Control what your coding agent can do
Giving an AI coding agent access to a terminal is useful, but it also gives the agent ways to change files, install packages and access sensitive configuration. HOL Guard adds a policy checkpoint to supported agent workflows: a covered action can be allowed, paused for review or blocked before it has side effects. You can inspect the decision instead of relying only on the agent's explanation.
Local protection without a subscription
The publisher offers a permanently free local workflow on one machine. Local policy, approval prompts and decision receipts do not require a cloud account or a paid subscription. The Guard Local runtime is open source under Apache-2.0, so developers can inspect its implementation and licensing.
Guard Cloud is a separate, optional service. Cross-device history, shared team policies, fleet dashboards and some connected workflows belong to cloud plans. Those services should not be confused with the free local runtime or with the subscriptions charged by an AI model provider.
What the runtime checks
- Commands and file access: review covered destructive operations, sensitive paths and suspicious outbound commands.
- Packages and extensions: inspect supported package-install workflows and changes to plugins, skills or agent settings.
- MCP configuration and tools: apply controls through supported hooks and managed proxies.
- Approvals and evidence: keep local decision records that help explain why a covered action was permitted or stopped.
Integration is specific to the coding tool. The publisher documents support for tools including Claude Code, Codex, Cursor, OpenCode and Hermes, but they do not all expose identical events. Check the agent coverage matrix for your tool before assuming that a particular command or operation will be intercepted.
Desktop and command-line setup
The official installation page offers a Windows x64 MSI, a Linux x86_64 AppImage and an Apple-silicon macOS desktop download requiring macOS 13 or later. Desktop provides a local control center; the Guard runtime makes the security decisions. A separate command-line installation is available for users who prefer managing their setup in a terminal and requires Python 3.10 or newer.
The publisher currently labels Windows CLI support experimental and recommends WSL for that route. This is distinct from the availability of the Windows Desktop MSI. Follow the official setup guide, select your coding agent and verify the integration after installation.
Understand the security boundary
HOL Guard is not a conventional system antivirus, a network firewall or a guarantee that every prompt injection will be prevented. Enforcement depends on the selected integration, the events it exposes and the configured policy. It complements careful permissions and the agent's own approval controls rather than replacing them.
Local decision-making and optional cloud synchronization are different paths. Review the publisher's data-handling documentation before enabling connected features. Our description is based on the official product documentation and pricing details, not an executed test of the installer.
- Best for
- Developers who want policy checks and review prompts around AI coding-agent actions.
- Good to know
- Coverage depends on the agent and event. Cloud features are optional and paid; Windows CLI support is experimental.
Checking an existing integration
Before trusting a managed agent launch, review the publisher's diagnostic instructions. The CLI offers hol-guard status for the current state and hol-guard doctor for setup checks. Review pending approvals and decision receipts to understand the configured policy. A successful installation alone does not establish that every action exposed by your coding tool is covered.