HOL Guard
What is HOL Guard?
HOL Guard is an open-source, local-first runtime guard for AI coding agents. On supported harnesses it applies policy to actions such as shell commands, file changes, MCP tool calls and package installs, and can allow, ask for approval, or block them before they run; which events it can see differs by harness. HOL's coverage matrix lists 15 stable harnesses, including Codex, Claude Code, Cursor, OpenCode and GitHub Copilot CLI. Plans run Free $0 forever, Solo $4.99/mo, Pro $15/mo, Team $30/seat/mo, and Enterprise contact sales.
Last verifiedHow we evaluate
At a glance
- HOL Guard is best for developers and platform teams running AI coding agents who want pre-execution control over risky actions.
- Free $0 forever; Solo $4.99/mo; Pro $15/mo; Team $30/seat/mo (billed monthly; $4.17, $12 and $24/seat billed annually); Enterprise Custom
- Yes — HOL's OpenAPI document lists an authenticated Guard Cloud endpoint (/api/guard/mcp) that answers MCP JSON-RPC requests under OAuth scopes for reading workspace data and receipts.
What it actually does
HOL Guard installs a local hook, proxy or wrapper layer in front of a coding agent (Codex, Claude Code, Cursor, Gemini CLI, OpenCode and others) and applies policy to the events that agent exposes: where a pre-action hook exists it can allow, ask for approval, or block an action before it runs, and it records other supported events for review. Which events that covers depends on the harness. In HOL's coverage matrix, Codex and Claude Code expose shell, prompt, MCP tool, file-read and tool-result events; Cursor exposes shell, MCP tool and file-read events but not prompt submission; Gemini CLI exposes shell and MCP tool calls only; and on OpenClaw Guard sees MCP tool calls alone. Some surfaces are observation-only (Cline's native post-tool hooks, Grok Build's prompt hooks), and HOL lists Kimi Code, Grok Build and ZCode as failing open. Guard runs as a Python package (pipx install hol-guard) or as a desktop app for macOS, Windows and Linux, and ships a second CLI, plugin-scanner, for scanning agent plugins and skills for secrets and unsafe MCP config before publishing them. Core local enforcement needs no account and works with no internet connection, per the vendor's own FAQ. (Sources: https://hol.org/guard/security/coverage; https://hol.org/guard/features; PyPI project description, https://pypi.org/pypi/hol-guard/json; install page, https://hol.org/guard/install; checked 2026-09-24)
Where it's genuinely strong: honest, dated coverage claims
Guard publishes a per-harness coverage matrix that states, for each of 15 agents in both a 'stable' and an 'alpha' channel, which event types are actually observable (shell, prompt, mcp_tool, file_read, etc.), whether native approval UI exists, what happens on failure (surface-specific vs. fail-open), and named limitations — e.g. it says plainly that shell commands in Cursor's built-in terminal bypass Guard unless run inside an agent session, and that OpenCode file reads/writes bypass Guard unless OpenCode's own permission rules block them. Every row links to the exact GitHub commit it was verified against, is dated (last reviewed 2026-09-09), and carries an explicit 30-day expiry (2026-10-09) after which the claim is stale. The vendor's own runtime-security benchmark is similarly disclosed as a rule-based fixture simulation rather than live attack measurements across five independently run harnesses. This level of self-imposed, dated, sourced disclosure about a security product's own limits is unusual and is the strongest reason to trust what it does claim. (Source: https://hol.org/guard/security/coverage; https://hol.org/guard/research/ai-coding-agent-runtime-security-benchmark)
Pricing: local blocking is free, paid tiers are for sync and teams
Free tier includes the full local runtime — command interception, approvals, local audit log, all supported agents — with no account or credit card, according to Guard's own pricing FAQ, and this was corroborated on the pricing page's plan table. Paid tiers monetize things layered on top: Solo ($4.99/mo) adds two-device cloud sync of approval history plus GitHub secret-leak monitoring on up to 5 repos; Pro ($15/mo) adds longer retention, real-time alerts, and full evidence search; Team ($30/seat/mo) adds shared org policy and fleet dashboards. Enterprise is quote-only: HOL describes it as a scoped security review covering identity and access, redacted evidence export via webhook, custom threat feeds and self-hosted or VPC deployment, with availability confirmed per deployment. None of the paid tiers gate the actual blocking behavior — the vendor states local blocking 'does not depend on' Guard Cloud, which for a security tool is the right default. (Source: https://hol.org/guard/pricing, checked 2026-09-24)
How young this is
