Applies to: Guard >= 0.5.0
Maintained by: HOL Guard Team Guard docs
Guard documentation Published guides for HOL Guard and plugin-scanner, pulled from the AI Plugin Scanner library docs so the product page stays aligned with the canonical documentation source.
Security trust packet Architecture boundary, release proof, issue intake, SIEM examples, and Enterprise handoff.
Open packet Browse guides
Search guides
OverviewAI Plugin Scanner overview
Product map for HOL Guard, plugin-scanner, and the GitHub Action wrapper.
HOL GuardGuard get started
Run guided Guard init, connect Cloud when useful, record the first baseline, and start protecting harness launches.
Local-first runtime and approvals
Follow the pre-launch Guard loop for local evaluation, inline approvals, and blocked harness runs.
Local-first and optional cloud
See which protections stay local by default, what shared cloud features add later, and when sync is worth turning on.
Approval center and audit trail
Review queued approvals, receipt evidence, diff history, and the local approval center audit workflow.
Guard architecture
Understand the runtime layers behind harness detection, policy evaluation, receipts, and launch interception.
Harness support matrix
See how Codex, Claude Code, Cursor, Gemini, and OpenCode are handled today.
Codex harness
Set up Guard in front of Codex, understand its approval center flow, and validate project versus global MCP scope.
Claude Code harness
Use Guard with Claude hooks, workspace agents, and the strongest current deferred approval path.
Cursor harness
Keep Cursor native tool approvals while Guard handles artifact trust and runtime MCP sanity checks.
Gemini harness
Inspect Gemini extension manifests, embedded MCP servers, and the Guard approval center path for blocked changes.
OpenCode harness
Track OpenCode config, JSONC, and workspace command surfaces while preserving OpenCode native permissions.
Policy presets
Apply bundled rule sets for strict, balanced, or permissive security postures.
Mitigation guidance
Read and act on mitigation recommendations for supply-chain risks.
Testing and validation
Use the release validation loop for harness smoke coverage, manual checks, and Guard canaries.
Event routing workflows
Build event routing workflows that send Guard events to Slack, Jira, GitHub, email, webhooks, and AI responders.
Guard CloudGuard Cloud command center
Understand the signed-in Guard console, route map, and how local Guard hands off to the cloud command center.
Devices and shared trust memory
See how Guard tracks protected devices, harness coverage, last seen status, and cross-device trust memory.
Inventory, ABOM, and artifact detail
Learn when to use inventory, ABOM, or per-artifact detail to inspect the shared Guard trust estate.
Receipts, changes, and history
Follow the decision loop from latest receipt evidence to changed approvals and long-term artifact history.
Alerts, watchlists, and advisories
Control Guard digests, watchlists, and advisory-aware follow-up so only the right risks break through.
Team policy and delegated approvals
Document seeded Guard policy packs, team and repo inheritance, break-glass governance, and delegated approvals for workspace operators.
Exceptions and expiring windows
Explain repo and harness scoped bypass windows, approval queues, expiry handling, and audit export without turning exceptions into permanent policy.
Billing, credits, and plans
Clarify what stays local, what Guard Cloud meters, and which plan or credit pressure actually matters.
IntegrationsIntegrations overview
Route Guard investigation alerts to Slack, GitHub, Jira, PagerDuty, email, or webhooks.
Slack
Connect Slack, select channels, and manage OAuth scopes for alert routing.
GitHub
Install the GitHub App, select repositories, and track investigations as issues.
Jira
Connect Jira, select projects, and map issue types for investigation tracking.
PagerDuty
Connect PagerDuty services and configure urgency levels for critical investigations.
Email
Configure owner inbox routing, delivery modes, and redaction for email alerts.
Webhook
Configure webhook endpoints, verify HMAC signatures, and handle retry logic.
RoutingRouting overview
How Guard workflows route alerts through triggers, enrichment, conditions, controls, and actions.
Triggers
Event types that start workflows and how to configure trigger criteria.
Enrichment
Enrich alerts with registry metadata, vulnerability data, and trust scores.
Conditions
Route alerts based on severity, trust score, or custom criteria with conditional branching.
Controls
Pacing, deduplication, rate limiting, and business-hours windows for alert routing.
Actions
Notification and issue-creation actions for multi-provider alert routing.
Terminals
Terminal states, audit trails, and workflow resolution tracking.
Plugin ScannerScanner quick start
Install the scanner, run the main commands, and understand supported ecosystems.
Ecosystems and repository mode
Scan one plugin package or an entire marketplace-style repository across supported ecosystems.
Quality suite commands
Choose between scan, lint, verify, submit, and doctor based on the release question you need to answer.
Policies, output, and trust provenance
Policy profiles, config files, output formats, and trust provenance references.
Trust provenance guide
See how bundled skills, MCP config, and plugin trust are explained and surfaced.
Report formats and CI automation
Export text, JSON, Markdown, or SARIF output and wire the scanner into local hooks or CI workflows.
