HOL Guard extension coverage directory
Command and MCP coverage with source, activation model, maintainer identity, and stated limitations for every entry — so a listing never reads like a security guarantee.
- Amazon S3 command protectionCommand
Reviews AWS CLI S3 commands including copy, list, sync, website, and deletion.
Built-in coverageData and resilienceProject maintained - API gateway command protectionCommand
Reviews API and gateway deletion through supported cloud CLIs.
Built-in coverageCloud and infrastructureProject maintained - AWS command protectionCommand
Reviews a validated AWS CLI operation matrix for permanent resource deletion and service termination.
Built-in coverageCloud and infrastructureProject maintained - Azure Blob Storage command protectionCommand
Reviews Azure CLI storage commands including upload, list, copy, and deletion.
Built-in coverageData and resilienceProject maintained - Azure command protectionCommand
Reviews a validated Azure CLI operation matrix for permanent resource deletion across subscription, identity, network, compute, application,
Built-in coverageCloud and infrastructureProject maintained - BlitcpCommand
Reviews blitcp copies that leave the host, elevate privileges, or skip verification.
External · opt-inOther extensionsCommunity contribution - Borg command protectionCommand
Reviews Borg operations that delete, prune, or recreate archives.
Built-in coverageData and resilienceProject maintained - CDN command protectionCommand
Reviews distribution, profile, and endpoint deletion through supported cloud CLIs.
Built-in coverageCloud and infrastructureProject maintained - CircleCI command protectionCommand
Reviews remote pipeline execution through CircleCI CLI.
Built-in coverageDelivery and remote operationsProject maintained - Command data protectionCommand
Detects shell flows that can send credentials or local file contents to a network destination.
Built-in coverageCore safetyProject maintained - Container runtime protectionCommand
Reviews container lifecycle, cleanup, execution, network, and persistent-data operations that can expose credentials or mutate host state.
Built-in coverageCore safetyProject maintained - DNS command protectionCommand
Reviews hosted-zone deletion through supported cloud CLIs.
Built-in coverageCloud and infrastructureProject maintained - Elasticsearch command protectionCommand
Reviews explicit DELETE requests to recognizable Elasticsearch API targets.
Built-in coverageManaged servicesProject maintained - Email service command protectionCommand
Reviews email identity and contact-list deletion through AWS CLI.
Built-in coverageManaged servicesProject maintained - Encoded execution protectionCommand
Reviews decode-and-execute flows whose effective program is hidden from normal command inspection.
Built-in coverageCore safetyProject maintained - esshCommand
Reviews essh host group execution and removal of cached hosts, keys, and workspaces.
External · opt-inDelivery and remote operationsCommunity contribution - Feature flag command protectionCommand
Reviews permanent feature-flag deletion through LaunchDarkly CLI.
Built-in coverageManaged servicesProject maintained - Filesystem MCPMCP
Reviews official filesystem MCP tools. Off until you turn it on.
External · opt-inSpecialized toolsCommunity contribution - Filesystem protectionCommand
Reviews recursive deletion and access-control changes across filesystem trees.
Required protectionCore safetyProject maintained - Git protectionCommand
Reviews everyday Git porcelain plus local and remote operations that can discard work, replace history, refresh a remote Guard cannot verify
Required protectionCore safetyProject maintained - GitHub Actions command protectionCommand
Reviews workflow-run cancellation, deletion, and workflow disabling through GitHub CLI.
Built-in coverageDelivery and remote operationsProject maintained - GitHub capability protectionCommand
Reviews distinct GitHub maintenance, content, merge, publication, workflow, and control effects.
Built-in coverageDelivery and remote operationsProject maintained - GitLab CI/CD command protectionCommand
Reviews remote pipeline cancellation through GitLab CLI.
Built-in coverageDelivery and remote operationsProject maintained - Go package protectionCommand
Routes Go module and tool installation requests through Guard's package firewall.
