Foo Guard and Check Point AI Agent Security
Check Point documents platform discovery, a configuration risk rating, and a separate Guard API. Foo Guard scores a configuration file you submit and does not inventory those platforms.
The overview describes two layers
The pages reviewed here are published at docs.lakera.ai. The product name on the AI Agent Security overview is Check Point AI Agent Security. That page, reviewed on 2026-10-05, says the product is an early access release and that the docs cover the capabilities described there today.
The overview splits the product into posture and runtime. Posture is the structural state of an agent: tools and toolsets, connected MCP servers, model, authentication, and level of autonomy, assessed from configuration. Runtime is live behavior: screening prompts, tool calls, tool responses, and actions, and blocking what policy does not allow when enforcement is configured. Discovery and risk assessment are the posture capabilities. Runtime protection integrates through the Guard API. The overview says native platform runtime integrations are on the roadmap.
Discovery builds an inventory from platforms
The discovery page says discovery connects to the platforms where agents run. The platforms listed there are Amazon Bedrock, Amazon Bedrock AgentCore, Google Cloud, Microsoft Copilot Studio, Salesforce Agentforce, n8n, and Relevance AI. Most are discovered continuously. Some use scheduled scans.
For each agent, the inventory records what the platform exposes: name, owner, model, recent activity, tools and what they can read and write where that detail exists, connected MCP servers, and platform-specific fields such as Bedrock action groups or Copilot Studio authentication. The page says discovery depth depends on the platform API. Where a field is missing, the risk assessment runs on the fields that are available and shows what it could not assess.
Foo Guard does not connect to those platforms and does not build that inventory. A Foo Guard scan sees the JSON or YAML someone submits or commits. An agent that exists only inside Copilot Studio or Bedrock is invisible to that scan until its configuration is represented in a file Foo Guard can parse.
The rating is a different instrument from a Foo Guard score
The risk assessment page gives every discovered agent a rating of Critical, High, Medium, or Low, with the contributing factors explained. It also describes informational findings that are present in configuration but not currently active. The page says severity asks how close a finding is to a realizable loss and how large that loss would be. The four factors it names are impact, preconditions, control strength, and finding confidence.
Two rules on that page matter when you put the rating next to another product's number. Severity is inherited when an authoritative score already exists, and the page gives CVSS for a published CVE as the example. Combinations escalate, and scores do not sum: individually low or medium conditions can combine into a critical finding. The framework is described as modelled on the Common Weakness Scoring System, with mappings to OWASP and MITRE ATLAS.
Foo Guard's score is the fixed severity weight of the findings in one submitted file, capped at 100. A higher score means more severity weight. Grades run from A, for a low score, through F, for a high score. The same file produces the same score. Check Point's page is explicit that the assessment does not cover the risk of live behavior. Foo Guard's scan does not cover live behavior either. The assessment essay describes what the stored score, grade, findings, and evidence mean.
Runtime protection is a separate integration
The overview lists the runtime suite applied through the Guard API: Prompt Defense, Content Moderation, Data Leakage Prevention, Malicious Links, and Agent Behavior Defense, across user prompts, model outputs, tool calls, tool responses, and tool descriptions. AI Guardrails is also described as a standalone tier for teams that want that runtime layer without the discovery product.
Foo Guard does not provide that API. Optional remediation text in Foo Guard is advisory. It does not choose the severity, the score, the grade, or whether a rule passed, and it does not block a live tool call.
A repository that wants a merge blocked on declared capabilities still uses a file policy. Check Point's published overview does not describe a .fooguard.yml-style file or a scan of a pasted JSON document. That absence is a statement about these pages, not a claim that no such feature can exist. The control those pages do document for agents already running on the listed platforms is discovery, then the risk rating, then the Guard API.
Sources
- AI Agent Security Overview · Check Point
- Agent Discovery · Check Point
- Agent Risk Assessment · Check Point