Use approved configurations from Library
Add, review, publish, use, retire and restore versioned agent configurations in your Team workspace.
Page text and source link for your AI assistant. Nothing is sent automatically.
What Library is for
Library is your team's catalog of reviewed agent configurations. Repositories hold source files; Scans assess them; Library records reusable versions and their declared dependencies. Gateway separately checks routed runtime requests. Publishing a configuration does not install it into an agent or start any tool server.
Add and review
An owner or admin can paste a JSON or YAML configuration under Add a configuration, or import a file from a connected GitHub repository. Reuse the exact name and kind of a manual item to add a revision. Identical content reuses existing evidence. GitHub imports pin the commit and path.
Open Review versions to inspect the immutable score, grade and findings. Markdown skills can be archived, but are not assessed and cannot be published. A completed scan is not a guarantee that a configuration is safe in every environment.
Publish and use
Publish an assessed version that meets current organization policy. Members can open Use this version and download a sanitized JSON copy. YAML is converted to JSON and detected secrets are redacted. Supply credentials through your secret store before use. The original checksum identifies uploaded source evidence, not the transformed download.
After configuring your agent, record its dependency on the exact version. This records your declaration; it does not verify runtime installation. Updating Library does not automatically update agents.
Connect an MCP client
Create an organization service key under Team Settings → Service credentials. Use an MCP client that supports Streamable HTTP with custom bearer headers. Set its server URL to https://fooguard.com/api/mcp and its Authorization header to Bearer <organization-service-key>. Store the key in the client's secret manager, not a committed configuration. Personal API keys cannot read the Team Library.
The client must accept application/json, text/event-stream. Supported protocol versions are 2025-06-18 and 2025-03-26. The server supports stateless JSON responses, not subscriptions or server-side tool execution.
Call list_published_library to discover currently available versions. Use read_published_library_version with the exact versionId, or read the fooguard://library/versions/<versionId> resource shown on the version page. The response contains sanitized JSON in retainedBody, assessment metadata and a pin recording the service key's read of that version. A read pin does not prove that an agent installed or executed it.
Exceptions and current availability
Scores and findings never change when an exception is created. Active, time-limited exceptions can waive matching findings for publication and new reads. The minimum-grade requirement still applies. One-time exceptions are review decisions only, not a durable distribution permission.
Every content download and MCP discovery/read checks current policy, active time-limited exceptions and retirement status. Revoked or expired exceptions no longer authorize new reads. A stricter policy can block a previously published version. Publication is historical; current availability is shown separately.
Check policy evaluates stored assessments; it does not inspect running agents or automatically fetch changes from GitHub. Import again to assess updated source files.
Retire, restore and recover
An owner or admin can retire a published version with a reason. New downloads and MCP reads stop; existing copies and running agents are unaffected. Review recorded dependencies and arrange updates with their owners. Restore explicitly with a reason only after current policy passes. History retains the retirement and restoration decisions.
If a read is blocked, review the version's current availability. Fix the configuration and add a revision, restore a retired version when appropriate, or ask an administrator to review a time-limited exception. A missing or inaccessible version may belong to another workspace; choose the correct workspace or service key. Revoke unused service keys under Settings when offboarding clients.
Personal and Team navigation
Open Library → Agents, Configs, or Skills. Agents records ownership and declared relationships. Configs holds reusable files; Scans holds results of individual runs. Personal files stay private to their owner. Team files stay in that team's existing versioned catalog; owners and admins manage them.
On New scan, select Save to Library. Uploading prefills the editable File name field; for pasted content, enter a .json, .yaml, or .yml name in the same field. Choose the destination workspace. The file is saved after analysis succeeds; saving the initial scan result remains a separate action. If storage fails, the completed analysis stays visible and the error explains that the file was not saved.
From Configs, choose Run scan to create a new Scans entry. This evaluates the retained, normalized JSON copy, with detected secrets redacted. Original secret findings may therefore differ; upload the original file for a full reassessment. Prior assessments are unchanged. Personal files can be archived and restored. Team version availability and publication rules remain in force. Markdown Skills are stored without an assessment and cannot be rescanned.
Download or install a pinned copy
Choose Download for manual setup, or Copy install command to retrieve the exact retained version. For Team versions, open Review versions → Use this version; only currently available versions can be delivered.
The copied command works in a POSIX shell with curl and shasum. Set FOOGUARD_API_KEY securely in the process environment using your secret manager. Personal retrieval requires a personal API key with Pro API access; Team retrieval requires an organization service key and active Team API access. Never paste the key into source control or the command itself.
The command downloads over HTTPS, verifies the retained copy's SHA-256, and creates a file in the current directory without replacing an existing file. This checksum differs from the original source checksum because configurations are normalized and sanitized. Review the file, supply credentials through your secret store, then configure the consuming agent to load it. The command does not execute the configuration, restart an agent, or claim that an agent is using it. Each retrieval rechecks access and Team availability; retiring a version cannot remove previously downloaded copies.