HOL Guard logo
NofollowScheduled

HOL Guard

Local-first runtime firewall for AI coding agents

Scheduled projects can’t be voted on until the launch week is live
Website

AI-friendly Markdown · structured for AI citations

Built byHOL

External link

Visit website

HOL Guard preview

hol.org/guard

Open

Overview

About HOL Guard

HOL Guard is a local-first runtime firewall for AI coding agents. It intercepts tool calls (shell, secrets, MCP, package installs) before they execute. Apache-2.0. Install: pipx install hol-guard && hol-guard init. Scan is not a safety guarantee. Maker: HOL. Free. AI coding agents are increasingly given real power over real machines. They run shell commands, edit files, read environment variables, install packages, and talk to external services through MCP servers. That power is what makes them useful, and it is also what makes them risky. A single mistaken command, a prompt-injected instruction hidden in a web page, or an unreviewed package install can delete work, leak a secret, or reach a network endpoint nobody intended. HOL Guard exists to put a checkpoint in front of those actions while the agent is still running, not after the damage is visible in a diff or a log. HOL Guard runs entirely on your own machine. There is no cloud service in the path and no code upload, which is what local-first means here. It sits between the agent and the operating system and inspects each tool call as it is about to run. Shell commands, secret and environment reads, MCP tool invocations, and package installation steps are the four categories it watches most closely. When a call matches a rule you care about, HOL Guard pauses it and surfaces the decision to you: approve once, approve for the session, or deny. Everything else keeps flowing so you are not drowned in prompts for harmless reads. Key features: interception of shell, secrets, MCP, and package install tool calls before execution; a local approval flow with clear, readable context about what the agent is trying to do; configurable rules so teams can encode their own policies; and an Apache-2.0 license so the whole thing can be audited, forked, and used inside commercial workflows without licensing friction. Getting started is deliberately short: pipx install hol-guard && hol-guard init. Typical use cases include running an autonomous agent on a repository that holds production credentials, letting a coding agent install dependencies without unattended network and package freedom, reviewing MCP servers of unknown provenance, and giving a team a shared, reviewable policy for what agents may do on developer laptops. The benefit is simple: you keep the speed of agentic development while keeping a human decision point at the moments that actually matter. An important limitation, stated plainly: a scan is not a safety guarantee. HOL Guard reduces the blast radius of agent mistakes and makes risky actions visible, but it cannot prove that any given command is safe. Treat it as a seatbelt, not as an excuse to stop steering. HOL Guard is made by HOL and is free.

AI assistants

Ask AI about this project

Opens ChatGPT, Claude, Gemini, Perplexity, Mistral with a pre-filled prompt about this project. Review and send the message in the AI app.

Community

Comments

Sign in to post a comment

No comments yet

Be the first to comment!

Info

Project details

StatusScheduled
Launch typenofollow
Launch weekMon, Jan 18 – 25 Mon, 2027
PricingFree
Total votes0

Maker

HOL

View founder profile →

Content

Launch story

HOL Guard logo

Launch story publishes after the project completes its launch week.

Need more content and distribution? Meet Posting Dude.