MoltGuard has a coherent security purpose, but it asks users or agents to install a persistent external guard plugin that stores credentials, changes configuration, and exposes API-key material without enough user-controlled scoping.
Install only if you trust OpenGuardrails/MoltGuard as a security provider and are comfortable with a persistent plugin handling security telemetry and local credentials. Require explicit user approval before install, update, enterprise enrollment, or uninstall; do not share /og_status or /og_claim output without redacting keys; verify any enterprise Core URL before enrolling; and understand what data Core receives before using it in sensitive workspaces.