdated yesterday
    SecurityAuto-check: warnings
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Auditing MCP Servers For Tool Poisoning

    mukul975/Anthropic-Cybersecurity-Skills

    Audit MCP servers for tool poisoning, tool shadowing, rug pulls, SSRF, and unauthenticated exposure using Invariant Labs' mcp-scan for static/runtime scanning plus manual SSRF/auth checks and…

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    SecurityAuto-check: warnings

More from hashgraph-online/hol-guard

  • Setup

    hashgraph-online/hol-guard

    Install or initialize HOL Guard local runtime protection for Claude Code.

    827 GitHub stars~443 tokensUpdated today
    Auto-check passed
  • Status

    hashgraph-online/hol-guard

    Check HOL Guard local protection status for Claude Code without changing configuration.

    827 GitHub stars~231 tokensUpdated today
    Auto-check passed
  • Hol Guard Protection

    hashgraph-online/hol-guard

    Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows.

    827 GitHub stars~605 tokensUpdated today
    Auto-check passed

Categories

Questions about Hol Guard

What does Hol Guard do?

Run HOL Guard scanner and guard operations via uv run hol-guard. Hol Guard is an agent skill from hashgraph-online/hol-guard. Run HOL Guard scanner and guard operations via uv run hol-guard.

When should I use Hol Guard?

Hol Guard fits situations like: the user asks to scan plugins/MCP/skills for security; ecosystem compliance; they ask to run guard detect/install/protect workflows for local AI harnesses.

How do I install Hol Guard in Claude Code?

Run `npx skills add hashgraph-online/hol-guard --skill hol-guard -a claude-code`. Or copy the skill folder (.factory/skills/hol-guard in hashgraph-online/hol-guard) into .claude/skills/hol-guard in your project. Claude Code loads it when a task matches its description.

How do I install Hol Guard in Codex?

Run `npx skills add hashgraph-online/hol-guard --skill hol-guard -a codex`. Or copy the skill folder (.factory/skills/hol-guard in hashgraph-online/hol-guard) into .agents/skills/hol-guard in your project. Codex loads it when a task matches its description.

Can I use Hol Guard in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hashgraph-online/hol-guard --skill hol-guard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hol-guard, .gemini/skills/hol-guard, .github/skills/hol-guard and .opencode/skills/hol-guard in your project.

What does Hol Guard need to run?

Going by SKILL.md and its folder, Hol Guard needs the command-line tools its instructions call (uv, claude, cursor and gemini). Our summary lists: Python 3.

Does Hol Guard access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Hol Guard safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hol Guard use?

Hol Guard is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hol Guard use?

About 542 tokens (SKILL.md is roughly 2.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hol Guard?

Skills that share tags, products or a category with Hol Guard: Forensify (alexgreensh/repo-forensics, 188 stars), Plugin Scanner (iflytek/skillhub, 5.2k stars), Hunt MCP (Encod3d-Sec/TORCH, 329 stars) and MCP Server Security Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hol Guard?

hashgraph-online (a GitHub organization) maintains it in hashgraph-online/hol-guard, which has 827 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 9, 2026.

Source: hashgraph-online/hol-guard on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.