Agent skill
Hol Guard
Run HOL Guard scanner and guard operations via uv run hol-guard. Use when the user asks to scan plugins/MCP/skills for security, quality, or ecosystem compliance, or when they ask to run guard detect/install/protect workflows for local AI harnesses.
Get the complete skill folder, including its scripts and reference files.
·
When to use this skill
Use Hol Guard when an AI agent needs a reusable SKILL.md workflow for this job: Run HOL Guard scanner and guard operations via uv run hol-guard. Use when the user asks to scan plugins/MCP/skills for security, quality, or ecosystem compliance, or when they ask to run guard detect/install/protect workflows for local AI harnesses.
When not to use it
Skip Hol Guard when the task is outside the coding category, or when a more specific skill in this directory already covers the same workflow with clearer triggers.
How to install
- Claude Code personal install: place the skill and its bundled files at ~/.claude/skills/hol-guard/SKILL.md. For a shared project, commit the folder at .claude/skills/hol-guard/ instead.
- Current Claude Code detects SKILL.md changes in watched directories during the session. If you just created a top-level skills directory, run /reload-skills. Check that the skill is listed before testing its trigger.
- For Claude chat or Cowork in the Desktop app, manage uploaded skills in Customize > Skills; copying files into a local Claude Code folder is not a Desktop install. Other agents may use different install locations.
What supports this recommendation?
70/100 provisional content score. This measures documentation, practical detail and source signals. It is not a measured task success rate or a security certification.
- Documentation
- 77/100
- Practical detail
- 68/100
- Source evidence
- 63/100
- Source signals
- 70/100
Model compatibility evidence
- claude · inferred
The skill text mentions Claude or a closely associated term. This is keyword-derived compatibility; no hands-on model test is recorded.
- chatgpt · untested
No model-specific signal or recorded compatibility test was found.
- gemini · inferred
The skill text mentions Gemini or a closely associated term. This is keyword-derived compatibility; no hands-on model test is recorded.
- copilot · untested
No model-specific signal or recorded compatibility test was found.
- llama · untested
No model-specific signal or recorded compatibility test was found.
- perplexity · untested
No model-specific signal or recorded compatibility test was found.
- mistral · untested
No model-specific signal or recorded compatibility test was found.
- grok · untested
No model-specific signal or recorded compatibility test was found.
Inferred compatibility is based on content signals. Check the app, its available tools and setup requirements before running a skill.
What this skill does
# HOL Guard
HOL Guard is an AI Antivirus scanner that checks plugins, MCP servers, skills, and local AI harnesses for security, quality, and ecosystem compliance.
## Prerequisites
- Always run from the `hol-guard` project root. - Use `uv run hol-guard` to invoke the CLI. Never invoke Python modules directly. - Ensure `uv sync --frozen --extra dev` has been run before invoking.
## Scanner Operations
Scan a plugin or skill directory:
``` uv run hol-guard scan <directory> [--format json|text|markdown|sarif] [--profile default|public-marketplace|strict-security] [--fail-on-severity critical|high|medium|low|info|none] ```
Lint rules:
``` uv run hol-guard lint <directory> [--list-rules] [--explain <rule-id>] ```
Verify runtime:
``` uv run hol-guard verify <directory> [--online] ```
List ecosystems:
``` uv run hol-guard --list-ecosystems ```
## Guard Operations
Detect harnesses:
``` uv run hol-guard detect [codex|claude|cursor|gemini|opencode] [--json] ```
Run guard in dry-run mode:
``` uv run hol-guard run <harness> --dry-run --default-action allow --json ```
Check guard status:
``` uv run hol-guard status [--json] ```
## Common Test Fixtures
Test fixtures live in `tests/fixtures/`: - `good-plugin/` - clean Codex plugin with all required fields - `bad-plugin/` - plugin with secrets, missing fields, bad practices - `malicious-skill-plugin/` - skill with malicious patterns - `multi-ecosystem-repo/` - repo with Codex, Claude, and Gemini configs - `claude-plugin-good/` - clean Claude plugin - `opencode-good/` - clean OpenCode plugin - `gemini-extension-good/` - clean Gemini extension
## Verification
After each operation, verify: - Exit code 0 for clean targets - Exit code non-zero for targets with findings - Output is valid JSON when `--format json` or `--json` is used - Scanner reports findings with correct rule IDs and severities
Try it, then tell us how it went
A copied prompt does not tell us whether the task worked. Report your result after checking the output. We collect your tool and outcome, never your files or prompt.
Open your saved libraryIntended uses
- Use Hol Guard when this documented workflow matches the task.
Related skills
Related skills in this directory, for comparison before you install another skill.
coding
Prompt template
A Half-Built Pyramid and the Leader Who Turned Labor Into Legacy
A reusable prompt for asking an AI assistant to work as A Half-Built Pyramid and the Leader Who Turned Labor Into Legacy.
Content score 57/100 · provisional
coding
Prompt template
Act as a Patient, Non-Technical Android Studio Guide
A reusable prompt for asking an AI assistant to work as Act as a Patient, Non-Technical Android Studio Guide.
Content score 56/100 · provisional
coding
Agent skill
Add Ave Record
The main workflow for this repo. Adds one new AVE record end to end.
Content score 65/100 · provisional
coding
Agent skill
Add Backend
Guide for adding a backend (Rust or Python) to the agent-sec-core security middleware. Use when creating new backends, integrating Rust or Python code into the security middleware, or extending with new backend actions.
Content score 70/100 · provisional