{"id":"195e2e58-0d9f-4621-9f73-8b1d08644f5d","entityType":"agent","slug":"clawhub-msaad00-agent-bom-compliance","name":"agent-bom compliance","canonicalUrl":"https://www.xpersona.co/agent/clawhub-msaad00-agent-bom-compliance","canonicalPath":"/agent/clawhub-msaad00-agent-bom-compliance","generatedAt":"2026-10-10T01:14:22.397Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T04:24:17.496Z","emptyReason":null},"description":"AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks. Generate SBOMs and compliance reports. Use when: \"compliance report\", \"NIST\", \"SOC 2\", \"ISO 27001\", \"OWASP\", \"EU AI Act\", \"AISVS\", \"generate SBOM\", \"policy check\". Skill: agent-bom compliance Owner: msaad00 Summary: AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks. Generate SBOMs and compliance reports. Use when: \"compliance report\", \"NIST\", \"SOC 2\", \"ISO 27001\", \"OWASP\", \"EU AI Act\", \"AISVS\", \"generate SBOM\", \"policy check\". Tags: latest:0.108.3 Version history: v0.108.3 | 2026-10","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 5.1K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom-compliance","sourceUrl":"https://clawhub.ai/msaad00/agent-bom-compliance","homepage":"https://clawhub.ai/msaad00/skills/agent-bom-compliance","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/msaad00/agent-bom-compliance","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/msaad00/skills/agent-bom-compliance","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":56,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks. Generate SBO"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T04:24:17.496Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T04:24:17.496Z","emptyReason":null},"stars":null,"forks":null,"downloads":5096,"packageName":null,"latestVersion":"0.108.3","tractionLabel":"5.1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T04:24:17.496Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T04:24:17.496Z","lastCrawledAt":"2026-10-09T04:24:17.496Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T04:24:17.496Z","lastVerifiedAt":null,"highlights":[{"version":"0.108.3","createdAt":"2026-10-08T22:17:46.772Z","changelog":"Release v0.108.3","fileCount":3,"zipByteSize":4487},{"version":"0.108.2","createdAt":"2026-10-08T05:00:59.069Z","changelog":"Release v0.108.2","fileCount":3,"zipByteSize":4565},{"version":"0.108.1","createdAt":"2026-10-06T17:47:43.059Z","changelog":"Release v0.108.1","fileCount":3,"zipByteSize":4563},{"version":"0.108.0","createdAt":"2026-10-04T07:12:41.374Z","changelog":"Release v0.108.0","fileCount":3,"zipByteSize":4501},{"version":"0.107.2","createdAt":"2026-10-01T23:32:16.294Z","changelog":"Release v0.107.2","fileCount":3,"zipByteSize":4571},{"version":"0.107.0","createdAt":"2026-09-30T20:17:52.805Z","changelog":"Release v0.107.0","fileCount":3,"zipByteSize":4484},{"version":"0.106.1","createdAt":"2026-09-27T00:18:17.729Z","changelog":"Release v0.106.1","fileCount":3,"zipByteSize":4561},{"version":"0.105.0","createdAt":"2026-09-18T11:11:24.856Z","changelog":"Release v0.105.0","fileCount":3,"zipByteSize":4737}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom-compliance","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-compliance/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-compliance/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-compliance/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-compliance/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-compliance/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-compliance/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T01:14:22.395Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-compliance/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-compliance/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-compliance/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-compliance/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T04:24:17.496Z","emptyReason":null},"readme":"Skill: agent-bom compliance\n\nOwner: msaad00\n\nSummary: AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks. Generate SBOMs and compliance reports. Use when: \"compliance report\", \"NIST\", \"SOC 2\", \"ISO 27001\", \"OWASP\", \"EU AI Act\", \"AISVS\", \"generate SBOM\", \"policy check\".\n\nTags: latest:0.108.3\n\nVersion history:\n\nv0.108.3 | 2026-10-08T22:17:46.772Z | user\n\nRelease v0.108.3\n\nv0.108.2 | 2026-10-08T05:00:59.069Z | user\n\nRelease v0.108.2\n\nv0.108.1 | 2026-10-06T17:47:43.059Z | user\n\nRelease v0.108.1\n\nv0.108.0 | 2026-10-04T07:12:41.374Z | user\n\nRelease v0.108.0\n\nv0.107.2 | 2026-10-01T23:32:16.294Z | user\n\nRelease v0.107.2\n\nv0.107.0 | 2026-09-30T20:17:52.805Z | user\n\nRelease v0.107.0\n\nv0.106.1 | 2026-09-27T00:18:17.729Z | user\n\nRelease v0.106.1\n\nv0.105.0 | 2026-09-18T11:11:24.856Z | user\n\nRelease v0.105.0\n\nv0.104.0 | 2026-09-09T20:55:56.367Z | user\n\nRelease v0.104.0\n\nv0.103.2 | 2026-09-02T07:23:56.228Z | user\n\nRelease v0.103.2\n\nv0.102.0 | 2026-08-24T04:49:36.651Z | user\n\nRelease v0.102.0\n\nv0.101.0 | 2026-08-16T23:12:59.591Z | user\n\nRelease v0.101.0\n\nv0.100.0 | 2026-08-12T20:54:50.160Z | user\n\nRelease v0.100.0\n\nv0.99.0 | 2026-08-06T00:52:24.701Z | user\n\nRelease v0.99.0\n\nv0.98.3 | 2026-08-03T06:08:58.195Z | user\n\nRelease v0.98.3\n\nv0.98.2 | 2026-07-27T08:50:01.842Z | user\n\nRelease v0.98.2\n\nv0.98.1 | 2026-07-27T02:02:04.464Z | user\n\nRelease v0.98.1\n\nv0.98.0 | 2026-07-25T01:51:06.320Z | user\n\nRelease v0.98.0\n\nv0.97.5 | 2026-07-24T01:43:31.469Z | user\n\nRelease v0.97.5\n\nv0.97.4 | 2026-07-23T00:59:07.770Z | user\n\nRelease v0.97.4\n\nv0.97.2 | 2026-07-21T18:19:06.876Z | user\n\nRelease v0.97.2\n\nv0.97.1 | 2026-07-21T03:31:33.283Z | user\n\nRelease v0.97.1\n\nv0.97.0 | 2026-07-20T18:10:48.000Z | user\n\nRelease v0.97.0\n\nv0.96.4 | 2026-07-20T15:05:39.744Z | user\n\nRelease v0.96.4\n\nv0.96.3 | 2026-07-16T04:05:36.756Z | user\n\nRelease v0.96.3\n\nv0.96.2 | 2026-07-15T23:05:16.672Z | user\n\nRelease v0.96.2\n\nv0.95.0 | 2026-07-13T21:38:32.427Z | user\n\nRelease v0.95.0\n\nv0.94.2 | 2026-07-09T18:24:36.522Z | user\n\nRelease v0.94.2\n\nv0.94.1 | 2026-07-09T05:50:53.205Z | user\n\nRelease v0.94.1\n\nv0.94.0 | 2026-07-08T21:48:06.338Z | user\n\nRelease v0.94.0\n\nv0.93.0 | 2026-07-06T07:42:58.347Z | user\n\nRelease v0.93.0\n\nv0.91.0 | 2026-06-30T23:36:34.201Z | user\n\nRelease v0.91.0\n\nv0.90.0 | 2026-06-30T03:47:49.998Z | user\n\nRelease v0.90.0\n\nv0.89.2 | 2026-06-22T03:17:52.558Z | user\n\nRelease v0.89.2\n\nv0.88.5 | 2026-06-01T06:23:58.742Z | user\n\nRelease v0.88.5\n\nv0.88.4 | 2026-05-26T04:20:22.369Z | user\n\nRelease v0.88.4\n\nv0.88.1 | 2026-05-22T04:38:28.954Z | user\n\nRelease v0.88.1\n\nv0.87.1 | 2026-05-18T20:25:45.223Z | user\n\nRelease v0.87.1\n\nv0.87.0 | 2026-05-18T00:36:53.406Z | user\n\nRelease v0.87.0\n\nv0.86.5 | 2026-05-11T16:16:07.835Z | user\n\nRelease v0.86.5\n\nv0.86.2 | 2026-05-07T15:45:19.865Z | user\n\nRelease v0.86.2\n\nv0.86.1 | 2026-05-06T06:42:26.986Z | user\n\nRelease v0.86.1\n\nv0.85.0 | 2026-05-02T22:48:53.082Z | user\n\nRelease v0.85.0\n\nv0.84.6 | 2026-05-02T06:44:11.603Z | user\n\nRelease v0.84.6\n\nv0.84.5 | 2026-05-02T03:29:22.485Z | user\n\nRelease v0.84.5\n\nv0.84.4 | 2026-05-01T19:07:41.319Z | user\n\nRelease v0.84.4\n\nv0.84.0 | 2026-05-01T01:53:37.465Z | user\n\nRelease v0.84.0\n\nv0.83.4 | 2026-04-30T19:33:47.004Z | user\n\nRelease v0.83.4\n\nv0.83.3 | 2026-04-30T05:47:44.217Z | user\n\nRelease v0.83.3\n\nv0.83.2 | 2026-04-30T04:46:26.271Z | user\n\nRelease v0.83.2\n\nArchive index:\n\nArchive v0.108.3: 3 files, 4487 bytes\n\nFiles: skill-card.md (1788b), SKILL.md (7934b), _meta.json (141b)\n\nFile v0.108.3:SKILL.md\n\n---\nname: agent-bom-compliance\ndescription: >-\n  AI compliance and policy engine — evaluate scan results against OWASP, NIST,\n  SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.\n  Generate SBOMs and compliance reports. Use when:\n  \"compliance report\", \"NIST\", \"SOC 2\", \"ISO 27001\", \"OWASP\", \"EU AI Act\",\n  \"AISVS\", \"generate SBOM\", \"policy check\".\nversion: 0.108.3\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. OWASP/NIST/EU AI Act/MITRE\n  evaluation and SBOM generation are fully local with zero credentials. CIS\n  benchmark checks optionally use cloud SDK credentials (AWS/Azure/GCP/Snowflake)\n  and make read-only API calls to cloud providers when explicitly invoked.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.108.3\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required for OWASP/NIST/EU AI Act compliance and SBOM generation. CIS benchmark checks (AWS, Azure, GCP, Snowflake) optionally accept cloud credentials — only used locally to call cloud APIs, never transmitted elsewhere.\"\n    credential_handling: \"Use only operator-configured cloud SDK credentials for explicitly requested CIS checks. Do not ask users to paste secrets, and never print cloud tokens, private keys, passwords, or connection strings.\"\n    optional_env:\n      - name: AWS_PROFILE\n        purpose: \"AWS CIS benchmark checks — uses boto3 with your local AWS profile\"\n        required: false\n      - name: AZURE_TENANT_ID\n        purpose: \"Azure CIS benchmark checks (azure-mgmt-* SDK)\"\n        required: false\n      - name: AZURE_CLIENT_ID\n        purpose: \"Azure CIS benchmark checks — service principal client ID\"\n        required: false\n      - name: AZURE_CLIENT_SECRET\n        purpose: \"Azure CIS benchmark checks — service principal secret\"\n        required: false\n      - name: GOOGLE_APPLICATION_CREDENTIALS\n        purpose: \"GCP CIS benchmark checks (google-cloud-* SDK)\"\n        required: false\n      - name: SNOWFLAKE_ACCOUNT\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_USER\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_PRIVATE_KEY_PATH\n        purpose: \"Snowflake key-pair auth (CI/CD)\"\n        required: false\n      - name: SNOWFLAKE_AUTHENTICATOR\n        purpose: \"Snowflake auth method (default: externalbrowser SSO)\"\n        required: false\n    optional_bins: []\n    emoji: \"\\U00002705\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: >-\n      OWASP/NIST/EU AI Act/MITRE/SBOM evaluation is purely local — zero network\n      calls. CIS benchmark checks (optional, user-initiated) call cloud provider\n      APIs (AWS/Azure/GCP/Snowflake) using locally configured credentials. No data\n      is stored or transmitted beyond the cloud provider's own API. File reads are\n      limited to user-provided SBOMs and policy files.\n    file_reads:\n      - \"user-provided SBOM files (CycloneDX/SPDX JSON)\"\n      - \"user-provided policy files (YAML/JSON policy-as-code)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://*.amazonaws.com\"\n        purpose: \"AWS CIS benchmark checks — read-only API calls (IAM, S3, CloudTrail, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://management.azure.com\"\n        purpose: \"Azure CIS benchmark checks — read-only API calls (Azure Resource Manager)\"\n        auth: true\n        optional: true\n      - url: \"https://*.googleapis.com\"\n        purpose: \"GCP CIS benchmark checks — read-only API calls (Cloud Resource Manager, IAM, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake CIS benchmark checks — read-only API calls (ACCOUNT_USAGE views)\"\n        auth: true\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-compliance — AI Compliance & Policy Engine\n\nEvaluate AI infrastructure scan results against 14 security and regulatory\nframeworks. Enforce policy-as-code rules. Generate SBOMs in standard formats.\nRun AISVS v1.0 and CIS benchmark checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom scan --compliance --compliance-export nist-ai-rmf\nagent-bom scan -f cyclonedx -o sbom.json\n```\n\n## When to Use\n\n- \"compliance report\" / \"run compliance\"\n- \"NIST\" / \"NIST AI RMF\" / \"NIST CSF\" / \"NIST 800-53\"\n- \"SOC 2\" / \"SOC2\"\n- \"ISO 27001\"\n- \"OWASP\" / \"OWASP LLM Top 10\" / \"OWASP Agentic Top 10\"\n- \"EU AI Act\"\n- \"AISVS\" / \"AI Security Verification Standard\"\n- \"CMMC\" / \"FedRAMP\"\n- \"generate SBOM\" / \"CycloneDX\" / \"SPDX\"\n- \"policy check\" / \"policy enforcement\"\n\n## Tools (5)\n\n| Tool | Description |\n|------|-------------|\n| `compliance` | OWASP LLM/Agentic Top 10, EU AI Act, MITRE ATLAS, NIST AI RMF |\n| `policy_check` | Evaluate results against custom security policy (17 conditions) |\n| `cis_benchmark` | Run CIS benchmark checks against cloud accounts |\n| `generate_sbom` | Generate SBOM (CycloneDX or SPDX format) |\n| `aisvs_benchmark` | OWASP AISVS v1.0 compliance — 9 AI security checks |\n\n## Supported Frameworks (15)\n\n- **OWASP LLM Top 10** (2025) — prompt injection, supply chain, data leakage\n- **OWASP MCP Top 10** — MCP-specific security risks\n- **OWASP Agentic Top 10** — tool poisoning, rug pulls, credential theft\n- **MITRE ATLAS** — adversarial ML threat framework\n- **MITRE ATT&CK Enterprise** — adversary techniques tagged via CWE → CAPEC → ATT&CK on every blast-radius finding\n- **NIST AI RMF** — govern, map, measure, manage lifecycle\n- **NIST CSF 2.0** — identify, protect, detect, respond, recover\n- **NIST 800-53 Rev 5** — federal security controls (CM-8, RA-5, SI-2, SR-3)\n- **FedRAMP Moderate** — derived from NIST 800-53 controls\n- **EU AI Act** — risk classification, transparency, SBOM requirements\n- **ISO 27001:2022** — information security controls (Annex A)\n- **SOC 2** — Trust Services Criteria\n- **CIS Controls v8** — implementation groups IG1/IG2/IG3\n- **CMMC 2.0** — cybersecurity maturity model (Level 1-3)\n- **PCI DSS v4.0** — payment-card data security requirements\n\nOWASP AISVS v1.0 ships as a **benchmark surface** alongside the tag-mapped frameworks (9 verification checks).\n\n## Examples\n\n```\n# Run compliance check against multiple frameworks\ncompliance(frameworks=[\"owasp_llm\", \"eu_ai_act\", \"nist_ai_rmf\"])\n\n# Enforce custom policy\npolicy_check(policy={\"max_critical\": 0, \"max_high\": 5})\n\n# Generate SBOM\ngenerate_sbom(format=\"cyclonedx\")\n\n# Run AISVS v1.0 compliance\naisvs_benchmark()\n\n# Run AWS CIS benchmark\ncis_benchmark(provider=\"aws\")\n```\n\n## Privacy & Data Handling\n\n**OWASP, NIST, EU AI Act, MITRE ATLAS, AISVS, SBOM generation, and policy\nchecks** run entirely locally on scan data already in memory. No network calls,\nno credentials needed for these features.\n\n**CIS benchmark checks** (optional, user-initiated) call cloud provider APIs\nusing your locally configured credentials. These are read-only API calls to\nAWS, Azure, GCP, or Snowflake. You must explicitly run `cis_benchmark(provider=...)`\nand confirm before any cloud API calls are made.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.108.3:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-compliance\",\n  \"version\": \"0.108.3\",\n  \"publishedAt\": 1791497866772\n}\n\nFile v0.108.3:skill-card.md\n\n## Description:\n\nHelps agents evaluate AI security and compliance findings against common frameworks, check policies, and generate SBOMs and compliance reports.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security teams use this skill to request compliance and policy checks on AI infrastructure scan results, generate SBOMs, and optionally run cloud CIS benchmark checks.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Optional CIS checks access cloud provider APIs using configured credentials and may expose more account information than needed.\n\nMitigation: Run CIS checks only after explicit confirmation and use a minimally privileged cloud profile.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/msaad00/skills/agent-bom-compliance)\n- [Project homepage](https://github.com/msaad00/agent-bom)\n- [Python package](https://pypi.org/project/agent-bom/)\n- [OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Guidance]\n\n**Output Format:** [Markdown with compliance guidance and example commands]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Can guide generation of CycloneDX or SPDX SBOMs and compliance reports.]\n\n## Skill Version(s):\n\n0.108.3 (source: release metadata and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.108.2: 3 files, 4565 bytes\n\nFiles: skill-card.md (2000b), SKILL.md (7934b), _meta.json (141b)\n\nFile v0.108.2:SKILL.md\n\n---\nname: agent-bom-compliance\ndescription: >-\n  AI compliance and policy engine — evaluate scan results against OWASP, NIST,\n  SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.\n  Generate SBOMs and compliance reports. Use when:\n  \"compliance report\", \"NIST\", \"SOC 2\", \"ISO 27001\", \"OWASP\", \"EU AI Act\",\n  \"AISVS\", \"generate SBOM\", \"policy check\".\nversion: 0.108.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. OWASP/NIST/EU AI Act/MITRE\n  evaluation and SBOM generation are fully local with zero credentials. CIS\n  benchmark checks optionally use cloud SDK credentials (AWS/Azure/GCP/Snowflake)\n  and make read-only API calls to cloud providers when explicitly invoked.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.108.2\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required for OWASP/NIST/EU AI Act compliance and SBOM generation. CIS benchmark checks (AWS, Azure, GCP, Snowflake) optionally accept cloud credentials — only used locally to call cloud APIs, never transmitted elsewhere.\"\n    credential_handling: \"Use only operator-configured cloud SDK credentials for explicitly requested CIS checks. Do not ask users to paste secrets, and never print cloud tokens, private keys, passwords, or connection strings.\"\n    optional_env:\n      - name: AWS_PROFILE\n        purpose: \"AWS CIS benchmark checks — uses boto3 with your local AWS profile\"\n        required: false\n      - name: AZURE_TENANT_ID\n        purpose: \"Azure CIS benchmark checks (azure-mgmt-* SDK)\"\n        required: false\n      - name: AZURE_CLIENT_ID\n        purpose: \"Azure CIS benchmark checks — service principal client ID\"\n        required: false\n      - name: AZURE_CLIENT_SECRET\n        purpose: \"Azure CIS benchmark checks — service principal secret\"\n        required: false\n      - name: GOOGLE_APPLICATION_CREDENTIALS\n        purpose: \"GCP CIS benchmark checks (google-cloud-* SDK)\"\n        required: false\n      - name: SNOWFLAKE_ACCOUNT\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_USER\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_PRIVATE_KEY_PATH\n        purpose: \"Snowflake key-pair auth (CI/CD)\"\n        required: false\n      - name: SNOWFLAKE_AUTHENTICATOR\n        purpose: \"Snowflake auth method (default: externalbrowser SSO)\"\n        required: false\n    optional_bins: []\n    emoji: \"\\U00002705\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: >-\n      OWASP/NIST/EU AI Act/MITRE/SBOM evaluation is purely local — zero network\n      calls. CIS benchmark checks (optional, user-initiated) call cloud provider\n      APIs (AWS/Azure/GCP/Snowflake) using locally configured credentials. No data\n      is stored or transmitted beyond the cloud provider's own API. File reads are\n      limited to user-provided SBOMs and policy files.\n    file_reads:\n      - \"user-provided SBOM files (CycloneDX/SPDX JSON)\"\n      - \"user-provided policy files (YAML/JSON policy-as-code)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://*.amazonaws.com\"\n        purpose: \"AWS CIS benchmark checks — read-only API calls (IAM, S3, CloudTrail, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://management.azure.com\"\n        purpose: \"Azure CIS benchmark checks — read-only API calls (Azure Resource Manager)\"\n        auth: true\n        optional: true\n      - url: \"https://*.googleapis.com\"\n        purpose: \"GCP CIS benchmark checks — read-only API calls (Cloud Resource Manager, IAM, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake CIS benchmark checks — read-only API calls (ACCOUNT_USAGE views)\"\n        auth: true\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-compliance — AI Compliance & Policy Engine\n\nEvaluate AI infrastructure scan results against 14 security and regulatory\nframeworks. Enforce policy-as-code rules. Generate SBOMs in standard formats.\nRun AISVS v1.0 and CIS benchmark checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom scan --compliance --compliance-export nist-ai-rmf\nagent-bom scan -f cyclonedx -o sbom.json\n```\n\n## When to Use\n\n- \"compliance report\" / \"run compliance\"\n- \"NIST\" / \"NIST AI RMF\" / \"NIST CSF\" / \"NIST 800-53\"\n- \"SOC 2\" / \"SOC2\"\n- \"ISO 27001\"\n- \"OWASP\" / \"OWASP LLM Top 10\" / \"OWASP Agentic Top 10\"\n- \"EU AI Act\"\n- \"AISVS\" / \"AI Security Verification Standard\"\n- \"CMMC\" / \"FedRAMP\"\n- \"generate SBOM\" / \"CycloneDX\" / \"SPDX\"\n- \"policy check\" / \"policy enforcement\"\n\n## Tools (5)\n\n| Tool | Description |\n|------|-------------|\n| `compliance` | OWASP LLM/Agentic Top 10, EU AI Act, MITRE ATLAS, NIST AI RMF |\n| `policy_check` | Evaluate results against custom security policy (17 conditions) |\n| `cis_benchmark` | Run CIS benchmark checks against cloud accounts |\n| `generate_sbom` | Generate SBOM (CycloneDX or SPDX format) |\n| `aisvs_benchmark` | OWASP AISVS v1.0 compliance — 9 AI security checks |\n\n## Supported Frameworks (15)\n\n- **OWASP LLM Top 10** (2025) — prompt injection, supply chain, data leakage\n- **OWASP MCP Top 10** — MCP-specific security risks\n- **OWASP Agentic Top 10** — tool poisoning, rug pulls, credential theft\n- **MITRE ATLAS** — adversarial ML threat framework\n- **MITRE ATT&CK Enterprise** — adversary techniques tagged via CWE → CAPEC → ATT&CK on every blast-radius finding\n- **NIST AI RMF** — govern, map, measure, manage lifecycle\n- **NIST CSF 2.0** — identify, protect, detect, respond, recover\n- **NIST 800-53 Rev 5** — federal security controls (CM-8, RA-5, SI-2, SR-3)\n- **FedRAMP Moderate** — derived from NIST 800-53 controls\n- **EU AI Act** — risk classification, transparency, SBOM requirements\n- **ISO 27001:2022** — information security controls (Annex A)\n- **SOC 2** — Trust Services Criteria\n- **CIS Controls v8** — implementation groups IG1/IG2/IG3\n- **CMMC 2.0** — cybersecurity maturity model (Level 1-3)\n- **PCI DSS v4.0** — payment-card data security requirements\n\nOWASP AISVS v1.0 ships as a **benchmark surface** alongside the tag-mapped frameworks (9 verification checks).\n\n## Examples\n\n```\n# Run compliance check against multiple frameworks\ncompliance(frameworks=[\"owasp_llm\", \"eu_ai_act\", \"nist_ai_rmf\"])\n\n# Enforce custom policy\npolicy_check(policy={\"max_critical\": 0, \"max_high\": 5})\n\n# Generate SBOM\ngenerate_sbom(format=\"cyclonedx\")\n\n# Run AISVS v1.0 compliance\naisvs_benchmark()\n\n# Run AWS CIS benchmark\ncis_benchmark(provider=\"aws\")\n```\n\n## Privacy & Data Handling\n\n**OWASP, NIST, EU AI Act, MITRE ATLAS, AISVS, SBOM generation, and policy\nchecks** run entirely locally on scan data already in memory. No network calls,\nno credentials needed for these features.\n\n**CIS benchmark checks** (optional, user-initiated) call cloud provider APIs\nusing your locally configured credentials. These are read-only API calls to\nAWS, Azure, GCP, or Snowflake. You must explicitly run `cis_benchmark(provider=...)`\nand confirm before any cloud API calls are made.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.108.2:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-compliance\",\n  \"version\": \"0.108.2\",\n  \"publishedAt\": 1791435659069\n}\n\nFile v0.108.2:skill-card.md\n\n## Description:\n\nEvaluates AI infrastructure scan results against security and regulatory frameworks, checks policies, and generates compliance reports and SBOMs.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security teams use this skill to check scan results against compliance frameworks, evaluate policies, produce SBOMs, and optionally run cloud CIS benchmarks.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Optional CIS checks can read cloud account configuration using existing SDK credentials.\n\nMitigation: Confirm the intended cloud provider and account before explicitly running a CIS check; use operator-configured credentials and do not share secrets in prompts or output.\n\nRisk: Installing the external agent-bom package introduces a third-party software dependency.\n\nMitigation: Verify the package source before installing it in a sensitive environment.