agent-bom-compliance

Evaluate AI scan results against OWASP, NIST, EU AI Act, and related frameworks.

29|7|Updated Feb 22, 2026
One-click install
npx skills add https://github.com/msaad00/agent-bom --skill agent-bom-compliance
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: agent-bom-compliance
Source: https://github.com/msaad00/agent-bom/tree/main/integrations/openclaw/compliance
Command: npx skills add https://github.com/msaad00/agent-bom --skill agent-bom-compliance

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Evaluate AI scan results against a broad set of security and regulatory frameworks to produce auditable compliance outcomes and SBOMs.

Core Features & Use Cases

  • Compliance engine: Evaluate scan results against OWASP, NIST, ISO 27001, EU AI Act, AISVS, MITRE ATLAS, and SOC 2.
  • Policy enforcement: Enforce policy-as-code rules across AI systems and agents.
  • SBOM generation: Generate CycloneDX/SPDX SBOMs from scanned artifacts.
  • Optional CIS benchmarks: Run AWS/Azure/GCP/Snowflake CIS checks with locally configured credentials.

Quick Start

Install agent-bom and run the compliance workflow on your scans to generate a report.

Frequently Asked Questions about agent-bom-compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate an SBOM for AI systems and evaluate it against NIST and OWASP frameworks?

Yes, you can enforce policy-as-code rules across AI systems and agents by evaluating scan results against OWASP, NIST, ISO 27001, EU AI Act, AISVS, MITRE ATLAS, and SOC 2 frameworks. This applies across agent platforms, MSPs, and CI/CD pipelines to generate auditable compliance reports.

Do I need cloud credentials to run EU AI Act and NIST compliance checks on AI agents?

No, you do not need cloud credentials for EU AI Act and NIST compliance checks. The evaluation satisfies local, zero-credential evaluation for OWASP, NIST, EU AI Act, SBOM generation, and policy checks. Optional CIS benchmark checks for AWS, Azure, GCP, and Snowflake require locally configured credentials.

Can I run CIS benchmark checks for AWS and Azure alongside AI compliance scanning?

Yes, you can run optional CIS benchmark checks for AWS, Azure, GCP, and Snowflake alongside your AI compliance evaluation. These optional checks require locally configured credentials, while the core OWASP, NIST, and EU AI Act evaluations operate with zero credentials.

What is the best way to automate AI compliance reporting across CI/CD pipelines?

The best way to automate AI compliance reporting in CI/CD pipelines is to evaluate scan results against frameworks like OWASP, NIST, and the EU AI Act. This process applies policy-as-code rules across your pipelines to generate auditable compliance outcomes and CycloneDX/SPDX SBOMs.

Does this compliance engine support AISVS and MITRE ATLAS framework evaluations?

Yes, the compliance engine supports AISVS and MITRE ATLAS framework evaluations. It evaluates AI scan results against these frameworks along with OWASP, NIST, ISO 27001, EU AI Act, and SOC 2 to generate comprehensive, auditable compliance reports.