The hol-guard GitHub repository was created 2026-03-28, and its first PyPI release shipped 2026-06-11. PyPI has carried more than 200 versions since, across three major lines (2.0 on 7 July, 3.0 on 27 August), which is fast even for an actively developed CLI. HOL's release page lists v3.4.1, published 22 September 2026, as the latest recommended stable release. The repository has 664 stars, 96 forks and 112 open issues and pull requests, is Apache-2.0 licensed, and is not archived. pypistats.org, which covers 10 April to 23 September 2026, counts about 1.27 million downloads including mirror traffic and about 393,000 excluding it; the landing page's '716K+ Guard PyPI downloads' sits between the two, and HOL does not say which count it uses. OSV and GitHub's advisory database list no published vulnerabilities for the hol-guard package. (Sources: https://hol.org/guard/releases; https://api.github.com/repos/hashgraph-online/hol-guard; https://pypi.org/pypi/hol-guard/json; https://pypistats.org/api/packages/hol-guard/overall; https://api.github.com/advisories?ecosystem=pip&affects=hol-guard; all checked 2026-09-24)
Who's behind it
HOL Guard is built by Hashgraph Online DAO LLC ('HOL'), a consortium whose primary work is open standards and a discovery registry for the Hedera/Hashgraph ecosystem (HCS standards, the Universal Agentic Registry) — Guard is one product line alongside those, not the work of a dedicated application-security company. The DAO LLC's published business address is in the Marshall Islands. The landing page's '4.8K+ HOL GitHub stars' figure is an org-wide total across dozens of HOL repositories (its largest, standards-sdk, alone has 1,227 stars; awesome-codex-plugins has 1,075), not stars on the Guard repository itself, which has 664. Similarly, the '37M+ HOL network transactions' and '34 ecosystem partners' stats on Guard's own page describe the broader HOL registry/standards business, not anything about Guard's security efficacy, and the partner logos shown beneath them are HOL consortium and ecosystem partners rather than Guard customers. None of this makes the product worse, but a buyer evaluating Guard specifically should read the Guard-specific numbers (664 stars, 15 stable harnesses) rather than the consortium-wide ones presented alongside them. (Sources: https://hol.org/about; https://hol.org/guard; https://api.github.com/repos/hashgraph-online/hol-guard; https://api.github.com/orgs/hashgraph-online/repos; checked 2026-09-24)
What to confirm before a security review
Guard's Security Trust Packet says its source claims were verified on 16 September 2026, which predates the 3.1 through 3.4 releases of 20 to 22 September. A team running a formal review against a current build can reasonably ask HOL whether anything in the packet changed with those releases. The coverage matrix carries its own expiry, 9 October 2026, after which HOL treats its harness claims as stale, so check that date before relying on a row. (Sources: https://hol.org/guard/security/trust; https://hol.org/guard/security/coverage; https://hol.org/guard/releases; checked 2026-09-24)
How much does HOL Guard cost?
| Plan | Price | What's included |
|---|---|---|
| Free | $0 forever |
|
| Solo | $4.99/mo |
|
| Pro | $15/mo |
|
| Team | $30/seat/mo |
|
| Enterprise | Contact sales |
|
Frequently asked questions
What is HOL Guard?
HOL Guard is an open-source, local-first runtime guard for AI coding agents. On supported harnesses it applies policy to actions such as shell commands, file changes, MCP tool calls and package installs, and can allow, ask for approval, or block them before they run; which events it can see differs by harness. HOL's coverage matrix lists 15 stable harnesses, including Codex, Claude Code, Cursor, OpenCode and GitHub Copilot CLI. Plans run Free $0 forever, Solo $4.99/mo, Pro $15/mo, Team $30/seat/mo, and Enterprise contact sales.
How much does HOL Guard cost? Is it free?
HOL Guard has a free plan: local protection needs no account or credit card. Guard Cloud plans cost Solo $4.99/mo, Pro $15/mo and Team $30/seat/mo billed monthly, or $4.17, $12 and $24/seat per month billed annually. Enterprise is priced on request.
What is HOL Guard used for? Who is it for?
HOL Guard is used for Runtime protection, Policy routing, and Review workbench. It's built for Platform engineers, Security teams, and Developers.
Does HOL Guard have an API and what does it integrate with?
Yes: HOL's OpenAPI document lists an authenticated Guard Cloud endpoint that answers MCP JSON-RPC requests under OAuth scopes. HOL's coverage matrix lists 15 stable harnesses: Codex, Claude Code, OpenCode, GitHub Copilot CLI, Cursor, Cline, Gemini CLI, Hermes, OpenClaw, Antigravity, Kimi Code, Grok Build, Pi, Oh My Pi and ZCode. It marks five of them (GitHub Copilot CLI, Gemini CLI, Hermes, OpenClaw and Antigravity) as partial, and the events Guard can see and block differ for each one; the per-harness limits are published at https://hol.org/guard/security/coverage.
Editor's read
Check whether your workflow depends on Guard Cloud features like synced history, alerts, or shared policy. The free local tier works offline, but those coordination features are only added in Guard Cloud.
