
If you're running AI agents in production or building on MCP, this scanner gives you the blast radius view you actually need. It inventories agents, MCP servers, tools, packages, and credential references, then maps vulnerabilities from OSV and GHSA through the dependency graph to show you which agents can reach which exposed attack paths. You get CLI output for CI gates, MCP tools for agent driven security queries, and a self hosted dashboard that visualizes the full mesh. The quickstart command seeds demo data so you can see graph backed findings before pointing it at your own stack. Useful when you need to answer "what breaks if this package is compromised" or enforce pre install guards across a fleet.
Public tool metadata for what this MCP can expose to an agent.
scanRun a full AI supply chain security scan. Discovers local MCP configurations (Claude Desktop, Cursor, Windsurf, VS Code Copilot, OpenClaw, etc.), extracts package dependencies, queries OSV.dev for CVEs, assesses config security (credential exposure, tool access), computes blas...13 paramsRun a full AI supply chain security scan. Discovers local MCP configurations (Claude Desktop, Cursor, Windsurf, VS Code Copilot, OpenClaw, etc.), extracts package dependencies, queries OSV.dev for CVEs, assesses config security (credential exposure, tool access), computes blas...
auto_update_dbbooleanconfig_pathvaluedb_sourcesvalueenrichbooleanfail_severityvalueimagevalueoutput_formatstringpolicyvaluesbom_pathvaluescorecardbooleantransitivebooleanverify_integritybooleanwarn_severityvaluecheckCheck a specific package for known CVEs before installing. Queries OSV.dev for vulnerabilities in the given package. Use this before installing an MCP server or dependency to verify it is safe. Args: package: Package name with optional version, e.g. "express@4.18.2", "@modelco...2 paramsCheck a specific package for known CVEs before installing. Queries OSV.dev for vulnerabilities in the given package. Use this before installing an MCP server or dependency to verify it is safe. Args: package: Package name with optional version, e.g. "express@4.18.2", "@modelco...
ecosystemstringpackagestringblast_radiusLook up the blast radius of a specific CVE across your AI agent setup. Scans local MCP configurations, finds the specified CVE, and returns the full attack chain: which packages are affected, which MCP servers use those packages, which agents connect to those servers, and what...1 paramsLook up the blast radius of a specific CVE across your AI agent setup. Scans local MCP configurations, finds the specified CVE, and returns the full attack chain: which packages are affected, which MCP servers use those packages, which agents connect to those servers, and what...
cve_idstringpolicy_checkEvaluate a security policy against current scan results. Runs a scan, then evaluates the provided policy rules against the findings. Policies can gate on severity thresholds, CISA KEV status, AI risk flags, credential exposure, and denied packages. Args: policy_json: JSON stri...1 paramsEvaluate a security policy against current scan results. Runs a scan, then evaluates the provided policy rules against the findings. Policies can gate on severity thresholds, CISA KEV status, AI risk flags, credential exposure, and denied packages. Args: policy_json: JSON stri...
policy_jsonstringregistry_lookupQuery the agent-bom MCP server threat intelligence registry. Look up risk level, known tools, credential requirements, and verification status for known MCP servers. The registry contains 109+ servers with security metadata. Args: server_name: MCP server name to look up (e.g....2 paramsQuery the agent-bom MCP server threat intelligence registry. Look up risk level, known tools, credential requirements, and verification status for known MCP servers. The registry contains 109+ servers with security metadata. Args: server_name: MCP server name to look up (e.g....
package_namevalueserver_namevaluegenerate_sbomGenerate a Software Bill of Materials (SBOM) for your AI agent setup. Discovers AI agents and MCP servers, extracts all package dependencies, and generates a standards-compliant SBOM. Args: format: SBOM format — "cyclonedx" (CycloneDX 1.6) or "spdx" (SPDX 3.0). config_path: Pa...2 paramsGenerate a Software Bill of Materials (SBOM) for your AI agent setup. Discovers AI agents and MCP servers, extracts all package dependencies, and generates a standards-compliant SBOM. Args: format: SBOM format — "cyclonedx" (CycloneDX 1.6) or "spdx" (SPDX 3.0). config_path: Pa...
