Foo GuardBeta
Resources↗PricingFeedbackLog inSign up
Menu
Resources↗PricingFeedbackLog inSign up

Getting Started

  • Foo Guard overview
  • Your first security assessment
  • Understanding risk scores
  • Understanding findings

Agent Configuration

  • Supported configuration formats

Team Workspaces

  • Create a Team workspace
  • Team roles and permissions

GitHub Integration

  • Connect GitHub
  • GitHub App permissions
  • Enable repositories
  • .fooguard.yml — repository policy-as-code
  • Repository scanning
  • Automatic push scans
  • GitHub Checks
  • Pull request scanning
  • Branch protection
  • Manual scans
  • Scan history
  • Baselines
  • Repository posture
  • Troubleshooting GitHub integration

Rules & Findings

  • Rule overview
  • Severity levels

Developer & API

  • Developer & API overview
  • Authentication
  • API keys
  • REST API
  • Rate limits
  • Error handling
  • CLI
  • CI/CD enforcement
  • GitHub Action

Security & Privacy

  • Security and privacy

Troubleshooting

  • GitHub setup troubleshooting

Rules

Rule reference

Rule reference

Canonical documentation for Foo Guard production rules AG-001 through AG-023.

  • AG-001

    Missing Agent Identity

    high

  • AG-002

    Missing Owner

    medium

  • AG-003

    Missing Lifecycle Information

    low

  • AG-004

    AG-004

    critical

  • AG-005

    AG-005

    critical

  • AG-006

    Long-Lived Credential

    high

  • AG-007

    Shared Credential

    high

  • AG-008

    Wildcard Permission

    critical

  • AG-009

    Administrative Permission

    critical

  • AG-010

    Production Write Access

    critical

  • AG-011

    Excessive Permission Scope

    high

  • AG-012

    Cross-Resource Unrestricted Access

    high

  • AG-013

    Shell or Command Execution

    critical

  • AG-014

    Arbitrary HTTP Requests

    high

  • AG-015

    Filesystem Write Access

    high

  • AG-016

    Database Write Access

    high

  • AG-017

    Destructive Operations Without Approval

    critical

  • AG-018

    Excessive or Unlimited Autonomy

    high

  • AG-019

    Agent Self-Modification

    critical

  • AG-020

    Missing Action Attribution

    high

  • AG-021

    Missing Human Approval

    high

  • AG-022

    Potential Data Exfiltration Path

    critical

  • AG-023

    Compound Modification + Network Risk

    high

23 rule pages available.