Applies to: Guard >= 0.5.0
Maintained by: HOL Guard Team Guard docs
Guard documentation Published guides for HOL Guard and plugin-scanner, pulled from the AI Plugin Scanner library docs so the product page stays aligned with the canonical documentation source.
Security trust packet Architecture boundary, release proof, issue intake, SIEM examples, and Enterprise handoff.
Open packet Browse guides
Search guides
OverviewAI Plugin Scanner overview
Product map for HOL Guard, plugin-scanner, and the GitHub Action wrapper.
HOL GuardGuard get started
Run guided Guard init, connect Cloud when useful, record the first baseline, and start protecting harness launches.
Local-first runtime and approvals
Follow the pre-launch Guard loop for local evaluation, inline approvals, and blocked harness runs.
Local-first and optional cloud
See which protections stay local by default, what shared cloud features add later, and when sync is worth turning on.
Approval center and audit trail
Review queued approvals, receipt evidence, diff history, and the local approval center audit workflow.
Guard architecture
Understand the runtime layers behind harness detection, policy evaluation, receipts, and launch interception.
Harness support matrix
See how Codex, Claude Code, Cursor, Gemini, and OpenCode are handled today.
Codex harness
Set up Guard in front of Codex, understand its approval center flow, and validate project versus global MCP scope.
Claude Code harness
Use Guard with Claude hooks, workspace agents, and the strongest current deferred approval path.
Cursor harness
Keep Cursor native tool approvals while Guard handles artifact trust and runtime MCP sanity checks.
Gemini harness
Inspect Gemini extension manifests, embedded MCP servers, and the Guard approval center path for blocked changes.
OpenCode harness
Track OpenCode config, JSONC, and workspace command surfaces while preserving OpenCode native permissions.
Policy presets
Apply bundled rule sets for strict, balanced, or permissive security postures.
Mitigation guidance
Read and act on mitigation recommendations for supply-chain risks.
Testing and validation
Use the release validation loop for harness smoke coverage, manual checks, and Guard canaries.
Event routing workflows
Build event routing workflows that send Guard events to Slack, Jira, GitHub, email, webhooks, and AI responders.
Guard CloudGuard Cloud command center
Understand the signed-in Guard console, route map, and how local Guard hands off to the cloud command center.
Devices and shared trust memory
See how Guard tracks protected devices, harness coverage, last seen status, and cross-device trust memory.
Inventory, ABOM, and artifact detail
Learn when to use inventory, ABOM, or per-artifact detail to inspect the shared Guard trust estate.
Receipts, changes, and history
Follow the decision loop from latest receipt evidence to changed approvals and long-term artifact history.
Alerts, watchlists, and advisories
Control Guard digests, watchlists, and advisory-aware follow-up so only the right risks break through.
Team policy and delegated approvals
Document seeded Guard policy packs, team and repo inheritance, break-glass governance, and delegated approvals for workspace operators.
Exceptions and expiring windows
Explain repo and harness scoped bypass windows, approval queues, expiry handling, and audit export without turning exceptions into permanent policy.
Billing, credits, and plans
Clarify what stays local, what Guard Cloud meters, and which plan or credit pressure actually matters.
IntegrationsIntegrations overview
Route Guard investigation alerts to Slack, GitHub, Jira, PagerDuty, email, or webhooks.
Slack
Connect Slack, select channels, and manage OAuth scopes for alert routing.
GitHub
Install the GitHub App, select repositories, and track investigations as issues.
Jira
Connect Jira, select projects, and map issue types for investigation tracking.
PagerDuty
Connect PagerDuty services and configure urgency levels for critical investigations.
Email
Configure owner inbox routing, delivery modes, and redaction for email alerts.
Webhook
Configure webhook endpoints, verify HMAC signatures, and handle retry logic.
RoutingRouting overview
How Guard workflows route alerts through triggers, enrichment, conditions, controls, and actions.
Triggers
Event types that start workflows and how to configure trigger criteria.
Enrichment
Enrich alerts with registry metadata, vulnerability data, and trust scores.
Conditions
Route alerts based on severity, trust score, or custom criteria with conditional branching.
Controls
Pacing, deduplication, rate limiting, and business-hours windows for alert routing.
Actions
Notification and issue-creation actions for multi-provider alert routing.
Terminals
Terminal states, audit trails, and workflow resolution tracking.
Plugin ScannerScanner quick start
Install the scanner, run the main commands, and understand supported ecosystems.
Ecosystems and repository mode
Scan one plugin package or an entire marketplace-style repository across supported ecosystems.
Quality suite commands
Choose between scan, lint, verify, submit, and doctor based on the release question you need to answer.
Policies, output, and trust provenance
Policy profiles, config files, output formats, and trust provenance references.
Trust provenance guide
See how bundled skills, MCP config, and plugin trust are explained and surfaced.
Report formats and CI automation
Export text, JSON, Markdown, or SARIF output and wire the scanner into local hooks or CI workflows.
GitHub ActionGitHub Action quality gate
Use the action wrapper in PR checks, SARIF upload flows, and submission pipelines.
