Comparisons

Foo Guard and Snyk Agent Scan

Snyk Agent Scan discovers local agent components and starts MCP servers to read their tool descriptions. Foo Guard scores the configuration file you submit and does not start those servers.

What the README says the scan does

The Snyk Agent Scan README, reviewed at github.com/invariantlabs-ai/mcp-scan on 2026-10-05, describes a scanner that discovers installed agent components on a machine: harnesses, MCP servers, and skills. It scans them for prompt injections, sensitive data handling, and malware payloads hidden in natural language. The same page says both the v0.5.x line and v0.6 and later scan MCP servers, tools, prompts, resources, and skills, and discover supported agent configurations such as Claude, Cursor, Windsurf, and Gemini CLI.

The README also says the raw CLI output is experimental and may change without notice. For v0.5.x that warning covers issue codes, field names, severity labels, and response structure. For v0.6 and later it covers risk indicator names, scores, field names, and response structure. Snyk tells readers not to build production workflows that depend on specific CLI output fields. An enterprise deployment may show a different result in Snyk's platform than the CLI prints. A comparison that treats one CLI severity string as a stable gate is ahead of what that README supports.

Scanning the file can start the servers in the file

The README's security warning says that scanning an MCP configuration executes the commands defined in it. Agent Scan starts stdio MCP servers with the configured command and arguments because it needs those processes to retrieve tool descriptions. The page recommends a sandbox when the configuration is untrusted, a careful reading of the consent prompt, and the --dangerously-run-mcp-servers flag only in an environment where those commands have already been verified. Interactive runs ask for consent before each stdio server starts.

That execution step is the main operational difference from Foo Guard. Foo Guard's MCP page says the scan does not start MCP servers, does not speak the MCP protocol, and does not treat a top-level mcpServers list as a live inventory. Server command lines are not executed, and they are not, by themselves, a finding. If the tool entries omit a dangerous capability, Foo Guard does not infer it from the server package name.

Each scan can see a different object

Snyk's scan is aimed at the tool, prompt, resource, and skill text it can retrieve, including text that is not written out in the client configuration. The v0.5.x highlights name prompt injection, tool poisoning, tool shadowing, and toxic flows for MCP, and prompt injection, malware payloads, untrusted content, credential handling, and hardcoded secrets for skills. The v0.6 highlights regroup those risks. Those names come from the README. This article does not restate them as measured detection rates.

Foo Guard is aimed at the fields in the file you submit: filesystem access, network access, database access, shell execution, credentials, permissions, and whether a person must approve a change. The same file produces the same findings and the same score. A higher score means more severity weight. An AI suggestion does not choose the severity, the score, the grade, or whether a rule passed.

A tool description that exists only after the server starts is outside a Foo Guard scan. A capability flag that exists only in the committed YAML is outside a scan that never opens that file and only talks to a running server. Teams that care about both objects need both kinds of review. One product's result does not substitute for the other.

A practical split

Use Foo Guard on the change in Git. The configuration is the review item, the rules are fixed, and the policy file can fail the pull request without launching the servers named in the diff.

Use Snyk Agent Scan when you need an inventory of agent components already installed on a machine, or when you need the descriptions those MCP servers return. Follow Snyk's own warning for untrusted configs: run that scan where executing the configured command is an acceptable side effect. Keep the CLI output out of a production gate unless you have confirmed, with Snyk, that the field you depend on is one they support.

The README requires a Snyk API token before a scan. This article does not repeat a token command or a sample secret.

Sources

All comparisons