Reviews API and gateway deletion through supported cloud CLIs.
HOL Guard extension coverage directory
Command and MCP coverage with source, activation model, maintainer identity, and stated limitations for every entry — so a listing never reads like a security guarantee.
How coverage is classified
- Required protection
- Part of Guard’s required safety floor. It runs whenever Guard runs and cannot be opted out per workspace.
- Built-in coverage
- Ships with the native Guard runtime and follows your existing Guard policy configuration.
- Package firewall
- Coverage is delegated to Guard package-firewall controls for installs, scripts, and dependencies.
- External · opt-in
- Off by default. Enable it deliberately through Guard controls; this directory never activates coverage.
- API gateway command protectionCommandBy HOL Guard TeamBuilt-in coverageCloud and infrastructureProject maintained
- AWS command protectionCommand
Reviews a validated AWS CLI operation matrix for permanent resource deletion and service termination.
By HOL Guard TeamBuilt-in coverageCloud and infrastructureProject maintained - Azure command protectionCommand
Reviews a validated Azure CLI operation matrix for permanent resource deletion across subscription, identity, network, compute, application,
By HOL Guard TeamBuilt-in coverageCloud and infrastructureProject maintained - CDN command protectionCommand
Reviews distribution, profile, and endpoint deletion through supported cloud CLIs.
By HOL Guard TeamBuilt-in coverageCloud and infrastructureProject maintained - DNS command protectionCommand
Reviews hosted-zone deletion through supported cloud CLIs.
By HOL Guard TeamBuilt-in coverageCloud and infrastructureProject maintained - Google Cloud command protectionCommand
Reviews a validated gcloud operation matrix for permanent resource deletion across stable and supported release tracks.
By HOL Guard TeamBuilt-in coverageCloud and infrastructureProject maintained - Infrastructure-as-code protectionCommand
Reviews infrastructure teardown through Terraform, OpenTofu, and Pulumi.
By HOL Guard TeamBuilt-in coverageCloud and infrastructureProject maintained - Kubernetes operation protectionCommand
Reviews cluster mutations, remote execution, file transfer, tunnels, certificate decisions, and Helm lifecycle operations.
By HOL Guard TeamBuilt-in coverageCloud and infrastructureProject maintained - Load balancer command protectionCommand
Reviews load-balancer and forwarding-rule deletion through supported cloud CLIs.
By HOL Guard TeamBuilt-in coverageCloud and infrastructureProject maintained
Community coverage, provenance recorded
Contributions marked “Community contribution” entered this directory through public pull requests with a recorded merge, digest, and source path. A verified publisher profile attributes the contributor; it is not an upstream endorsement or a HOL safety certification.
Questions worth asking before you enable
Is a listing here a security guarantee?
No. Every entry documents source, activation model, maintainer identity, and stated limitations so you can evaluate coverage before enabling it. A listing is documentation, not a certification, and a maintainer profile is not an upstream endorsement.
How current is this directory?
The directory is generated from the canonical extension catalog in the hol-guard repository and checked on every page load. Each entry page links to the exact source tree it was reviewed at.
How do I contribute new coverage?
Community extensions are merged through public pull requests with recorded provenance. Open the Publisher Studio to claim a publisher page for a contribution you maintain.
Run Guard with the coverage you understand
Install the CLI, connect your agents, and review each entry’s limits here before it ever intercepts a command.