HOL Guard extension coverage directory

Command and MCP coverage with source, activation model, maintainer identity, and stated limitations for every entry — so a listing never reads like a security guarantee.

Showing 67 of 67 coverage entries

Source from last verified snapshot · f440ae1a9f

What activation means before you enable anything

Every entry declares one of four activation models. Knowing which one applies tells you whether coverage is already protecting you or waits for a deliberate decision.

Required protection
Part of Guard’s required safety floor. It runs whenever Guard runs and cannot be opted out per workspace.
Built-in coverage
Ships with the native Guard runtime and follows your existing Guard policy configuration.
Package firewall
Coverage is delegated to Guard package-firewall controls for installs, scripts, and dependencies.
External · opt-in
Off by default. Enable it deliberately through Guard controls; this directory never activates coverage.

Community coverage, provenance recorded

Contributions marked “Community contribution” entered this directory through public pull requests with a recorded merge, digest, and source path. A verified publisher profile attributes the contributor; it is not an upstream endorsement or a HOL safety certification.

Questions worth asking before you enable

Is a listing here a security guarantee?

No. Every entry documents source, activation model, maintainer identity, and stated limitations so you can evaluate coverage before enabling it. A listing is documentation, not a certification, and a maintainer profile is not an upstream endorsement.

How current is this directory?

The directory is generated from the canonical extension catalog in the hol-guard repository and checked on every page load. Each entry page links to the exact source tree it was reviewed at.

How do I contribute new coverage?

Community extensions are merged through public pull requests with recorded provenance. Open the Publisher Studio to claim a publisher page for a contribution you maintain.

Run Guard with the coverage you understand

Install the CLI, connect your agents, and review each entry’s limits here before it ever intercepts a command.