config_pathvalueformatstringcomplianceGet OWASP LLM Top 10 / OWASP MCP Top 10 / MITRE ATLAS / NIST AI RMF compliance posture. Scans local MCP configurations, maps findings to 47 security controls across four AI security frameworks, and returns per-control pass/warning/fail status with an overall compliance score....2 paramsGet OWASP LLM Top 10 / OWASP MCP Top 10 / MITRE ATLAS / NIST AI RMF compliance posture. Scans local MCP configurations, maps findings to 47 security controls across four AI security frameworks, and returns per-control pass/warning/fail status with an overall compliance score....
config_pathvalueimagevalueremediateGenerate a remediation plan for vulnerabilities in your AI agent setup. Scans for vulnerabilities, then generates actionable fix commands for each affected package (npm install, pip install), credential scope reduction guidance, and reports on unfixable vulnerabilities. Args:...2 paramsGenerate a remediation plan for vulnerabilities in your AI agent setup. Scans for vulnerabilities, then generates actionable fix commands for each affected package (npm install, pip install), credential scope reduction guidance, and reports on unfixable vulnerabilities. Args:...
config_pathvalueimagevalueskill_scanScan skill and instruction files for trust, findings, and provenance. Discovers supported files such as `CLAUDE.md`, `AGENTS.md`, `.cursorrules`, and `skills/*.md`, then parses referenced packages, MCP servers, credential env vars, audit findings, and trust verdicts.1 paramsScan skill and instruction files for trust, findings, and provenance. Discovers supported files such as `CLAUDE.md`, `AGENTS.md`, `.cursorrules`, and `skills/*.md`, then parses referenced packages, MCP servers, credential env vars, audit findings, and trust verdicts.
pathstringskill_verifyVerify Sigstore provenance for skill and instruction files.1 paramsVerify Sigstore provenance for skill and instruction files.
pathstringskill_trustAssess the trust level of a SKILL.md file using ClawHub-style categories. Parses a SKILL.md file, runs security audit checks, then evaluates trust across 5 categories: Purpose & Capability, Instruction Scope, Install Mechanism, Credentials, and Persistence & Privilege. Returns...1 paramsAssess the trust level of a SKILL.md file using ClawHub-style categories. Parses a SKILL.md file, runs security audit checks, then evaluates trust across 5 categories: Purpose & Capability, Instruction Scope, Install Mechanism, Credentials, and Persistence & Privilege. Returns...
skill_pathstringverifyVerify package integrity and SLSA provenance against registries. Checks SHA-256/SRI hashes against npm/PyPI registries and looks up SLSA build provenance attestations to confirm the package was built from its claimed source repository. Returns: JSON with integrity verification...2 paramsVerify package integrity and SLSA provenance against registries. Checks SHA-256/SRI hashes against npm/PyPI registries and looks up SLSA build provenance attestations to confirm the package was built from its claimed source repository. Returns: JSON with integrity verification...
ecosystemstringpackagestringwhereShow all MCP discovery paths and which config files exist. Lists every known MCP client config path per platform, indicating which files are present on the current system. Useful for debugging discovery issues or understanding where MCP configs live. Returns: JSON with per-cli...Show all MCP discovery paths and which config files exist. Lists every known MCP client config path per platform, indicating which files are present on the current system. Useful for debugging discovery issues or understanding where MCP configs live. Returns: JSON with per-cli...
No parameter schema in public metadata yet.
inventoryList all discovered MCP configurations and servers without CVE scanning. Performs fast discovery and package extraction only — no vulnerability scanning. Use this for a quick inventory of configs, servers, and packages. Returns: JSON with discovered agents, their MCP servers,...1 paramsList all discovered MCP configurations and servers without CVE scanning. Performs fast discovery and package extraction only — no vulnerability scanning. Use this for a quick inventory of configs, servers, and packages. Returns: JSON with discovered agents, their MCP servers,...