\n\n## Reference(s):\n\n- [agent-bom project homepage](https://github.com/msaad00/agent-bom)\n- [agent-bom package on PyPI](https://pypi.org/project/agent-bom/)\n- [agent-bom OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Analysis, Markdown, JSON, Shell commands]\n\n**Output Format:** [Markdown guidance and shell commands; JSON compliance reports and CycloneDX or SPDX SBOMs]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Cloud benchmark checks require explicit invocation and locally configured provider credentials.]\n\n## Skill Version(s):\n\n0.108.2 (source: frontmatter and ClawHub release)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.108.1: 3 files, 4563 bytes\n\nFiles: skill-card.md (2005b), SKILL.md (7934b), _meta.json (141b)\n\nFile v0.108.1:SKILL.md\n\n---\nname: agent-bom-compliance\ndescription: >-\n  AI compliance and policy engine — evaluate scan results against OWASP, NIST,\n  SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.\n  Generate SBOMs and compliance reports. Use when:\n  \"compliance report\", \"NIST\", \"SOC 2\", \"ISO 27001\", \"OWASP\", \"EU AI Act\",\n  \"AISVS\", \"generate SBOM\", \"policy check\".\nversion: 0.108.1\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. OWASP/NIST/EU AI Act/MITRE\n  evaluation and SBOM generation are fully local with zero credentials. CIS\n  benchmark checks optionally use cloud SDK credentials (AWS/Azure/GCP/Snowflake)\n  and make read-only API calls to cloud providers when explicitly invoked.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.108.1\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required for OWASP/NIST/EU AI Act compliance and SBOM generation. CIS benchmark checks (AWS, Azure, GCP, Snowflake) optionally accept cloud credentials — only used locally to call cloud APIs, never transmitted elsewhere.\"\n    credential_handling: \"Use only operator-configured cloud SDK credentials for explicitly requested CIS checks. Do not ask users to paste secrets, and never print cloud tokens, private keys, passwords, or connection strings.\"\n    optional_env:\n      - name: AWS_PROFILE\n        purpose: \"AWS CIS benchmark checks — uses boto3 with your local AWS profile\"\n        required: false\n      - name: AZURE_TENANT_ID\n        purpose: \"Azure CIS benchmark checks (azure-mgmt-* SDK)\"\n        required: false\n      - name: AZURE_CLIENT_ID\n        purpose: \"Azure CIS benchmark checks — service principal client ID\"\n        required: false\n      - name: AZURE_CLIENT_SECRET\n        purpose: \"Azure CIS benchmark checks — service principal secret\"\n        required: false\n      - name: GOOGLE_APPLICATION_CREDENTIALS\n        purpose: \"GCP CIS benchmark checks (google-cloud-* SDK)\"\n        required: false\n      - name: SNOWFLAKE_ACCOUNT\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_USER\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_PRIVATE_KEY_PATH\n        purpose: \"Snowflake key-pair auth (CI/CD)\"\n        required: false\n      - name: SNOWFLAKE_AUTHENTICATOR\n        purpose: \"Snowflake auth method (default: externalbrowser SSO)\"\n        required: false\n    optional_bins: []\n    emoji: \"\\U00002705\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: >-\n      OWASP/NIST/EU AI Act/MITRE/SBOM evaluation is purely local — zero network\n      calls. CIS benchmark checks (optional, user-initiated) call cloud provider\n      APIs (AWS/Azure/GCP/Snowflake) using locally configured credentials. No data\n      is stored or transmitted beyond the cloud provider's own API. File reads are\n      limited to user-provided SBOMs and policy files.\n    file_reads:\n      - \"user-provided SBOM files (CycloneDX/SPDX JSON)\"\n      - \"user-provided policy files (YAML/JSON policy-as-code)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://*.amazonaws.com\"\n        purpose: \"AWS CIS benchmark checks — read-only API calls (IAM, S3, CloudTrail, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://management.azure.com\"\n        purpose: \"Azure CIS benchmark checks — read-only API calls (Azure Resource Manager)\"\n        auth: true\n        optional: true\n      - url: \"https://*.googleapis.com\"\n        purpose: \"GCP CIS benchmark checks — read-only API calls (Cloud Resource Manager, IAM, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake CIS benchmark checks — read-only API calls (ACCOUNT_USAGE views)\"\n        auth: true\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-compliance — AI Compliance & Policy Engine\n\nEvaluate AI infrastructure scan results against 14 security and regulatory\nframeworks. Enforce policy-as-code rules. Generate SBOMs in standard formats.\nRun AISVS v1.0 and CIS benchmark checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom scan --compliance --compliance-export nist-ai-rmf\nagent-bom scan -f cyclonedx -o sbom.json\n```\n\n## When to Use\n\n- \"compliance report\" / \"run compliance\"\n- \"NIST\" / \"NIST AI RMF\" / \"NIST CSF\" / \"NIST 800-53\"\n- \"SOC 2\" / \"SOC2\"\n- \"ISO 27001\"\n- \"OWASP\" / \"OWASP LLM Top 10\" / \"OWASP Agentic Top 10\"\n- \"EU AI Act\"\n- \"AISVS\" / \"AI Security Verification Standard\"\n- \"CMMC\" / \"FedRAMP\"\n- \"generate SBOM\" / \"CycloneDX\" / \"SPDX\"\n- \"policy check\" / \"policy enforcement\"\n\n## Tools (5)\n\n| Tool | Description |\n|------|-------------|\n| `compliance` | OWASP LLM/Agentic Top 10, EU AI Act, MITRE ATLAS, NIST AI RMF |\n| `policy_check` | Evaluate results against custom security policy (17 conditions) |\n| `cis_benchmark` | Run CIS benchmark checks against cloud accounts |\n| `generate_sbom` | Generate SBOM (CycloneDX or SPDX format) |\n| `aisvs_benchmark` | OWASP AISVS v1.0 compliance — 9 AI security checks |\n\n## Supported Frameworks (15)\n\n- **OWASP LLM Top 10** (2025) — prompt injection, supply chain, data leakage\n- **OWASP MCP Top 10** — MCP-specific security risks\n- **OWASP Agentic Top 10** — tool poisoning, rug pulls, credential theft\n- **MITRE ATLAS** — adversarial ML threat framework\n- **MITRE ATT&CK Enterprise** — adversary techniques tagged via CWE → CAPEC → ATT&CK on every blast-radius finding\n- **NIST AI RMF** — govern, map, measure, manage lifecycle\n- **NIST CSF 2.0** — identify, protect, detect, respond, recover\n- **NIST 800-53 Rev 5** — federal security controls (CM-8, RA-5, SI-2, SR-3)\n- **FedRAMP Moderate** — derived from NIST 800-53 controls\n- **EU AI Act** — risk classification, transparency, SBOM requirements\n- **ISO 27001:2022** — information security controls (Annex A)\n- **SOC 2** — Trust Services Criteria\n- **CIS Controls v8** — implementation groups IG1/IG2/IG3\n- **CMMC 2.0** — cybersecurity maturity model (Level 1-3)\n- **PCI DSS v4.0** — payment-card data security requirements\n\nOWASP AISVS v1.0 ships as a **benchmark surface** alongside the tag-mapped frameworks (9 verification checks).\n\n## Examples\n\n```\n# Run compliance check against multiple frameworks\ncompliance(frameworks=[\"owasp_llm\", \"eu_ai_act\", \"nist_ai_rmf\"])\n\n# Enforce custom policy\npolicy_check(policy={\"max_critical\": 0, \"max_high\": 5})\n\n# Generate SBOM\ngenerate_sbom(format=\"cyclonedx\")\n\n# Run AISVS v1.0 compliance\naisvs_benchmark()\n\n# Run AWS CIS benchmark\ncis_benchmark(provider=\"aws\")\n```\n\n## Privacy & Data Handling\n\n**OWASP, NIST, EU AI Act, MITRE ATLAS, AISVS, SBOM generation, and policy\nchecks** run entirely locally on scan data already in memory. No network calls,\nno credentials needed for these features.\n\n**CIS benchmark checks** (optional, user-initiated) call cloud provider APIs\nusing your locally configured credentials. These are read-only API calls to\nAWS, Azure, GCP, or Snowflake. You must explicitly run `cis_benchmark(provider=...)`\nand confirm before any cloud API calls are made.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.108.1:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-compliance\",\n  \"version\": \"0.108.1\",\n  \"publishedAt\": 1791308863059\n}\n\nFile v0.108.1:skill-card.md\n\n## Description:\n\nEvaluates AI scan results against security and compliance frameworks, checks policies, and helps generate compliance reports and SBOMs.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security teams use this skill to assess AI scan results against compliance frameworks, enforce policies, and produce SBOMs. Optional cloud benchmark checks require explicit confirmation.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Installing an external package from an untrusted source could expose the user's environment.\n\nMitigation: Verify that you trust the agent-bom package and source before installation.\n\nRisk: Optional cloud benchmark checks contact provider APIs using configured credentials.\n\nMitigation: Run these checks only when needed, with explicitly approved least-privilege read-only credentials.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/msaad00/skills/agent-bom-compliance)\n- [Project homepage (skill metadata; not verified import provenance)](https://github.com/msaad00/agent-bom)\n- [agent-bom on PyPI](https://pypi.org/project/agent-bom/)\n- [Project OpenSSF Scorecard (skill metadata)](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, JSON, Shell commands, Guidance]\n\n**Output Format:** [Compliance reports and guidance in text or Markdown; CycloneDX or SPDX SBOMs in JSON]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [None]\n\n## Skill Version(s):\n\n0.108.1 (source: SKILL.md frontmatter and ClawHub release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.108.0: 3 files, 4501 bytes\n\nFiles: skill-card.md (1970b), SKILL.md (7934b), _meta.json (141b)\n\nFile v0.108.0:SKILL.md\n\n---\nname: agent-bom-compliance\ndescription: >-\n  AI compliance and policy engine — evaluate scan results against OWASP, NIST,\n  SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.\n  Generate SBOMs and compliance reports. Use when:\n  \"compliance report\", \"NIST\", \"SOC 2\", \"ISO 27001\", \"OWASP\", \"EU AI Act\",\n  \"AISVS\", \"generate SBOM\", \"policy check\".\nversion: 0.108.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. OWASP/NIST/EU AI Act/MITRE\n  evaluation and SBOM generation are fully local with zero credentials. CIS\n  benchmark checks optionally use cloud SDK credentials (AWS/Azure/GCP/Snowflake)\n  and make read-only API calls to cloud providers when explicitly invoked.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.108.0\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required for OWASP/NIST/EU AI Act compliance and SBOM generation. CIS benchmark checks (AWS, Azure, GCP, Snowflake) optionally accept cloud credentials — only used locally to call cloud APIs, never transmitted elsewhere.\"\n    credential_handling: \"Use only operator-configured cloud SDK credentials for explicitly requested CIS checks. Do not ask users to paste secrets, and never print cloud tokens, private keys, passwords, or connection strings.\"\n    optional_env:\n      - name: AWS_PROFILE\n        purpose: \"AWS CIS benchmark checks — uses boto3 with your local AWS profile\"\n        required: false\n      - name: AZURE_TENANT_ID\n        purpose: \"Azure CIS benchmark checks (azure-mgmt-* SDK)\"\n        required: false\n      - name: AZURE_CLIENT_ID\n        purpose: \"Azure CIS benchmark checks — service principal client ID\"\n        required: false\n      - name: AZURE_CLIENT_SECRET\n        purpose: \"Azure CIS benchmark checks — service principal secret\"\n        required: false\n      - name: GOOGLE_APPLICATION_CREDENTIALS\n        purpose: \"GCP CIS benchmark checks (google-cloud-* SDK)\"\n        required: false\n      - name: SNOWFLAKE_ACCOUNT\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_USER\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_PRIVATE_KEY_PATH\n        purpose: \"Snowflake key-pair auth (CI/CD)\"\n        required: false\n      - name: SNOWFLAKE_AUTHENTICATOR\n        purpose: \"Snowflake auth method (default: externalbrowser SSO)\"\n        required: false\n    optional_bins: []\n    emoji: \"\\U00002705\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: >-\n      OWASP/NIST/EU AI Act/MITRE/SBOM evaluation is purely local — zero network\n      calls. CIS benchmark checks (optional, user-initiated) call cloud provider\n      APIs (AWS/Azure/GCP/Snowflake) using locally configured credentials. No data\n      is stored or transmitted beyond the cloud provider's own API. File reads are\n      limited to user-provided SBOMs and policy files.