agentCLAWHUBUnverified

agent-bom

Open security scanner for agentic infrastructure — agents, MCP, packages, blast radius, runtime, and trust across MCP discovery, CVEs, SBOMs, CIS benchmarks...

OpenClaw

Rank

62

Safety

84

Downloads

2.5k

Updated

Oct 9, 2026

Version

0.76.4

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 2.5K downloads reported by the source. Last updated 10/9/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 9, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 9, 2026
Adoption signal
2.5K downloadsadoption · observed Oct 9, 2026
Latest release
0.76.4release · observed Apr 13, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom
  1. Install using `clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/msaad00/agent-bom before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom/snapshot"

Documentation

CLAWHUB

147,782 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

analyze/SKILL.md

---
name: agent-bom-analyze
description: >-
  Analyze blast radius, attack paths, and threat landscape across your AI
  infrastructure. Use when: "blast radius", "threat intel", "risk score",
  "attack path", "lateral movement", "context graph", "who can reach what".
version: 0.76.4
license: Apache-2.0
compatibility: >-
  Requires Python 3.11+. Install via pipx or pip. No credentials required for
  blast radius and context graph analysis. Threat intelligence lookups query
  EPSS and CVE databases.
metadata:
  author: msaad00
  homepage: https://github.com/msaad00/agent-bom
  source: https://github.com/msaad00/agent-bom
  pypi: https://pypi.org/project/agent-bom/
  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom
  tests: 7239
  install:
    pipx: agent-bom
    pip: agent-bom
    docker: ghcr.io/msaad00/agent-bom:0.76.4
  openclaw:
    requires:
      bins: []
      env: []
      credentials: none
    credential_policy: "Zero credentials required. Blast radius and context graph analysis operate on local scan data. EPSS and CVE lookups send only public CVE IDs — no internal data."
    optional_env: []
    optional_bins: []
    emoji: "\U0001F4A5"
    homepage: https://github.com/msaad00/agent-bom
    source: https://github.com/msaad00/agent-bom
    license: Apache-2.0
    os:
      - darwin
      - linux
      - windows
    data_flow: "Blast radius and context graph analysis operate on local scan results in memory. Only public CVE IDs are sent to EPSS and vulnerability databases for threat intelligence enrichment. No internal config data, credentials, or scan results leave the machine."
    file_reads: []
    file_writes: []
    network_endpoints:
      - url: "https://api.first.org/data/v1/epss"
        purpose: "EPSS exploit probability scores for CVEs found in scan"
        auth: false
      - url: "https://api.osv.dev/v1"
        purpose: "OSV vulnerability database — CVE detail lookup"
        auth: false
    telemetry: false
    persistence: false
    privilege_escalation: false
    always: false
    autonomous_invocation: restricted
---

# agent-bom-analyze — Blast Radius & Attack Path Analysis

Analyzes blast radius, attack paths, and the threat landscape across your AI
infrastructure. Maps lateral movement risks, identifies high-impact CVEs, and
visualizes agent context graphs.

## Install

```bash
pipx install agent-bom
agent-bom agents --verbose   # blast radius detail for each agent
agent-bom graph              # generate context graph
```

## When to Use

- "blast radius" / "what's the blast radius"
- "threat intel" / "threat intelligence"
- "risk score" / "risk scoring"
- "attack path" / "attack paths"
- "lateral movement"
- "context graph" / "agent graph"
- "who can reach what"

## Commands

```bash
# Blast radius detail (verbose)
agent-bom agents --verbose

# Generate context graph
agent-bom graph
```

## Tools

| Tool | Description |
|------|-------------|
| `blast_radius` | Map CVE impact chain ac