config_pathvaluetool_risk_assessmentScore live-introspected MCP tool capabilities and server risk. Uses runtime `tools/list` data to classify tool capabilities (READ/WRITE/EXECUTE/NETWORK/etc.) and compute a per-server risk profile. Returns: JSON with per-server tool profiles, capability counts, dangerous combin...2 paramsScore live-introspected MCP tool capabilities and server risk. Uses runtime `tools/list` data to classify tool capabilities (READ/WRITE/EXECUTE/NETWORK/etc.) and compute a per-server risk profile. Returns: JSON with per-server tool profiles, capability counts, dangerous combin...
config_pathvaluetimeoutnumberdiffCompare a fresh scan against a baseline to find new and resolved vulns. Runs a new scan, then diffs it against the provided baseline (or the latest saved report). Shows new vulnerabilities, resolved ones, and changes in the package inventory. Returns: JSON with new findings, r...1 paramsCompare a fresh scan against a baseline to find new and resolved vulns. Runs a new scan, then diffs it against the provided baseline (or the latest saved report). Shows new vulnerabilities, resolved ones, and changes in the package inventory. Returns: JSON with new findings, r...
baselinevaluemarketplace_checkPre-install trust check for an MCP server package. Queries the package registry (npm or PyPI) for metadata and cross-references against the agent-bom MCP threat intelligence registry. Returns trust signals including download count, CVE status, and registry verification. Args:...2 paramsPre-install trust check for an MCP server package. Queries the package registry (npm or PyPI) for metadata and cross-references against the agent-bom MCP threat intelligence registry. Returns trust signals including download count, CVE status, and registry verification. Args:...
ecosystemstringpackagestringcode_scanRun SAST (Static Application Security Testing) on source code via Semgrep. Scans for security flaws: SQL injection, XSS, command injection, hardcoded credentials, insecure deserialization, path traversal, etc. Returns findings with CWE classifications and severity levels. Requ...2 paramsRun SAST (Static Application Security Testing) on source code via Semgrep. Scans for security flaws: SQL injection, XSS, command injection, hardcoded credentials, insecure deserialization, path traversal, etc. Returns findings with CWE classifications and severity levels. Requ...
configstringpathstringcontext_graphBuild an agent context graph with lateral movement analysis. Models reachability between agents, servers, credentials, tools, and vulnerabilities. Answers: "If agent X is compromised, what else becomes reachable?" Returns: JSON with nodes, edges, lateral_paths, interaction_ris...3 paramsBuild an agent context graph with lateral movement analysis. Models reachability between agents, servers, credentials, tools, and vulnerabilities. Answers: "If agent X is compromised, what else becomes reachable?" Returns: JSON with nodes, edges, lateral_paths, interaction_ris...
config_pathvaluemax_depthintegersource_agentvaluegraph_exportExport the agent dependency graph in graph-native formats. Formats: - **graphml** — yEd, Gephi, NetworkX compatible with AIBOM-typed attributes - **cypher** — Neo4j import script with AIBOM node labels (AIAgent, MCPServer, Package, Vulnerability) - **dot** — Graphviz (pipe thr...2 paramsExport the agent dependency graph in graph-native formats. Formats: - **graphml** — yEd, Gephi, NetworkX compatible with AIBOM-typed attributes - **cypher** — Neo4j import script with AIBOM node labels (AIAgent, MCPServer, Package, Vulnerability) - **dot** — Graphviz (pipe thr...
config_pathvalueformatstringanalytics_queryQuery vulnerability trends, posture history, and runtime event summaries from ClickHouse. Requires AGENT_BOM_CLICKHOUSE_URL to be set. Returns empty results if ClickHouse is not configured.5 paramsQuery vulnerability trends, posture history, and runtime event summaries from ClickHouse. Requires AGENT_BOM_CLICKHOUSE_URL to be set. Returns empty results if ClickHouse is not configured.
agentvaluedaysintegerhoursintegerlimitintegerquery_typestringcis_benchmarkRun CIS benchmark checks against a cloud account. Evaluates security posture against CIS Foundations Benchmarks: - AWS Foundations v3.0: 18 checks (IAM, Storage, Logging, Networking) - Snowflake v1.0: 12 checks (Auth, Network, Data Protection, Monitoring, Access Control) - Azu...6 paramsRun CIS benchmark checks against a cloud account. Evaluates security posture against CIS Foundations Benchmarks: - AWS Foundations v3.0: 18 checks (IAM, Storage, Logging, Networking) - Snowflake v1.0: 12 checks (Auth, Network, Data Protection, Monitoring, Access Control) - Azu...
