Comparisons

How to choose an AI agent security control

A practical split among repository configuration review, MCP metadata inspection, platform inventory, and runtime filtering, using vendor pages reviewed on 2026-10-05.

Questions and the control that answers them
QuestionControl reviewed
What capabilities does this committed file declare?Foo Guard scores the JSON or YAML you submit.
What does an MCP server advertise after it starts?Snyk Agent Scan and Microsoft mcp-scan can connect. Their live modes start or contact the server.
Which agents already exist on a connected platform?Check Point AI Agent Security documents discovery for seven named platforms.
Should this live prompt or tool response be blocked?Check Point documents a Guard API. Google Model Armor documents floor settings for Google and Google Cloud MCP servers.

Start from the question

Agent security products are easy to line up as if they scanned the same object and returned the same kind of result. The pages reviewed for this note describe four different objects: a file in a repository, metadata a server returns when a scanner connects, an inventory built from a platform API, and a prompt or tool response already in flight.

A useful comparison asks which of those objects you can see today, and which decision you need to make. A pull request can show a file. It cannot list every agent an employee created in another product. A runtime filter can block a tool response. It does not explain the capability flags in the file you are about to merge.

A file review and a live connection answer different questions

Foo Guard's MCP page describes a review of declared tools, permissions, credentials, and approval settings in JSON or YAML. That scan does not start MCP servers and does not speak the MCP protocol. If the dangerous capability is only implied by a package name in mcpServers, Foo Guard does not invent a finding from that name.

The Snyk Agent Scan README says scanning an MCP configuration starts the stdio servers named in the file so the scan can retrieve tool descriptions. The Microsoft mcp-scan tutorial separates that kind of connection from --static-only, which scans inline tool arrays and launch metadata without launching commands or contacting endpoints. Use the live path when the thing you need is the metadata the server actually advertises. Use a file review when the thing you need is the capability declaration in the change under review, and when starting the server on a laptop or a CI runner is not acceptable.

Inventory and runtime are separate layers

Check Point's AI Agent Security overview describes two layers. Posture is the structural state of an agent, assessed from configuration. Runtime is screening of prompts, tool calls, tool responses, and actions while the agent operates. The same overview says discovery and risk assessment are managed in the portal, and runtime protection integrates through the Guard API.

Discovery connects to Amazon Bedrock, Amazon Bedrock AgentCore, Google Cloud, Microsoft Copilot Studio, Salesforce Agentforce, n8n, and Relevance AI. The risk assessment then rates each discovered agent. That rating uses the fields the platform exposes. It is a different instrument from Foo Guard's score, which adds a fixed severity weight and caps the total at 100. A higher score means more severity weight. Grades run from A, for a low score, through F, for a high score. The two results are not interchangeable, and neither page publishes a shared test set that would support a detection-rate claim.

Google's Model Armor integrations page, last updated 2026-10-05 UTC, describes sanitizing MCP tool calls and responses for Google and Google Cloud MCP servers through floor settings. The coverage row for that integration is text, with inspect-only and inspect-and-block modes, limited to those Google MCP servers. That is a filter on traffic inside Google Cloud. It is not a review of a configuration file in Git.

What Foo Guard is for

Foo Guard is the file and policy control in this set. You paste or upload JSON or YAML, or you point the CLI, API, or GitHub Action at files in a repository. Deterministic rules produce the findings, the severity, the score, and the pass or fail result. Optional AI remediation can suggest a change. That suggestion is advisory: it does not choose the severity, the score, the grade, or whether a rule passed.

Repository thresholds live in the policy file. A team can fail a pull request from that policy through GitHub and CI. The static-analysis research note shows how four fixture files score. It is a vendor-run illustration of the rules engine, and the note says it is not a third-party certification.

What these pages leave out

These articles cite the public pages linked below. They do not rank vendors, estimate false positives, or compare price. They also do not treat a missing sentence as proof that a product lacks a feature. If a later page from the same vendor documents a repository scanner, a platform inventory, or a runtime filter, that page supersedes this reading.

Foo Guard does not discover agents on the platforms Check Point lists, does not screen live prompts, and does not connect to an MCP server to read the tools it advertises. Those are separate controls. The notes on Snyk Agent Scan, Check Point AI Agent Security, and Microsoft mcp-scan stay inside the pages reviewed on 2026-10-05.

Sources

All comparisons