Submission and registry payloads
Open or reuse submission issues and export registry payload artifacts from the same workflow run.
docs/libraries/ai-plugin-scanner
Plugin Scanner
Scanner quick start
Next
Ecosystems and repository mode
Applies to: Guard >= 0.5.0
Maintained by: HOL Guard Team Guard docs
Guard documentation Published guides for HOL Guard and plugin-scanner, pulled from the AI Plugin Scanner library docs so the product page stays aligned with the canonical documentation source.
Security trust packet Architecture boundary, release proof, issue intake, SIEM examples, and Enterprise handoff.
Open packet Browse guides
Search guides
OverviewAI Plugin Scanner overview
Product map for HOL Guard, plugin-scanner, and the GitHub Action wrapper.
HOL GuardGuard get started
Run guided Guard init, connect Cloud when useful, record the first baseline, and start protecting harness launches.
Local-first runtime and approvals
Follow the pre-launch Guard loop for local evaluation, inline approvals, and blocked harness runs.
Local-first and optional cloud
See which protections stay local by default, what shared cloud features add later, and when sync is worth turning on.
Approval center and audit trail
Review queued approvals, receipt evidence, diff history, and the local approval center audit workflow.
Guard architecture
Understand the runtime layers behind harness detection, policy evaluation, receipts, and launch interception.
Harness support matrix
See how Codex, Claude Code, Cursor, Gemini, and OpenCode are handled today.
Codex harness
Set up Guard in front of Codex, understand its approval center flow, and validate project versus global MCP scope.
Claude Code harness
Use Guard with Claude hooks, workspace agents, and the strongest current deferred approval path.
Cursor harness
Keep Cursor native tool approvals while Guard handles artifact trust and runtime MCP sanity checks.
Gemini harness
Inspect Gemini extension manifests, embedded MCP servers, and the Guard approval center path for blocked changes.
OpenCode harness
Track OpenCode config, JSONC, and workspace command surfaces while preserving OpenCode native permissions.
Policy presets
Apply bundled rule sets for strict, balanced, or permissive security postures.
Mitigation guidance
Read and act on mitigation recommendations for supply-chain risks.
Testing and validation
Use the release validation loop for harness smoke coverage, manual checks, and Guard canaries.
Event routing workflows
Build event routing workflows that send Guard events to Slack, Jira, GitHub, email, webhooks, and AI responders.
Guard CloudGuard Cloud command center
Understand the signed-in Guard console, route map, and how local Guard hands off to the cloud command center.
Devices and shared trust memory
See how Guard tracks protected devices, harness coverage, last seen status, and cross-device trust memory.
Inventory, ABOM, and artifact detail
Learn when to use inventory, ABOM, or per-artifact detail to inspect the shared Guard trust estate.
Receipts, changes, and history
Follow the decision loop from latest receipt evidence to changed approvals and long-term artifact history.
Alerts, watchlists, and advisories
Control Guard digests, watchlists, and advisory-aware follow-up so only the right risks break through.
Team policy and delegated approvals
Document seeded Guard policy packs, team and repo inheritance, break-glass governance, and delegated approvals for workspace operators.
Exceptions and expiring windows
Explain repo and harness scoped bypass windows, approval queues, expiry handling, and audit export without turning exceptions into permanent policy.
Billing, credits, and plans
Clarify what stays local, what Guard Cloud meters, and which plan or credit pressure actually matters.
IntegrationsIntegrations overview
Route Guard investigation alerts to Slack, GitHub, Jira, PagerDuty, email, or webhooks.
Slack
Connect Slack, select channels, and manage OAuth scopes for alert routing.
GitHub
Install the GitHub App, select repositories, and track investigations as issues.
Jira
Connect Jira, select projects, and map issue types for investigation tracking.
PagerDuty
Connect PagerDuty services and configure urgency levels for critical investigations.
Email
Configure owner inbox routing, delivery modes, and redaction for email alerts.
Webhook
Configure webhook endpoints, verify HMAC signatures, and handle retry logic.
RoutingRouting overview
How Guard workflows route alerts through triggers, enrichment, conditions, controls, and actions.
Triggers
Event types that start workflows and how to configure trigger criteria.
Enrichment
Enrich alerts with registry metadata, vulnerability data, and trust scores.
Conditions
Route alerts based on severity, trust score, or custom criteria with conditional branching.
Controls
Pacing, deduplication, rate limiting, and business-hours windows for alert routing.
Actions
Notification and issue-creation actions for multi-provider alert routing.
Terminals
Terminal states, audit trails, and workflow resolution tracking.
Plugin ScannerScanner quick start
Install the scanner, run the main commands, and understand supported ecosystems.
Ecosystems and repository mode
Scan one plugin package or an entire marketplace-style repository across supported ecosystems.
Quality suite commands
Choose between scan, lint, verify, submit, and doctor based on the release question you need to answer.
Policies, output, and trust provenance
Policy profiles, config files, output formats, and trust provenance references.
Trust provenance guide
See how bundled skills, MCP config, and plugin trust are explained and surfaced.
Report formats and CI automation
Export text, JSON, Markdown, or SARIF output and wire the scanner into local hooks or CI workflows.