checksvalueprofilevalueproject_idvalueproviderstringregionvaluesubscription_idvaluefleet_scanBatch-scan a list of MCP server names against the security metadata registry. Designed for fleet inventory data (CrowdStrike, SIEM, CSV exports) where you have server names but not versions. Returns per-server risk assessment with registry match status, risk category, tools, c...1 paramsBatch-scan a list of MCP server names against the security metadata registry. Designed for fleet inventory data (CrowdStrike, SIEM, CSV exports) where you have server names but not versions. Returns per-server risk assessment with registry match status, risk category, tools, c...
serversstringruntime_correlateCross-reference vulnerability scan results with proxy runtime audit logs. Identifies which vulnerable tools were ACTUALLY CALLED in production, distinguishing confirmed attack surface from theoretical risk. Produces risk-amplified findings: a vulnerable tool that was called 10...3 paramsCross-reference vulnerability scan results with proxy runtime audit logs. Identifies which vulnerable tools were ACTUALLY CALLED in production, distinguishing confirmed attack surface from theoretical risk. Produces risk-amplified findings: a vulnerable tool that was called 10...
audit_logstringconfig_pathstringotel_tracestringvector_db_scanScan for running vector databases and assess their security posture. Probes well-known ports for Qdrant (6333), Weaviate (8080), Chroma (8000), and Milvus (9091). For each discovered instance checks: - Authentication required (no_auth flag if collections accessible without cre...1 paramsScan for running vector databases and assess their security posture. Probes well-known ports for Qdrant (6333), Weaviate (8080), Chroma (8000), and Milvus (9091). For each discovered instance checks: - Authentication required (no_auth flag if collections accessible without cre...
hostsvalueaisvs_benchmarkRun AISVS v1.0 (AI Security Verification Standard) compliance checks. Evaluates the local AI system stack against OWASP AISVS v1.0 controls: - AI-4.1 Model files use safe serialization (not pickle/pt/bin) - AI-4.2 Model files have cryptographic integrity digest - AI-4.3 Ollama...1 paramsRun AISVS v1.0 (AI Security Verification Standard) compliance checks. Evaluates the local AI system stack against OWASP AISVS v1.0 controls: - AI-4.1 Model files use safe serialization (not pickle/pt/bin) - AI-4.2 Model files have cryptographic integrity digest - AI-4.3 Ollama...
checksvaluegpu_infra_scanDiscover GPU/AI compute infrastructure: containers, K8s nodes, and DCGM endpoints. Scans for GPU-enabled workloads from the local Docker daemon and Kubernetes clusters. Identifies NVIDIA base images, CUDA/cuDNN versions, explicit GPU device assignments, and unauthenticated DCG...2 paramsDiscover GPU/AI compute infrastructure: containers, K8s nodes, and DCGM endpoints. Scans for GPU-enabled workloads from the local Docker daemon and Kubernetes clusters. Identifies NVIDIA base images, CUDA/cuDNN versions, explicit GPU device assignments, and unauthenticated DCG...
k8s_contextvalueprobe_dcgmbooleandataset_card_scanScan a directory for ML dataset card metadata and provenance. Discovers and parses: - HuggingFace dataset_info.json (auto-generated metadata) - HuggingFace README.md YAML frontmatter (dataset cards) - DVC .dvc tracking files (data versioning provenance) Flags: UNLICENSED_DATAS...1 paramsScan a directory for ML dataset card metadata and provenance. Discovers and parses: - HuggingFace dataset_info.json (auto-generated metadata) - HuggingFace README.md YAML frontmatter (dataset cards) - DVC .dvc tracking files (data versioning provenance) Flags: UNLICENSED_DATAS...
