hol-guard
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing
hol-guardandplugin-scannerusingpipx. These are CLI tools provided by the vendor (hashgraph-online) to facilitate the security functions described in the skill. - [COMMAND_EXECUTION]: The skill relies on executing shell commands to manage security harnesses and perform audits. This includes commands for bootstrapping guards, installing protection for specific AI harnesses (like Claude Code or Codex), and running security scans on external packages.
- [INDIRECT_PROMPT_INJECTION]: The skill includes an attack surface for indirect prompt injection as it is designed to ingest and analyze untrusted external data such as third-party plugins, skills, and MCP servers.
- Ingestion points: External files and directories targeted by
plugin-scanner lintandplugin-scanner verifycommands. - Boundary markers: Not explicitly defined in the prompt instructions, as the data is processed by the external scanner tool.
- Capability inventory: The skill has the capability to execute shell commands and install packages via
pipx. - Sanitization: The skill relies on the internal logic of the
plugin-scannertool to safely handle and report on external content.
Audit Metadata