HOL Guard is local-first runtime control for AI coding agents. It governs high-risk actions such as shell execution, secret-file reads, MCP server changes, and plugin/skill installs. Apache-2.0 open source. It is not a cloud MCP gateway, not a complete prompt-injection preventer, and not a secrets manager or SCA replacement.
Coding agents need runtime guardrails that stay on the developer machine. We built HOL Guard so teams can control agent actions locally without sending traffic through a cloud proxy.