Skip to main content
Favicon of HOL Guard

HOL Guard

What is HOL Guard?

HOL Guard is an open-source, local-first runtime guard for AI coding agents. On supported harnesses it applies policy to actions such as shell commands, file changes, MCP tool calls and package installs, and can allow, ask for approval, or block them before they run; which events it can see differs by harness. HOL's coverage matrix lists 15 stable harnesses, including Codex, Claude Code, Cursor, OpenCode and GitHub Copilot CLI. Plans run Free $0 forever, Solo $4.99/mo, Pro $15/mo, Team $30/seat/mo, and Enterprise contact sales.

Last verifiedHow we evaluate

Screenshot of HOL Guard website

At a glance

Best for
HOL Guard is best for developers and platform teams running AI coding agents who want pre-execution control over risky actions.
Pricing
Free $0 forever; Solo $4.99/mo; Pro $15/mo; Team $30/seat/mo (billed monthly; $4.17, $12 and $24/seat billed annually); Enterprise Custom
API
Yes — HOL's OpenAPI document lists an authenticated Guard Cloud endpoint (/api/guard/mcp) that answers MCP JSON-RPC requests under OAuth scopes for reading workspace data and receipts.

What it actually does

HOL Guard installs a local hook, proxy or wrapper layer in front of a coding agent (Codex, Claude Code, Cursor, Gemini CLI, OpenCode and others) and applies policy to the events that agent exposes: where a pre-action hook exists it can allow, ask for approval, or block an action before it runs, and it records other supported events for review. Which events that covers depends on the harness. In HOL's coverage matrix, Codex and Claude Code expose shell, prompt, MCP tool, file-read and tool-result events; Cursor exposes shell, MCP tool and file-read events but not prompt submission; Gemini CLI exposes shell and MCP tool calls only; and on OpenClaw Guard sees MCP tool calls alone. Some surfaces are observation-only (Cline's native post-tool hooks, Grok Build's prompt hooks), and HOL lists Kimi Code, Grok Build and ZCode as failing open. Guard runs as a Python package (pipx install hol-guard) or as a desktop app for macOS, Windows and Linux, and ships a second CLI, plugin-scanner, for scanning agent plugins and skills for secrets and unsafe MCP config before publishing them. Core local enforcement needs no account and works with no internet connection, per the vendor's own FAQ. (Sources: https://hol.org/guard/security/coverage; https://hol.org/guard/features; PyPI project description, https://pypi.org/pypi/hol-guard/json; install page, https://hol.org/guard/install; checked 2026-09-24)

Where it's genuinely strong: honest, dated coverage claims

Guard publishes a per-harness coverage matrix that states, for each of 15 agents in both a 'stable' and an 'alpha' channel, which event types are actually observable (shell, prompt, mcp_tool, file_read, etc.), whether native approval UI exists, what happens on failure (surface-specific vs. fail-open), and named limitations — e.g. it says plainly that shell commands in Cursor's built-in terminal bypass Guard unless run inside an agent session, and that OpenCode file reads/writes bypass Guard unless OpenCode's own permission rules block them. Every row links to the exact GitHub commit it was verified against, is dated (last reviewed 2026-09-09), and carries an explicit 30-day expiry (2026-10-09) after which the claim is stale. The vendor's own runtime-security benchmark is similarly disclosed as a rule-based fixture simulation rather than live attack measurements across five independently run harnesses. This level of self-imposed, dated, sourced disclosure about a security product's own limits is unusual and is the strongest reason to trust what it does claim. (Source: https://hol.org/guard/security/coverage; https://hol.org/guard/research/ai-coding-agent-runtime-security-benchmark)

Pricing: local blocking is free, paid tiers are for sync and teams

Free tier includes the full local runtime — command interception, approvals, local audit log, all supported agents — with no account or credit card, according to Guard's own pricing FAQ, and this was corroborated on the pricing page's plan table. Paid tiers monetize things layered on top: Solo ($4.99/mo) adds two-device cloud sync of approval history plus GitHub secret-leak monitoring on up to 5 repos; Pro ($15/mo) adds longer retention, real-time alerts, and full evidence search; Team ($30/seat/mo) adds shared org policy and fleet dashboards. Enterprise is quote-only: HOL describes it as a scoped security review covering identity and access, redacted evidence export via webhook, custom threat feeds and self-hosted or VPC deployment, with availability confirmed per deployment. None of the paid tiers gate the actual blocking behavior — the vendor states local blocking 'does not depend on' Guard Cloud, which for a security tool is the right default. (Source: https://hol.org/guard/pricing, checked 2026-09-24)

How young this is

The hol-guard GitHub repository was created 2026-03-28, and its first PyPI release shipped 2026-06-11. PyPI has carried more than 200 versions since, across three major lines (2.0 on 7 July, 3.0 on 27 August), which is fast even for an actively developed CLI. HOL's release page lists v3.4.1, published 22 September 2026, as the latest recommended stable release. The repository has 664 stars, 96 forks and 112 open issues and pull requests, is Apache-2.0 licensed, and is not archived. pypistats.org, which covers 10 April to 23 September 2026, counts about 1.27 million downloads including mirror traffic and about 393,000 excluding it; the landing page's '716K+ Guard PyPI downloads' sits between the two, and HOL does not say which count it uses. OSV and GitHub's advisory database list no published vulnerabilities for the hol-guard package. (Sources: https://hol.org/guard/releases; https://api.github.com/repos/hashgraph-online/hol-guard; https://pypi.org/pypi/hol-guard/json; https://pypistats.org/api/packages/hol-guard/overall; https://api.github.com/advisories?ecosystem=pip&affects=hol-guard; all checked 2026-09-24)