GitHub ActionGitHub Action quality gate
Use the action wrapper in PR checks, SARIF upload flows, and submission pipelines.
Submission and registry payloads
Open or reuse submission issues and export registry payload artifacts from the same workflow run.
docs/libraries/ai-plugin-scanner
Plugin Scanner
Policies, output, and trust provenance
Previous
Quality suite commands
Next
Trust provenance guide
Applies to: Guard >= 0.5.0
Maintained by: HOL Guard Team Guard docs
Guard documentation Published guides for HOL Guard and plugin-scanner, pulled from the AI Plugin Scanner library docs so the product page stays aligned with the canonical documentation source.
Security trust packet Architecture boundary, release proof, issue intake, SIEM examples, and Enterprise handoff.
Open packet Browse guides
Search guides
OverviewAI Plugin Scanner overview
Product map for HOL Guard, plugin-scanner, and the GitHub Action wrapper.
HOL GuardGuard get started
Run guided Guard init, connect Cloud when useful, record the first baseline, and start protecting harness launches.
Local-first runtime and approvals
Follow the pre-launch Guard loop for local evaluation, inline approvals, and blocked harness runs.
Local-first and optional cloud
See which protections stay local by default, what shared cloud features add later, and when sync is worth turning on.
Approval center and audit trail
Review queued approvals, receipt evidence, diff history, and the local approval center audit workflow.
Guard architecture
Understand the runtime layers behind harness detection, policy evaluation, receipts, and launch interception.
Harness support matrix
See how Codex, Claude Code, Cursor, Gemini, and OpenCode are handled today.
Codex harness
Set up Guard in front of Codex, understand its approval center flow, and validate project versus global MCP scope.
Claude Code harness
Use Guard with Claude hooks, workspace agents, and the strongest current deferred approval path.
Cursor harness
Keep Cursor native tool approvals while Guard handles artifact trust and runtime MCP sanity checks.
Gemini harness
Inspect Gemini extension manifests, embedded MCP servers, and the Guard approval center path for blocked changes.
OpenCode harness
Track OpenCode config, JSONC, and workspace command surfaces while preserving OpenCode native permissions.
Policy presets
Apply bundled rule sets for strict, balanced, or permissive security postures.
Mitigation guidance
Read and act on mitigation recommendations for supply-chain risks.
Testing and validation
Use the release validation loop for harness smoke coverage, manual checks, and Guard canaries.
Event routing workflows
Build event routing workflows that send Guard events to Slack, Jira, GitHub, email, webhooks, and AI responders.
Guard CloudGuard Cloud command center
Understand the signed-in Guard console, route map, and how local Guard hands off to the cloud command center.
Devices and shared trust memory
See how Guard tracks protected devices, harness coverage, last seen status, and cross-device trust memory.
Inventory, ABOM, and artifact detail
Learn when to use inventory, ABOM, or per-artifact detail to inspect the shared Guard trust estate.
Receipts, changes, and history
Follow the decision loop from latest receipt evidence to changed approvals and long-term artifact history.
Alerts, watchlists, and advisories
Control Guard digests, watchlists, and advisory-aware follow-up so only the right risks break through.
Team policy and delegated approvals
Document seeded Guard policy packs, team and repo inheritance, break-glass governance, and delegated approvals for workspace operators.
Exceptions and expiring windows
Explain repo and harness scoped bypass windows, approval queues, expiry handling, and audit export without turning exceptions into permanent policy.
Billing, credits, and plans
Clarify what stays local, what Guard Cloud meters, and which plan or credit pressure actually matters.
IntegrationsIntegrations overview
Route Guard investigation alerts to Slack, GitHub, Jira, PagerDuty, email, or webhooks.
Slack
Connect Slack, select channels, and manage OAuth scopes for alert routing.
GitHub
Install the GitHub App, select repositories, and track investigations as issues.
Jira
Connect Jira, select projects, and map issue types for investigation tracking.
PagerDuty
Connect PagerDuty services and configure urgency levels for critical investigations.
Email
Configure owner inbox routing, delivery modes, and redaction for email alerts.
Webhook
Configure webhook endpoints, verify HMAC signatures, and handle retry logic.
RoutingRouting overview
How Guard workflows route alerts through triggers, enrichment, conditions, controls, and actions.
Triggers
Event types that start workflows and how to configure trigger criteria.
Enrichment
Enrich alerts with registry metadata, vulnerability data, and trust scores.
Conditions
Route alerts based on severity, trust score, or custom criteria with conditional branching.
Controls
Pacing, deduplication, rate limiting, and business-hours windows for alert routing.
Actions
Notification and issue-creation actions for multi-provider alert routing.
Terminals
Terminal states, audit trails, and workflow resolution tracking.
Plugin ScannerScanner quick start
Install the scanner, run the main commands, and understand supported ecosystems.
Ecosystems and repository mode
Scan one plugin package or an entire marketplace-style repository across supported ecosystems.
