Agent skill

Hol Guard Protection

by hashgraph-online in hashgraph-online/hol-guard

Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows.

Apache-2.0Auto-check passedSecurity

Install Hol Guard Protection

skills CLI
$ npx skills add hashgraph-online/hol-guard --skill hol-guard-protection -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hashgraph-online/hol-guard hol-guard-protection --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hashgraph-online/hol-guard.git skills-src && mkdir -p .claude/skills && cp -r skills-src/docs/guard .claude/skills/hol-guard-protection && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hol-guard-protection
GitHub stars
838
Token cost
~605 tokens
SKILL.md length
296 words
Files
270
Skills in repo
4
Repo updated
First seen
Licence
Apache-2.0

At a glance

Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows.

  • Works in 5 steps: Preview the install decision → Check current workspace risk posture → Explain a specific package verdict → …
  • Tasks that involve Workflow automation
  • SKILL.md covers Before package installs, Cursor editor and Cursor CLI, During CI and automation and If Guard blocks a package
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Hol Guard Protection is an agent skill from hashgraph-online/hol-guard. Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows.

Its SKILL.md is about 610 tokens, which your agent loads only when the skill is triggered. The skill folder holds 271 other files (for example `adr/0001-mdm-managed-install-contract.md`, `adr/0002-self-protection-authority.md` and `adr/0003-desktop-shell-and-tray-ownership.md`).

It sits in Security, covering Workflow automation, Prompt injection and agent security and Supply chain security. It works with Model Context Protocol and npm. The repository describes itself as: Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Workflow automation
  • Tasks that involve Prompt injection and agent security
  • Tasks that involve Supply chain security

Example prompts

  • “/hol-guard-protection”

Requirements

  • Node.js

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Preview the install decision
  2. Check current workspace risk posture
  3. Explain a specific package verdict
  4. Confirm package manager interception is installed
  5. Repair a missing or tampered package manager shim

What it can do on your machine

Read from SKILL.md and the folder at commit a3b4f6b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hol Guard Protection loads about 605 tokens when it runs. Until then it costs about 33 tokens; SKILL.md has 296 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~33
When it runs · the whole SKILL.md, loaded when a task matches
~605

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hashgraph-online/hol-guard at commit a3b4f6b, republished under its Apache-2.0 licence (© hashgraph-online). 296 words, ~605 tokens.

Download SKILL.mdSave it as .claude/skills/hol-guard-protection/SKILL.md (or your agent's skills folder). This skill also uses 269 other files; get the full folder from GitHub.
name
hol-guard-protection
description
Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows.

HOL Guard Skill Guidance

Use this guidance when an AI agent is about to add or update dependencies.

Before package installs

  1. Preview the install decision:
    • hol-guard protect --dry-run -- npm install <package>
  2. Check current workspace risk posture:
    • hol-guard supply-chain scan --json
  3. Explain a specific package verdict:
    • hol-guard supply-chain explain <package>@<version> --ecosystem <ecosystem>
  4. Confirm package manager interception is installed:
    • hol-guard package-shims status --json
  5. Repair a missing or tampered package manager shim:
    • hol-guard package-shims repair --manager npm --json

Cursor editor and Cursor CLI

Cursor has two protection surfaces. Cursor editor covers MCP servers in .cursor/mcp.json. Cursor CLI covers the cursor-agent command path. Keep them distinct when activating, checking, repairing, or removing Guard.

  1. Connect Cursor editor protection:
    • hol-guard apps connect cursor --surface editor
  2. Connect Cursor CLI protection:
    • hol-guard apps connect cursor --surface cli
  3. Test a Cursor surface without changing config:
    • hol-guard apps test cursor --surface editor
    • hol-guard apps test cursor --surface cli
  4. Repair only the stale surface named by Guard Cloud:
    • hol-guard apps repair cursor --surface editor
    • hol-guard apps repair cursor --surface cli
  5. Remove protection only after confirmation:
    • hol-guard apps disconnect cursor --surface editor --confirm disconnect-cursor
    • hol-guard apps disconnect cursor --surface cli --confirm disconnect-cursor

Guard owns trust checks, drift repair, redacted receipts, and Cloud sync. Cursor owns its native editor and CLI behavior. If a surface is missing, unsupported, or unavailable, report that state instead of inventing an install URL or fallback command.

During CI and automation

  • Route dependency installs through Guard:
    • hol-guard protect -- npm ci
  • Use workspace audits before release:
    • hol-guard supply-chain audit --json

If Guard blocks a package

  • Review the blocking reason and suggested fix version.
  • Prefer upgrading to a safe version.
  • If it is a verified false positive, use a scoped and expiring exception with recorded reason.

© hashgraph-online, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 269 other files in docs/guard of hashgraph-online/hol-guard.

