Preventing Silent MCP Drift: Open-Source Local Security Tool HOL Guard
kantorcodes1 · reddit · 2026-08-13
A developer has released HOL Guard, an open-source local checkpoint tool designed to enhance security for AI coding agents like Claude Code.
While existing permission layers and sandboxes catch obvious threats like executing commands or modifying files, they fail to address silent drift in pre-approved MCP servers (e.g., a server adding new endpoints or tools a week later without re-prompting the user).
Running entirely locally, the tool evaluates MCP registrations, commands, file access, and tool calls against policies before execution. It supports actions like allow, warn, ask, or block, and maintains a receipt of every decision for later auditing.
More from coding & agent
- Developer Shares Workflow for Maintaining AI Coding Streak Remotely — Dimillian · 2026-08-13
- Docktail: Expose Docker Containers as Tailscale Services via Labels — tom_doerr · 2026-08-13
- Developer Shares AI Coding Workflow: Cloud Design Handoff to Local Agent — Dimillian · 2026-08-13
- Orchestrator MCP: Enabling Claude Code and Codex to Consult Each Other — crakintokyo · 2026-08-13
- Generating High-Quality 3D Terrain Assets with AI, Soon Open-Sourced — jasonkneen · 2026-08-13
- Testing 1.6T Param DeepSeek V4 Pro: Average Coding, Outpriced by GPT-5.6 — curiousily_ · 2026-08-13