Quality suite commands
Choose between scan, lint, verify, submit, and doctor based on the release question you need to answer.
Policies, output, and trust provenance
Policy profiles, config files, output formats, and trust provenance references.
Trust provenance guide
See how bundled skills, MCP config, and plugin trust are explained and surfaced.
Report formats and CI automation
Export text, JSON, Markdown, or SARIF output and wire the scanner into local hooks or CI workflows.
GitHub ActionGitHub Action quality gate
Use the action wrapper in PR checks, SARIF upload flows, and submission pipelines.
Submission and registry payloads
Open or reuse submission issues and export registry payload artifacts from the same workflow run.
docs/libraries/ai-plugin-scanner
Plugin Scanner
Policies, output, and trust provenance
Previous
Quality suite commands
Next
Trust provenance guide
plugin-scanner separates quality scoring from trust provenance so maintainers can see both readiness and evidence.
The scanner ships with policy profiles such as:
default
public-marketplace
strict-security
It also supports baseline suppressions and repository-level configuration through .plugin-scanner.toml.
Example config:
Copy [scanner]
profile = "public-marketplace"
baseline_file = "baseline.txt"
ignore_paths = ["tests/*" , "fixtures/*" ]
[rules]
disabled = ["README_MISSING" ]
severity_overrides = { CODEXIGNORE_MISSING = "low" }
[verification]
online = false
[submission]
repos = ["hashgraph-online/awesome-codex-plugins" ]
labels = ["plugin-submission" ]
Common output modes:
text for local terminal review
JSON for CI and downstream automation
Markdown for reviewer-facing summaries
SARIF for GitHub code scanning
Examples:
Copy plugin-scanner scan . --format text
plugin-scanner scan . --format json
plugin-scanner scan . --format markdown
plugin-scanner scan . --format sarif --output plugin-scanner.sarif
You can also fail CI on severity thresholds:
Copy plugin-scanner scan . --fail-on-severity high
The scanner can emit policy outputs such as:
score
grade
policy_pass
verify_pass
max_severity
That makes it easy to gate review, registry ingestion, or release workflows on one predictable artifact.
The scanner emits explicit trust provenance alongside quality grades:
bundled skills use published HCS-28 baseline adapter IDs, weights, and denominator rules
MCP configuration trust uses HCS-style adapter and contribution-mode patterns
top-level plugin trust follows the same pattern locally
Start with the local trust guide:
Container-first environments can use the published image:
Copy docker run --rm \
-v "$PWD :/workspace" \
ghcr.io/hashgraph-online/ai-plugin-scanner:<version> \
scan /workspace --format text
Scanner quick start
Quality suite commands
Report formats and CI automation
Trust provenance guide
GitHub Action quality gate
Local-first runtime and approvals
Docs Best Agents Community More Settings Copyright © 2026 HOL DAO LLC. All rights reserved.
plugin-scanner separates quality scoring from trust provenance so maintainers can see both readiness and evidence.
The scanner ships with policy profiles such as:
default
public-marketplace
strict-security
It also supports baseline suppressions and repository-level configuration through .plugin-scanner.toml.
Example config:
Copy [scanner]
profile = "public-marketplace"
baseline_file = "baseline.txt"
ignore_paths = ["tests/*" , "fixtures/*" ]
[rules]
disabled = ["README_MISSING" ]
severity_overrides = { CODEXIGNORE_MISSING = "low" }
[verification]
online = false
[submission]
repos = ["hashgraph-online/awesome-codex-plugins" ]
labels = ["plugin-submission" ]
Common output modes:
text for local terminal review
JSON for CI and downstream automation
Markdown for reviewer-facing summaries
SARIF for GitHub code scanning
Examples:
Copy plugin-scanner scan . --format text
plugin-scanner scan . --format json
plugin-scanner scan . --format markdown
plugin-scanner scan . --format sarif --output plugin-scanner.sarif
You can also fail CI on severity thresholds:
Copy plugin-scanner scan . --fail-on-severity high
The scanner can emit policy outputs such as:
score
grade
policy_pass
verify_pass
max_severity
That makes it easy to gate review, registry ingestion, or release workflows on one predictable artifact.
The scanner emits explicit trust provenance alongside quality grades:
bundled skills use published HCS-28 baseline adapter IDs, weights, and denominator rules
MCP configuration trust uses HCS-style adapter and contribution-mode patterns
top-level plugin trust follows the same pattern locally
Start with the local trust guide:
Container-first environments can use the published image:
Copy docker run --rm \
-v "$PWD :/workspace" \
ghcr.io/hashgraph-online/ai-plugin-scanner:<version> \
scan /workspace --format text
Scanner quick start
Quality suite commands
Report formats and CI automation
Trust provenance guide
GitHub Action quality gate
Local-first runtime and approvals
Docs Best Agents Community More Settings Copyright © 2026 HOL DAO LLC. All rights reserved.