GitHub ActionGitHub Action quality gate
Use the action wrapper in PR checks, SARIF upload flows, and submission pipelines.
Submission and registry payloads
Open or reuse submission issues and export registry payload artifacts from the same workflow run.
docs/libraries/ai-plugin-scanner
Plugin Scanner
Scanner quick start
Next
Ecosystems and repository mode
plugin-scanner is the maintainer and CI-facing quality suite inside hashgraph-online/ai-plugin-scanner.
Use it after a plugin is scaffolded and before release, registry ingestion, or GitHub review.
Copy pip install plugin-scanner
For isolated shells:
Copy pipx install plugin-scanner
Optional Cisco-backed MCP analysis is available on supported Python versions:
Copy pip install "plugin-scanner[cisco]"
Copy plugin-scanner lint .
plugin-scanner verify .
plugin-scanner scan . --format json
Add online probing when you want runtime endpoint validation:
Copy plugin-scanner verify . --online
Use doctor when you want targeted diagnostics and a bundle you can attach to support or CI output:
Copy plugin-scanner doctor . --component mcp --bundle dist/doctor.zip
Copy plugin-scanner --list-ecosystems
Current built-in ecosystem adapters:
Codex
Claude Code
Gemini CLI
OpenCode
Detection surfaces:
Ecosystem Detection surfaces Codex .codex-plugin/plugin.json, marketplace.json, .agents/plugins/marketplace.jsonClaude Code .claude-plugin/plugin.json, .claude-plugin/marketplace.jsonGemini CLI gemini-extension.json, commands/**/*.tomlOpenCode opencode.json, opencode.jsonc, .opencode/commands, .opencode/plugins
Command Purpose scanweighted repository or plugin scan with policy evaluation lintrule-level findings, --list-rules, --explain, and safe autofix support verifyruntime and install-surface readiness checks, with optional --online probing submitscan + verify + policy gate that emits a plugin-quality artifact doctortargeted diagnostics and troubleshooting bundles
If your repository uses a Codex marketplace root like .agents/plugins/marketplace.json, keep plugin_dir: ".". The scanner will discover local ./plugins/... entries automatically, scan each local plugin manifest, and skip remote marketplace entries instead of treating the repository root as one plugin.
plugin-scanner currently covers:
plugin manifests and marketplace metadata
MCP stdio and remote HTTP verification
skills, assets, and .app.json surfaces
security posture such as secrets, dangerous commands, action pinning, and lockfiles
trust provenance for skills, MCP configuration, and top-level plugin packages
Ecosystems and repository mode
Quality suite commands
Policies, output, and trust provenance
GitHub Action quality gate
Guard get started
Docs Best Agents Community More Settings Copyright © 2026 HOL DAO LLC. All rights reserved.
plugin-scanner is the maintainer and CI-facing quality suite inside hashgraph-online/ai-plugin-scanner.
Use it after a plugin is scaffolded and before release, registry ingestion, or GitHub review.
Copy pip install plugin-scanner
For isolated shells:
Copy pipx install plugin-scanner
Optional Cisco-backed MCP analysis is available on supported Python versions:
Copy pip install "plugin-scanner[cisco]"
Copy plugin-scanner lint .
plugin-scanner verify .
plugin-scanner scan . --format json
Add online probing when you want runtime endpoint validation:
Copy plugin-scanner verify . --online
Use doctor when you want targeted diagnostics and a bundle you can attach to support or CI output:
Copy plugin-scanner doctor . --component mcp --bundle dist/doctor.zip
Copy plugin-scanner --list-ecosystems
Current built-in ecosystem adapters:
Codex
Claude Code
Gemini CLI
OpenCode
Detection surfaces:
Ecosystem Detection surfaces Codex .codex-plugin/plugin.json, marketplace.json, .agents/plugins/marketplace.jsonClaude Code .claude-plugin/plugin.json, .claude-plugin/marketplace.jsonGemini CLI gemini-extension.json, commands/**/*.tomlOpenCode opencode.json, opencode.jsonc, .opencode/commands, .opencode/plugins
Command Purpose scanweighted repository or plugin scan with policy evaluation lintrule-level findings, --list-rules, --explain, and safe autofix support verifyruntime and install-surface readiness checks, with optional --online probing submitscan + verify + policy gate that emits a plugin-quality artifact doctortargeted diagnostics and troubleshooting bundles
If your repository uses a Codex marketplace root like .agents/plugins/marketplace.json, keep plugin_dir: ".". The scanner will discover local ./plugins/... entries automatically, scan each local plugin manifest, and skip remote marketplace entries instead of treating the repository root as one plugin.
plugin-scanner currently covers:
plugin manifests and marketplace metadata
MCP stdio and remote HTTP verification
skills, assets, and .app.json surfaces
security posture such as secrets, dangerous commands, action pinning, and lockfiles
trust provenance for skills, MCP configuration, and top-level plugin packages
Ecosystems and repository mode
Quality suite commands
Policies, output, and trust provenance
GitHub Action quality gate
Guard get started
Docs Best Agents Community More Settings Copyright © 2026 HOL DAO LLC. All rights reserved.