compliance/SKILL.md

---
name: agent-bom-compliance
description: >-
  AI compliance and policy engine — evaluate scan results against OWASP, NIST,
  SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.
  Generate SBOMs and compliance reports. Use when:
  "compliance report", "NIST", "SOC 2", "ISO 27001", "OWASP", "EU AI Act",
  "AISVS", "generate SBOM", "policy check".
version: 0.76.4
license: Apache-2.0
compatibility: >-
  Requires Python 3.11+. Install via pipx or pip. OWASP/NIST/EU AI Act/MITRE
  evaluation and SBOM generation are fully local with zero credentials. CIS
  benchmark checks optionally use cloud SDK credentials (AWS/Azure/GCP/Snowflake)
  and make read-only API calls to cloud providers when explicitly invoked.
metadata:
  author: msaad00
  homepage: https://github.com/msaad00/agent-bom
  source: https://github.com/msaad00/agent-bom
  pypi: https://pypi.org/project/agent-bom/
  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom
  tests: 7239
  install:
    pipx: agent-bom
    pip: agent-bom
    docker: ghcr.io/msaad00/agent-bom:0.76.4
  openclaw:
    requires:
      bins: []
      env: []
      credentials: none
    credential_policy: "Zero credentials required for OWASP/NIST/EU AI Act compliance and SBOM generation. CIS benchmark checks (AWS, Azure, GCP, Snowflake) optionally accept cloud credentials — only used locally to call cloud APIs, never transmitted elsewhere."
    optional_env:
      - name: AWS_PROFILE
        purpose: "AWS CIS benchmark checks — uses boto3 with your local AWS profile"
        required: false
      - name: AZURE_TENANT_ID
        purpose: "Azure CIS benchmark checks (azure-mgmt-* SDK)"
        required: false
      - name: AZURE_CLIENT_ID
        purpose: "Azure CIS benchmark checks — service principal client ID"
        required: false
      - name: AZURE_CLIENT_SECRET
        purpose: "Azure CIS benchmark checks — service principal secret"
        required: false
      - name: GOOGLE_APPLICATION_CREDENTIALS
        purpose: "GCP CIS benchmark checks (google-cloud-* SDK)"
        required: false
      - name: SNOWFLAKE_ACCOUNT
        purpose: "Snowflake CIS benchmark checks"
        required: false
      - name: SNOWFLAKE_USER
        purpose: "Snowflake CIS benchmark checks"
        required: false
      - name: SNOWFLAKE_PRIVATE_KEY_PATH
        purpose: "Snowflake key-pair auth (CI/CD)"
        required: false
      - name: SNOWFLAKE_AUTHENTICATOR
        purpose: "Snowflake auth method (default: externalbrowser SSO)"
        required: false
    optional_bins: []
    emoji: "\U00002705"
    homepage: https://github.com/msaad00/agent-bom
    source: https://github.com/msaad00/agent-bom
    license: Apache-2.0
    os:
      - darwin
      - linux
      - windows
    data_flow: >-
      OWASP/NIST/EU AI Act/MITRE/SBOM evaluation is purely local — zero network
      calls. CIS benchmark checks (optional, user-initiated) call cloud provider
      APIs (AWS/Azure/GCP/Snowflake

discover/SKILL.md

---
name: agent-bom-discover
description: >-
  Discover AI agents, MCP servers, and configurations on this machine or
  environment. Use when: "find agents", "what's configured", "doctor",
  "what MCP servers", "show me what's installed", "mcp inventory".
version: 0.76.4
license: Apache-2.0
compatibility: >-
  Requires Python 3.11+. Install via pipx or pip. No credentials required.
  Registry data (427+ MCP servers) is bundled in-package with zero network calls.
metadata:
  author: msaad00
  homepage: https://github.com/msaad00/agent-bom
  source: https://github.com/msaad00/agent-bom
  pypi: https://pypi.org/project/agent-bom/
  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom
  tests: 7239
  install:
    pipx: agent-bom
    pip: agent-bom
    docker: ghcr.io/msaad00/agent-bom:0.76.4
  openclaw:
    requires:
      bins: []
      env: []
      credentials: none
    credential_policy: "Zero credentials required. Discovery reads only structural config data (server names, commands, args, URLs). Env var values are replaced with ***REDACTED*** by sanitize_env_vars() before any processing."
    optional_env: []
    optional_bins: []
    emoji: "\U0001F50E"
    homepage: https://github.com/msaad00/agent-bom
    source: https://github.com/msaad00/agent-bom
    license: Apache-2.0
    os:
      - darwin
      - linux
      - windows
    credential_handling: "Env var values are NEVER extracted from config files. sanitize_env_vars() replaces all env values with ***REDACTED*** BEFORE any config data is processed or stored. Source: https://github.com/msaad00/agent-bom/blob/main/src/agent_bom/security.py#L159"
    data_flow: "Purely local. Reads MCP client config files across 22+ AI tools. Only structural data (server names, commands, URLs) is extracted. Env var values are redacted before processing. No data leaves the machine."
    file_reads:
      # Claude Desktop
      - "~/Library/Application Support/Claude/claude_desktop_config.json"
      - "~/.config/Claude/claude_desktop_config.json"
      # Claude Code
      - "~/.claude/settings.json"
      - "~/.claude.json"
      # Cursor
      - "~/.cursor/mcp.json"
      - "~/Library/Application Support/Cursor/User/globalStorage/cursor.mcp/mcp.json"
      # Windsurf
      - "~/.windsurf/mcp.json"
      # Cline
      - "~/Library/Application Support/Code/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.json"
      # VS Code Copilot
      - "~/Library/Application Support/Code/User/mcp.json"
      # Codex CLI
      - "~/.codex/config.toml"
      # Gemini CLI
      - "~/.gemini/settings.json"
      # Goose
      - "~/.config/goose/config.yaml"
      # Continue
      - "~/.continue/config.json"
      # Zed
      - "~/.config/zed/settings.json"
      # Roo Code
      - "~/Library/Application Support/Code/User/globalStorage/rooveterinaryinc.roo-cline/settings/cline_mcp_settings.json"
      # Amazon Q
      - "~/Library/Application Support/Code/User/globalStorage/am

