What problem does it solve?
Open security platform for agentic infrastructure — broad scanning, blast radius, runtime, and trust across MCP discovery, CVEs, SBOMs, CIS benchmarks (AWS, Azure, GCP, Snowflake), OWASP/NIST/MITRE compliance, AISVS v1.0, MAESTRO layer tagging, and vector database security checks. Use when the user mentions vulnerability scanning, MCP server trust, compliance, SBOM generation, CIS benchmarks, blast radius, or AI supply chain risk.
Core Features & Use Cases
- Discover AI agents and MCP servers across 22+ tools and map blast radius and trust scores for risk assessment.
- Generate SBOMs and run CIS benchmarks (AWS/Azure/GCP/Snowflake) with optional cloud credentials.
- Ensure AISVS v1.0, MITRE ATLAS, NIST AI RMF, and other framework mappings for compliance in local workflows.
Quick Start
Install via pipx and run agent-bom agents to discover and scan locally.