\n    file_reads:\n      - \"user-provided SBOM files (CycloneDX/SPDX JSON)\"\n      - \"user-provided policy files (YAML/JSON policy-as-code)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://*.amazonaws.com\"\n        purpose: \"AWS CIS benchmark checks — read-only API calls (IAM, S3, CloudTrail, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://management.azure.com\"\n        purpose: \"Azure CIS benchmark checks — read-only API calls (Azure Resource Manager)\"\n        auth: true\n        optional: true\n      - url: \"https://*.googleapis.com\"\n        purpose: \"GCP CIS benchmark checks — read-only API calls (Cloud Resource Manager, IAM, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake CIS benchmark checks — read-only API calls (ACCOUNT_USAGE views)\"\n        auth: true\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-compliance — AI Compliance & Policy Engine\n\nEvaluate AI infrastructure scan results against 14 security and regulatory\nframeworks. Enforce policy-as-code rules. Generate SBOMs in standard formats.\nRun AISVS v1.0 and CIS benchmark checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom scan --compliance --compliance-export nist-ai-rmf\nagent-bom scan -f cyclonedx -o sbom.json\n```\n\n## When to Use\n\n- \"compliance report\" / \"run compliance\"\n- \"NIST\" / \"NIST AI RMF\" / \"NIST CSF\" / \"NIST 800-53\"\n- \"SOC 2\" / \"SOC2\"\n- \"ISO 27001\"\n- \"OWASP\" / \"OWASP LLM Top 10\" / \"OWASP Agentic Top 10\"\n- \"EU AI Act\"\n- \"AISVS\" / \"AI Security Verification Standard\"\n- \"CMMC\" / \"FedRAMP\"\n- \"generate SBOM\" / \"CycloneDX\" / \"SPDX\"\n- \"policy check\" / \"policy enforcement\"\n\n## Tools (5)\n\n| Tool | Description |\n|------|-------------|\n| `compliance` | OWASP LLM/Agentic Top 10, EU AI Act, MITRE ATLAS, NIST AI RMF |\n| `policy_check` | Evaluate results against custom security policy (17 conditions) |\n| `cis_benchmark` | Run CIS benchmark checks against cloud accounts |\n| `generate_sbom` | Generate SBOM (CycloneDX or SPDX format) |\n| `aisvs_benchmark` | OWASP AISVS v1.0 compliance — 9 AI security checks |\n\n## Supported Frameworks (15)\n\n- **OWASP LLM Top 10** (2025) — prompt injection, supply chain, data leakage\n- **OWASP MCP Top 10** — MCP-specific security risks\n- **OWASP Agentic Top 10** — tool poisoning, rug pulls, credential theft\n- **MITRE ATLAS** — adversarial ML threat framework\n- **MITRE ATT&CK Enterprise** — adversary techniques tagged via CWE → CAPEC → ATT&CK on every blast-radius finding\n- **NIST AI RMF** — govern, map, measure, manage lifecycle\n- **NIST CSF 2.0** — identify, protect, detect, respond, recover\n- **NIST 800-53 Rev 5** — federal security controls (CM-8, RA-5, SI-2, SR-3)\n- **FedRAMP Moderate** — derived from NIST 800-53 controls\n- **EU AI Act** — risk classification, transparency, SBOM requirements\n- **ISO 27001:2022** — information security controls (Annex A)\n- **SOC 2** — Trust Services Criteria\n- **CIS Controls v8** — implementation groups IG1/IG2/IG3\n- **CMMC 2.0** — cybersecurity maturity model (Level 1-3)\n- **PCI DSS v4.0** — payment-card data security requirements\n\nOWASP AISVS v1.0 ships as a **benchmark surface** alongside the tag-mapped frameworks (9 verification checks).\n\n## Examples\n\n```\n# Run compliance check against multiple frameworks\ncompliance(frameworks=[\"owasp_llm\", \"eu_ai_act\", \"nist_ai_rmf\"])\n\n# Enforce custom policy\npolicy_check(policy={\"max_critical\": 0, \"max_high\": 5})\n\n# Generate SBOM\ngenerate_sbom(format=\"cyclonedx\")\n\n# Run AISVS v1.0 compliance\naisvs_benchmark()\n\n# Run AWS CIS benchmark\ncis_benchmark(provider=\"aws\")\n```\n\n## Privacy & Data Handling\n\n**OWASP, NIST, EU AI Act, MITRE ATLAS, AISVS, SBOM generation, and policy\nchecks** run entirely locally on scan data already in memory. No network calls,\nno credentials needed for these features.\n\n**CIS benchmark checks** (optional, user-initiated) call cloud provider APIs\nusing your locally configured credentials. These are read-only API calls to\nAWS, Azure, GCP, or Snowflake. You must explicitly run `cis_benchmark(provider=...)`\nand confirm before any cloud API calls are made.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.108.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-compliance\",\n  \"version\": \"0.108.0\",\n  \"publishedAt\": 1791097961374\n}\n\nFile v0.108.0:skill-card.md\n\n## Description:\n\nHelps evaluate AI security scan results against compliance frameworks, check policies, and generate SBOMs and compliance reports.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security teams use this skill to assess scan results against AI security and regulatory frameworks, enforce policies, and generate SBOMs or compliance reports. Optional CIS checks inspect cloud accounts only when explicitly requested.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Optional CIS checks inspect cloud accounts using existing credentials.\n\nMitigation: Run them only when intentionally requested, use operator-configured credentials, and do not disclose secrets in reports or chat.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/msaad00/skills/agent-bom-compliance)\n- [Project homepage listed in skill metadata](https://github.com/msaad00/agent-bom)\n- [agent-bom package](https://pypi.org/project/agent-bom/)\n- [OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Compliance reports, SBOM files, Policy results, Shell commands, Guidance]\n\n**Output Format:** [Markdown guidance and commands; compliance reports and CycloneDX or SPDX SBOMs]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Local compliance, policy, and SBOM checks need no cloud credentials; optional CIS checks use operator-configured cloud credentials.]\n\n## Skill Version(s):\n\n0.108.0 (source: ClawHub release metadata and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.107.2: 3 files, 4571 bytes\n\nFiles: skill-card.md (2086b), SKILL.md (7934b), _meta.json (141b)\n\nFile v0.107.2:SKILL.md\n\n---\nname: agent-bom-compliance\ndescription: >-\n  AI compliance and policy engine — evaluate scan results against OWASP, NIST,\n  SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.\n  Generate SBOMs and compliance reports. Use when:\n  \"compliance report\", \"NIST\", \"SOC 2\", \"ISO 27001\", \"OWASP\", \"EU AI Act\",\n  \"AISVS\", \"generate SBOM\", \"policy check\".\nversion: 0.107.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. OWASP/NIST/EU AI Act/MITRE\n  evaluation and SBOM generation are fully local with zero credentials. CIS\n  benchmark checks optionally use cloud SDK credentials (AWS/Azure/GCP/Snowflake)\n  and make read-only API calls to cloud providers when explicitly invoked.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.107.2\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required for OWASP/NIST/EU AI Act compliance and SBOM generation. CIS benchmark checks (AWS, Azure, GCP, Snowflake) optionally accept cloud credentials — only used locally to call cloud APIs, never transmitted elsewhere.\"\n    credential_handling: \"Use only operator-configured cloud SDK credentials for explicitly requested CIS checks. Do not ask users to paste secrets, and never print cloud tokens, private keys, passwords, or connection strings.\"\n    optional_env:\n      - name: AWS_PROFILE\n        purpose: \"AWS CIS benchmark checks — uses boto3 with your local AWS profile\"\n        required: false\n      - name: AZURE_TENANT_ID\n        purpose: \"Azure CIS benchmark checks (azure-mgmt-* SDK)\"\n        required: false\n      - name: AZURE_CLIENT_ID\n        purpose: \"Azure CIS benchmark checks — service principal client ID\"\n        required: false\n      - name: AZURE_CLIENT_SECRET\n        purpose: \"Azure CIS benchmark checks — service principal secret\"\n        required: false\n      - name: GOOGLE_APPLICATION_CREDENTIALS\n        purpose: \"GCP CIS benchmark checks (google-cloud-* SDK)\"\n        required: false\n      - name: SNOWFLAKE_ACCOUNT\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_USER\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_PRIVATE_KEY_PATH\n        purpose: \"Snowflake key-pair auth (CI/CD)\"\n        required: false\n      - name: SNOWFLAKE_AUTHENTICATOR\n        purpose: \"Snowflake auth method (default: externalbrowser SSO)\"\n        required: false\n    optional_bins: []\n    emoji: \"\\U00002705\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: >-\n      OWASP/NIST/EU AI Act/MITRE/SBOM evaluation is purely local — zero network\n      calls. CIS benchmark checks (optional, user-initiated) call cloud provider\n      APIs (AWS/Azure/GCP/Snowflake) using locally configured credentials. No data\n      is stored or transmitted beyond the cloud provider's own API. File reads are\n      limited to user-provided SBOMs and policy files.\n    file_reads:\n      - \"user-provided SBOM files (CycloneDX/SPDX JSON)\"\n      - \"user-provided policy files (YAML/JSON policy-as-code)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://*.amazonaws.com\"\n        purpose: \"AWS CIS benchmark checks — read-only API calls (IAM, S3, CloudTrail, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://management.azure.com\"\n        purpose: \"Azure CIS benchmark checks — read-only API calls (Azure Resource Manager)\"\n        auth: true\n        optional: true\n      - url: \"https://*.googleapis.com\"\n        purpose: \"GCP CIS benchmark checks — read-only API calls (Cloud Resource Manager, IAM, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake CIS benchmark checks — read-only API calls (ACCOUNT_USAGE views)\"\n        auth: true\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-compliance — AI Compliance & Policy Engine\n\nEvaluate AI infrastructure scan results against 14 security and regulatory\nframeworks. Enforce policy-as-code rules. Generate SBOMs in standard formats.\nRun AISVS v1.0 and CIS benchmark checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom scan --compliance --compliance-export nist-ai-rmf\nagent-bom scan -f cyclonedx -o sbom.json\n```\n\n## When to Use\n\n- \"compliance report\" / \"run compliance\"\n- \"NIST\" / \"NIST AI RMF\" / \"NIST CSF\" / \"NIST 800-53\"\n- \"SOC 2\" / \"SOC2\"\n- \"ISO 27001\"\n- \"OWASP\" / \"OWASP LLM Top 10\" / \"OWASP Agentic Top 10\"\n- \"EU AI Act\"\n- \"AISVS\" / \"AI Security Verification Standard\"\n- \"CMMC\" / \"FedRAMP\"\n- \"generate SBOM\" / \"CycloneDX\" / \"SPDX\"\n- \"policy check\" / \"policy enforcement\"\n\n## Tools (5)\n\n| Tool | Description |\n|------|-------------|\n| `compliance` | OWASP LLM/Agentic Top 10, EU AI Act, MITRE ATLAS, NIST AI RMF |\n| `policy_check` | Evaluate results against custom security policy (17 conditions) |\n| `cis_benchmark` | Run CIS benchmark checks against cloud accounts |\n| `generate_sbom` | Generate SBOM (CycloneDX or SPDX format) |\n| `aisvs_benchmark` | OWASP AISVS v1.0 compliance — 9 AI security checks |\n\n## Supported Frameworks (15)\n\n- **OWASP LLM Top 10** (2025) — prompt injection, supply chain, data leakage\n- **OWASP MCP Top 10** — MCP-specific security risks\n- **OWASP Agentic Top 10** — tool poisoning, rug pulls, credential theft\n- **MITRE ATLAS** — adversarial ML threat framework\n- **MITRE ATT&CK Enterprise** — adversary techniques tagged via CWE → CAPEC → ATT&CK on every blast-radius finding\n- **NIST AI RMF** — govern, map, measure, manage lifecycle\n- **NIST CSF 2.0** — identify, protect, detect, respond, recover\n- **NIST 800-53 Rev 5** — federal security controls (CM-8, RA-5, SI-2, SR-3)\n- **FedRAMP Moderate** — derived from NIST 800-53 controls\n- **EU AI Act** — risk classification, transparency, SBOM requirements\n- **ISO 27001:2022** — information security controls (Annex A)\n- **SOC 2** — Trust Services Criteria\n- **CIS Controls v8** — implementation groups IG1/IG2/IG3\n- **CMMC 2.0** — cybersecurity maturity model (Level 1-3)\n- **PCI DSS v4.0** — payment-card data security requirements\n\nOWASP AISVS v1.0 ships as a **benchmark surface** alongside the tag-mapped frameworks (9 verification checks).