HOL Guard adds local runtime protection for MCP servers and agent tool calls
kantorcodes1 · reddit · 2026-07-23
HOL Guard adds a local runtime security layer for MCP servers and agent tool calls.
- It sits between agents and the machine to inspect MCP registrations, tool-call patterns, package installs, config changes, and sensitive file access before they happen.
- Based on policy, it can allow, warn, require approval, or block actions, and it keeps a receipt for later tracing.
- The project is free and open source, with no cloud account required.
- It currently supports Codex, Claude Code, Copilot CLI, Cursor, Gemini CLI, OpenCode, Hermes, OpenClaw, Pi, Kimi, Grok, ZCode, and others.
The author is asking for feedback on how much detail to surface when an approved MCP server changes, and where local enforcement is better than an MCP gateway.
More from coding & agent
- Pond pitches outcome-based agents that only charge when the work is delivered — ThePeterMick · 2026-07-23
- Factory ships model routing after costs drop 25% on task-by-task model selection — matanSF · 2026-07-23
- Claude Code has a hidden /radio command for surprisingly decent background music — ryanbed · 2026-07-23
- Claude Code, Cursor, CodeRabbit and MCP form a one-line AI coding stack — IndraVahan · 2026-07-23
- DBOS claims 20x faster durable streams in a summer release for Java and AI agents — CShorten30 · 2026-07-23
- AI SDK adds `firstChunkMs` to fail fast on stalled model streams — ayushtweetshere · 2026-07-23