enforce/SKILL.md

---
name: agent-bom-enforce
description: >-
  Enforce security policies on MCP tool calls and block dangerous operations at
  runtime. Use when: "block risky calls", "apply policy", "proxy",
  "runtime protection", "policy enforcement", "intercept MCP calls".
version: 0.76.4
license: Apache-2.0
compatibility: >-
  Requires Python 3.11+. Install via pipx or pip. No credentials required.
  Policy files are user-provided YAML/JSON. Proxy runs locally.
metadata:
  author: msaad00
  homepage: https://github.com/msaad00/agent-bom
  source: https://github.com/msaad00/agent-bom
  pypi: https://pypi.org/project/agent-bom/
  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom
  tests: 7239
  install:
    pipx: agent-bom
    pip: agent-bom
    docker: ghcr.io/msaad00/agent-bom:0.76.4
  openclaw:
    requires:
      bins: []
      env: []
      credentials: none
    credential_policy: "Zero credentials required. Policy evaluation is local. Proxy operates on local network only. Policy files are user-provided and never transmitted."
    optional_env: []
    optional_bins: []
    emoji: "\U0001F6AB"
    homepage: https://github.com/msaad00/agent-bom
    source: https://github.com/msaad00/agent-bom
    license: Apache-2.0
    os:
      - darwin
      - linux
      - windows
    data_flow: "Purely local. Policy evaluation runs on scan results in memory. Proxy intercepts MCP calls on local network only. Audit logs are written locally (JSONL). No data leaves the machine."
    file_reads:
      - "user-provided policy files (YAML/JSON policy-as-code)"
      - "user-provided audit log files (JSONL from agent-bom proxy)"
    file_writes:
      - "proxy-audit.jsonl (local audit log, only when proxy is running)"
    network_endpoints: []
    telemetry: false
    persistence: false
    privilege_escalation: false
    always: false
    autonomous_invocation: restricted
    disable-model-invocation: true
---

# agent-bom-enforce — Runtime Policy Enforcement

Enforces security policies on MCP tool calls and blocks dangerous operations
at runtime. Runs a local proxy that intercepts MCP calls and evaluates them
against policy-as-code rules.

