Applies to: Guard >= 0.5.0
Maintained by: HOL Guard Team Guard docs
Guard documentation Published guides for HOL Guard and plugin-scanner, pulled from the AI Plugin Scanner library docs so the product page stays aligned with the canonical documentation source.
Security trust packet Architecture boundary, release proof, issue intake, SIEM examples, and Enterprise handoff.
Open packet Browse guides
Search guides
OverviewAI Plugin Scanner overview
Product map for HOL Guard, plugin-scanner, and the GitHub Action wrapper.
HOL GuardGuard get started
Run guided Guard init, connect Cloud when useful, record the first baseline, and start protecting harness launches.
Local-first runtime and approvals
Follow the pre-launch Guard loop for local evaluation, inline approvals, and blocked harness runs.
Local-first and optional cloud
See which protections stay local by default, what shared cloud features add later, and when sync is worth turning on.
Approval center and audit trail
Review queued approvals, receipt evidence, diff history, and the local approval center audit workflow.
Guard architecture
Understand the runtime layers behind harness detection, policy evaluation, receipts, and launch interception.
Harness support matrix
See how Codex, Claude Code, Cursor, Gemini, and OpenCode are handled today.
Codex harness
Set up Guard in front of Codex, understand its approval center flow, and validate project versus global MCP scope.
Claude Code harness
Use Guard with Claude hooks, workspace agents, and the strongest current deferred approval path.
Cursor harness
Keep Cursor native tool approvals while Guard handles artifact trust and runtime MCP sanity checks.
Gemini harness
Inspect Gemini extension manifests, embedded MCP servers, and the Guard approval center path for blocked changes.
OpenCode harness
Track OpenCode config, JSONC, and workspace command surfaces while preserving OpenCode native permissions.
Policy presets
Apply bundled rule sets for strict, balanced, or permissive security postures.
Mitigation guidance
Read and act on mitigation recommendations for supply-chain risks.
Testing and validation
Use the release validation loop for harness smoke coverage, manual checks, and Guard canaries.
Event routing workflows
Build event routing workflows that send Guard events to Slack, Jira, GitHub, email, webhooks, and AI responders.
Guard CloudGuard Cloud command center
Understand the signed-in Guard console, route map, and how local Guard hands off to the cloud command center.
Devices and shared trust memory
See how Guard tracks protected devices, harness coverage, last seen status, and cross-device trust memory.
Inventory, ABOM, and artifact detail
Learn when to use inventory, ABOM, or per-artifact detail to inspect the shared Guard trust estate.
Receipts, changes, and history
Follow the decision loop from latest receipt evidence to changed approvals and long-term artifact history.
Alerts, watchlists, and advisories
Control Guard digests, watchlists, and advisory-aware follow-up so only the right risks break through.
Team policy and delegated approvals
Document seeded Guard policy packs, team and repo inheritance, break-glass governance, and delegated approvals for workspace operators.
Exceptions and expiring windows
Explain repo and harness scoped bypass windows, approval queues, expiry handling, and audit export without turning exceptions into permanent policy.
Billing, credits, and plans
Clarify what stays local, what Guard Cloud meters, and which plan or credit pressure actually matters.
IntegrationsIntegrations overview
Route Guard investigation alerts to Slack, GitHub, Jira, PagerDuty, email, or webhooks.
Slack
Connect Slack, select channels, and manage OAuth scopes for alert routing.
GitHub
Install the GitHub App, select repositories, and track investigations as issues.
Jira
Connect Jira, select projects, and map issue types for investigation tracking.
PagerDuty
Connect PagerDuty services and configure urgency levels for critical investigations.
Email
Configure owner inbox routing, delivery modes, and redaction for email alerts.
Webhook
Configure webhook endpoints, verify HMAC signatures, and handle retry logic.
RoutingRouting overview
How Guard workflows route alerts through triggers, enrichment, conditions, controls, and actions.
Triggers
Event types that start workflows and how to configure trigger criteria.
Enrichment
Enrich alerts with registry metadata, vulnerability data, and trust scores.
Conditions
Route alerts based on severity, trust score, or custom criteria with conditional branching.
Controls
Pacing, deduplication, rate limiting, and business-hours windows for alert routing.
Actions
Notification and issue-creation actions for multi-provider alert routing.
Terminals
Terminal states, audit trails, and workflow resolution tracking.
Plugin ScannerScanner quick start
Install the scanner, run the main commands, and understand supported ecosystems.
Ecosystems and repository mode
Scan one plugin package or an entire marketplace-style repository across supported ecosystems.
Quality suite commands
Choose between scan, lint, verify, submit, and doctor based on the release question you need to answer.
Policies, output, and trust provenance
Policy profiles, config files, output formats, and trust provenance references.
Trust provenance guide
See how bundled skills, MCP config, and plugin trust are explained and surfaced.
Report formats and CI automation
Export text, JSON, Markdown, or SARIF output and wire the scanner into local hooks or CI workflows.
