Product
About Foo Guard
Foo Guard is a pre-deployment security scanner for AI agent configurations, MCP/tool definitions, permissions, credentials, and autonomy risks.
Foo Guard is a software security product for AI agent configuration and policy analysis.
What Foo Guard is
Foo Guard reviews the files that describe an AI agent before that agent is deployed. Those files declare identity, tools, permissions, credentials, and how much the agent may do without a person in the loop. The scanner reads that declaration and reports security findings with a deterministic rules engine. Scores, severities, and pass or fail results come from those rules. An optional language-model explanation can suggest a fix afterward. It does not assign the score.
Teams use the same analysis in three places: the website, a command-line scan in CI, and GitHub Checks on a pull request or default-branch push. Repository policy can live in .fooguard.yml. Organization policy, where a Team workspace sets it, applies across repositories and cannot be weakened by a single repo file.
What Foo Guard scans
A scan looks at configuration and repository artifacts, not at a live conversation with a model. Typical inputs are JSON or YAML agent definitions and MCP-style tool definitions checked out at a commit.
- Agent identity, ownership, and whether actions can be attributed
- Permissions and capabilities, including administrative or production write access
- Tool definitions that can run a shell, write files, write a database, or call arbitrary HTTP endpoints
- Secret-like values and other exposed credential material in the configuration
- Autonomy settings, including long-lived authority and missing human approval
- Combinations of those conditions, where one flag is acceptable and several together are not
The scanner does not inspect model weights, training data, or the text of a prompt that a user types at runtime. If a risk exists only while a request is in flight, this product will not see it.
How Foo Guard works
Analysis follows a fixed path. Foo Guard parses the configuration, redacts secret-like values before they appear in saved output, and normalizes the declared capabilities into one agent model. Deterministic rules then evaluate that model. The same file and the same policy produce the same findings, score, and grade. Policy thresholds such as failOn and minGrade decide whether the result passes.
Anonymous scans in the browser are not stored. Signed-in users can save a sanitized snapshot and download a report built from that result. The report restates the findings, score, and grade. It does not add a second opinion from a model. AI remediation, when someone asks for it, reads the sanitized findings and proposes changes. Those suggestions stay separate from the score and from the pass or fail decision.
A Team workspace keeps repository inventory and scan history for the commits it analyzed. Each scan is tied to a commit SHA. Later runs do not rewrite an earlier result. That history is how a reviewer sees whether a configuration change introduced a new finding or cleared one.
Where Foo Guard fits
AI security work splits across the lifecycle. Before deployment, someone has to decide whether the configuration itself is an acceptable grant of authority. After deployment, other systems may watch prompts, model responses, or tool calls as they happen. Foo Guard is built for the first problem: static, pre-deployment analysis of the configuration and the repository artifacts that define the agent.
Foo Guard does not currently:
- Proxy live prompts
- Inspect live model responses
- Sit inline between an application and an LLM
- Act as a runtime prompt firewall
It is also not a data-loss-prevention proxy for live completions, a runtime MCP gateway, a model-weight scanner, a SIEM, or an IDE plugin. A runtime control that blocks a prompt or a tool call solves a different problem. Static analysis and runtime controls can sit next to each other. One does not replace the other.
GitHub and CI enforcement
On a Team workspace, Foo Guard can connect a GitHub App, inventory repositories, and publish a check named Foo Guard Security for the commit under review. The check fails when the effective policy fails. Branch protection can require that check before merge. Foo Guard does not change branch protection for you.
Pro and Team plans can run the same rules from the CLI or the GitHub Action. A policy failure exits with code 1 so a pipeline can stop. The web app remains available for a one-off scan without wiring CI. Enforcement still depends on the policy you configure and on the files the scanner can read at that commit.
Research and methodology
Foo Guard publishes technical research showing how its deterministic rule engine evaluates agent configurations and where static analysis has limits. The public benchmark uses Foo Guard-maintained fixtures and the same rules as the product. It is not an independent certification, and it does not measure runtime behavior.
Read the static analysis research note.
Who it is for
Foo Guard is for people who ship agents and need a repeatable check on the configuration before it reaches production. That includes application developers reviewing a pull request, platform teams setting organization policy, and security reviewers who want a stable finding id instead of a one-off read of a YAML file.
Anyone can run an analysis in the browser with no account. A Pro subscription adds the CLI, GitHub Action, and API. A Team subscription adds GitHub App scanning, organization policy, and shared repository inventory. Pricing is listed on the pricing page.