Who's behind it

HOL Guard is built by Hashgraph Online DAO LLC ('HOL'), a consortium whose primary work is open standards and a discovery registry for the Hedera/Hashgraph ecosystem (HCS standards, the Universal Agentic Registry) — Guard is one product line alongside those, not the work of a dedicated application-security company. The DAO LLC's published business address is in the Marshall Islands. The landing page's '4.8K+ HOL GitHub stars' figure is an org-wide total across dozens of HOL repositories (its largest, standards-sdk, alone has 1,227 stars; awesome-codex-plugins has 1,075), not stars on the Guard repository itself, which has 664. Similarly, the '37M+ HOL network transactions' and '34 ecosystem partners' stats on Guard's own page describe the broader HOL registry/standards business, not anything about Guard's security efficacy, and the partner logos shown beneath them are HOL consortium and ecosystem partners rather than Guard customers. None of this makes the product worse, but a buyer evaluating Guard specifically should read the Guard-specific numbers (664 stars, 15 stable harnesses) rather than the consortium-wide ones presented alongside them. (Sources: https://hol.org/about; https://hol.org/guard; https://api.github.com/repos/hashgraph-online/hol-guard; https://api.github.com/orgs/hashgraph-online/repos; checked 2026-09-24)

What to confirm before a security review

Guard's Security Trust Packet says its source claims were verified on 16 September 2026, which predates the 3.1 through 3.4 releases of 20 to 22 September. A team running a formal review against a current build can reasonably ask HOL whether anything in the packet changed with those releases. The coverage matrix carries its own expiry, 9 October 2026, after which HOL treats its harness claims as stale, so check that date before relying on a row. (Sources: https://hol.org/guard/security/trust; https://hol.org/guard/security/coverage; https://hol.org/guard/releases; checked 2026-09-24)

How much does HOL Guard cost?

PlanPriceWhat's included
Free$0 forever
  • Local protection and local protection modules
  • Local leaked-secret scanning, approvals and receipts
  • No account, credit card or internet connection needed
Solo$4.99/mo
  • Or $4.17/mo billed annually
  • 2 Cloud-connected devices
  • Cloud approval and receipt sync, with module settings across devices
  • 30-day Cloud retention and 1 GB storage
  • Weekly personal security digest and matched critical advisories
Pro$15/mo
  • Or $12/mo billed annually
  • Everything in Solo, with 5 Cloud-connected devices
  • 180-day Cloud retention and 5 GB storage
  • Real-time activity alerts
  • Policy versioning and rollback
  • Advanced search, full evidence and searchable decision history
Team$30/seat/mo
  • Or $24/seat/mo billed annually
  • Everything in Pro, with up to 25 Cloud-connected devices
  • 365-day Cloud retention and 25 GB + 5 GB per seat storage
  • Organization module policy
  • Shared policy and team workflows
EnterpriseContact sales
  • Enterprise identity and access review
  • Redacted evidence export via webhook
  • Custom threat-feed requirements review
  • Self-hosted / VPC deployment review
  • Volume pricing and support planning

Frequently asked questions

What is HOL Guard?

HOL Guard is an open-source, local-first runtime guard for AI coding agents. On supported harnesses it applies policy to actions such as shell commands, file changes, MCP tool calls and package installs, and can allow, ask for approval, or block them before they run; which events it can see differs by harness. HOL's coverage matrix lists 15 stable harnesses, including Codex, Claude Code, Cursor, OpenCode and GitHub Copilot CLI. Plans run Free $0 forever, Solo $4.99/mo, Pro $15/mo, Team $30/seat/mo, and Enterprise contact sales.

How much does HOL Guard cost? Is it free?

HOL Guard has a free plan: local protection needs no account or credit card. Guard Cloud plans cost Solo $4.99/mo, Pro $15/mo and Team $30/seat/mo billed monthly, or $4.17, $12 and $24/seat per month billed annually. Enterprise is priced on request.

What is HOL Guard used for? Who is it for?

HOL Guard is used for Runtime protection, Policy routing, and Review workbench. It's built for Platform engineers, Security teams, and Developers.

Does HOL Guard have an API and what does it integrate with?

Yes: HOL's OpenAPI document lists an authenticated Guard Cloud endpoint that answers MCP JSON-RPC requests under OAuth scopes. HOL's coverage matrix lists 15 stable harnesses: Codex, Claude Code, OpenCode, GitHub Copilot CLI, Cursor, Cline, Gemini CLI, Hermes, OpenClaw, Antigravity, Kimi Code, Grok Build, Pi, Oh My Pi and ZCode. It marks five of them (GitHub Copilot CLI, Gemini CLI, Hermes, OpenClaw and Antigravity) as partial, and the events Guard can see and block differ for each one; the per-harness limits are published at https://hol.org/guard/security/coverage.

Editor's read

Check whether your workflow depends on Guard Cloud features like synced history, alerts, or shared policy. The free local tier works offline, but those coordination features are only added in Guard Cloud.

Share:

Sponsored
Favicon

 

  
 

Explore other Security AI Agents

Favicon

 

  
  
Favicon

 

  
  
Favicon