Registry › Compare › HOL Guard vs open-kritt

HOL Guard vs open-kritt

HOL Guard leads on trust: 92.1/100 (Grade A) against 57.7/100 (Grade C), a 34.4-point gap. HOL Guard leads on supply-chain integrity and provenance, and rests on broader evidence.

A HOL Guard 92.1

Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.

hashgraph-online/hol-guard · #7 overall · #1 Security & Guardrails · coverage B (3/5)

Choose HOL Guard if supply-chain integrity and provenance matter most.

  • +15.7Safety / Integrity: 94% of recent commits signed, against 51%
  • +7.2Identity / Provenance: package provenance attested, against none
  • +4.1Transparency: OSSF Scorecard 9.6 against 4.8
  • +4.1Adoption
C open-kritt 57.7

Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security issues in code.

Kritt-ai/open-kritt · #704 overall · #8 Security & Guardrails · coverage C (2/5)

open-kritt doesn't lead on any scored dimension in this pair.

Where they differ

24.2
Safety / IntegrityHOL Guard +15.7
8.5
18.0
Identity / ProvenanceHOL Guard +7.2
10.8
16.7
TransparencyHOL Guard +4.1
12.6
20.0
MaintenanceHOL Guard +2.2
17.8
12.1
AdoptionHOL Guard +4.1
8.0
+1.1
Runtime calibrationHOL Guard +1.1
+0.0

Full evidence table

An independent, evidence-based trust comparison of HOL Guard and open-kritt, two Security & Guardrails projects in the HVTracker registry. Scores come from public, checkable signals — supply-chain provenance, OSSF Scorecard, maintenance, and adoption — not popularity.

Full evidence

Signal HOL Guardhashgraph-online/hol-guard open-krittKritt-ai/open-kritt
HVTrust score 92.1 57.7
Evidence grade A C
Coverage grade B C
Overall rank #7 #704
Rank in Security & Guardrails #1 #8
GitHub stars 670 2.2k
Last updated today today
Build provenance Yes No
OSSF Scorecard 9.6 / 10 4.8 / 10
License Apache-2.0 AGPL-3.0
Downloads 10k/wk —
Trust dimensions (points earned)
Safety / integrity / 25 24.2 8.5
Identity & provenance / 18 18.0 10.8
Transparency / 17 16.7 12.6
Maintenance / 20 20.0 17.8
Adoption / 20 12.1 8.0
Runtime capability surface (full matrix)
MCP server Implemented —
External providers 3 — Anthropic, Google Gemini, Multi-provider (LiteLLM) —
Requires API keys No No
Plugin surface extensions —
Provenance drift Match —
Open in the live compare tool → HOL Guard profile open-kritt profile More Security & Guardrails →

How to read this: HVTrust (0–100) weighs supply-chain signals (provenance, OSSF Scorecard, signed commits, open license) alongside real-world adoption, scaled by an evidence-confidence factor. Grade bands: A ≥ 80, B ≥ 65, C ≥ 50, D < 50. Signals refresh daily. Full methodology v4.3 →