Skip to content

Latest commit

 

History

History
60 lines (46 loc) · 1.69 KB

File metadata and controls

60 lines (46 loc) · 1.69 KB

HOL Guard DevContainer Feature

Installs HOL Guard into your dev container — local-first security for AI coding agents.

Quick Start

Add this to your devcontainer.json:

{
    "image": "mcr.microsoft.com/devcontainers/python:3.12",
    "features": {
        "ghcr.io/hashgraph-online/devcontainer-features/hol-guard:1": {}
    }
}

That's it. HOL Guard installs automatically on container build.

Options

Option Type Default Description
version string latest HOL Guard version (latest or a specific version like 2.0.1004)
initHarness string auto Harness to configure: auto, codex, claude-code, cursor, gemini, opencode, pi, or none
strictMode boolean false Enable strict mode (blocks untrusted tool actions by default)

Example: Cursor + Strict Mode

{
    "features": {
        "ghcr.io/hashgraph-online/devcontainer-features/hol-guard:1": {
            "version": "latest",
            "initHarness": "cursor",
            "strictMode": true
        }
    }
}

Example: Claude Code with Auto-Detect

{
    "features": {
        "ghcr.io/hashgraph-online/devcontainer-features/hol-guard:1": {
            "initHarness": "claude-code"
        }
    }
}

What is HOL Guard?

HOL Guard intercepts tool actions before files change or networks are contacted. It protects AI coding agents (Codex, Claude Code, Cursor, Gemini, OpenCode, Pi) from supply-chain attacks in plugins and MCP servers.