Registry › Compare › HOL Guard vs SkillSpector

HOL Guard vs SkillSpector

HOL Guard leads on trust: 92.2/100 (Grade A) against 62.9/100 (Grade C), a 29.3-point gap. HOL Guard leads on supply-chain integrity and provenance, and rests on broader evidence.

A HOL Guard 92.2

Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.

hashgraph-online/hol-guard · #7 overall · #1 Security & Guardrails · coverage B (3/5)

Choose HOL Guard if supply-chain integrity and provenance matter most.

  • +13.9Safety / Integrity: 98% of recent commits signed, against 78%
  • +7.2Identity / Provenance: package provenance attested, against none
  • +3.7Transparency: OSSF Scorecard 9.6 against 5.3
  • +1.8Adoption
C SkillSpector 62.9

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.

NVIDIA/SkillSpector · #550 overall · #7 Security & Guardrails · coverage C (2/5)

SkillSpector doesn't lead on any scored dimension in this pair.

Where they differ

24.4
Safety / IntegrityHOL Guard +13.9
10.5
18.0
Identity / ProvenanceHOL Guard +7.2
10.8
16.7
TransparencyHOL Guard +3.7
13.0
20.0
MaintenanceHOL Guard +0.1
19.9
12.1
AdoptionHOL Guard +1.8
10.3
+1.0
Runtime calibrationHOL Guard +2.6
-1.6

Full evidence table

An independent, evidence-based trust comparison of HOL Guard and SkillSpector, two Security & Guardrails projects in the HVTracker registry. Scores come from public, checkable signals — supply-chain provenance, OSSF Scorecard, maintenance, and adoption — not popularity.

Full evidence

Signal HOL Guardhashgraph-online/hol-guard SkillSpectorNVIDIA/SkillSpector
HVTrust score 92.2 62.9
Evidence grade A C
Coverage grade B C
Overall rank #7 #550
Rank in Security & Guardrails #1 #7
GitHub stars 684 18.8k
Last updated today 1d ago
Build provenance Yes No
OSSF Scorecard 9.6 / 10 5.3 / 10
License Apache-2.0 Apache-2.0
Downloads 9k/wk —
Trust dimensions (points earned)
Safety / integrity / 25 24.4 10.5
Identity & provenance / 18 18.0 10.8
Transparency / 17 16.7 13.0
Maintenance / 20 20.0 19.9
Adoption / 20 12.1 10.3
Runtime capability surface (full matrix)
MCP server Implemented Implemented
External providers 3 — Anthropic, Google Gemini, Multi-provider (LiteLLM) 5 — Amazon Bedrock, Anthropic, Azure OpenAI, …
Requires API keys No Yes
Plugin surface extensions extensions
Provenance drift Match —
Open in the live compare tool → HOL Guard profile SkillSpector profile More Security & Guardrails →

How to read this: HVTrust (0–100) weighs supply-chain signals (provenance, OSSF Scorecard, signed commits, open license) alongside real-world adoption, scaled by an evidence-confidence factor. Grade bands: A ≥ 80, B ≥ 65, C ≥ 50, D < 50. Signals refresh daily. Full methodology v4.4 →