## Install

```bash
pipx install agent-bom
agent-bom proxy              # start enforcement proxy
agent-bom policy apply policy.yaml  # apply a policy file
agent-bom policy check       # check current policy status
```

## When to Use

- "block risky calls" / "block dangerous MCP calls"
- "apply policy" / "enforce policy"
- "proxy" / "MCP proxy"
- "runtime protection"
- "policy enforcement"
- "intercept MCP calls"

## Commands

```bash
# Start the enforcement proxy
agent-bom proxy

# Apply a policy file
agent-bom policy apply policy.yaml

# Check current policy status
agent-bom policy check
```

## Example Policy File

```yaml
# policy.yaml
rules:
  - id: block-shell-exec
    description: Block shell execution tool calls
    match:
      tool: "bash|shell|exec|run_command"
    action: block
    severity: cri

monitor/SKILL.md

---
name: agent-bom-monitor
description: >-
  Monitor agent fleet, track trust scores, and manage lifecycle states. Use
  when: "fleet", "watch agents", "runtime status", "trust scores",
  "fleet sync", "agent lifecycle", "serve dashboard".
version: 0.76.4
license: Apache-2.0
compatibility: >-
  Requires Python 3.11+. Install via pipx or pip. No credentials required for
  fleet listing and trust score tracking. Optional server dashboard available
  via agent-bom serve.
metadata:
  author: msaad00
  homepage: https://github.com/msaad00/agent-bom
  source: https://github.com/msaad00/agent-bom
  pypi: https://pypi.org/project/agent-bom/
  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom
  tests: 7239
  install:
    pipx: agent-bom
    pip: agent-bom
    docker: ghcr.io/msaad00/agent-bom:0.76.4
  openclaw:
    requires:
      bins: []
      env: []
      credentials: none
    credential_policy: "Zero credentials required for fleet listing and trust score tracking. Fleet sync reads local scan state. Dashboard server (agent-bom serve) runs on localhost only."
    optional_env: []
    optional_bins: []
    emoji: "\U0001F4CA"
    homepage: https://github.com/msaad00/agent-bom
    source: https://github.com/msaad00/agent-bom
    license: Apache-2.0
    os:
      - darwin
      - linux
      - windows
    data_flow: "Purely local. Fleet data is read from local scan state. Dashboard server (agent-bom serve) runs on localhost and exposes no data externally. No data leaves the machine."
    file_reads:
      - "local scan state and fleet registry (managed by agent-bom)"
    file_writes: []
    network_endpoints: []
    telemetry: false
    persistence: false
    privilege_escalation: false
    always: false
    autonomous_invocation: restricted
---

# agent-bom-monitor — Agent Fleet Monitor

Monitor agent fleet health, track trust scores, and manage agent lifecycle
states across your AI infrastructure. Start a local dashboard server for
continuous monitoring.

## Install

```bash
pipx install agent-bom
agent-bom fleet sync         # sync fleet state with latest scan
agent-bom fleet list         # list all agents and trust scores
agent-bom serve              # start local monitoring dashboard
```

## When to Use

- "fleet" / "agent fleet"
- "watch agents" / "monitor agents"
- "runtime status"
- "trust scores"
- "fleet sync"
- "agent lifecycle"
- "serve dashboard" / "start dashboard"

## Commands

```bash
# Sync fleet state with latest scan
agent-bom fleet sync

# List all agents with trust scores
agent-bom fleet list

# Start local monitoring dashboard
agent-bom serve
```

## Examples

```
# Sync fleet
fleet_sync()

# List agents and trust scores
fleet_list()

# Start dashboard server
serve()
```

**Example fleet list output:**
```
Agent Fleet — 7 agents tracked
  filesystem   trust: 92  status: healthy   last-scan: 2m ago
  brave-search trust: 88  status: healthy   last-scan: 2m ago
  github       trust: 95  status: healthy 
Github ReposUpdated 4h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/msaad00/skills/agent-bom",
      "sourceUrl": "https://clawhub.ai/msaad00/skills/agent-bom",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T14:12:25.466Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-09T14:12:25.466Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "2.5K downloads",
      "href": "https://clawhub.ai/msaad00/agent-bom",
      "sourceUrl": "https://clawhub.ai/msaad00/agent-bom",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T14:12:25.466Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "0.76.4",
      "href": "https://clawhub.ai/msaad00/agent-bom",
      "sourceUrl": "https://clawhub.ai/msaad00/agent-bom",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-04-13T05:42:38.812Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 0.76.4",
      "description": "Release v0.76.4",
      "href": "https://clawhub.ai/msaad00/agent-bom",
      "sourceUrl": "https://clawhub.ai/msaad00/agent-bom",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-04-13T05:42:38.812Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 9, 2026.

Sponsored

Ads related to agent-bom and adjacent AI workflows.