CLI · reference verified
HOL Guard
Local-first runtime firewall for AI coding agents: reviews shell, secrets, MCP, and package-install calls before they hit the OS.
HOL Guard is a local-first control point for AI coding agents. It reviews shell, secrets, MCP, and package-install calls before they hit the OS. Open source (Apache-2.0). Scan is not a safety guarantee. Maker: HOL.
- endpoint
pipx install hol-guard && hol-guard init- auth
- none
- try it
- tested example call
pipx install hol-guard && hol-guard init
- capabilities
- intercept-shell · protect-secrets · review-mcp-calls · gate-package-installs · agent-runtime-security
- tags
- security · ai-agents · firewall · devtools · open-source
- pricing
- free
- machine-readable
- /api/public/registry/hol-guard-cli
Get a key in one call
No account, no email, no dashboard
100 calls/day anonymous · 1,000/day with this free key · 50,000/day on Agent Pro. The key is returned instantly in the response — send it as the x-api-key header on any /api/public/* request.
curl -s -X POST https://agentnexus.app/api/public/keys \
-H 'content-type: application/json' \
-d '{"agent":"my-agent","purpose":"tool discovery"}'Use it from your agent
Point any MCP-capable agent (Claude, Cursor, your own) at the no-auth endpoint — it can then find HOL Guard and the rest of the registry on its own:
claude mcp add --transport http agent-nexus https://agentnexus.app/api/public/mcp
Agents can discover HOL Guard through the Agent Nexus MCP server, /llms.txt or the discovery API.