99
/ 100
Exemplary work. Strong across engineering, project hygiene, and documentation.
Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
Outstanding. A score of 99/100 puts this repo in a very small tier of truly well-engineered projects.
Top fixes
Highest-impact changes first, ranked by point weight
Working through the fixes? Let every push regrade itself.
The free GitHub App rescans this repo on every push and posts the grade as a commit check, so the score climbs without coming back to rescan by hand.
Scorecard
Every check, grouped by category and sorted worst-first
Documentation
97
README documents how to install the project.
README is present.
Licensed under Apache-2.0.
Contributing guide is detailed and thorough.
Engineering
100
Test files detected (ci/native_runtime/test_command_model_differential.py).
CI is configured (.github/workflows/ci.yml).
Linter or formatter configured ([tool.ruff] / [tool.black] in pyproject.toml).
Lockfile present (requirements.txt). Installs are reproducible.
Issue or PR templates present.
Project health
100
Dependency manifest found (pyproject.toml).
Repository has a description.
Actively maintained (pushed within the last month).
.gitignore present.
Repository health signals
Activity, community, and responsiveness at scan time
Activity
- -Commits (30d / 90d)
- 29Forks
- 1000Releaseslatest 3mo ago
Community
- 75% - GoodCommunity health
- 1 bus factorlowauthor own >50% of commits
- 554Watchers
Responsiveness
- 21hMedian issue response
- <1hMedian PR merge time
- 38Open issues
Repository files46 root entries
- .clusterfuzzliteGood: Environment pinned via .clusterfuzzlite/Dockerfile.
- .factory
- .githubGood: CI is configured (.github/workflows/ci.yml).Good: Dependabot covers 3 ecosystems (pip, github-actions, docker). Dependencies stay current.Good: Issue or PR templates present.
- action
- ciGood: Test files detected (ci/native_runtime/test_command_model_differential.py).
- contracts
- contributions
- dashboard
- devcontainer-features
- distributions
- docs
- fuzzers
- guarded-repository
- integrations
- release-metadata
- rust
- schemas
- scripts
- spec
- src
- tests
- .dockerignore
- .gitattributes
- .gitignoreGood: .gitignore present.
- .gitleaksignore
- .pre-commit-hooks.yaml
- CHANGELOG.md
- CITATION.cff
- conftest.py
- CONTRIBUTING.mdGood: Contributing guide is detailed and thorough.Good: Contributing guide includes setup/install instructions.Good: Contributing guide describes code style expectations.Good: Contributing guide explains how to run tests.Good: Contributing guide describes the PR/review workflow.Good: Contributing guide includes code examples.
- docker-requirements.txt
- Dockerfile
- HOL_GUARD_ANSWERS.md
- LICENSEGood: Licensed under Apache-2.0.
- llms-install.md
- OPEN_SOURCE.md
- pr-body.md
- PRODUCT.md
- pyproject.tomlGood: Dependency manifest found (pyproject.toml).
- README.mdGood: README is present.Good: README is well structured with multiple sections.Good: README includes screenshots or visuals. Great for first impressions.Good: README has code examples.Good: README links to a live demo or deployed app.Good: README includes status badges.Good: README documents how to install the project.Good: README documents how to run the project.
- requirements.txtGood: Lockfile present (requirements.txt). Installs are reproducible.
- security-insights.yml
- SECURITY.mdGood: Security policy present.
- server.json
- sonar-project.properties
- uv.lock
Add this badge to your README
It updates automatically each time the repo is re-graded.
[](https://www.repo-grade.com/report/hashgraph-online/hol-guard)