GitHub ActionGitHub Action quality gate
Use the action wrapper in PR checks, SARIF upload flows, and submission pipelines.
Submission and registry payloads
Open or reuse submission issues and export registry payload artifacts from the same workflow run.
docs/libraries/ai-plugin-scanner
GitHub Action
Submission and registry payloads
Previous
GitHub Action quality gate
Applies to: Guard >= 0.5.0
Maintained by: HOL Guard Team Guard docs
Guard documentation Published guides for HOL Guard and plugin-scanner, pulled from the AI Plugin Scanner library docs so the product page stays aligned with the canonical documentation source.
Security trust packet Architecture boundary, release proof, issue intake, SIEM examples, and Enterprise handoff.
Open packet Browse guides
Search guides
OverviewAI Plugin Scanner overview
Product map for HOL Guard, plugin-scanner, and the GitHub Action wrapper.
HOL GuardGuard get started
Run guided Guard init, connect Cloud when useful, record the first baseline, and start protecting harness launches.
Local-first runtime and approvals
Follow the pre-launch Guard loop for local evaluation, inline approvals, and blocked harness runs.
Local-first and optional cloud
See which protections stay local by default, what shared cloud features add later, and when sync is worth turning on.
Approval center and audit trail
Review queued approvals, receipt evidence, diff history, and the local approval center audit workflow.
Guard architecture
Understand the runtime layers behind harness detection, policy evaluation, receipts, and launch interception.
Harness support matrix
See how Codex, Claude Code, Cursor, Gemini, and OpenCode are handled today.
Codex harness
Set up Guard in front of Codex, understand its approval center flow, and validate project versus global MCP scope.
Claude Code harness
Use Guard with Claude hooks, workspace agents, and the strongest current deferred approval path.
Cursor harness
Keep Cursor native tool approvals while Guard handles artifact trust and runtime MCP sanity checks.
Gemini harness
Inspect Gemini extension manifests, embedded MCP servers, and the Guard approval center path for blocked changes.
OpenCode harness
Track OpenCode config, JSONC, and workspace command surfaces while preserving OpenCode native permissions.
Policy presets
Apply bundled rule sets for strict, balanced, or permissive security postures.
Mitigation guidance
Read and act on mitigation recommendations for supply-chain risks.
Testing and validation
Use the release validation loop for harness smoke coverage, manual checks, and Guard canaries.
Event routing workflows
Build event routing workflows that send Guard events to Slack, Jira, GitHub, email, webhooks, and AI responders.
Guard CloudGuard Cloud command center
Understand the signed-in Guard console, route map, and how local Guard hands off to the cloud command center.
Devices and shared trust memory
See how Guard tracks protected devices, harness coverage, last seen status, and cross-device trust memory.
Inventory, ABOM, and artifact detail
Learn when to use inventory, ABOM, or per-artifact detail to inspect the shared Guard trust estate.
Receipts, changes, and history
Follow the decision loop from latest receipt evidence to changed approvals and long-term artifact history.
Alerts, watchlists, and advisories
Control Guard digests, watchlists, and advisory-aware follow-up so only the right risks break through.
Team policy and delegated approvals
Document seeded Guard policy packs, team and repo inheritance, break-glass governance, and delegated approvals for workspace operators.
Exceptions and expiring windows
Explain repo and harness scoped bypass windows, approval queues, expiry handling, and audit export without turning exceptions into permanent policy.
Billing, credits, and plans
Clarify what stays local, what Guard Cloud meters, and which plan or credit pressure actually matters.
IntegrationsIntegrations overview
Route Guard investigation alerts to Slack, GitHub, Jira, PagerDuty, email, or webhooks.
Slack
Connect Slack, select channels, and manage OAuth scopes for alert routing.
GitHub
Install the GitHub App, select repositories, and track investigations as issues.
Jira
Connect Jira, select projects, and map issue types for investigation tracking.
PagerDuty
Connect PagerDuty services and configure urgency levels for critical investigations.
Email
Configure owner inbox routing, delivery modes, and redaction for email alerts.
Webhook
Configure webhook endpoints, verify HMAC signatures, and handle retry logic.
RoutingRouting overview
How Guard workflows route alerts through triggers, enrichment, conditions, controls, and actions.
Triggers
Event types that start workflows and how to configure trigger criteria.
Enrichment
Enrich alerts with registry metadata, vulnerability data, and trust scores.
Conditions
Route alerts based on severity, trust score, or custom criteria with conditional branching.
Controls
Pacing, deduplication, rate limiting, and business-hours windows for alert routing.
Actions
Notification and issue-creation actions for multi-provider alert routing.
Terminals
Terminal states, audit trails, and workflow resolution tracking.
Plugin ScannerScanner quick start
Install the scanner, run the main commands, and understand supported ecosystems.
Ecosystems and repository mode
Scan one plugin package or an entire marketplace-style repository across supported ecosystems.
