if an AI agent runs commands on your machine, HOL Guard decides what it can touch: risky commands get blocked or sandboxed, filesystem paths are fenced off, and everything lands in an audit log.
three releases landed this week, v3.4.5 through v3.5.1. the big one: Devin CLI support. `hol-guard install devin` writes managed hooks into Devin's config, keeps the hooks you already have, and routes events through the same runtime Claude Code uses. Guard only blocks, never approves.
also shipped: Linux enrollment recovery that keeps native authority, fixed Windows command paths and daemon startup, clearer command activity labels in the dashboard, an in-app confirmation dialog, and a bounded parser for command events.
uv tool install "hol-guard[cisco]==3.5.1"