directorystringtraining_pipeline_scanScan a directory for ML training pipeline lineage and provenance. Discovers and parses: - MLflow: meta.yaml, MLmodel, requirements.txt, conda.yaml - Kubeflow: Argo workflow YAML, KFP v2 pipelineSpec YAML - W&B: wandb-metadata.json, config.yaml, wandb-summary.json Flags: UNSAFE...1 paramsScan a directory for ML training pipeline lineage and provenance. Discovers and parses: - MLflow: meta.yaml, MLmodel, requirements.txt, conda.yaml - Kubeflow: Argo workflow YAML, KFP v2 pipelineSpec YAML - W&B: wandb-metadata.json, config.yaml, wandb-summary.json Flags: UNSAFE...
directorystringbrowser_extension_scanScan installed browser extensions for dangerous permissions. Scans Chrome, Chromium, Brave, Edge, and Firefox for extensions with: - nativeMessaging (can execute arbitrary commands) - debugger (can intercept all browser traffic) - cookies/clipboardRead on AI domains - Broad ho...1 paramsScan installed browser extensions for dangerous permissions. Scans Chrome, Chromium, Brave, Edge, and Firefox for extensions with: - nativeMessaging (can execute arbitrary commands) - debugger (can intercept all browser traffic) - cookies/clipboardRead on AI domains - Broad ho...
include_low_riskbooleanmodel_provenance_scanCheck ML model provenance and supply chain metadata. Queries HuggingFace Hub or Ollama for: - Serialization format (safetensors=safe, pickle/pt=unsafe) - SHA256 digest verification - Gated/private status - Model card presence - Risk assessment (critical/high/medium/safe) Retur...2 paramsCheck ML model provenance and supply chain metadata. Queries HuggingFace Hub or Ollama for: - Serialization format (safetensors=safe, pickle/pt=unsafe) - SHA256 digest verification - Gated/private status - Model card presence - Risk assessment (critical/high/medium/safe) Retur...
model_idstringsourcestringprompt_scanScan prompt template files for injection risks and security issues. Discovers and analyzes: - .prompt files - system_prompt.* files - Files in prompts/ directories Checks for injection patterns, unsafe variable interpolation, and missing guardrails in prompt templates.1 paramsScan prompt template files for injection risks and security issues. Discovers and analyzes: - .prompt files - system_prompt.* files - Files in prompts/ directories Checks for injection patterns, unsafe variable interpolation, and missing guardrails in prompt templates.
directorystringmodel_file_scanScan a directory for ML model files and assess serialization risks. Discovers model files and checks: - Serialization format (safetensors=safe, pickle/joblib=unsafe) - File size and format metadata - GGUF/GGML quantization details - Known unsafe patterns in pickle-based format...1 paramsScan a directory for ML model files and assess serialization risks. Discovers model files and checks: - Serialization format (safetensors=safe, pickle/joblib=unsafe) - File size and format metadata - GGUF/GGML quantization details - Known unsafe patterns in pickle-based format...
directorystringai_inventory_scanScan source code for AI component usage patterns. Detects: - AI SDK imports (openai, anthropic, langchain, etc.) across 7 languages - Model string references (gpt-4o, claude-3-5-sonnet, llama-3, etc.) - Hardcoded API keys (sk-proj-*, sk-ant-*, hf_*, etc.) - Deprecated model us...1 paramsScan source code for AI component usage patterns. Detects: - AI SDK imports (openai, anthropic, langchain, etc.) across 7 languages - Model string references (gpt-4o, claude-3-5-sonnet, llama-3, etc.) - Hardcoded API keys (sk-proj-*, sk-ant-*, hf_*, etc.) - Deprecated model us...
directorystringlicense_compliance_scanEvaluate package licenses against compliance policy. Categorizes each package license using the full SPDX catalog (2,500+ licenses) with proper expression parsing (OR/AND/WITH), deprecated ID normalization, and network-copyleft detection (AGPL, EUPL, OSL). Risk tiers: permissi...2 paramsEvaluate package licenses against compliance policy. Categorizes each package license using the full SPDX catalog (2,500+ licenses) with proper expression parsing (OR/AND/WITH), deprecated ID normalization, and network-copyleft detection (AGPL, EUPL, OSL). Risk tiers: permissi...
