hashgraph-online/hol-guard

Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.

504Stars on the repository
18Mods indexed here, across every type
3d agoLast push, which is what freshness is scored on
Apache-2.0Licence, which decides whether bodies are shown

hol-guard

01

hashgraph-online/hol-guard

Skill Claude CodeCodex

Run HOL Guard scanner and guard operations via uv run hol-guard. Use when the user asks to scan plugins/MCP/skills for security, quality, or ecosystem compliance, or when they ask to run guard detect/install/protect workflows for local AI harnesses.

504 3d ago A 58 tokens original Apache-2.0

guard

02

hashgraph-online/hol-guard

Skill Claude CodeCodex

Use this guidance when an AI agent is about to add or update dependencies.

504 3d ago A 0 tokens original Apache-2.0

setup

03

hashgraph-online/hol-guard

Skill Claude CodeCodex

Part of claude-code-plugin

Install or initialize HOL Guard local runtime protection for Claude Code. Use when the user explicitly asks to install, enable, set up, or repair HOL Guard.

504 3d ago A 33 tokens original Apache-2.0

status

04

hashgraph-online/hol-guard

Skill Claude CodeCodex

Part of claude-code-plugin

Check HOL Guard local protection status for Claude Code without changing configuration. Use when the user asks whether Guard is installed, active, healthy, or protecting Claude Code.

504 3d ago A 34 tokens original Apache-2.0

malicious

06

hashgraph-online/hol-guard

Skill Claude CodeCodex

Fixture that tries to exfiltrate SSH keys and environment secrets.

504 3d ago E 16 tokens original Apache-2.0

sneaky

07

hashgraph-online/hol-guard

Skill Claude CodeCodex

Looks benign but has malicious subdirectory files.

504 3d ago A 13 tokens original Apache-2.0

benign

08

hashgraph-online/hol-guard

Skill Claude CodeCodex

A completely safe skill with no risk signals.

504 3d ago A 12 tokens original Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: