Agent skill

Hol Guard

Run HOL Guard scanner and guard operations via uv run hol-guard. Use when the user asks to scan plugins/MCP/skills for security, quality, or ecosystem compliance, or when they ask to run guard detect/install/protect workflows for local AI harnesses.

Get started

Get the complete skill folder, including its scripts and reference files.

·

When to use this skill

Use Hol Guard when an AI agent needs a reusable SKILL.md workflow for this job: Run HOL Guard scanner and guard operations via uv run hol-guard. Use when the user asks to scan plugins/MCP/skills for security, quality, or ecosystem compliance, or when they ask to run guard detect/install/protect workflows for local AI harnesses.

When not to use it

Skip Hol Guard when the task is outside the coding category, or when a more specific skill in this directory already covers the same workflow with clearer triggers.

How to install

  1. Claude Code personal install: place the skill and its bundled files at ~/.claude/skills/hol-guard/SKILL.md. For a shared project, commit the folder at .claude/skills/hol-guard/ instead.
  2. Current Claude Code detects SKILL.md changes in watched directories during the session. If you just created a top-level skills directory, run /reload-skills. Check that the skill is listed before testing its trigger.
  3. For Claude chat or Cowork in the Desktop app, manage uploaded skills in Customize > Skills; copying files into a local Claude Code folder is not a Desktop install. Other agents may use different install locations.

Full install guide for Claude, Cursor, and Codex

What supports this recommendation?

70/100 provisional content score. This measures documentation, practical detail and source signals. It is not a measured task success rate or a security certification.

Documentation
77/100
Practical detail
68/100
Source evidence
63/100
Source signals
70/100
Model compatibility evidence
  • claude · inferred

    The skill text mentions Claude or a closely associated term. This is keyword-derived compatibility; no hands-on model test is recorded.

  • chatgpt · untested

    No model-specific signal or recorded compatibility test was found.

  • gemini · inferred

    The skill text mentions Gemini or a closely associated term. This is keyword-derived compatibility; no hands-on model test is recorded.

  • copilot · untested

    No model-specific signal or recorded compatibility test was found.

  • llama · untested

    No model-specific signal or recorded compatibility test was found.

  • perplexity · untested

    No model-specific signal or recorded compatibility test was found.

  • mistral · untested

    No model-specific signal or recorded compatibility test was found.

  • grok · untested

    No model-specific signal or recorded compatibility test was found.

Inferred compatibility is based on content signals. Check the app, its available tools and setup requirements before running a skill.

What this skill does

# HOL Guard

HOL Guard is an AI Antivirus scanner that checks plugins, MCP servers, skills, and local AI harnesses for security, quality, and ecosystem compliance.

## Prerequisites

- Always run from the `hol-guard` project root. - Use `uv run hol-guard` to invoke the CLI. Never invoke Python modules directly. - Ensure `uv sync --frozen --extra dev` has been run before invoking.

## Scanner Operations

Scan a plugin or skill directory:

``` uv run hol-guard scan <directory> [--format json|text|markdown|sarif] [--profile default|public-marketplace|strict-security] [--fail-on-severity critical|high|medium|low|info|none] ```

Lint rules:

``` uv run hol-guard lint <directory> [--list-rules] [--explain <rule-id>] ```

Verify runtime:

``` uv run hol-guard verify <directory> [--online] ```

List ecosystems:

``` uv run hol-guard --list-ecosystems ```

## Guard Operations

Detect harnesses:

``` uv run hol-guard detect [codex|claude|cursor|gemini|opencode] [--json] ```

Run guard in dry-run mode:

``` uv run hol-guard run <harness> --dry-run --default-action allow --json ```

Check guard status:

``` uv run hol-guard status [--json] ```

## Common Test Fixtures

Test fixtures live in `tests/fixtures/`: - `good-plugin/` - clean Codex plugin with all required fields - `bad-plugin/` - plugin with secrets, missing fields, bad practices - `malicious-skill-plugin/` - skill with malicious patterns - `multi-ecosystem-repo/` - repo with Codex, Claude, and Gemini configs - `claude-plugin-good/` - clean Claude plugin - `opencode-good/` - clean OpenCode plugin - `gemini-extension-good/` - clean Gemini extension

## Verification

After each operation, verify: - Exit code 0 for clean targets - Exit code non-zero for targets with findings - Output is valid JSON when `--format json` or `--json` is used - Scanner reports findings with correct rule IDs and severities

Try it, then tell us how it went

A copied prompt does not tell us whether the task worked. Report your result after checking the output. We collect your tool and outcome, never your files or prompt.

Open your saved library

Intended uses

  • Use Hol Guard when this documented workflow matches the task.

Related skills

Related skills in this directory, for comparison before you install another skill.

coding

Agent skill

Add Ave Record

The main workflow for this repo. Adds one new AVE record end to end.

Content score 65/100 · provisional

View skill

coding

Agent skill

Add Backend

Guide for adding a backend (Rust or Python) to the agent-sec-core security middleware. Use when creating new backends, integrating Rust or Python code into the security middleware, or extending with new backend actions.

Content score 70/100 · provisional

View skill

Ranked Claude skills