policy_jsonstringscan_jsonstringingest_external_scanIngest Trivy, Grype, or Syft JSON scan output and return packages with blast radius analysis. Auto-detects the scanner format from the JSON structure: - Trivy (``trivy fs --format json``): Results + Vulnerabilities - Grype (``grype --output json``): matches array - Syft (``syf...1 paramsIngest Trivy, Grype, or Syft JSON scan output and return packages with blast radius analysis. Auto-detects the scanner format from the JSON structure: - Trivy (``trivy fs --format json``): Results + Vulnerabilities - Grype (``grype --output json``): matches array - Syft (``syf...
scan_jsonstring
Supported backends vary by capability. Capability matrix.
Open security scanner and self-hosted control plane for AI, MCP, and cloud infrastructure.
Scan repositories, software supply chains, identity, and data infrastructure locally in under a minute. Connect read-only sources when the team is ready. Keep raw data, credentials, findings, and policy decisions inside your environment.
Quick start · Live demo · Docs
Security teams rarely lack scanners. They lack one trustworthy view of what was scanned, what was discovered, which findings are actually connected to critical systems, who owns the fix, and whether the fix held.
agent-bom closes that loop with two honest entry paths:
| Start from | First action | What produces inventory |
|---|---|---|
| A repository, image, SBOM, workstation, or MCP config | Run a local or CI scan—no connection required | The scanner reads the target and emits inventory, findings, provenance, and graph evidence together |
| AWS, Azure, GCP, Snowflake, Kubernetes, or another managed source | Add a read-only connection in the self-hosted control plane, then run or schedule a scan | The connection defines scope and credentials; the scan collects the source and creates the inventory snapshot |
Both paths converge after collection: normalize evidence into the same Finding + UnifiedGraph contracts, correlate reachable risk, assign an owner and SLA, then re-scan to verify the result. Inventory is always the output of a named target or connected source—never unexplained preloaded data.
The product promise: start with one useful artifact today; keep the same evidence model as you add CI, connected sources, history, assignments, compliance exports, and runtime enforcement in your own environment.
Quick start · Evidence workflow · Integration capability matrix · Measured matcher proof · Control-plane architecture
The views below come from the committed Reference evidence lab — modeled
local infrastructure. The credential-free run uses the real repository parser
and bundled advisory scanner for pillow@9.0.0 / CVE-2023-4863, then
correlates exact OCI digest, Kubernetes UID, MCP tool, workload identity, and
runtime receipts. It is not customer evidence or a live-cloud claim.
Investigation loads the latest completed correlation automatically and shows the source-to-path journey first. Custom snapshot selection remains available as an explicit advanced workflow with the freshness policy visible.
The resulting path is confirmed only because every directed hop is traversable
and provenance-backed: exposed service → workload → digest-pinned container →
pillow@9.0.0 / CVE-2023-4863 → MCP capability → workload identity →
modeled sensitive object store. The same lab records an observed gateway call
and a separate strict opt-in block before the remediation handoff.
Regenerate the reference lab · Open the full product gallery · See the capture protocol
| Role | Start here | Primary outcome |
|---|---|---|
| Developer / AI engineer | agent-bom scan . | See dependencies, secrets, IaC, agents, MCP, and whether Click, Flask, or FastAPI entry points can reach vulnerable packages before shipping |
| AppSec / product security | agent-bom agents --gha . --offline | Inventory remote actions and reusable workflows with their refs, source provenance, and CI-hardening findings |
| Cloud security | Add a read-only connection, then run a scan | Build scoped cloud, identity, and posture inventory with explicit coverage and provenance |
| Platform / DevOps | pip install 'agent-bom[ui]' && AGENT_BOM_NO_AUTH_ROLE=analyst agent-bom serve --persist ~/.agent-bom/control-plane.db | Schedule scans, centralize evidence, assign owners and SLAs, and verify remediation |
| GRC / audit | agent-bom report compliance-narrative scan.json | Export mapped evidence while preserving unavailable, partial, and not-assessed states |
| CISO / engineering leader | Open Architecture in the self-hosted graph | Compare observed Current state with modeled Proposed and Difference views; proposals remain labeled as not observed or deployed |
Security engineering and GRC remain separate workflows: findings and reachability are not presented as audit certification. See product boundaries. GitHub Actions collection and credential requirements are documented in permissions; scenario truth boundaries are defined by the graph contract.
