Is HOL Guard safe?
Probably. Read the findings first.
Use with care. Some checks failed or could not be verified.
What to know before installing
- highWhole environment serialized (possible credential exfil)
Public scan report
scanner v0.1.3 · 2026-09-19 · same rubric, same numbers if you re-run it
1 high2 medium
- Code scan1500 source files scanned3/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 0 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year9/10
Findings (3)
- mediumNetwork call to a raw IP address
net.raw-iphol_guard-3.0.190/dashboard/src/approval-center-layout.test.ts: … request-layout-test", approval_url: "http://127.0.0.1:4781/approvals/request-layout-test", status…
- mediumeval / new Function used
exec.evalhol_guard-3.0.190/dashboard/src/apps/app-catalog.ts: …key: "encoded_execution", example: "eval(atob(...)) or base64-decoded shell paylo…
- highWhole environment serialized (possible credential exfil)
env.dumphol_guard-3.0.190/src/codex_plugin_scanner/guard/cli/commands_support_runtime_resolution.py: …ronment(server_config) launch_env = dict(os.environ) launch_env.update(configured_env) …
Overall 60/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON