No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by hashgraph-online · MCP Server · ★ 728
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is hol-guard safe to install? View the security audit →
HOL Guard [](https://scorecard.dev/vie
| Stars | 728 |
| Forks | 130 |
| Language | Python |
| Category | MCP Server |
| License | Apache-2.0 |
| Quality Score | 69.5548084104075/100 |
| Open Issues | 134 |
| Last Updated | 2026-10-03 |
| Created | 2026-03-28 |
| Platforms | claude-code, cli, codex, gemini, mcp, python |
| Est. Tokens | ~22k |
These tools work well together with hol-guard for enhanced workflows:
Looking for a hol-guard alternative? If you're comparing hol-guard with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
nono - a capability-based, multiplexing sandbox tool, built for developers - lift'n'shift seamless path to pro
Access control for AI agents. Set what Claude Code, Codex, Gemini, Cursor and any MCP server are allowed to do
See what your AI agents can access. Scan MCP configs for exposed secrets, shadow APIs, and AI models. Generate
📚 Your AI coding setup, everywhere. Manage skills, agents, rules, MCP connections and hooks in one place, wit
Open-source cross-agent memory layer for coding agents via MCP. Compatible with Claude Code, Codex, Cursor, Wi
Open-source runtime AI agent security tool - monitors and controls AI agents, catching malicious tool use, pro
Explore other popular mcp server tools:
hol-guard is Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.. It is categorized as a MCP Server with 728 GitHub stars.
hol-guard is primarily written in Python. It covers topics such as agent-security, ai-agent-security, ai-agents.
You can find installation instructions and usage details in the hol-guard GitHub repository at github.com/hashgraph-online/hol-guard. The project has 728 stars and 130 forks, indicating an active community.
hol-guard is released under the Apache-2.0 license, making it free to use and modify according to the license terms.
The top alternatives to hol-guard on Agent Skills Hub include nono, node9-proxy, mcp-audit. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: