AI coding app quick start

Kimi quick start

Connect Guard to Kimi so every tool call and MCP request is checked before it runs.

Prerequisite

Install Guard

If you haven't installed Guard yet, run the install script first. This installs hol-guard via pipx and configures it for Kimi in one step.

Install Guard for Kimi
Preparing install command…

Already have Guard installed? Skip to the harness command below. Full install guide.

Coverage

Event surfaces

shellprompt

Native approval

No

Browser fallback

Yes

Resume support

No

Smoke command

hol-guard install kimi --dry-run

Known blind spot

Tool output post-processing and inline edits applied without a tool call are not visible to Guard. Hooks run in parallel and fail open on crash or timeout.

Harness command

Attach to Kimi

Terminal

hol-guard install kimi

Guard stays local by default — no account required to protect your first session. Connect Guard Cloud later to sync security records across your devices.

What Guard checks

  • ~/.kimi/config.json
  • declared MCP server entries and tool surfaces
  • linked extension and plugin paths

What install changes

  • Adds Guard hook entries to the Kimi runtime config so Guard runs before each tool call.
  • Wrapper mode stays available as a low-risk fallback while you evaluate coverage.
  • Writes a local security record for every decision so you can review what changed later.

Verification

Confirm the setup before your first protected session.

1

Run the setup command

Start with the Guard command matched to this AI coding app and its setup mode.

Command

hol-guard install kimi
2

Run the next verification commands

Confirm Guard sees the expected config paths before your first protected session.

Command

hol-guard doctor kimi
hol-guard run kimi --dry-run
3

Check your first security record

After Guard records a local decision, open the receipt list to confirm what was scanned.

Command

hol-guard receipts

Safe demo & test protection

Use --dry-run for demos and CI. Guard scans and reports without blocking, so you can show what it catches without interrupting a live session.

Sync to Guard Cloud

Connect Guard Cloud to carry your security records, team memory, and approval history across every machine and teammate — no rebuilding approvals when you switch devices.

Review Guard Cloud plans →

Troubleshooting

Something not working?

  • Guard does not intercept launches

    Run hol-guard doctor kimi and check that the wrapper path matches your installed binary.

  • No security record after the first run

    Check that ~/.hol-guard/ is writable. Guard writes every decision there by default.

  • Cloud sync not reflecting local decisions

    Run hol-guard sync --status to see if Guard Cloud can reach the server. Local protection keeps running even when sync is unavailable.

Approval surface

Guard local approval center (browser, localhost) via preToolUse hook — blocks inline when a new or changed tool needs a decision.

Run command

hol-guard run kimi

Uninstall / revert

Guard leaves no background services. Your approval history stays on disk in ~/.hol-guard/ unless you delete that folder.

Uninstall command

hol-guard uninstall kimi

Current phase notes

  • Hook-based integration requires Kimi config write access. Wrapper mode is the fallback if hooks cannot be registered.
  • Custom Kimi plugin surfaces may not be fully enumerated in v1. Run `hol-guard doctor kimi` to see what Guard resolved.

Kimi FAQ

Does HOL Guard replace Kimi permissions?
No. It adds a local review layer around risky actions so permissions are easier to understand.
Does HOL Guard publish my activity?
No. Public warnings are opt-in, redacted, and held for moderation before indexing.

Related security content