hol-guard
View on GitHubOpen-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
Local-first runtime security for AI agents: hooks and MCP proxies that classify shell commands, file access, package installs and tool calls, then allow, block or request approval. Also ships plugin-scanner, a CLI/CI scanner for agent plugins, skills and MCP servers.
Use Cases
Block risky shell commands and file access from AI coding agents before executionDetect and redact secret/credential exposure in agent tool callsScreen prompts and tool results for prompt injectionScan and police MCP server configuration and MCP tool callsScan, lint and verify agent plugins, skills and MCP packages before publishingSupply-chain scanning of package installs (npm/PyPI advisories) before installGenerate an AI bill of materials (ABOM) and audit receipts for agent actionsApproval workflows routing risky agent actions to a human approval centerCI/GitHub Actions plugin security scanning with SARIF outputRuntime policy enforcement across Claude Code, Cursor, Codex, Gemini CLI, OpenClaw and OpenCode
Built With
- Language
- Python
- Frameworks
- Model Context Protocol (MCP) · Cisco AI Skill Scanner · litellm · FastAPI · Playwright · Vite · hatchling · pytest
Tags
agent-security · mcp-security · ai-antivirus · prompt-injection · secrets-detection · supply-chain-security · runtime-security · devsecops · plugin-security · skill-security · cli · claude-code · cursor · codex · gemini-cli · sarif