HOL Plugin Security

Explorer for HashgraphOnline/hol-plugin-security: 205 scored registry plugins, 22 public Guard advisories, 220 modeled runtime fixtures, and an honest OWASP MCP Top 10 mapping.

Not claimed here: first firewall, unlabeled 450K+ anything, or Guard-only GitHub stars. Hashgraph Online org-wide stars (3.5K+) are not attributed to this Space, this dataset, or Guard.
Honest limits
  • 205 scored plugins ≠ Registry Broker agent counts (do not confuse with 249k agents / 24k MCP servers).
  • Scanner on plugin rows is registry-broker-fallback. Scan ≠ safety. Most findings are publishability, not confirmed vulns.
  • HOL Guard is local-first (shell, secrets/file reads, MCP server change, plugin/skill install). Not a cloud MCP gateway.
  • Runtime fixtures are modeled. Same outcome across harnesses. Latency values are placeholders. No real secrets or attacks executed.
  • Cursor artifact trust is not full pre-exec of every tool description / MCP tool call.
  • Not a complete prompt-injection preventer.
  • MCP08 has 0 advisory rows in this snapshot.
  • HOL publishes this. Not independent third-party validation.

Default config: plugins (205 scored registry plugins). Filterable and sortable. scanner_provider is registry-broker-fallback on every current row. Scan ≠ safety.

22 public HOL Guard advisory pages. owasp_mcp is HOL's primary mapping to one OWASP MCP Top 10 (beta) ID. threat_class comes from hub listing badges on hol.org/guard/security, not inferred from titles. A mapped advisory is not proof a plugin is safe. MCP08 has 0 rows.

220 modeled harness outcomes from the published Guard benchmark record. Same outcome across all 5 harnesses. Latency values are placeholders. No real secrets or attacks executed. This is not a live exploit test.

OWASP MCP Top 10 mapping (beta)

Copied from the dataset card. HOL's mapping of local Guard + catalog scanner to the OWASP MCP Top 10 beta (Phase 3). Not complete coverage.

MCP06 on the Top 10 list is Intent Flow Subversion. The same OWASP page later also titles that item "Prompt Injection via Contextual Payloads". HOL Guard is not a complete prompt-injection preventer.

IDs and names are cited; long OWASP descriptions are not copied. OWASP document license: CC BY-NC-SA 4.0. advisory_rows is counted from this snapshot's advisories.owasp_mcp (one primary ID per advisory).

IDNameAdvisory rowsDetectPreventGap
MCP01Token Mismanagement & Secret Exposure4 catalog/advisory secret-exfil + mcp-token-theft Guard can block secret-file / env reads at the local action boundary not a secrets manager; does not rotate tokens; does not scrub secrets already inside model context
MCP02Privilege Escalation via Scope Creep1 tool-permission-creep advisory Guard approval on plugin/skill install and MCP server change not an OAuth scope-expiry gateway
MCP03Tool Poisoning2 tool-description-poisoning advisory + scanner MCP posture Guard on changed MCP servers / plugin install Cursor path is artifact trust, not full pre-exec of every tool description
MCP04Software Supply Chain Attacks & Dependency Tampering4 catalog scores, lockfile/publishability findings, supply-chain advisories Guard on plugin/skill install not a signing/SBOM authority
MCP05Command Injection & Execution1 unsafe-command / rm-rf advisory Guard intercepts local shell/file-destructive actions does not sandbox every MCP server's own backend
MCP06Intent Flow Subversion5 several prompt-injection advisories (Intent Flow Subversion / contextual payloads) limited (some injected-instruction to shell paths hit Guard) NOT a complete prompt-injection preventer
MCP07Insufficient Authentication & Authorization1 MCP transport hardening (insecure HTTP, wildcard binds, missing auth posture) on Guard pages local only not an MCP gateway identity layer
MCP08Lack of Audit and Telemetry0 local decision trail / receipts on the developer machine local decision trail / receipts not an immutable SIEM; local logs
MCP09Shadow MCP Servers1 shadow-mcp-server-discovery advisory Guard on new/changed MCP servers before the harness launches not continuous org-wide network discovery of shadow servers
MCP10Context Injection & Over-Sharing3 context-window-scraping / data-overexposure advisories Guard on excessive local file reads does not quarantine or partition model context windows

This mapping does not replace the disclaimers above. Guard is local-first, not a cloud MCP gateway. Fixtures are modeled. 205 plugins ≠ Registry Broker agent counts. Scan ≠ safety.