Package firewallPackage supply chainProject maintained - Google Cloud command protectionCommand
Reviews a validated gcloud operation matrix for permanent resource deletion across stable and supported release tracks.
Built-in coverageCloud and infrastructureProject maintained - Google Cloud Storage command protectionCommand
Reviews Google CLI storage commands including copy, list, sync, and deletion.
Built-in coverageData and resilienceProject maintained - Guard self-protectionCommand
Prevents commands from authorizing their own Guard approval or weakening protected Guard state.
Required protectionCore safetyProject maintained - Heroku command protectionCommand
Reviews app destruction, pipeline promotion, and release rollback.
Built-in coverageDelivery and remote operationsProject maintained - Infrastructure-as-code protectionCommand
Reviews infrastructure teardown through Terraform, OpenTofu, and Pulumi.
Built-in coverageCloud and infrastructureProject maintained - JVM package protectionCommand
Routes Maven and Gradle dependency operations through Guard's package firewall.
Package firewallPackage supply chainProject maintained - Kafka command protectionCommand
Reviews Kafka topic, group, offset, and record deletion operations.
Built-in coverageManaged servicesProject maintained - Kubernetes operation protectionCommand
Reviews cluster mutations, remote execution, file transfer, tunnels, certificate decisions, and Helm lifecycle operations.
Built-in coverageCloud and infrastructureProject maintained - Kubernetes secret protectionCommand
Reviews Kubernetes CLI operations that can reveal cluster or application secrets.
Built-in coverageCore safetyProject maintained - Laravel command protectionCommand
Reviews destructive Artisan database wipes, migration resets, and queue purges.
Built-in coverageOther extensionsProject maintained - Load balancer command protectionCommand
Reviews load-balancer and forwarding-rule deletion through supported cloud CLIs.
Built-in coverageCloud and infrastructureProject maintained - MinIO command protectionCommand
Reviews MinIO Client commands including copy, list, mirror, and deletion.
Built-in coverageData and resilienceProject maintained - MongoDB command protectionCommand
Reviews restore operations that drop and replace collections.
Built-in coverageData and resilienceProject maintained - Monitoring command protectionCommand
Reviews alarm and alert deletion through supported cloud CLIs.
Built-in coverageManaged servicesProject maintained - MySQL command protectionCommand
Reviews mysqladmin database removal operations.
Built-in coverageData and resilienceProject maintained - NATS command protectionCommand
Reviews NATS stream, consumer, key-value, and object-store removal operations.
Built-in coverageManaged servicesProject maintained - Netlify command protectionCommand
Reviews site deletion and production deployments.
Built-in coverageDelivery and remote operationsProject maintained - Node package protectionCommand
Routes Node package installs and one-shot execution through Guard's package firewall.
Package firewallPackage supply chainProject maintained - NoodleCommand
Reviews Noodle terminal REST client request and collection runs.
External · opt-inOther extensionsCommunity contribution - Payment service command protectionCommand
Reviews product, coupon, customer, and webhook endpoint deletion through Stripe CLI.
Built-in coverageManaged servicesProject maintained - PHP package protectionCommand
Routes Composer dependency operations through Guard's package firewall.
Package firewallPackage supply chainProject maintained - PostgreSQL command protectionCommand
Reviews explicit PostgreSQL database removal commands.
Built-in coverageData and resilienceProject maintained - ProbeCommand
Reviews HTTP execution and OpenCollection workspace mutations through the Probe CLI.
External · opt-inOther extensionsCommunity contribution - Python package protectionCommand
Routes Python dependency installs and isolated package execution through Guard's package firewall.
Package firewallPackage supply chainProject maintained - RabbitMQ command protectionCommand
Reviews RabbitMQ deletion and broker reset operations.
Built-in coverageManaged servicesProject maintained - Rclone command protectionCommand
Reviews rclone operations that delete, move, purge, or synchronize data.
