HOL Guard
Local-first runtime firewall that intercepts AI coding agent tool calls before they run
HOL Guard sits between an AI coding agent and the machine it runs on, checking each tool call before it executes. Shell commands, file reads, package installs and MCP server calls are evaluated against policy, then blocked or held for approval.
The stated targets are secret and credential exposure, destructive file operations, prompt injection and malicious packages. Everything runs locally, so prompts and files are not sent anywhere, and it works offline.
Supported harnesses include Claude Code, Codex, Cursor, OpenCode, Gemini CLI and OpenClaw. The Guard Local runtime is open source under Apache-2.0; the hosted app and enterprise features are separate.
HOL Guard Alternatives
Explore 48 products in the Observability & Analytics category. View all HOL Guard alternatives.
EidoStack
Browser workspace for comparing LLM responses side by side using your own API keys
Weckr
Tracks LLM cost and margin per end customer, with spending caps that fire before the call
RAGAS
Open-source evaluation and testing framework for LLM and RAG applications
Work on HOL Guard? Feature it at the top of Observability & Analytics.
Is your product missing?