Skip to content

Add optional HOL Guard runtime enforcement to AI Agent security skill - #4

Open
kantorcodes wants to merge 1 commit into
ProgrammerAnthony:masterfrom
kantorcodes:feat/hol-guard-runtime-enforcement
Open

Add optional HOL Guard runtime enforcement to AI Agent security skill#4
kantorcodes wants to merge 1 commit into
ProgrammerAnthony:masterfrom
kantorcodes:feat/hol-guard-runtime-enforcement

Conversation

@kantorcodes

Copy link
Copy Markdown

Summary

Adds an optional HOL Guard local runtime boundary to the maintained ai-agent-security skill and its Cursor mirror before high-risk agent tool execution.

The new section installs and invokes the real HOL Guard CLI, derives the exact supported harness from hol-guard detect --json, then uses bootstrap → install → protected dry-run → guarded run → harness doctor/status. Deny, review-required, error, timeout, or unproven protection stops mutation-bearing work instead of falling back to an unprotected agent.

Boundary

HOL Guard is additive to the existing security guidance. It does not replace authentication, authorization, human confirmation/review, sandboxing, or target-service server-side controls, and the text does not claim HOL Guard runs inside third-party services.

Validation

  • updated only skills/ai-agent-security/SKILL.md and its maintained .cursor mirror
  • the two copies remain byte-identical after the change
  • git diff --check passes
  • branch is one commit ahead and zero behind current master

Affiliation: I maintain HOL Guard / Hashgraph Online. AI assistance was used to prepare this focused contribution; I checked the submitted diff and runtime-boundary claims against the current HOL Guard skill/source before opening the PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant