How to read a Foo Guard assessment
What the deterministic score, grade, findings, and configuration evidence mean, and what an optional AI suggestion does not change.
Start with the configuration you submitted
Foo Guard assesses a supported agent configuration. The scan does not execute the agent or the tools named in that configuration.
A saved assessment keeps a sanitized snapshot. The score, grade, findings, and evidence on that snapshot stay with the assessment that was stored.
Read the findings before the grade
Each finding comes from a deterministic rule. It has a rule id, a severity, a title, and the configuration location that triggered it.
The useful next step is the evidence path. That path shows where in the configuration the rule matched, which is the place to change before you run the scan again.
The score is a severity weight
The rules engine adds a fixed weight for each finding's severity and caps the total at 100. A higher score means more severity weight. Grades run from A, for a low score, through F, for a high score.
The same configuration produces the same score. An AI suggestion does not choose the severity, the score, the grade, or whether a rule passed.
Treat AI remediation as advice
When remediation is available, it can suggest a change. The suggestion is advisory. The findings and score above it remain the rules-engine result until you change the configuration and scan it again.
Do not paste credentials or source into a feedback comment. Foo Guard stores the feedback category and the comment you submit, not a new copy of the configuration.