Reviews AWS CLI S3 commands including copy, list, sync, website, and deletion.
HOL Guard extension coverage directory
Command and MCP coverage with source, activation model, maintainer identity, and stated limitations for every entry — so a listing never reads like a security guarantee.
How coverage is classified
- Required protection
- Part of Guard’s required safety floor. It runs whenever Guard runs and cannot be opted out per workspace.
- Built-in coverage
- Ships with the native Guard runtime and follows your existing Guard policy configuration.
- Package firewall
- Coverage is delegated to Guard package-firewall controls for installs, scripts, and dependencies.
- External · opt-in
- Off by default. Enable it deliberately through Guard controls; this directory never activates coverage.
- Amazon S3 command protectionCommandBy HOL Guard TeamBuilt-in coverageData and resilienceProject maintained
- Azure Blob Storage command protectionCommand
Reviews Azure CLI storage commands including upload, list, copy, and deletion.
By HOL Guard TeamBuilt-in coverageData and resilienceProject maintained - Borg command protectionCommand
Reviews Borg operations that delete, prune, or recreate archives.
By HOL Guard TeamBuilt-in coverageData and resilienceProject maintained - Google Cloud Storage command protectionCommand
Reviews Google CLI storage commands including copy, list, sync, and deletion.
By HOL Guard TeamBuilt-in coverageData and resilienceProject maintained - MinIO command protectionCommand
Reviews MinIO Client commands including copy, list, mirror, and deletion.
By HOL Guard TeamBuilt-in coverageData and resilienceProject maintained - MongoDB command protectionCommand
Reviews restore operations that drop and replace collections.
By HOL Guard TeamBuilt-in coverageData and resilienceProject maintained - MySQL command protectionCommand
Reviews mysqladmin database removal operations.
By HOL Guard TeamBuilt-in coverageData and resilienceProject maintained - PostgreSQL command protectionCommand
Reviews explicit PostgreSQL database removal commands.
By HOL Guard TeamBuilt-in coverageData and resilienceProject maintained - Rclone command protectionCommand
Reviews rclone operations that delete, move, purge, or synchronize data.
By HOL Guard TeamBuilt-in coverageData and resilienceProject maintained - Redis command protectionCommand
Reviews Redis key deletion and database flush commands.
By HOL Guard TeamBuilt-in coverageData and resilienceProject maintained - Restic command protectionCommand
Reviews restic operations that remove snapshots or repository data.
By HOL Guard TeamBuilt-in coverageData and resilienceProject maintained - SQLite command protectionCommand
Reviews SQLite restore operations that replace database content.
By HOL Guard TeamBuilt-in coverageData and resilienceProject maintained - Supabase command protectionCommand
Reviews database reset and migration rollback commands.
By HOL Guard TeamBuilt-in coverageData and resilienceProject maintained - Velero command protectionCommand
Reviews Velero operations that delete backup data or recovery records.
By HOL Guard TeamBuilt-in coverageData and resilienceProject maintained
Community coverage, provenance recorded
Contributions marked “Community contribution” entered this directory through public pull requests with a recorded merge, digest, and source path. A verified publisher profile attributes the contributor; it is not an upstream endorsement or a HOL safety certification.
Questions worth asking before you enable
Is a listing here a security guarantee?
No. Every entry documents source, activation model, maintainer identity, and stated limitations so you can evaluate coverage before enabling it. A listing is documentation, not a certification, and a maintainer profile is not an upstream endorsement.
How current is this directory?
The directory is generated from the canonical extension catalog in the hol-guard repository and checked on every page load. Each entry page links to the exact source tree it was reviewed at.
How do I contribute new coverage?
Community extensions are merged through public pull requests with recorded provenance. Open the Publisher Studio to claim a publisher page for a contribution you maintain.
Run Guard with the coverage you understand
Install the CLI, connect your agents, and review each entry’s limits here before it ever intercepts a command.