  • SKILL.md
  • adr/0001-mdm-managed-install-contract.md
  • adr/0002-self-protection-authority.md
  • adr/0003-desktop-shell-and-tray-ownership.md
  • adr/0004-extension-control-center-semantics.md
  • adr/0005-protection-center-semantics.md
  • adr/0006-native-rust-runtime-boundary.md
  • adr/0007-native-runtime-packaging.md
  • adr/0008-native-resident-protocol-and-admission.md
  • adr/0009-native-and-daemon-critical-failure.md
  • adr/0010-native-posttool-default-auto.md
  • adr/0011-extension-first-managed-controls.md
  • adr/0012-everyday-and-technical-presentation.md
  • adr/0012-python-hook-capability-cleanup.md
  • adr/0013-native-resident-retirement.md
  • adr/0014-native-catalog-read-model.md
  • all-harness-hook-review.md
  • architecture.md
  • audits/rm011-rtm006-gap-report.md
  • … and 251 more

Open the folder on GitHubat commit a3b4f6b

Compare with similar skills

Hol Guard Protection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hol Guard Protection compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hol Guard Protection this skillhashgraph-online/hol-guard838—~605Automated safety check: PassApache-2.0
Skill InspectorNVIDIA/SkillSpector20k—~1.8kAutomated safety check: PassApache-2.0
Reins Runtime Securitypegasi-ai/reins392—~1.4kAutomated safety check: WarnApache-2.0
Plugin Scanneriflytek/skillhub5.2k2 repos~1.1kAutomated safety check: NotesApache-2.0
Securing AI Systemstrilwu/secskills157—~2.9kAutomated safety check: PassMIT
Securitytelagod/code-abyss244—~907Automated safety check: PassMIT

Similar skills

  • Skill Inspector

    NVIDIA/SkillSpector

    Official

    Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.

    20k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Reins Runtime Security

    pegasi-ai/reins

    Installs hooks that check each agent action against security policies before it runs, blocking destructive commands and logging every decision.

    392 GitHub stars~1.4k tokensUpdated yesterday
    SecurityAuto-check: warnings
  • Plugin Scanner

    iflytek/skillhub

    Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.

    5.2k GitHub starsUsed in 2 repos~1.1k tokens
    SecurityAuto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Security

    telagod/code-abyss

    Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries…

    244 GitHub stars~907 tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK.

    376 GitHub stars~2.3k tokensUpdated 12 days ago
    SecurityAuto-check passed

More from hashgraph-online/hol-guard

  • Hol Guard

    hashgraph-online/hol-guard

    Run HOL Guard scanner and guard operations via uv run hol-guard.

    838 GitHub stars~542 tokensUpdated today
    Auto-check passed
  • Setup

    hashgraph-online/hol-guard

    Install or initialize HOL Guard local runtime protection for Claude Code.

    838 GitHub stars~443 tokensUpdated today
    Auto-check passed
  • Status

    hashgraph-online/hol-guard

    Check HOL Guard local protection status for Claude Code without changing configuration.

    838 GitHub stars~231 tokensUpdated today
    Auto-check passed

Categories

Questions about Hol Guard Protection

What does Hol Guard Protection do?

Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows. Hol Guard Protection is an agent skill from hashgraph-online/hol-guard. Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows.

When should I use Hol Guard Protection?

Hol Guard Protection fits situations like: tasks that involve Workflow automation; tasks that involve Prompt injection and agent security; tasks that involve Supply chain security.

How do I install Hol Guard Protection in Claude Code?

Run `npx skills add hashgraph-online/hol-guard --skill hol-guard-protection -a claude-code`. Or copy the skill folder (docs/guard in hashgraph-online/hol-guard) into .claude/skills/hol-guard-protection in your project. Claude Code loads it when a task matches its description.

How do I install Hol Guard Protection in Codex?

Run `npx skills add hashgraph-online/hol-guard --skill hol-guard-protection -a codex`. Or copy the skill folder (docs/guard in hashgraph-online/hol-guard) into .agents/skills/hol-guard-protection in your project. Codex loads it when a task matches its description.

Can I use Hol Guard Protection in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hashgraph-online/hol-guard --skill hol-guard-protection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hol-guard-protection, .gemini/skills/hol-guard-protection, .github/skills/hol-guard-protection and .opencode/skills/hol-guard-protection in your project.

What does Hol Guard Protection need to run?

SKILL.md names no scripts, command-line tools or credentials: Hol Guard Protection is instructions for the agent only. Our summary lists: Node.js.

Does Hol Guard Protection access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hol Guard Protection safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hol Guard Protection use?

Hol Guard Protection is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hol Guard Protection use?

About 605 tokens (SKILL.md is roughly 2.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hol Guard Protection?

Skills that share tags, products or a category with Hol Guard Protection: Skill Inspector (NVIDIA/SkillSpector, 20k stars), Reins Runtime Security (pegasi-ai/reins, 392 stars), Plugin Scanner (iflytek/skillhub, 5.2k stars) and Securing AI Systems (trilwu/secskills, 157 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hol Guard Protection?

hashgraph-online (a GitHub organization) maintains it in hashgraph-online/hol-guard, which has 838 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 10, 2026.

Source: hashgraph-online/hol-guard on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.