Choose the smallest path that proves value. No account or control plane is required for repository, image, SBOM, workstation, or MCP configuration scans.
The offline sample completes without downloading an advisory database and shows the inventory, finding, reachable path, and remediation output shape.
pip install agent-bom
agent-bom scan --demo --offline
The sample intentionally contains a known-malicious package, so exit status 1 is expected
and the printed report is complete. Scan a repository next:
agent-bom scan .
The repository scan shows inventory, findings, and reachable impact.
agent-bom scan . and agent-bom scan -p . are the same command; PATH is an
alias for --project.
Use this path when the source is an account or platform rather than a local target. Start the customer-controlled control plane, open Connections, add the provider's read-only grant, and run the first scan. The browser flow defaults to an explicit first scan after verification; scheduled scans are an explicit operator opt-in.
pip install 'agent-bom[ui]'
AGENT_BOM_NO_AUTH_ROLE=analyst agent-bom serve --persist ~/.agent-bom/control-plane.db
The explicit SQLite path keeps scan jobs, findings, compliance history, and
graph inventory available together after a restart. Omit --persist only for
an intentionally ephemeral process. The explicit local analyst role permits
this loopback operator to run scans; the server's default anonymous role remains
read-only.
For headless onboarding, agent-bom connect <provider> prints the exact grant,
credential boundary, verification step, and next scan command. The
cloud connection guide documents AWS, Azure, GCP, and
Snowflake, including organization scope and scheduler behavior.
Need a disconnected scan? Seed the smallest package-advisory database first:
agent-bom db update --osv-ecosystem PyPI
agent-bom scan . --offline
If that database is missing or unreadable, the scan writes a partial artifact
when -o is set and exits 1; CI therefore cannot mistake unavailable
advisory coverage for a clean scan.
On a fresh database, that command covers only the selected ecosystem; packages
from other ecosystems remain explicit offline coverage gaps. Repeat
--osv-ecosystem for a polyglot repository, or use
agent-bom db update --source osv for OSV's all-ecosystems archive. The full
archive can exceed 1 GB, may take several minutes, and shows live progress with
the exact total when the server supplies it. Run the broader
agent-bom db update when you also need distro, exploit-probability, and
known-exploited-vulnerability feeds.
A non-zero exit is a verdict, not a crash. scan exits 0 when nothing
matched a gate, and 1 when one did — a --fail-on-* threshold you set, a
known-malicious package, or a scan that did not complete. The report is printed
in full either way, and the last line names the gate that matched. Full
exit-code contract.
Save an artifact with agent-bom scan . -f sarif -o findings.sarif, or follow
the first-run guide for formats and CI use.
Try the scanner without installing it, then check a package before adding it:
uvx agent-bom scan .
uvx agent-bom check requests@2.33.0 --ecosystem pypi
check returns an allow/unsafe/incomplete pre-install verdict; scan covers the
repository plus discovered AI/MCP configuration. To make both dependency and
secret gates automatic for a team, pin the shipped consumer hooks:
repos:
- repo: https://github.com/msaad00/agent-bom
rev: v0.103.2
hooks:
- id: agent-bom-secrets
- id: agent-bom-scan
Run pre-commit install once. The hooks install agent-bom into their own
isolated environment, so contributors do not need a separate global install.
Hook behavior and CI examples.
| You want to | Go to |
|---|---|
| Scan your repository | agent-bom scan . |
| A dashboard on your laptop | Self-host |
| A shared deployment (Docker, Helm, EKS, Snowflake) | Self-host table |
| Gate a pull request | first-run guide §5 |
| Give an AI agent the tools | agent-bom mcp server — MCP server |
| Connect a cloud account | agent-bom connect aws --emit --out agent-bom-aws-readonly.json — cloud connections |
Use the curated, explicitly synthetic sample when you only want to inspect the output shape:
agent-bom scan --demo --offline
The sample intentionally contains a known-malicious package, which fails closed.
