A neutral home for open AI-agent infrastructure. Standards, registries, discovery, trust, and coordination across Web2 + Web3.

Pinned Tweet
1/ Today we’re launching the HOL Partner Program. Cohort One brings together 30+ signed partners, including XMTP, GoDaddy, and DSR, to help shape open infrastructure for AI agents. Registries. Payments. Privacy. Security. Communication. Standards. The agent stack is forming now.
108
201
649
3,083,204
HOL retweeted
if an AI agent runs commands on your machine, HOL Guard decides what it can touch: risky commands get blocked or sandboxed, filesystem paths are fenced off, and everything lands in an audit log. three releases landed this week, v3.4.5 through v3.5.1. the big one: Devin CLI support. `hol-guard install devin` writes managed hooks into Devin's config, keeps the hooks you already have, and routes events through the same runtime Claude Code uses. Guard only blocks, never approves. also shipped: Linux enrollment recovery that keeps native authority, fixed Windows command paths and daemon startup, clearer command activity labels in the dashboard, an in-app confirmation dialog, and a bounded parser for command events. uv tool install "hol-guard[cisco]==3.5.1"
2
3
11
712
Anyone who can reach your MikroTik's public SSH can open a session without logging in. CISA put that SSH rekey bug on the federal must-patch list today, due Sep 28. hol.org/blog/cve-2026-67276-…
1
2
556
HOL retweeted
Your Magento storefront can be jumped to higher privileges with no login. CISA put this on KEV today (due Sep 27). Move to the August security train: hol.org/blog/cve-2026-71362-…
3
1
4
890
Your WordPress site can include a stranger-picked PHP file through template resolution. CISA put this on KEV today (due Sep 28). Upgrade to 7.1.2 (or your branch patch): hol.org/blog/cve-2026-87902-…
535
Someone with a low-priv SharePoint login can run code on your on-prem farm. CISA put this on KEV today (due Sep 28). Install the August SharePoint KBs: hol.org/blog/cve-2026-65660-…
1
544
HOL retweeted
if an AI agent runs tools on your machine, HOL Guard decides what it can touch. risky commands get blocked, everything else gets logged with the evidence to back it up. three patch releases in two days, v3.4.2 through v3.4.4: - guard authority on Linux survives keyring sessions, so you stop re-authorizing after a reboot - workspace audits ask which project folder to scan instead of guessing - evidence rows keep the full command context, so an audit entry tells you exactly what ran - the dashboard shows the Cloud Review authenticator field - package matching keeps `--` terminators, and decision reports stay accurate after matcher updates - release wheels get verified against their git tag before they ship uv tool install hol-guard==3.4.4
1
1
6
636
if an AI agent runs commands on your machine, HOL Guard decides what it can touch: risky commands get blocked or sandboxed, filesystem paths are fenced off, and everything lands in an audit log. three releases landed this week, v3.4.5 through v3.5.1. the big one: Devin CLI support. `hol-guard install devin` writes managed hooks into Devin's config, keeps the hooks you already have, and routes events through the same runtime Claude Code uses. Guard only blocks, never approves. also shipped: Linux enrollment recovery that keeps native authority, fixed Windows command paths and daemon startup, clearer command activity labels in the dashboard, an in-app confirmation dialog, and a bounded parser for command events. uv tool install "hol-guard[cisco]==3.5.1"
2
3
11
712
HOL retweeted
Big AI day: OpenAI launched GPT-6 Sol + Luna, Meta is doubling down on its Muse agent, and Australia says an OpenAI agent breached a Medicare portal. We’re breaking down what matters on HOL x AI today. 10 AM ET nitter.net/i/broadcasts/1YxNrbqQr…

HOL

HOL x AI: Episode 6

1
3
8
1,044
HOL retweeted
If you run agents with MCP tools, HOL Guard sits between the model and the server, deciding which calls pass, which get denied, and which need review. 3.0.190 extends that to hosted MCP servers (remote HTTP endpoints like InstaPods). Sensitive hosted actions (delete pod, exec, file writes) default to review, and a hosted server can't relax your policy to allow. uv tool install "hol-guard[cisco]==3.0.190"
2
3
14
1,144
HOL retweeted
Anyone who can reach your OpenShift console Route can poke internal cluster services with no login. Unauth Devfile API. No RHSA yet. Lock down the Route, then watch for the errata. CVE-2026-75885 hol.org/blog/cve-2026-75885-…
2
7
1,211
HOL retweeted
A stranger can leave script in your WordPress comments. Core bug. WordPress 7.1.1 closes CVE-2026-93485 plus 10 other security fixes. Update now. hol.org/blog/cve-2026-93485-…
1
1
3
1,109
HOL retweeted
AI-powered cyberattacks aren’t coming. They’re already here. Criminals are using AI agents to automate hacks at scale... and companies are scrambling to keep up. The twist? AI might also make attackers easier to catch. Are we ready for this?
2
7
10
799
HOL retweeted
if an AI agent runs tools on your machine, HOL Guard decides what it can touch. risky commands get allowed, paused, or blocked before they run. 3.3.1 through 3.4.1 shipped this week. the security-relevant parts: guard now reviews its own updates. a newly published hol-guard or plugin-scanner release stays on review instead of being trusted on package name alone, and only an exact-version reinstall from the default index goes through. unauthenticated launchers are denied tool use, except the one exact repair command. 3.4.1 keeps that local repair path responsive when you work across multiple workspaces. contributors get Gitar auto-repair on ready PRs, and extension permissions get bulk controls in the dashboard. uv tool install "hol-guard[cisco]==3.4.1"
3
2
8
866
numbers don’t lie
HOL Guard Adoption is growing like a hockey stick. - We're on track to reach 1m+ PyPI downloads. - 3–4 external pull requests for extensions and adapters per day. - Nearly 100 forks and 700 Github Stars. There is no better time to get involved: github.com/hashgraph-online/…
2
8
735