\n\n## Examples\n\n```\n# Run compliance check against multiple frameworks\ncompliance(frameworks=[\"owasp_llm\", \"eu_ai_act\", \"nist_ai_rmf\"])\n\n# Enforce custom policy\npolicy_check(policy={\"max_critical\": 0, \"max_high\": 5})\n\n# Generate SBOM\ngenerate_sbom(format=\"cyclonedx\")\n\n# Run AISVS v1.0 compliance\naisvs_benchmark()\n\n# Run AWS CIS benchmark\ncis_benchmark(provider=\"aws\")\n```\n\n## Privacy & Data Handling\n\n**OWASP, NIST, EU AI Act, MITRE ATLAS, AISVS, SBOM generation, and policy\nchecks** run entirely locally on scan data already in memory. No network calls,\nno credentials needed for these features.\n\n**CIS benchmark checks** (optional, user-initiated) call cloud provider APIs\nusing your locally configured credentials. These are read-only API calls to\nAWS, Azure, GCP, or Snowflake. You must explicitly run `cis_benchmark(provider=...)`\nand confirm before any cloud API calls are made.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.107.2:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-compliance\",\n  \"version\": \"0.107.2\",\n  \"publishedAt\": 1790897536294\n}\n\nFile v0.107.2:skill-card.md\n\n## Description:\n\nEvaluates AI infrastructure scans against security and compliance frameworks, checks policy rules, and generates SBOMs and compliance reports.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nApache-2.0\n\n## Use Case:\n\nDevelopers and security teams use this skill to evaluate scan results against AI security and compliance frameworks, enforce policies, and generate SBOMs or compliance reports. Optional CIS checks assess configured cloud accounts when explicitly requested.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Optional CIS checks access cloud account data using locally configured credentials.\n\nMitigation: Run cloud benchmarks only when intended, confirm the target account, and use appropriately scoped credentials.\n\nRisk: Compliance reports may be mistaken for a complete certification assessment.\n\nMitigation: Review findings and framework coverage with a qualified compliance owner before relying on them for decisions.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/msaad00/skills/agent-bom-compliance)\n- [agent-bom project homepage](https://github.com/msaad00/agent-bom)\n- [agent-bom on PyPI](https://pypi.org/project/agent-bom/)\n- [OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Analysis, Guidance, Markdown, JSON, Shell commands]\n\n**Output Format:** [Text or Markdown reports; JSON or SARIF findings; CycloneDX or SPDX SBOMs]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Optional cloud benchmark results require an explicitly requested check.]\n\n## Skill Version(s):\n\n0.107.2 (source: skill frontmatter and ClawHub release)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.107.0: 3 files, 4484 bytes\n\nFiles: skill-card.md (1846b), SKILL.md (7934b), _meta.json (141b)\n\nFile v0.107.0:SKILL.md\n\n---\nname: agent-bom-compliance\ndescription: >-\n  AI compliance and policy engine — evaluate scan results against OWASP, NIST,\n  SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.\n  Generate SBOMs and compliance reports. Use when:\n  \"compliance report\", \"NIST\", \"SOC 2\", \"ISO 27001\", \"OWASP\", \"EU AI Act\",\n  \"AISVS\", \"generate SBOM\", \"policy check\".\nversion: 0.107.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. OWASP/NIST/EU AI Act/MITRE\n  evaluation and SBOM generation are fully local with zero credentials. CIS\n  benchmark checks optionally use cloud SDK credentials (AWS/Azure/GCP/Snowflake)\n  and make read-only API calls to cloud providers when explicitly invoked.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.107.0\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required for OWASP/NIST/EU AI Act compliance and SBOM generation. CIS benchmark checks (AWS, Azure, GCP, Snowflake) optionally accept cloud credentials — only used locally to call cloud APIs, never transmitted elsewhere.\"\n    credential_handling: \"Use only operator-configured cloud SDK credentials for explicitly requested CIS checks. Do not ask users to paste secrets, and never print cloud tokens, private keys, passwords, or connection strings.\"\n    optional_env:\n      - name: AWS_PROFILE\n        purpose: \"AWS CIS benchmark checks — uses boto3 with your local AWS profile\"\n        required: false\n      - name: AZURE_TENANT_ID\n        purpose: \"Azure CIS benchmark checks (azure-mgmt-* SDK)\"\n        required: false\n      - name: AZURE_CLIENT_ID\n        purpose: \"Azure CIS benchmark checks — service principal client ID\"\n        required: false\n      - name: AZURE_CLIENT_SECRET\n        purpose: \"Azure CIS benchmark checks — service principal secret\"\n        required: false\n      - name: GOOGLE_APPLICATION_CREDENTIALS\n        purpose: \"GCP CIS benchmark checks (google-cloud-* SDK)\"\n        required: false\n      - name: SNOWFLAKE_ACCOUNT\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_USER\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_PRIVATE_KEY_PATH\n        purpose: \"Snowflake key-pair auth (CI/CD)\"\n        required: false\n      - name: SNOWFLAKE_AUTHENTICATOR\n        purpose: \"Snowflake auth method (default: externalbrowser SSO)\"\n        required: false\n    optional_bins: []\n    emoji: \"\\U00002705\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: >-\n      OWASP/NIST/EU AI Act/MITRE/SBOM evaluation is purely local — zero network\n      calls. CIS benchmark checks (optional, user-initiated) call cloud provider\n      APIs (AWS/Azure/GCP/Snowflake) using locally configured credentials. No data\n      is stored or transmitted beyond the cloud provider's own API. File reads are\n      limited to user-provided SBOMs and policy files.\n    file_reads:\n      - \"user-provided SBOM files (CycloneDX/SPDX JSON)\"\n      - \"user-provided policy files (YAML/JSON policy-as-code)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://*.amazonaws.com\"\n        purpose: \"AWS CIS benchmark checks — read-only API calls (IAM, S3, CloudTrail, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://management.azure.com\"\n        purpose: \"Azure CIS benchmark checks — read-only API calls (Azure Resource Manager)\"\n        auth: true\n        optional: true\n      - url: \"https://*.googleapis.com\"\n        purpose: \"GCP CIS benchmark checks — read-only API calls (Cloud Resource Manager, IAM, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake CIS benchmark checks — read-only API calls (ACCOUNT_USAGE views)\"\n        auth: true\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-compliance — AI Compliance & Policy Engine\n\nEvaluate AI infrastructure scan results against 14 security and regulatory\nframeworks. Enforce policy-as-code rules. Generate SBOMs in standard formats.\nRun AISVS v1.0 and CIS benchmark checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom scan --compliance --compliance-export nist-ai-rmf\nagent-bom scan -f cyclonedx -o sbom.json\n```\n\n## When to Use\n\n- \"compliance report\" / \"run compliance\"\n- \"NIST\" / \"NIST AI RMF\" / \"NIST CSF\" / \"NIST 800-53\"\n- \"SOC 2\" / \"SOC2\"\n- \"ISO 27001\"\n- \"OWASP\" / \"OWASP LLM Top 10\" / \"OWASP Agentic Top 10\"\n- \"EU AI Act\"\n- \"AISVS\" / \"AI Security Verification Standard\"\n- \"CMMC\" / \"FedRAMP\"\n- \"generate SBOM\" / \"CycloneDX\" / \"SPDX\"\n- \"policy check\" / \"policy enforcement\"\n\n## Tools (5)\n\n| Tool | Description |\n|------|-------------|\n| `compliance` | OWASP LLM/Agentic Top 10, EU AI Act, MITRE ATLAS, NIST AI RMF |\n| `policy_check` | Evaluate results against custom security policy (17 conditions) |\n| `cis_benchmark` | Run CIS benchmark checks against cloud accounts |\n| `generate_sbom` | Generate SBOM (CycloneDX or SPDX format) |\n| `aisvs_benchmark` | OWASP AISVS v1.0 compliance — 9 AI security checks |\n\n## Supported Frameworks (15)\n\n- **OWASP LLM Top 10** (2025) — prompt injection, supply chain, data leakage\n- **OWASP MCP Top 10** — MCP-specific security risks\n- **OWASP Agentic Top 10** — tool poisoning, rug pulls, credential theft\n- **MITRE ATLAS** — adversarial ML threat framework\n- **MITRE ATT&CK Enterprise** — adversary techniques tagged via CWE → CAPEC → ATT&CK on every blast-radius finding\n- **NIST AI RMF** — govern, map, measure, manage lifecycle\n- **NIST CSF 2.0** — identify, protect, detect, respond, recover\n- **NIST 800-53 Rev 5** — federal security controls (CM-8, RA-5, SI-2, SR-3)\n- **FedRAMP Moderate** — derived from NIST 800-53 controls\n- **EU AI Act** — risk classification, transparency, SBOM requirements\n- **ISO 27001:2022** — information security controls (Annex A)\n- **SOC 2** — Trust Services Criteria\n- **CIS Controls v8** — implementation groups IG1/IG2/IG3\n- **CMMC 2.0** — cybersecurity maturity model (Level 1-3)\n- **PCI DSS v4.0** — payment-card data security requirements\n\nOWASP AISVS v1.0 ships as a **benchmark surface** alongside the tag-mapped frameworks (9 verification checks).\n\n## Examples\n\n```\n# Run compliance check against multiple frameworks\ncompliance(frameworks=[\"owasp_llm\", \"eu_ai_act\", \"nist_ai_rmf\"])\n\n# Enforce custom policy\npolicy_check(policy={\"max_critical\": 0, \"max_high\": 5})\n\n# Generate SBOM\ngenerate_sbom(format=\"cyclonedx\")\n\n# Run AISVS v1.0 compliance\naisvs_benchmark()\n\n# Run AWS CIS benchmark\ncis_benchmark(provider=\"aws\")\n```\n\n## Privacy & Data Handling\n\n**OWASP, NIST, EU AI Act, MITRE ATLAS, AISVS, SBOM generation, and policy\nchecks** run entirely locally on scan data already in memory. No network calls,\nno credentials needed for these features.\n\n**CIS benchmark checks** (optional, user-initiated) call cloud provider APIs\nusing your locally configured credentials. These are read-only API calls to\nAWS, Azure, GCP, or Snowflake. You must explicitly run `cis_benchmark(provider=...)`\nand confirm before any cloud API calls are made.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.107.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-compliance\",\n  \"version\": \"0.107.0\",\n  \"publishedAt\": 1790799472805\n}\n\nFile v0.107.0:skill-card.md\n\n## Description:\n\nEvaluates AI infrastructure scan results against security and regulatory frameworks, checks policies, and generates compliance reports and SBOMs.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security teams use this skill to assess AI infrastructure scan results against compliance frameworks, enforce policies, and generate SBOMs. Optional CIS checks assess selected cloud accounts.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Optional CIS checks contact cloud providers using locally configured credentials.\n\nMitigation: Run cloud checks only with explicit confirmation against accounts you intend to assess.\n\n## Reference(s):\n\n- [Agent-BOM project homepage (skill metadata; import provenance unavailable)](https://github.com/msaad00/agent-bom)\n- [Agent-BOM on PyPI](https://pypi.org/project/agent-bom/)\n- [Agent-BOM OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n- [ClawHub skill listing](https://clawhub.ai/msaad00/skills/agent-bom-compliance)\n\n## Skill Output:\n\n**Output Type(s):** [Compliance reports, Policy findings, SBOMs, Shell commands]\n\n**Output Format:** [Markdown guidance and reports; CycloneDX or SPDX JSON SBOMs]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Cloud CIS checks are optional and require explicit confirmation.]\n\n## Skill Version(s):\n\n0.107.0 (source: server release and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.106.1: 3 files, 4561 bytes\n\nFiles: skill-card.md (1984b), SKILL.md (7934b), _meta.json (141b)\n\nFile v0.106.1:SKILL.md\n\n---\nname: agent-bom-compliance\ndescription: >-\n  AI compliance and policy engine — evaluate scan results against OWASP, NIST,\n  SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.\n  Generate SBOMs and compliance reports. Use when:\n  \"compliance report\", \"NIST\", \"SOC 2\", \"ISO 27001\", \"OWASP\", \"EU AI Act\",\n  \"AISVS\", \"generate SBOM\", \"policy check\".