Archive position — measured, not model output
1 like on Devpost
506 of the 7,856 archived projects have more likes, and 1,758 share exactly 1 — so this project's #1,202 place in the like-ranked listing is a tie-break inside that group, not a ranking.
Projects (log scale)
Likes on Devpost. ▲ marks this project's group.
Show the figures
| Likes | Projects | Share of archive |
|---|---|---|
| 0 | 5,592 | 71.2% |
| 1 | 1,758 | 22.4% |
| 2 | 285 | 3.6% |
| 3–4 | 132 | 1.7% |
| 5–9 | 75 | 1.0% |
| 10+ | 14 | 0.2% |
Executive Summary
What the company appears to be
HOL Guard is a self-reported local-first execution firewall for AI agents. The product is described as intercepting risky actions before they run, blocking known threats, routing contextual actions for human approval, and producing auditable receipts for decisions. It is built to protect against supply chain attacks and unauthorized access to systems by autonomous AI agents.
What changed
The project began as an internal tool used by the founders to manage risks associated with AI agents gaining access to devices and work environments. Over time, it evolved into a security product intended for broader organizational use, with a focus on enforcing policy at the point of execution rather than after actions occur.
Single most important open question
Is there evidence of real-world adoption or usage beyond the authors' own internal testing? The description states that HOL Guard has been downloaded 400K+ times and is used daily, but this claim lacks independent verification or data to confirm actual customer engagement or traction.
What The Product Actually Is
The description states that HOL Guard is a local-first execution firewall for AI agents. It sits between an agent and the environment it can act on, inspecting supported activity before execution such as:
- File access
- Shell commands
- Package installations
- MCP registrations
- Tool calls
- Configuration changes
- Potentially destructive operations
It can:
- Allow actions that match policy
- Automatically block known threats
- Route contextual actions to an Inbox for human approval
- Explain why an action was paused or blocked
- Produce an auditable receipt for each decision
The product is described as local-first, and enforcement decisions are independent from the model proposing the action. The agent recommends what should happen, but does not decide whether its own action is safe.
Inference HOL Guard appears to be a security layer that enforces policy at the execution boundary of AI agents, distinguishing between actions that are automatically allowed, blocked, or require human review.
Positioning & Claim Evolution
The description states that HOL Guard was originally built as an internal tool due to concerns about how quickly AI agents were gaining access to devices and work environments. It evolved from a personal solution to a product intended for broader organizational deployment.
Key claims:
- The tool aims to protect against supply chain attacks
- It focuses on execution-level protection, not scanning code or detecting problems after they happen
- It is positioned as a firewall for AI agents that intercepts risky actions before execution
The authors emphasize that the product is designed to make autonomous AI feel safer, and that it can be used by any organization deploying agents with access to local files, credentials, tools, or business systems.
Inference HOL Guard positions itself as a security control for AI agents at the point of action execution, distinct from traditional code scanning or post-incident detection methods. It is intended to be a shared control layer across teams and workflows.
Target Customer & ICP
The description states that HOL Guard was built with the intent to protect any organization deploying agents with access to local files, credentials, tools, and business systems.
It mentions use cases across:
- Engineering
- Sales
- Business development
- Content
- Operations
The authors note that the underlying risk is consistent whether an agent is changing infrastructure, accessing CRM data, handling internal research, deleting content, or publishing externally.
Inference The target customer appears to be organizations using AI agents in roles that involve system access and interaction. The ICP likely includes engineering teams, DevOps, security teams, and any department where autonomous AI agents are used with elevated privileges.
Business Model & Pricing Evidence
Not evidenced.
The description does not contain information about pricing, monetization strategy, or business model. No mention of customers, revenue, or commercial arrangements is present.
Technical & Delivery Signals
The description states that HOL Guard:
- Uses local-first architecture
- Is built with bun, codex, python, sol, typescript
- Implements a structured command safety engine using Codex and GPT-5.6
- Parses shell commands into a canonical representation to evaluate actions accurately
- Supports structured rules that evaluate complete actions rather than flat strings
It also mentions:
- Use of Codex and GPT-5.6 in engineering loop for threat modeling, rule design, adversarial testing, and review
- The model is used to move faster, but not as the source of authority for enforcement decisions
- The system separates terminal policy decisions from contextual approval decisions
Inference The technical approach involves structured command parsing and evaluation using AI tools in a development loop, while maintaining explicit human control over enforcement. It supports multiple agent environments and actions including Git, cloud infrastructure, databases, CI/CD, package operations, and filesystem activity.
Traction & Maturity Signals
The description states:
- HOL Guard has been downloaded 400K+ times
- It is used everyday
- The authors also operate Awesome Codex Plugins, which has ~700 stars
- Many plugin maintainers use the Plugin Scanner from HOL Guard to reduce attack vectors
It also mentions:
- A demo showing a real Codex action being intercepted before execution
- Known threats being automatically blocked
- Contextual actions appearing in the HOL Guard Inbox
- Human decision preventing underlying files from being changed
Inference There is self-reported evidence of adoption and usage, but no independent confirmation or data on actual customer engagement. The download count and daily use are claims without verification.
Competitive Context
Not evidenced.
The description does not mention any competitors or direct market context. No information is provided about existing products in the AI agent security space.
Key Risks & Red Flags
- Self-reported adoption: Claims of 400K+ downloads and daily use are unverified.
- No commercial evidence: No revenue, customers, or pricing data are provided.
- Unproven market traction: The product is described as a tool used internally before being expanded — no external validation of demand.
- Limited maturity signals: While the authors describe technical sophistication, there is no evidence of production deployment or scalability beyond internal use.
- No clear differentiation from other security tools: The description does not clearly articulate how HOL Guard differs from existing execution-level protections.
Diligence Questions To Ask The Founders
- What specific types of AI agents are currently supported by HOL Guard?
- How is the product being used in practice — what workflows or use cases drive adoption?
- Are there any known false positives or bypasses that have been encountered?
- What is the current user base — is it primarily individuals, teams, or organizations?
- How does the product integrate with existing security tools or workflows?
- What are the key challenges in scaling the product beyond internal use?
- Is there a plan to monetize the product, and if so, what is the business model?
Investment/Partnership Verdict
Not evidenced.
There is no information provided about funding rounds, valuation, or any investment or partnership interest from third parties. The description does not indicate whether the project has received external support or is seeking investment or collaboration.
Source
Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.
The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.
