HOL Guard extension coverage directory

Command and MCP coverage with source, activation model, maintainer identity, and stated limitations for every entry — so a listing never reads like a security guarantee.

How coverage is classified
Required protection
Part of Guard’s required safety floor. It runs whenever Guard runs and cannot be opted out per workspace.
Built-in coverage
Ships with the native Guard runtime and follows your existing Guard policy configuration.
Package firewall
Coverage is delegated to Guard package-firewall controls for installs, scripts, and dependencies.
External · opt-in
Off by default. Enable it deliberately through Guard controls; this directory never activates coverage.

Showing 9 of 67 coverage entries

Source from last verified snapshot · f440ae1a9f

Community coverage, provenance recorded

Contributions marked “Community contribution” entered this directory through public pull requests with a recorded merge, digest, and source path. A verified publisher profile attributes the contributor; it is not an upstream endorsement or a HOL safety certification.

Questions worth asking before you enable

Is a listing here a security guarantee?

No. Every entry documents source, activation model, maintainer identity, and stated limitations so you can evaluate coverage before enabling it. A listing is documentation, not a certification, and a maintainer profile is not an upstream endorsement.

How current is this directory?

The directory is generated from the canonical extension catalog in the hol-guard repository and checked on every page load. Each entry page links to the exact source tree it was reviewed at.

How do I contribute new coverage?

Community extensions are merged through public pull requests with recorded provenance. Open the Publisher Studio to claim a publisher page for a contribution you maintain.

Run Guard with the coverage you understand

Install the CLI, connect your agents, and review each entry’s limits here before it ever intercepts a command.