Built-in coverageData and resilienceProject maintained - Redis command protectionCommand
Reviews Redis key deletion and database flush commands.
Built-in coverageData and resilienceProject maintained - repo2nbCommand
Reviews repo2nb commands that can overwrite a destination directory or drop untracked notebook cells.
External · opt-inOther extensionsCommunity contribution - Restic command protectionCommand
Reviews restic operations that remove snapshots or repository data.
Built-in coverageData and resilienceProject maintained - Rsync deletion protectionCommand
Reviews rsync options that delete destination data or remove synchronized source files.
Built-in coverageDelivery and remote operationsProject maintained - Ruby package protectionCommand
Routes RubyGem and Bundler dependency operations through Guard's package firewall.
Package firewallPackage supply chainProject maintained - Rust package protectionCommand
Routes Cargo dependency and binary installation requests through Guard's package firewall.
Package firewallPackage supply chainProject maintained - SCP transfer protectionCommand
Reviews SCP transfers that can overwrite local or remote destination files.
Built-in coverageDelivery and remote operationsProject maintained - Shell, Git, and filesystem protectionCommand
Reviews destructive shell, Git, filesystem, redirection, and protected configuration mutations.
Built-in coverageCore safetyProject maintained - Skill SunsetCommand
Reviews the Skill Sunset audit surface and its local report and viewer side effects.
External · opt-inSpecialized toolsCommunity contribution - SQLite command protectionCommand
Reviews SQLite restore operations that replace database content.
Built-in coverageData and resilienceProject maintained - SSH remote execution protectionCommand
Reviews SSH invocations that explicitly execute a remote command.
Built-in coverageDelivery and remote operationsProject maintained - Supabase command protectionCommand
Reviews database reset and migration rollback commands.
Built-in coverageData and resilienceProject maintained - System package protectionCommand
Routes operating-system package installation requests through Guard's package firewall.
Package firewallPackage supply chainProject maintained - System protectionCommand
Reviews storage formatting and operating-system power-state mutations.
Required protectionCore safetyProject maintained - Velero command protectionCommand
Reviews Velero operations that delete backup data or recovery records.
Built-in coverageData and resilienceProject maintained - Vercel command protectionCommand
Reviews deployment and project deletion plus production deployment, promotion, and rollback.
Built-in coverageDelivery and remote operationsProject maintained - Windows protectionCommand
Reviews destructive Windows storage and operating-system commands.
Required protectionCore safetyProject maintained
What activation means before you enable anything
Every entry declares one of four activation models. Knowing which one applies tells you whether coverage is already protecting you or waits for a deliberate decision.
- Required protection
- Part of Guard’s required safety floor. It runs whenever Guard runs and cannot be opted out per workspace.
- Built-in coverage
- Ships with the native Guard runtime and follows your existing Guard policy configuration.
- Package firewall
- Coverage is delegated to Guard package-firewall controls for installs, scripts, and dependencies.
- External · opt-in
- Off by default. Enable it deliberately through Guard controls; this directory never activates coverage.
Community coverage, provenance recorded
Contributions marked “Community contribution” entered this directory through public pull requests with a recorded merge, digest, and source path. A verified publisher profile attributes the contributor; it is not an upstream endorsement or a HOL safety certification.
Questions worth asking before you enable
Is a listing here a security guarantee?
No. Every entry documents source, activation model, maintainer identity, and stated limitations so you can evaluate coverage before enabling it. A listing is documentation, not a certification, and a maintainer profile is not an upstream endorsement.
How current is this directory?
The directory is generated from the canonical extension catalog in the hol-guard repository and checked on every page load. Each entry page links to the exact source tree it was reviewed at.
How do I contribute new coverage?
Community extensions are merged through public pull requests with recorded provenance. Open the Publisher Studio to claim a publisher page for a contribution you maintain.
Run Guard with the coverage you understand
Install the CLI, connect your agents, and review each entry’s limits here before it ever intercepts a command.