HOL Guard vs Snyk Agent Scan
HOL Guard leads on trust: 92.2/100 (Grade A) against 63.8/100 (Grade C), a 28.4-point gap. HOL Guard leads on supply-chain integrity and provenance, and rests on broader evidence.
Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
Choose HOL Guard if supply-chain integrity and provenance matter most.
- +12.3Safety / Integrity: OSSF Scorecard 9.6 against 5.7
- +7.2Identity / Provenance: package provenance attested, against none
- +3.7Adoption
- +3.4Transparency: OSSF Scorecard 9.6 against 5.7
Security scanner for AI agents, MCP servers and agent skills.
Snyk Agent Scan doesn't lead on any scored dimension in this pair.
Where they differ
An independent, evidence-based trust comparison of HOL Guard and Snyk Agent Scan, two Security & Guardrails projects in the HVTracker registry. Scores come from public, checkable signals — supply-chain provenance, OSSF Scorecard, maintenance, and adoption — not popularity.
Full evidence
| Signal | HOL Guardhashgraph-online/hol-guard | Snyk Agent Scansnyk/agent-scan |
|---|---|---|
| HVTrust score | 92.2 | 63.8 |
| Evidence grade | A | C |
| Coverage grade | B | C |
| Overall rank | #7 | #519 |
| Rank in Security & Guardrails | #1 | #6 |
| GitHub stars | 683 | 3.1k |
| Last updated | today | 1d ago |
| Build provenance | Yes | No |
| OSSF Scorecard | 9.6 / 10 | 5.7 / 10 |
| License | Apache-2.0 | Apache-2.0 |
| Downloads | 9k/wk | — |
| Trust dimensions (points earned) | ||
| Safety / integrity / 25 | 24.4 | 12.1 |
| Identity & provenance / 18 | 18.0 | 10.8 |
| Transparency / 17 | 16.7 | 13.3 |
| Maintenance / 20 | 20.0 | 18.2 |
| Adoption / 20 | 12.1 | 8.4 |
| Runtime capability surface (full matrix) | ||
| MCP server | Implemented | Implemented |
| External providers | 3 — Anthropic, Google Gemini, Multi-provider (LiteLLM) | 1 — Anthropic |
| Requires API keys | No | Yes |
| Plugin surface | extensions | — |
| Provenance drift | Match | — |
How to read this: HVTrust (0–100) weighs supply-chain signals (provenance, OSSF Scorecard, signed commits, open license) alongside real-world adoption, scaled by an evidence-confidence factor. Grade bands: A ≥ 80, B ≥ 65, C ≥ 50, D < 50. Signals refresh daily. Full methodology v4.4 →