\nversion: 0.106.1\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. OWASP/NIST/EU AI Act/MITRE\n  evaluation and SBOM generation are fully local with zero credentials. CIS\n  benchmark checks optionally use cloud SDK credentials (AWS/Azure/GCP/Snowflake)\n  and make read-only API calls to cloud providers when explicitly invoked.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.106.1\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required for OWASP/NIST/EU AI Act compliance and SBOM generation. CIS benchmark checks (AWS, Azure, GCP, Snowflake) optionally accept cloud credentials — only used locally to call cloud APIs, never transmitted elsewhere.\"\n    credential_handling: \"Use only operator-configured cloud SDK credentials for explicitly requested CIS checks. Do not ask users to paste secrets, and never print cloud tokens, private keys, passwords, or connection strings.\"\n    optional_env:\n      - name: AWS_PROFILE\n        purpose: \"AWS CIS benchmark checks — uses boto3 with your local AWS profile\"\n        required: false\n      - name: AZURE_TENANT_ID\n        purpose: \"Azure CIS benchmark checks (azure-mgmt-* SDK)\"\n        required: false\n      - name: AZURE_CLIENT_ID\n        purpose: \"Azure CIS benchmark checks — service principal client ID\"\n        required: false\n      - name: AZURE_CLIENT_SECRET\n        purpose: \"Azure CIS benchmark checks — service principal secret\"\n        required: false\n      - name: GOOGLE_APPLICATION_CREDENTIALS\n        purpose: \"GCP CIS benchmark checks (google-cloud-* SDK)\"\n        required: false\n      - name: SNOWFLAKE_ACCOUNT\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_USER\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_PRIVATE_KEY_PATH\n        purpose: \"Snowflake key-pair auth (CI/CD)\"\n        required: false\n      - name: SNOWFLAKE_AUTHENTICATOR\n        purpose: \"Snowflake auth method (default: externalbrowser SSO)\"\n        required: false\n    optional_bins: []\n    emoji: \"\\U00002705\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: >-\n      OWASP/NIST/EU AI Act/MITRE/SBOM evaluation is purely local — zero network\n      calls. CIS benchmark checks (optional, user-initiated) call cloud provider\n      APIs (AWS/Azure/GCP/Snowflake) using locally configured credentials. No data\n      is stored or transmitted beyond the cloud provider's own API. File reads are\n      limited to user-provided SBOMs and policy files.\n    file_reads:\n      - \"user-provided SBOM files (CycloneDX/SPDX JSON)\"\n      - \"user-provided policy files (YAML/JSON policy-as-code)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://*.amazonaws.com\"\n        purpose: \"AWS CIS benchmark checks — read-only API calls (IAM, S3, CloudTrail, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://management.azure.com\"\n        purpose: \"Azure CIS benchmark checks — read-only API calls (Azure Resource Manager)\"\n        auth: true\n        optional: true\n      - url: \"https://*.googleapis.com\"\n        purpose: \"GCP CIS benchmark checks — read-only API calls (Cloud Resource Manager, IAM, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake CIS benchmark checks — read-only API calls (ACCOUNT_USAGE views)\"\n        auth: true\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-compliance — AI Compliance & Policy Engine\n\nEvaluate AI infrastructure scan results against 14 security and regulatory\nframeworks. Enforce policy-as-code rules. Generate SBOMs in standard formats.\nRun AISVS v1.0 and CIS benchmark checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom scan --compliance --compliance-export nist-ai-rmf\nagent-bom scan -f cyclonedx -o sbom.json\n```\n\n## When to Use\n\n- \"compliance report\" / \"run compliance\"\n- \"NIST\" / \"NIST AI RMF\" / \"NIST CSF\" / \"NIST 800-53\"\n- \"SOC 2\" / \"SOC2\"\n- \"ISO 27001\"\n- \"OWASP\" / \"OWASP LLM Top 10\" / \"OWASP Agentic Top 10\"\n- \"EU AI Act\"\n- \"AISVS\" / \"AI Security Verification Standard\"\n- \"CMMC\" / \"FedRAMP\"\n- \"generate SBOM\" / \"CycloneDX\" / \"SPDX\"\n- \"policy check\" / \"policy enforcement\"\n\n## Tools (5)\n\n| Tool | Description |\n|------|-------------|\n| `compliance` | OWASP LLM/Agentic Top 10, EU AI Act, MITRE ATLAS, NIST AI RMF |\n| `policy_check` | Evaluate results against custom security policy (17 conditions) |\n| `cis_benchmark` | Run CIS benchmark checks against cloud accounts |\n| `generate_sbom` | Generate SBOM (CycloneDX or SPDX format) |\n| `aisvs_benchmark` | OWASP AISVS v1.0 compliance — 9 AI security checks |\n\n## Supported Frameworks (15)\n\n- **OWASP LLM Top 10** (2025) — prompt injection, supply chain, data leakage\n- **OWASP MCP Top 10** — MCP-specific security risks\n- **OWASP Agentic Top 10** — tool poisoning, rug pulls, credential theft\n- **MITRE ATLAS** — adversarial ML threat framework\n- **MITRE ATT&CK Enterprise** — adversary techniques tagged via CWE → CAPEC → ATT&CK on every blast-radius finding\n- **NIST AI RMF** — govern, map, measure, manage lifecycle\n- **NIST CSF 2.0** — identify, protect, detect, respond, recover\n- **NIST 800-53 Rev 5** — federal security controls (CM-8, RA-5, SI-2, SR-3)\n- **FedRAMP Moderate** — derived from NIST 800-53 controls\n- **EU AI Act** — risk classification, transparency, SBOM requirements\n- **ISO 27001:2022** — information security controls (Annex A)\n- **SOC 2** — Trust Services Criteria\n- **CIS Controls v8** — implementation groups IG1/IG2/IG3\n- **CMMC 2.0** — cybersecurity maturity model (Level 1-3)\n- **PCI DSS v4.0** — payment-card data security requirements\n\nOWASP AISVS v1.0 ships as a **benchmark surface** alongside the tag-mapped frameworks (9 verification checks).\n\n## Examples\n\n```\n# Run compliance check against multiple frameworks\ncompliance(frameworks=[\"owasp_llm\", \"eu_ai_act\", \"nist_ai_rmf\"])\n\n# Enforce custom policy\npolicy_check(policy={\"max_critical\": 0, \"max_high\": 5})\n\n# Generate SBOM\ngenerate_sbom(format=\"cyclonedx\")\n\n# Run AISVS v1.0 compliance\naisvs_benchmark()\n\n# Run AWS CIS benchmark\ncis_benchmark(provider=\"aws\")\n```\n\n## Privacy & Data Handling\n\n**OWASP, NIST, EU AI Act, MITRE ATLAS, AISVS, SBOM generation, and policy\nchecks** run entirely locally on scan data already in memory. No network calls,\nno credentials needed for these features.\n\n**CIS benchmark checks** (optional, user-initiated) call cloud provider APIs\nusing your locally configured credentials. These are read-only API calls to\nAWS, Azure, GCP, or Snowflake. You must explicitly run `cis_benchmark(provider=...)`\nand confirm before any cloud API calls are made.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.106.1:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-compliance\",\n  \"version\": \"0.106.1\",\n  \"publishedAt\": 1790468297729\n}\n\nFile v0.106.1:skill-card.md\n\n## Description:\n\nEvaluates AI infrastructure scan results against security and regulatory frameworks, applies policy checks, and generates compliance reports and SBOMs.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security teams use this skill to review AI infrastructure findings against compliance frameworks, enforce policies, and produce software bills of materials.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Installing an untrusted package or source could expose the operator's environment.\n\nMitigation: Verify the package and publisher before installing.\n\nRisk: Optional CIS checks access cloud-account settings using configured credentials.\n\nMitigation: Confirm each cloud check, use least-privilege read-only profiles, and never share secrets in chat.\n\n## Reference(s):\n\n- [ClawHub skill release](https://clawhub.ai/msaad00/skills/agent-bom-compliance)\n- [Publisher-listed project page](https://github.com/msaad00/agent-bom)\n- [Publisher-listed PyPI package](https://pypi.org/project/agent-bom/)\n- [Publisher-listed security scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Analysis, JSON, Shell commands, Guidance]\n\n**Output Format:** [Markdown guidance and command examples; compliance reports and CycloneDX or SPDX SBOMs]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Cloud benchmark checks are optional and require explicit confirmation.]\n\n## Skill Version(s):\n\n0.106.1 (source: ClawHub release metadata and SKILL.md frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.105.0: 3 files, 4737 bytes\n\nFiles: skill-card.md (2328b), SKILL.md (7934b), _meta.json (141b)\n\nFile v0.105.0:SKILL.md\n\n---\nname: agent-bom-compliance\ndescription: >-\n  AI compliance and policy engine — evaluate scan results against OWASP, NIST,\n  SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.\n  Generate SBOMs and compliance reports. Use when:\n  \"compliance report\", \"NIST\", \"SOC 2\", \"ISO 27001\", \"OWASP\", \"EU AI Act\",\n  \"AISVS\", \"generate SBOM\", \"policy check\".\nversion: 0.105.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. OWASP/NIST/EU AI Act/MITRE\n  evaluation and SBOM generation are fully local with zero credentials. CIS\n  benchmark checks optionally use cloud SDK credentials (AWS/Azure/GCP/Snowflake)\n  and make read-only API calls to cloud providers when explicitly invoked.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.105.0\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required for OWASP/NIST/EU AI Act compliance and SBOM generation. CIS benchmark checks (AWS, Azure, GCP, Snowflake) optionally accept cloud credentials — only used locally to call cloud APIs, never transmitted elsewhere.\"\n    credential_handling: \"Use only operator-configured cloud SDK credentials for explicitly requested CIS checks. Do not ask users to paste secrets, and never print cloud tokens, private keys, passwords, or connection strings.\"\n    optional_env:\n      - name: AWS_PROFILE\n        purpose: \"AWS CIS benchmark checks — uses boto3 with your local AWS profile\"\n        required: false\n      - name: AZURE_TENANT_ID\n        purpose: \"Azure CIS benchmark checks (azure-mgmt-* SDK)\"\n        required: false\n      - name: AZURE_CLIENT_ID\n        purpose: \"Azure CIS benchmark checks — service principal client ID\"\n        required: false\n      - name: AZURE_CLIENT_SECRET\n        purpose: \"Azure CIS benchmark checks — service principal secret\"\n        required: false\n      - name: GOOGLE_APPLICATION_CREDENTIALS\n        purpose: \"GCP CIS benchmark checks (google-cloud-* SDK)\"\n        required: false\n      - name: SNOWFLAKE_ACCOUNT\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_USER\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_PRIVATE_KEY_PATH\n        purpose: \"Snowflake key-pair auth (CI/CD)\"\n        required: false\n      - name: SNOWFLAKE_AUTHENTICATOR\n        purpose: \"Snowflake auth method (default: externalbrowser SSO)\"\n        required: false\n    optional_bins: []\n    emoji: \"\\U00002705\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: >-\n      OWASP/NIST/EU AI Act/MITRE/SBOM evaluation is purely local — zero network\n      calls. CIS benchmark checks (optional, user-initiated) call cloud provider\n      APIs (AWS/Azure/GCP/Snowflake) using locally configured credentials. No data\n      is stored or transmitted beyond the cloud provider's own API. File reads are\n      limited to user-provided SBOMs and policy files.\n    file_reads:\n      - \"user-provided SBOM files (CycloneDX/SPDX JSON)\"\n      - \"user-provided policy files (YAML/JSON policy-as-code)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://*.amazonaws.com\"\n        purpose: \"AWS CIS benchmark checks — read-only API calls (IAM, S3, CloudTrail, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://management.azure.com\"\n        purpose: \"Azure CIS benchmark checks — read-only API calls (Azure Resource Manager)\"\n        auth: true\n        optional: true\n      - url: \"https://*.googleapis.com\"\n        purpose: \"GCP CIS benchmark checks — read-only API calls (Cloud Resource Manager, IAM, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake CIS benchmark checks — read-only API calls (ACCOUNT_USAGE views)\"\n        auth: true\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-compliance — AI Compliance & Policy Engine\n\nEvaluate AI infrastructure scan results against 14 security and regulatory\nframeworks. Enforce policy-as-code rules. Generate SBOMs in standard formats.