HOL Guard runs on your own machine — the client starts it, so there is no endpoint to ping. 90 145 installs a week from pypi. Last commit 10 Sep 2026.
Local-first AI agent security evidence and approval workflows through HOL Guard's stdio MCP server.
We read the source, 13 h ago · rules 3dff92dd89df
Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.
r">\s*(?:/proc/\S+|/dev/tcp/|/dev/udp/)",
| "doas"
return any("npm" in match.family.lower() or ".npmrc" in match.requested_path.lower() for match in secret_matches)
result = subprocess.run(cmd, input=message, capture_output=True, text=True, timeout=30)
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
re.compile(r"~/Library/LaunchAgents/", re.IGNORECASE),
rf"^\s*(?:(?:{_SAFE_INTERPRETER_SETUP_SEGMENT_PATTERN})\s*&&\s*)*(?P<interpreter>[^\s;&|<>$`]*(?:perl|pythonw?(?:\d+(?:\.\d+)*)?(?:\.exe)?|ruby))\b(?P<args>[^\n;&|]*)<<-?\s*(?P<quote>['\"]?)(?P<tag>[^\s'\";|&<>]+)(?P=quote)\s*\n(?P<body>.*)\n(?P=tag)\s*$",
result = subprocess.run(
operation = pickle.load(handle)
requested_path = os.path.join(directory_text, requested_name)
/\.npmrc/i,
environment = dict(os.environ if environ is None else environ)
r"webhook\.site|hooks\.slack\.com|discord\.com|pastebin\.com|gist\.github\.com|transfer\.sh|requestbin"
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
Code changes quietly between releases, and nobody reads the diff of a dependency. We do, on every release — watch HOL Guard and you get told the day something new turns up.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add hol-guard -- uvx hol-guard
{
"mcpServers": {
"hol-guard": {
"args": [
"hol-guard"
],
"command": "uvx"
}
}
}
[mcp_servers.hol-guard]
command = "uvx"
args = ["hol-guard"]
{
"mcpServers": {
"hol-guard": {
"args": [
"hol-guard"
],
"command": "uvx"
}
}
}
{
"mcpServers": {
"hol-guard": {
"args": [
"hol-guard"
],
"command": "uvx"
}
}
}
Local-first privacy MCP server for sensitive AI workflows
AI Agent Guardrails MCP server - security layer
Local-first document MCP for AI agents: create, read, secure and sign PDF/Word/Excel/PPTX.
Security scanner for AI agent skills and MCP servers
Control Krita through a secure local MCP server and authenticated Windows bridge.
Evidence-traced codebase understanding and security scanning for AI agents over MCP.
RunSec MCP server for workspace security scanning and remediation workflows.
Security-first MCP server that connects any OpenAPI, GraphQL, gRPC or SOAP API to AI agents.
Answers built from our own checks of this server.