The control plane is the growth path, not a prerequisite. Use it when one-off artifacts need to become a durable team workflow: registered sources, scheduled scans, history, inventory snapshots, finding ownership, graph investigation, compliance evidence, and runtime policy—all inside the customer's cloud, cluster, database, identity, and audit boundary.
Start the loopback evaluation profile:
pip install 'agent-bom[ui]'
AGENT_BOM_NO_AUTH_ROLE=analyst agent-bom serve --persist ~/.agent-bom/control-plane.db
Then open Connections to add a source or New Scan to target a repository, image, SBOM, MCP configuration, or IaC path. A scan produces the inventory; inventory is not populated merely by starting the server.
For a shared deployment, use the production-shaped Docker or Helm path and configure real identity, TLS, PostgreSQL, encryption, and audit keys before exposing it.
| Target | Start here |
|---|---|
| Docker Compose | Platform compose — PostgreSQL, split secrets, migration job |
| Docker Compose (evaluation) | Pilot compose — loopback only, SQLite, no auth |
| Helm / Kubernetes | helm install agent-bom oci://ghcr.io/msaad00/charts/agent-bom --version 0.103.2 |
| EKS | Terraform module |
| Snowflake SPCS / Native App | scripts/deploy/install.sh snowflake-native · install guide |
| Air-gapped | Image bundle guide |
Examples target this release candidate; confirm release availability before copying an exact pin. Otherwise, use the latest version shown on PyPI.
Deployment overview · Enterprise configuration · Cloud connections
| Need | First action | Artifact or next step |
|---|---|---|
| GitHub CI | uses: msaad00/agent-bom@v0.103.2 | SARIF, PR summary, and a policy exit code |
| Cloud evidence | agent-bom connect aws --emit --out agent-bom-aws-readonly.json | Deploy the read-only grant, then connect and scan |
| Runtime gateway | agent-bom gateway serve --from-control-plane http://127.0.0.1:8422 --bind 127.0.0.1:8090 | Allow, warn, and block audit events |
| Agent interface | agent-bom mcp server | 86 MCP tools, 6 resources, and 8 workflow prompts |
| Agent distribution | Smithery manifest · Glama · MCP registry · Docker MCP | Registry-specific installation metadata |
MCP server mode exposes 86 MCP tools, 6 resources, and 8 workflow prompts, all read-first: discovery and analysis never mutate a scanned target.
Set YDC_API_KEY to enable the optional youcom_search MCP tool for live web
and news context alongside the local threat-intel database. It is the only tool
that sends your query to a third party, it is off unless the key is set, and the
request is pinned to the You.com origin over TLS — so the key cannot be
redirected to another host by configuration.
The CLI, Docker, API, Helm chart, MCP server, gateway, and SDK are distribution surfaces of the same product. The Snowflake SPCS / Native App lane runs inside the customer's Snowflake account; it is a customer-owned deployment target, not an agent-bom-hosted service. Snowflake and Snowpark also remain connector and runtime integrations for the other deployment profiles.
| Surface | Get it |
|---|---|
| Python package | pip install agent-bom — PyPI |
| Container | docker pull agentbom/agent-bom — Docker Hub |
| Kubernetes | helm install agent-bom oci://ghcr.io/msaad00/charts/agent-bom |
| GitHub Action | msaad00/agent-bom |
| MCP server | pip install 'agent-bom[mcp-server]' && agent-bom mcp server |
| MCP registries | Smithery manifest · Glama · MCP registry · Docker MCP |
| SDKs | Python · TypeScript · Go |
Threat model · Release verification · Security policy · MCP security model
Stuck, or not sure where a question belongs? SUPPORT.md has the routing and an honest statement of what response to expect.
To contribute, start with CONTRIBUTING.md, AGENTS.md, and the open issues.
Apache-2.0 licensed.
NVD_API_KEYsecretNVD API key for higher rate limits on vulnerability enrichment