\nRun AISVS v1.0 and CIS benchmark checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom scan --compliance --compliance-export nist-ai-rmf\nagent-bom scan -f cyclonedx -o sbom.json\n```\n\n## When to Use\n\n- \"compliance report\" / \"run compliance\"\n- \"NIST\" / \"NIST AI RMF\" / \"NIST CSF\" / \"NIST 800-53\"\n- \"SOC 2\" / \"SOC2\"\n- \"ISO 27001\"\n- \"OWASP\" / \"OWASP LLM Top 10\" / \"OWASP Agentic Top 10\"\n- \"EU AI Act\"\n- \"AISVS\" / \"AI Security Verification Standard\"\n- \"CMMC\" / \"FedRAMP\"\n- \"generate SBOM\" / \"CycloneDX\" / \"SPDX\"\n- \"policy check\" / \"policy enforcement\"\n\n## Tools (5)\n\n| Tool | Description |\n|------|-------------|\n| `compliance` | OWASP LLM/Agentic Top 10, EU AI Act, MITRE ATLAS, NIST AI RMF |\n| `policy_check` | Evaluate results against custom security policy (17 conditions) |\n| `cis_benchmark` | Run CIS benchmark checks against cloud accounts |\n| `generate_sbom` | Generate SBOM (CycloneDX or SPDX format) |\n| `aisvs_benchmark` | OWASP AISVS v1.0 compliance — 9 AI security checks |\n\n## Supported Frameworks (15)\n\n- **OWASP LLM Top 10** (2025) — prompt injection, supply chain, data leakage\n- **OWASP MCP Top 10** — MCP-specific security risks\n- **OWASP Agentic Top 10** — tool poisoning, rug pulls, credential theft\n- **MITRE ATLAS** — adversarial ML threat framework\n- **MITRE ATT&CK Enterprise** — adversary techniques tagged via CWE → CAPEC → ATT&CK on every blast-radius finding\n- **NIST AI RMF** — govern, map, measure, manage lifecycle\n- **NIST CSF 2.0** — identify, protect, detect, respond, recover\n- **NIST 800-53 Rev 5** — federal security controls (CM-8, RA-5, SI-2, SR-3)\n- **FedRAMP Moderate** — derived from NIST 800-53 controls\n- **EU AI Act** — risk classification, transparency, SBOM requirements\n- **ISO 27001:2022** — information security controls (Annex A)\n- **SOC 2** — Trust Services Criteria\n- **CIS Controls v8** — implementation groups IG1/IG2/IG3\n- **CMMC 2.0** — cybersecurity maturity model (Level 1-3)\n- **PCI DSS v4.0** — payment-card data security requirements\n\nOWASP AISVS v1.0 ships as a **benchmark surface** alongside the tag-mapped frameworks (9 verification checks).\n\n## Examples\n\n```\n# Run compliance check against multiple frameworks\ncompliance(frameworks=[\"owasp_llm\", \"eu_ai_act\", \"nist_ai_rmf\"])\n\n# Enforce custom policy\npolicy_check(policy={\"max_critical\": 0, \"max_high\": 5})\n\n# Generate SBOM\ngenerate_sbom(format=\"cyclonedx\")\n\n# Run AISVS v1.0 compliance\naisvs_benchmark()\n\n# Run AWS CIS benchmark\ncis_benchmark(provider=\"aws\")\n```\n\n## Privacy & Data Handling\n\n**OWASP, NIST, EU AI Act, MITRE ATLAS, AISVS, SBOM generation, and policy\nchecks** run entirely locally on scan data already in memory. No network calls,\nno credentials needed for these features.\n\n**CIS benchmark checks** (optional, user-initiated) call cloud provider APIs\nusing your locally configured credentials. These are read-only API calls to\nAWS, Azure, GCP, or Snowflake. You must explicitly run `cis_benchmark(provider=...)`\nand confirm before any cloud API calls are made.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.105.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-compliance\",\n  \"version\": \"0.105.0\",\n  \"publishedAt\": 1789729884856\n}\n\nFile v0.105.0:skill-card.md\n\n## Description:\n\nAI compliance and policy engine that evaluates scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks, and generates SBOMs and compliance reports.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nApache-2.0\n\n## Use Case:\n\nDevelopers, security engineers, and compliance teams use this skill to evaluate AI infrastructure or scan results against common security and regulatory frameworks, generate SBOMs, enforce policy checks, and run explicitly requested CIS benchmark checks.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Optional CIS benchmark checks can read cloud account configuration through locally configured AWS, Azure, GCP, or Snowflake credentials.\n\nMitigation: Run CIS checks only for accounts and profiles intentionally selected for assessment, and use least-privilege read-only credentials where practical.\n\nRisk: Compliance and SBOM findings may be incomplete or context-dependent for formal audit decisions.\n\nMitigation: Review generated reports with qualified security or compliance staff before using them as authoritative evidence.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/msaad00/skills/agent-bom-compliance)\n- [Project homepage](https://github.com/msaad00/agent-bom)\n- [PyPI package](https://pypi.org/project/agent-bom/)\n- [OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Code, Shell commands, Configuration, Guidance, Files]\n\n**Output Format:** [Markdown guidance with command examples, structured compliance findings, SBOM output, and configuration snippets]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May produce CycloneDX or SPDX SBOM files and compliance reports when the underlying agent-bom commands are invoked.]\n\n## Skill Version(s):\n\n0.105.0 (source: frontmatter and release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.104.0: 3 files, 4818 bytes\n\nFiles: skill-card.md (2595b), SKILL.md (7934b), _meta.json (141b)\n\nFile v0.104.0:SKILL.md\n\n---\nname: agent-bom-compliance\ndescription: >-\n  AI compliance and policy engine — evaluate scan results against OWASP, NIST,\n  SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.\n  Generate SBOMs and compliance reports. Use when:\n  \"compliance report\", \"NIST\", \"SOC 2\", \"ISO 27001\", \"OWASP\", \"EU AI Act\",\n  \"AISVS\", \"generate SBOM\", \"policy check\".\nversion: 0.104.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. OWASP/NIST/EU AI Act/MITRE\n  evaluation and SBOM generation are fully local with zero credentials. CIS\n  benchmark checks optionally use cloud SDK credentials (AWS/Azure/GCP/Snowflake)\n  and make read-only API calls to cloud providers when explicitly invoked.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.104.0\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required for OWASP/NIST/EU AI Act compliance and SBOM generation. CIS benchmark checks (AWS, Azure, GCP, Snowflake) optionally accept cloud credentials — only used locally to call cloud APIs, never transmitted elsewhere.\"\n    credential_handling: \"Use only operator-configured cloud SDK credentials for explicitly requested CIS checks. Do not ask users to paste secrets, and never print cloud tokens, private keys, passwords, or connection strings.\"\n    optional_env:\n      - name: AWS_PROFILE\n        purpose: \"AWS CIS benchmark checks — uses boto3 with your local AWS profile\"\n        required: false\n      - name: AZURE_TENANT_ID\n        purpose: \"Azure CIS benchmark checks (azure-mgmt-* SDK)\"\n        required: false\n      - name: AZURE_CLIENT_ID\n        purpose: \"Azure CIS benchmark checks — service principal client ID\"\n        required: false\n      - name: AZURE_CLIENT_SECRET\n        purpose: \"Azure CIS benchmark checks — service principal secret\"\n        required: false\n      - name: GOOGLE_APPLICATION_CREDENTIALS\n        purpose: \"GCP CIS benchmark checks (google-cloud-* SDK)\"\n        required: false\n      - name: SNOWFLAKE_ACCOUNT\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_USER\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_PRIVATE_KEY_PATH\n        purpose: \"Snowflake key-pair auth (CI/CD)\"\n        required: false\n      - name: SNOWFLAKE_AUTHENTICATOR\n        purpose: \"Snowflake auth method (default: externalbrowser SSO)\"\n        required: false\n    optional_bins: []\n    emoji: \"\\U00002705\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: >-\n      OWASP/NIST/EU AI Act/MITRE/SBOM evaluation is purely local — zero network\n      calls. CIS benchmark checks (optional, user-initiated) call cloud provider\n      APIs (AWS/Azure/GCP/Snowflake) using locally configured credentials. No data\n      is stored or transmitted beyond the cloud provider's own API. File reads are\n      limited to user-provided SBOMs and policy files.\n    file_reads:\n      - \"user-provided SBOM files (CycloneDX/SPDX JSON)\"\n      - \"user-provided policy files (YAML/JSON policy-as-code)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://*.amazonaws.com\"\n        purpose: \"AWS CIS benchmark checks — read-only API calls (IAM, S3, CloudTrail, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://management.azure.com\"\n        purpose: \"Azure CIS benchmark checks — read-only API calls (Azure Resource Manager)\"\n        auth: true\n        optional: true\n      - url: \"https://*.googleapis.com\"\n        purpose: \"GCP CIS benchmark checks — read-only API calls (Cloud Resource Manager, IAM, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake CIS benchmark checks — read-only API calls (ACCOUNT_USAGE views)\"\n        auth: true\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-compliance — AI Compliance & Policy Engine\n\nEvaluate AI infrastructure scan results against 14 security and regulatory\nframeworks. Enforce policy-as-code rules. Generate SBOMs in standard formats.\nRun AISVS v1.0 and CIS benchmark checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom scan --compliance --compliance-export nist-ai-rmf\nagent-bom scan -f cyclonedx -o sbom.json\n```\n\n## When to Use\n\n- \"compliance report\" / \"run compliance\"\n- \"NIST\" / \"NIST AI RMF\" / \"NIST CSF\" / \"NIST 800-53\"\n- \"SOC 2\" / \"SOC2\"\n- \"ISO 27001\"\n- \"OWASP\" / \"OWASP LLM Top 10\" / \"OWASP Agentic Top 10\"\n- \"EU AI Act\"\n- \"AISVS\" / \"AI Security Verification Standard\"\n- \"CMMC\" / \"FedRAMP\"\n- \"generate SBOM\" / \"CycloneDX\" / \"SPDX\"\n- \"policy check\" / \"policy enforcement\"\n\n## Tools (5)\n\n| Tool | Description |\n|------|-------------|\n| `compliance` | OWASP LLM/Agentic Top 10, EU AI Act, MITRE ATLAS, NIST AI RMF |\n| `policy_check` | Evaluate results against custom security policy (17 conditions) |\n| `cis_benchmark` | Run CIS benchmark checks against cloud accounts |\n| `generate_sbom` | Generate SBOM (CycloneDX or SPDX format) |\n| `aisvs_benchmark` | OWASP AISVS v1.0 compliance — 9 AI security checks |\n\n## Supported Frameworks (15)\n\n- **OWASP LLM Top 10** (2025) — prompt injection, supply chain, data leakage\n- **OWASP MCP Top 10** — MCP-specific security risks\n- **OWASP Agentic Top 10** — tool poisoning, rug pulls, credential theft\n- **MITRE ATLAS** — adversarial ML threat framework\n- **MITRE ATT&CK Enterprise** — adversary techniques tagged via CWE → CAPEC → ATT&CK on every blast-radius finding\n- **NIST AI RMF** — govern, map, measure, manage lifecycle\n- **NIST CSF 2.0** — identify, protect, detect, respond, recover\n- **NIST 800-53 Rev 5** — federal security controls (CM-8, RA-5, SI-2, SR-3)\n- **FedRAMP Moderate** — derived from NIST 800-53 controls\n- **EU AI Act** — risk classification, transparency, SBOM requirements\n- **ISO 27001:2022** — information security controls (Annex A)\n- **SOC 2** — Trust Services Criteria\n- **CIS Controls v8** — implementation groups IG1/IG2/IG3\n- **CMMC 2.0** — cybersecurity maturity model (Level 1-3)\n- **PCI DSS v4.0** — payment-card data security requirements\n\nOWASP AISVS v1.0 ships as a **benchmark surface** alongside the tag-mapped frameworks (9 verification checks).\n\n## Examples\n\n```\n# Run compliance check against multiple frameworks\ncompliance(frameworks=[\"owasp_llm\", \"eu_ai_act\", \"nist_ai_rmf\"])\n\n# Enforce custom policy\npolicy_check(policy={\"max_critical\": 0, \"max_high\": 5})\n\n# Generate SBOM\ngenerate_sbom(format=\"cyclonedx\")\n\n# Run AISVS v1.0 compliance\naisvs_benchmark()\n\n# Run AWS CIS benchmark\ncis_benchmark(provider=\"aws\")\n```\n\n## Privacy & Data Handling\n\n**OWASP, NIST, EU AI Act, MITRE ATLAS, AISVS, SBOM generation, and policy\nchecks** run entirely locally on scan data already in memory. No network calls,\nno credentials needed for these features.