agent-bom

Automate vulnerability scanning, SBOM generation, and CIS benchmarking for MCP agents.

29|7|Updated Feb 22, 2026
One-click install
npx skills add https://github.com/msaad00/agent-bom --skill agent-bom
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: agent-bom
Source: https://github.com/msaad00/agent-bom/tree/main/integrations/openclaw
Command: npx skills add https://github.com/msaad00/agent-bom --skill agent-bom

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Open security platform for agentic infrastructure — broad scanning, blast radius, runtime, and trust across MCP discovery, CVEs, SBOMs, CIS benchmarks (AWS, Azure, GCP, Snowflake), OWASP/NIST/MITRE compliance, AISVS v1.0, MAESTRO layer tagging, and vector database security checks. Use when the user mentions vulnerability scanning, MCP server trust, compliance, SBOM generation, CIS benchmarks, blast radius, or AI supply chain risk.

Core Features & Use Cases

  • Discover AI agents and MCP servers across 22+ tools and map blast radius and trust scores for risk assessment.
  • Generate SBOMs and run CIS benchmarks (AWS/Azure/GCP/Snowflake) with optional cloud credentials.
  • Ensure AISVS v1.0, MITRE ATLAS, NIST AI RMF, and other framework mappings for compliance in local workflows.

Quick Start

Install via pipx and run agent-bom agents to discover and scan locally.

Frequently Asked Questions about agent-bom

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate an SBOM and run vulnerability scanning for MCP servers?

Automated vulnerability scanning and SBOM generation for MCP servers can be performed locally to map blast radius and trust scores. This process enforces local-first data handling and requires explicit user confirmation before executing any optional cloud checks.

What is the best way to check AI agents against CIS benchmarks and AISVS v1.0?

Checking AI agents against CIS benchmarks and AISVS v1.0 involves mapping compliance workflows across local environments. You can run CIS benchmarking for AWS, Azure, GCP, and Snowflake to ensure OWASP, NIST AI RMF, and MITRE ATLAS framework mappings.

Can I discover MCP servers and assess AI supply chain risk without sending data to the cloud?

Yes, you can discover agents across 22+ tools and assess AI supply chain risk using a local-first approach. The system redacts environment variables from config data and enforces Sigstore provenance verification without requiring cloud connectivity.

How does CVE enrichment and trust assessment work for agentic infrastructure?

CVE enrichment and trust assessment work by automating end-to-end vulnerability scanning across discovered MCP-powered AI agents. The system calculates blast radius and trust scores to evaluate risk, applying MAESTRO layer tagging for comprehensive infrastructure analysis.

Do I need cloud credentials to run compliance checks for AWS and Azure environments?

Cloud credentials are optional for running CIS compliance checks across AWS, Azure, GCP, and Snowflake. The system requires explicit user confirmation before performing any cloud-based checks, maintaining strict local-first data handling for security.

Why does agent-bom redact environment variables during MCP discovery?

Environment variables are redacted during MCP discovery to enforce local-first data handling and prevent sensitive configuration data leakage. This security measure ensures safe trust assessment and blast radius mapping without exposing underlying infrastructure credentials.