hol-guard
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill focuses on providing security controls, approval reviews, and monitoring for AI agent harnesses. It includes explicit safety rules such as avoiding
.envfiles and requiring command-verified protection states. - [EXTERNAL_DOWNLOADS]: The skill recommends installing the
hol-guardandplugin-scannerpackages usingpipx. These are the core tools described in the skill and are installed via a standard, isolated Python package manager. - [COMMAND_EXECUTION]: Various subcommands of
hol-guardandplugin-scannerare used for environment detection, status monitoring, and security auditing. All commands are legitimate and aligned with the tool's stated security-focused purpose. - [INDIRECT_PROMPT_INJECTION]: The
plugin-scannerutility is designed to process external paths and repository files for linting and verification. - Ingestion points: Untrusted data enters the context through files and packages at specified paths provided to the
plugin-scanner lintandplugin-scanner verifycommands inSKILL.md. - Boundary markers: The skill does not explicitly define boundary markers for the output of these scans.
- Capability inventory: The skill can install packages via
pipx, manage AI harnesses withhol-guard run/install, and synchronize data usinghol-guard sync. - Sanitization: No specific sanitization methods for the content of scanned packages are mentioned; however, the tool is explicitly described as a security scanner intended to identify risks in such content.
Audit Metadata