Claim this agent
agentCLAWHUBUnverified

agent-bom runtime

AI runtime security monitoring — context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries. Use when the user mentions runtime monitoring, context graphs, lateral movement analysis, audit log correlation, or vulnerability analytics. Skill: agent-bom runtime Owner: msaad00 Summary: AI runtime security monitoring — context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries. Use when the user mentions runtime monitoring, context graphs, lateral movement analysis, audit log correlation, or vulnerability analytics. Tags: latest:0.108.3 Version history: v0.108.3 | 2026-10-08T22:18:13.720Z | user Releas

OpenClaw

Rank

62

Safety

84

Downloads

5.7k

Updated

Oct 9, 2026

Version

0.108.3

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 5.7K downloads reported by the source. Last updated 10/9/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 9, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 9, 2026
Adoption signal
5.7K downloadsadoption · observed Oct 9, 2026
Latest release
0.108.3release · observed Oct 8, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom-runtime
  1. Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-runtime/snapshot"

Documentation

CLAWHUB

58,765 characters of source documentation, loaded on request.

Extracted files

3 files captured from the source.

SKILL.md

---
name: agent-bom-runtime
description: >-
  AI runtime security monitoring — context graph analysis, runtime audit log
  correlation with CVE findings, and vulnerability analytics queries. Use when
  the user mentions runtime monitoring, context graphs, lateral movement analysis,
  audit log correlation, or vulnerability analytics.
version: 0.108.3
license: Apache-2.0
compatibility: >-
  Requires Python 3.11+. Install via pipx or pip. Optional: kubectl for
  Kubernetes context, ClickHouse for analytics storage. No API keys required.
metadata:
  author: msaad00
  homepage: https://github.com/msaad00/agent-bom
  source: https://github.com/msaad00/agent-bom
  pypi: https://pypi.org/project/agent-bom/
  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom
  tests: 7239
  install:
    pipx: agent-bom
    pip: agent-bom
  openclaw:
    requires:
      bins: []
      env: []
      credentials: none
    credential_policy: "Zero credentials required. Optional ClickHouse URL enables analytics storage. Never auto-discovered or inferred."
    credential_handling: "Runtime audit data may include credential environment variable names but must not include raw values. Optional analytics credentials are operator-supplied and must not be displayed or inferred."
    optional_env: []
    optional_bins:
      - kubectl
    emoji: "\U0001F4CA"
    homepage: https://github.com/msaad00/agent-bom
    source: https://github.com/msaad00/agent-bom
    license: Apache-2.0
    os:
      - darwin
      - linux
      - windows
    data_flow: "Operates on scan results in memory and user-provided audit log files. Optional ClickHouse connection for persistent analytics (user-configured, not auto-discovered)."
    file_reads:
      - "user-provided audit log files (JSONL format from agent-bom proxy)"
    file_writes: []
    network_endpoints: []
    telemetry: false
    persistence: false
    privilege_escalation: false
    always: false
    autonomous_invocation: restricted
---

# agent-bom-runtime — AI Runtime Security Monitoring

Context graph analysis, runtime audit log correlation with CVE findings, and
vulnerability analytics queries.

## Install

```bash
pipx install agent-bom
```

## Tools (3)

| Tool | Description |
|------|-------------|
| `context_graph` | Agent context graph with lateral movement analysis |
| `analytics_query` | Query vulnerability trends, posture history, and runtime events |
| `runtime_correlate` | Cross-reference runtime audit logs with CVE findings |

## Example Workflows

```
# Build context graph from scan results
context_graph()

# Correlate runtime audit with CVE data
runtime_correlate(audit_file="proxy-audit.jsonl")

# Query analytics
analytics_query(query="top_cves", days=30)
```

## Privacy & Data Handling

Operates on scan results already in memory and user-provided audit log files.
No automatic file discovery. No network calls unless you configure an optional
ClickHouse endpoint for persistent analytics.

## 

_meta.json

{
  "ownerId": "kn7612j2dqa4vhvcpaygt6mcv981pft8",
  "slug": "agent-bom-runtime",
  "version": "0.108.3",
  "publishedAt": 1791497893720
}

skill-card.md

## Description:

Analyzes agent context graphs, correlates runtime audit logs with CVE findings, and queries vulnerability trends.

This skill is ready for commercial/non-commercial use.

## Publisher:

[msaad00](https://clawhub.ai/user/msaad00)

### License/Terms of Use:

MIT-0

## Use Case:

Developers and security teams use this skill to inspect agent context graphs, correlate user-supplied runtime audit logs with CVEs, and review vulnerability trends.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: Installing a third-party CLI introduces package supply-chain risk.

Mitigation: Review the PyPI package and project before installing, as recommended by the release security guidance.

Risk: Optional ClickHouse or kubectl access can expose analytics data or cluster resources.

Mitigation: Configure those connections only when needed and limit access to the intended environment.

## Reference(s):

- [ClawHub skill release](https://clawhub.ai/msaad00/skills/agent-bom-runtime)
- [Project homepage listed in skill metadata](https://github.com/msaad00/agent-bom)
- [agent-bom package on PyPI](https://pypi.org/project/agent-bom/)
- [Project OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)

## Skill Output:

**Output Type(s):** [Text, Analysis, Guidance]

**Output Format:** [Text or Markdown]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Context graph analysis, audit-to-CVE correlation, and vulnerability trend results; no fixed output schema is specified.]

## Skill Version(s):

0.108.3 (source: release metadata and skill frontmatter)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/msaad00/skills/agent-bom-runtime",
      "sourceUrl": "https://clawhub.ai/msaad00/skills/agent-bom-runtime",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T03:47:40.422Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-runtime/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-runtime/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-09T03:47:40.422Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "5.7K downloads",
      "href": "https://clawhub.ai/msaad00/agent-bom-runtime",
      "sourceUrl": "https://clawhub.ai/msaad00/agent-bom-runtime",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T03:47:40.422Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "0.108.3",
      "href": "https://clawhub.ai/msaad00/agent-bom-runtime",
      "sourceUrl": "https://clawhub.ai/msaad00/agent-bom-runtime",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-08T22:18:13.720Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-runtime/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-runtime/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 0.108.3",
      "description": "Release v0.108.3",
      "href": "https://clawhub.ai/msaad00/agent-bom-runtime",
      "sourceUrl": "https://clawhub.ai/msaad00/agent-bom-runtime",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-08T22:18:13.720Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 9, 2026.

Sponsored

Ads related to agent-bom runtime and adjacent AI workflows.