Comparisons

Foo Guard and Microsoft mcp-scan

Microsoft's mcp-scan tutorial describes a static-only file mode and a live listing of MCP metadata. Foo Guard reviews declared capabilities and does not connect to the server.

The tutorial inspects MCP metadata

Microsoft's MCP Scan CLI tutorial in the Agent Governance Toolkit, reviewed on 2026-10-05, describes mcp-scan from the agent-os-kernel package. The scanner checks MCP primitive metadata before an agent relies on it. The threat table names tool poisoning, hidden instructions, description injection, schema abuse, cross-server name collisions, and rug-pull drift against a stored fingerprint.

The page says the scan is metadata-only. Live inspection uses discovery and listing calls. It does not call tools, read resources, or render prompts by default. That is still a connection: live stdio scans launch the configured local command, and live HTTP and SSE scans connect to the configured endpoint.

Static-only is the mode for untrusted files

The tutorial tells readers to use --static-only for pull requests, staged commits, downloaded configs, and any other untrusted input, so the CLI does not launch commands or connect to remote endpoints. In that mode it scans inline tools arrays and launch or endpoint metadata already present in the file. It does not discover primitives that the server would only reveal after a connection.

The same page includes a release note: the stateless Streamable HTTP flow described for current main, including a 2026-07-28 discovery path with a 2025-11-25 fallback, landed after the 5.0.0 release and is not in the currently published agent-os-kernel packages. A comparison of today's pip install agent-os-kernel should not assume that unreleased flow. The static-only warning and the live-versus-static distinction are part of the tutorial as reviewed.

Declared capabilities and advertised metadata

Foo Guard and mcp-scan --static-only can both be pointed at a file without starting a server. They do not look for the same evidence. Foo Guard normalizes declared capabilities in the JSON or YAML it understands: shell, filesystem, network, database, credentials, permissions, and approval. The MCP page says a server command is not executed and is not, by itself, a finding.

Microsoft's static mode, as the tutorial describes it, validates launch and endpoint metadata and scans inline tool arrays for the metadata threats in its table. A hidden instruction in a tool description is the kind of evidence that table is about. A Foo Guard finding is a declared capability that matched a deterministic rule. A description that contains an instruction, and a tool entry that sets executesShell, are different inputs. A file can contain one, the other, or both.

CI evidence the tutorial demonstrates

The tutorial documents exit codes: 0 when the command succeeded with no critical scan, config, or inspection findings and no fingerprint drift; 1 for a config, usage, or file error; 2 for critical findings, live inspection failure, or fingerprint drift. It says a report is evidence for an MCP security review, not a certification. The GitHub Actions example installs agent-os-kernel and runs mcp-scan scan with --static-only. The surrounding text says a live CI scan is appropriate only in a protected job where the config is already trusted to execute on the runner.

Foo Guard's CI path is the CLI, the GitHub Action, and a policy file that states the scan paths, fail conditions, and minimum grade. The pass or fail result comes from that policy and the rules engine. It does not attach the OWASP MCP report the Microsoft tutorial generates, and it does not fingerprint server metadata across runs.

Use --static-only, as Microsoft documents it, when the review item is an untrusted MCP config and the failure you care about is in the metadata that file already contains. Use Foo Guard when the review item is an agent configuration whose declared permissions, tools, credentials, and autonomy should fail a policy before merge. Use a live mcp-scan only where launching the configured command, or connecting to the configured endpoint, is an accepted effect of the scan.

Sources

All comparisons