AI coding app quick start
Claude Code quick start
Connect Guard to Claude Code without losing your existing workflow.
Prerequisite
Install Guard
If you haven't installed Guard yet, run the install script first. This installs hol-guard via pipx and configures it for Claude Code in one step.
Install command unavailable.Already have Guard installed? Skip to the harness command below. Full install guide.
Coverage
Event surfaces
Native approval
Browser fallback
Resume support
Smoke command
hol-guard install claude --dry-runKnown blind spot
Background agent sessions that run without an active terminal do not surface hook events to Guard.
Harness command
Attach to Claude Code
hol-guard install claude-codeGuard stays local by default — no account required to protect your first session. Connect Guard Cloud later to sync security records across your devices.
What Guard checks
- global Claude settings
- project Claude settings
- .mcp.json surfaces and local workspace agents
What install changes
- Adds Guard hook entries to `.claude/settings.local.json` when you install.
- Keeps wrapper mode available as the fallback path.
Verification
Confirm the setup before your first protected session.
Run the setup command
Start with the Guard command matched to this AI coding app and its setup mode.
hol-guard install claude-codeRun the next verification commands
Confirm Guard sees the expected config paths before your first protected session.
hol-guard doctor claude-codeCheck your first security record
After Guard records a local decision, open the receipt list to confirm what was scanned.
hol-guard receiptsSafe demo & test protection
Use --dry-run for demos and CI. Guard scans and reports without blocking, so you can show what it catches without interrupting a live session.
Sync to Guard Cloud
Connect Guard Cloud to carry your security records, team memory, and approval history across every machine and teammate — no rebuilding approvals when you switch devices.
Review Guard Cloud plans →Troubleshooting
Something not working?
Guard does not intercept launches
Run
hol-guard doctor claude-codeand check that the wrapper path matches your installed binary.No security record after the first run
Check that
~/.hol-guard/is writable. Guard writes every decision there by default.Cloud sync not reflecting local decisions
Run
hol-guard sync --statusto see if Guard Cloud can reach the server. Local protection keeps running even when sync is unavailable.
Approval surface
Guard preToolUse hook blocks execution inline, then opens the local approval center (browser, localhost) if a decision is needed.
hol-guard run claude-codeUninstall / revert
Guard leaves no background services. Your approval history stays on disk in ~/.hol-guard/ unless you delete that folder.
hol-guard uninstall claude-codeCurrent phase notes
- Claude Code's native tool approval surface is unchanged — Guard adds an additional pre-tool check via the hook system.
- Hook registration writes to `.claude/settings.local.json`. Review this file to revert if needed.
Claude Code FAQ
No. It adds a local review layer around risky actions so permissions are easier to understand.
No. Public warnings are opt-in, redacted, and held for moderation before indexing.