Quality suite commands
Choose between scan, lint, verify, submit, and doctor based on the release question you need to answer.
Policies, output, and trust provenance
Policy profiles, config files, output formats, and trust provenance references.
Trust provenance guide
See how bundled skills, MCP config, and plugin trust are explained and surfaced.
Report formats and CI automation
Export text, JSON, Markdown, or SARIF output and wire the scanner into local hooks or CI workflows.
GitHub ActionGitHub Action quality gate
Use the action wrapper in PR checks, SARIF upload flows, and submission pipelines.
Submission and registry payloads
Open or reuse submission issues and export registry payload artifacts from the same workflow run.
docs/libraries/ai-plugin-scanner
GitHub Action
Submission and registry payloads
Previous
GitHub Action quality gate
The GitHub Action can do more than fail a pull request. It can also open or reuse ecosystem submission issues and emit a registry payload file for downstream automation.
The intended path is:
add the scanner action to plugin CI
require min_score: 80 and a severity gate such as fail_on_severity: high
enable submission mode with a token that has issues:write on hashgraph-online/awesome-codex-plugins
when the plugin clears the threshold, the action opens or reuses a submission issue
the issue body includes machine-readable registry payload data so the same event can drive ecosystem automation
Example:
Copy permissions:
contents: read
jobs:
scan-plugin:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Scan and submit if eligible
id: scan
uses: hashgraph-online/ai-plugin-scanner-action@v1
with:
plugin_dir: "."
min_score: 80
fail_on_severity: high
submission_enabled: true
submission_score_threshold: 80
submission_token: ${{ secrets.AWESOME_CODEX_PLUGINS_TOKEN }}
submission_token is required when submission_enabled: true. The flow is idempotent: if the plugin repository was already submitted, the action reuses the existing open issue instead of opening duplicates.
High-value outputs include:
score
grade
grade_label
max_severity
findings_total
submission_performed
submission_issue_urls
If you want to feed the same scan into a registry, badge pipeline, or another plugin ecosystem automation step, request a registry payload file directly from the action:
Copy permissions:
contents: read
jobs:
scan-plugin:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Scan plugin
id: scan
uses: hashgraph-online/ai-plugin-scanner-action@v1
with:
plugin_dir: "."
format: sarif
output: ai-plugin-scanner.sarif
registry_payload_output: ai-plugin-registry-payload.json
- name: Upload registry payload
uses: actions/upload-artifact@v4
with:
name: ai-plugin-registry-payload
path: ${{ steps.scan.outputs.registry_payload_path }}
The registry payload mirrors the submission data used by HOL ecosystem automation, so one scan can drive code scanning, review summaries, awesome-list intake, and registry trust ingestion.
GitHub Action quality gate
Report formats and CI automation
Policies, output, and trust provenance
Docs Best Agents Community More Settings Copyright © 2026 HOL DAO LLC. All rights reserved.
The GitHub Action can do more than fail a pull request. It can also open or reuse ecosystem submission issues and emit a registry payload file for downstream automation.
The intended path is:
add the scanner action to plugin CI
require min_score: 80 and a severity gate such as fail_on_severity: high
enable submission mode with a token that has issues:write on hashgraph-online/awesome-codex-plugins
when the plugin clears the threshold, the action opens or reuses a submission issue
the issue body includes machine-readable registry payload data so the same event can drive ecosystem automation
Example:
Copy permissions:
contents: read
jobs:
scan-plugin:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Scan and submit if eligible
id: scan
uses: hashgraph-online/ai-plugin-scanner-action@v1
with:
plugin_dir: "."
min_score: 80
fail_on_severity: high
submission_enabled: true
submission_score_threshold: 80
submission_token: ${{ secrets.AWESOME_CODEX_PLUGINS_TOKEN }}
submission_token is required when submission_enabled: true. The flow is idempotent: if the plugin repository was already submitted, the action reuses the existing open issue instead of opening duplicates.
High-value outputs include:
score
grade
grade_label
max_severity
findings_total
submission_performed
submission_issue_urls
If you want to feed the same scan into a registry, badge pipeline, or another plugin ecosystem automation step, request a registry payload file directly from the action:
Copy permissions:
contents: read
jobs:
scan-plugin:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Scan plugin
id: scan
uses: hashgraph-online/ai-plugin-scanner-action@v1
with:
plugin_dir: "."
format: sarif
output: ai-plugin-scanner.sarif
registry_payload_output: ai-plugin-registry-payload.json
- name: Upload registry payload
uses: actions/upload-artifact@v4
with:
name: ai-plugin-registry-payload
path: ${{ steps.scan.outputs.registry_payload_path }}
The registry payload mirrors the submission data used by HOL ecosystem automation, so one scan can drive code scanning, review summaries, awesome-list intake, and registry trust ingestion.
GitHub Action quality gate
Report formats and CI automation
Policies, output, and trust provenance
Docs Best Agents Community More Settings Copyright © 2026 HOL DAO LLC. All rights reserved.