Security1 distinct publisher3 min readPublished
HOL Guard pauses risky actions from Claude Code, Cursor and other coding agents locally. Its privacy design also means the vendor has no retention data to show you.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Locality is the choice the rest of the design follows from. Nothing is uploaded, no internet connection is required, and a typical check finishes in under 50 milliseconds [2]. On a session that fires 200 tool calls, that is under ten seconds of added time across the whole run [1], which is less than the agent spends waiting on one model response. So the constraint is not overhead. It is prompt count, because what kills a local interceptor is fatigue, not latency.
That makes the default line the whole product. Michael Kantor, president of HOL, gives the design goal as "protect me without making the agent unusable" [5], and Balanced re-asks on secret and exfiltration access, destructive or encoded execution, prompt injection, dangerous MCP calls, malicious skills and persistence, warns on network egress and package scripts, and blocks attempts to bypass the guard itself [6]. Read the middle clause the other way: on the shipped setting, a package install script that opens a network connection is a warning a hurried developer scrolls past. Strict layers on low-confidence signals and Paranoid interrupts on any unfamiliar action from an external tool server, and neither is on out of the box [7].
Then the gap HOL is candid about. The package has passed 552,000 downloads, and the company notes that a download count measures machines that fetched it, not machines still running it [13]. Asked whether first-week users tighten to Strict or fall back to Gentle, Kantor told Help Net Security there is no defensible number, because local telemetry and cloud sync are off by default and anything quoted would be invented [11]. Nothing is collected without opt-in, so the vendor cannot observe its own install base [12]. That is a consistent trade rather than an evasion, and it also means no one outside a given machine can say whether this class of control survives a week of real work. What does exist is a local record of every allowed and blocked action, with a bad block reversible in one approval [14].
The published-signature question is the least of it. The trigger list is public deliberately, and Kantor argues that hiding detector signatures is not a real security boundary [8]. Behind the simple checks sits parsing of actual command structure across wrappers, pipelines, redirects and embedded commands, plus executable and provenance checks, sensitive-path access, network destinations and artifact hash changes [9]. He also says pattern matching has not been eliminated and is one input among several [10]. Help Net Security's own read is that someone who reads the source can probably reword a command past the simple checks, and that fooling the layer watching what a command does is harder [17].
HOL calls the tool "not a complete prompt-injection preventer" and attaches no safety promise to the scores from its companion plugin scanner [15]. Those disclaimers are the useful part of the pitch. A free, locally run approval boundary at the command layer [1] is a reasonable thing to put in front of an agent that already has shell access. Whether it earns its interruptions is a question with exactly one place to be answered, and it is not on the vendor's side of the wire.
Ranked by verification strength, evidence, and original report placement.
HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on; when the assistant tries something risky it pauses and asks the user first. It is available free on GitHub.
HOL Guard installs in about a minute, runs on the user's own machine, a typical check takes under 50 milliseconds, files are never uploaded, and it works with no internet connection.
The people exposed are anyone using Claude Code, Cursor, Codex, Gemini CLI, OpenCode, Hermes, or OpenClaw.
HOL Guard ships four settings: Gentle, Balanced, Strict and Paranoid. Balanced is the default.
Michael Kantor, president of HOL, describes the design goal as "protect me without making the agent unusable."
Kantor says Balanced "asks again on things like secret/exfiltration access, destructive or encoded execution, prompt injection, dangerous MCP calls, malicious skills and persistence; warns on network egress/package scripts; and blocks attempts to bypass HOL Guard itself."
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single outlet, vendor-sourced technical detail
All substantive detail comes from one publisher relaying HOL's president: mode behavior, detection architecture, install time and sub-50ms latency are vendor assertions with no benchmark, code review or third-party test in the cluster. Evidence quality is lifted by the tool being open source and free to inspect, by unusually specific on-record quotes, and by the vendor volunteering its own limits (public signatures, retained pattern matching, incomplete prompt-injection coverage). It is held down by the absence of any independent verification and by the publisher's own evasion judgment being asserted without demonstration.
Half a million downloads, zero retention signal
There is one hard quantitative datapoint -- 552,000+ downloads -- plus verified public availability across seven named agent clients, which is real distribution evidence. But the vendor states on the record that it has no defensible Strict-vs-Gentle, churn or first-week conversion number because telemetry and cloud sync are off by default, and the article itself notes downloads do not indicate installs still switched on. No named deployments, enterprise rollouts or user counts appear, so measured adoption stays low despite the download figure.
Mildly overstated by framing, restrained by disclosure
The "antivirus for AI agents" framing and a 552,000-download headline number invite a stronger inference of protection and uptake than the evidence supports, and the strongest defensive claim -- the behavioral layer -- is unverified. That gap is largely offset by candor rare in tool coverage: the vendor concedes it is "not a complete prompt-injection preventer," that pattern matching remains, that its scanner scores promise nothing, and that it has no adoption or retention numbers at all, while the publisher itself discounts downloads as a proxy for active use. Net result is a small positive gap driven by framing rather than by claim inflation.
Vendor-supplied narrative in a tool-promotion format
The only technical voice is HOL's president, speaking about a product his company distributes, and the piece follows an open-source-tool showcase format that ends with GitHub availability, related tool roundups and a newsletter subscription call to action -- both sides benefit from the write-up existing. Offsetting factors are real: the tool is free and inspectable, the vendor's disclosures cut against its own marketing interest, and the article presses the uncomfortable retention question rather than avoiding it. The vendor's cloud-sync option is the one visible commercial adjacency and is disclosed as off by default.
Clear, candid, but uncorroborated
Confidence is moderate: the facts are internally consistent, precisely quoted, recent, and concern an open-source artifact anyone can check, and the most load-bearing negative claim -- that no retention data exists -- comes from the party that would most want to claim otherwise. It is capped by single-publisher sourcing, vendor-only technical description, no independent testing of detection or latency, and adoption that cannot be verified beyond a download counter.
build
Superpowers makes spec-driven work a precondition, then ships it to twelve harnesses1 distinct publisher
build
NVIDIA put a number on agent skills: 300+ verified, two harnesses, baselines under 50/1001 distinct publisher
build
Waku 0.1.0 bets the product is the control plane, not another coding agent1 distinct publisher
invest
65,000 pulls a day, one author: the AI coding stack's unpriced dependency1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 24, 2026