\n\n**CIS benchmark checks** (optional, user-initiated) call cloud provider APIs\nusing your locally configured credentials. These are read-only API calls to\nAWS, Azure, GCP, or Snowflake. You must explicitly run `cis_benchmark(provider=...)`\nand confirm before any cloud API calls are made.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.104.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-compliance\",\n  \"version\": \"0.104.0\",\n  \"publishedAt\": 1788987356367\n}\n\nFile v0.104.0:skill-card.md\n\n## Description:\n\nAgent-bom compliance helps agents evaluate AI infrastructure scan results against security and regulatory frameworks, enforce policy rules, generate SBOMs, and produce compliance reports.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nApache-2.0\n\n## Use Case:\n\nDevelopers, security engineers, and compliance teams use this skill to turn AI infrastructure scan results, SBOMs, and policy files into compliance checks and reports across OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS, and related frameworks. It also supports explicit, optional read-only CIS benchmark checks for cloud accounts.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Unpinned package installation can resolve to a different release over time.\n\nMitigation: Install a pinned version such as agent-bom==0.104.0 or use reviewed source before deploying the skill.\n\nRisk: Optional CIS benchmark checks use cloud SDK credentials and call provider APIs.\n\nMitigation: Run CIS checks only when explicitly requested, use least-privilege credentials, and verify the provider and account before execution.\n\nRisk: User-provided SBOMs and policy files may contain sensitive inventory or control information.\n\nMitigation: Run the skill in a controlled workspace and review generated reports before sharing them outside the intended audience.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/msaad00/skills/agent-bom-compliance)\n- [agent-bom project homepage](https://github.com/msaad00/agent-bom)\n- [agent-bom on PyPI](https://pypi.org/project/agent-bom/)\n- [OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance, JSON files]\n\n**Output Format:** [Markdown or text guidance with command examples; generated SBOM and compliance outputs may use CycloneDX, SPDX, or framework-specific report formats.]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Optional CIS checks use locally configured cloud credentials and read-only provider API calls only when explicitly invoked.]\n\n## Skill Version(s):\n\n0.104.0 (source: frontmatter and release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.103.2: 3 files, 4698 bytes\n\nFiles: skill-card.md (2315b), SKILL.md (7934b), _meta.json (141b)\n\nFile v0.103.2:SKILL.md\n\n---\nname: agent-bom-compliance\ndescription: >-\n  AI compliance and policy engine — evaluate scan results against OWASP, NIST,\n  SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.\n  Generate SBOMs and compliance reports. Use when:\n  \"compliance report\", \"NIST\", \"SOC 2\", \"ISO 27001\", \"OWASP\", \"EU AI Act\",\n  \"AISVS\", \"generate SBOM\", \"policy check\".\nversion: 0.103.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. OWASP/NIST/EU AI Act/MITRE\n  evaluation and SBOM generation are fully local with zero credentials. CIS\n  benchmark checks optionally use cloud SDK credentials (AWS/Azure/GCP/Snowflake)\n  and make read-only API calls to cloud providers when explicitly invoked.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.103.2\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required for OWASP/NIST/EU AI Act compliance and SBOM generation. CIS benchmark checks (AWS, Azure, GCP, Snowflake) optionally accept cloud credentials — only used locally to call cloud APIs, never transmitted elsewhere.\"\n    credential_handling: \"Use only operator-configured cloud SDK credentials for explicitly requested CIS checks. Do not ask users to paste secrets, and never print cloud tokens, private keys, passwords, or connection strings.\"\n    optional_env:\n      - name: AWS_PROFILE\n        purpose: \"AWS CIS benchmark checks — uses boto3 with your local AWS profile\"\n        required: false\n      - name: AZURE_TENANT_ID\n        purpose: \"Azure CIS benchmark checks (azure-mgmt-* SDK)\"\n        required: false\n      - name: AZURE_CLIENT_ID\n        purpose: \"Azure CIS benchmark checks — service principal client ID\"\n        required: false\n      - name: AZURE_CLIENT_SECRET\n        purpose: \"Azure CIS benchmark checks — service principal secret\"\n        required: false\n      - name: GOOGLE_APPLICATION_CREDENTIALS\n        purpose: \"GCP CIS benchmark checks (google-cloud-* SDK)\"\n        required: false\n      - name: SNOWFLAKE_ACCOUNT\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_USER\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_PRIVATE_KEY_PATH\n        purpose: \"Snowflake key-pair auth (CI/CD)\"\n        required: false\n      - name: SNOWFLAKE_AUTHENTICATOR\n        purpose: \"Snowflake auth method (default: externalbrowser SSO)\"\n        required: false\n    optional_bins: []\n    emoji: \"\\U00002705\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: >-\n      OWASP/NIST/EU AI Act/MITRE/SBOM evaluation is purely local — zero network\n      calls. CIS benchmark checks (optional, user-initiated) call cloud provider\n      APIs (AWS/Azure/GCP/Snowflake) using locally configured credentials. No data\n      is stored or transmitted beyond the cloud provider's own API. File reads are\n      limited to user-provided SBOMs and policy files.\n    file_reads:\n      - \"user-provided SBOM files (CycloneDX/SPDX JSON)\"\n      - \"user-provided policy files (YAML/JSON policy-as-code)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://*.amazonaws.com\"\n        purpose: \"AWS CIS benchmark checks — read-only API calls (IAM, S3, CloudTrail, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://management.azure.com\"\n        purpose: \"Azure CIS benchmark checks — read-only API calls (Azure Resource Manager)\"\n        auth: true\n        optional: true\n      - url: \"https://*.googleapis.com\"\n        purpose: \"GCP CIS benchmark checks — read-only API calls (Cloud Resource Manager, IAM, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake CIS benchmark checks — read-only API calls (ACCOUNT_USAGE views)\"\n        auth: true\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-compliance — AI Compliance & Policy Engine\n\nEvaluate AI infrastructure scan results against 14 security and regulatory\nframeworks. Enforce policy-as-code rules. Generate SBOMs in standard formats.\nRun AISVS v1.0 and CIS benchmark checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom scan --compliance --compliance-export nist-ai-rmf\nagent-bom scan -f cyclonedx -o sbom.json\n```\n\n## When to Use\n\n- \"compliance report\" / \"run compliance\"\n- \"NIST\" / \"NIST AI RMF\" / \"NIST CSF\" / \"NIST 800-53\"\n- \"SOC 2\" / \"SOC2\"\n- \"ISO 27001\"\n- \"OWASP\" / \"OWASP LLM Top 10\" / \"OWASP Agentic Top 10\"\n- \"EU AI Act\"\n- \"AISVS\" / \"AI Security Verification Standard\"\n- \"CMMC\" / \"FedRAMP\"\n- \"generate SBOM\" / \"CycloneDX\" / \"SPDX\"\n- \"policy check\" / \"policy enforcement\"\n\n## Tools (5)\n\n| Tool | Description |\n|------|-------------|\n| `compliance` | OWASP LLM/Agentic Top 10, EU AI Act, MITRE ATLAS, NIST AI RMF |\n| `policy_check` | Evaluate results against custom security policy (17 conditions) |\n| `cis_benchmark` | Run CIS benchmark checks against cloud accounts |\n| `generate_sbom` | Generate SBOM (CycloneDX or SPDX format) |\n| `aisvs_benchmark` | OWASP AISVS v1.0 compliance — 9 AI security checks |\n\n## Supported Frameworks (15)\n\n- **OWASP LLM Top 10** (2025) — prompt injection, supply chain, data leakage\n- **OWASP MCP Top 10** — MCP-specific security risks\n- **OWASP Agentic Top 10** — tool poisoning, rug pulls, credential theft\n- **MITRE ATLAS** — adversarial ML threat framework\n- **MITRE ATT&CK Enterprise** — adversary techniques tagged via CWE → CAPEC → ATT&CK on every blast-radius finding\n- **NIST AI RMF** — govern, map, measure, manage lifecycle\n- **NIST CSF 2.0** — identify, protect, detect, respond, recover\n- **NIST 800-53 Rev 5** — federal security controls (CM-8, RA-5, SI-2, SR-3)\n- **FedRAMP Moderate** — derived from NIST 800-53 controls\n- **EU AI Act** — risk classification, transparency, SBOM requirements\n- **ISO 27001:2022** — information security controls (Annex A)\n- **SOC 2** — Trust Services Criteria\n- **CIS Controls v8** — implementation groups IG1/IG2/IG3\n- **CMMC 2.0** — cybersecurity maturity model (Level 1-3)\n- **PCI DSS v4.0** — payment-card data security requirements\n\nOWASP AISVS v1.0 ships as a **benchmark surface** alongside the tag-mapped frameworks (9 verification checks).\n\n## Examples\n\n```\n# Run compliance check against multiple frameworks\ncompliance(frameworks=[\"owasp_llm\", \"eu_ai_act\", \"nist_ai_rmf\"])\n\n# Enforce custom policy\npolicy_check(policy={\"max_critical\": 0, \"max_high\": 5})\n\n# Generate SBOM\ngenerate_sbom(format=\"cyclonedx\")\n\n# Run AISVS v1.0 compliance\naisvs_benchmark()\n\n# Run AWS CIS benchmark\ncis_benchmark(provider=\"aws\")\n```\n\n## Privacy & Data Handling\n\n**OWASP, NIST, EU AI Act, MITRE ATLAS, AISVS, SBOM generation, and policy\nchecks** run entirely locally on scan data already in memory. No network calls,\nno credentials needed for these features.\n\n**CIS benchmark checks** (optional, user-initiated) call cloud provider APIs\nusing your locally configured credentials. These are read-only API calls to\nAWS, Azure, GCP, or Snowflake. You must explicitly run `cis_benchmark(provider=...)`\nand confirm before any cloud API calls are made.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.103.2:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-compliance\",\n  \"version\": \"0.103.2\",\n  \"publishedAt\": 1788333836228\n}\n\nFile v0.103.2:skill-card.md\n\n## Description:\n\nagent-bom compliance evaluates AI infrastructure scan results against security and regulatory frameworks, enforces policy-as-code, and generates SBOMs and compliance reports.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nApache-2.0\n\n## Use Case:\n\nDevelopers, security engineers, and compliance teams use this skill to assess AI infrastructure scan results against frameworks such as OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS, and related controls. It also supports policy checks and SBOM generation for compliance reporting.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Optional CIS benchmark checks can use cloud credentials and make read-only calls to AWS, Azure, GCP, or Snowflake APIs.\n\nMitigation: Use least-privilege read-only credentials and confirm the target provider account, tenant, or project before invoking CIS checks.\n\nRisk: Installing or invoking the referenced package trusts the upstream package source.\n\nMitigation: Install only when the publisher and package source are trusted, and review package provenance before operational use.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/msaad00/skills/agent-bom-compliance)\n- [agent-bom source repository](https://github.com/msaad00/agent-bom)\n- [agent-bom PyPI package](https://pypi.org/project/agent-bom/)\n- [OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown with inline command examples and structured compliance or SBOM output guidance]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Produces local compliance analysis, policy-check guidance, SBOM generation instructions, and optional read-only cloud benchmark guidance.]\n\n## Skill Version(s):\n\n0.103.2 (source: server release metadata and frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.","readmeExcerpt":"Skill: agent-bom compliance Owner: msaad00 Summary: AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks. Generate SBOMs and compliance reports. Use when: \"compliance report\", \"NIST\", \"SOC 2\", \"ISO 27001\", \"OWASP\", \"EU AI Act\", \"AISVS\", \"generate SBOM\", \"policy check\". Tags: latest:0.108.3 Version history: v0.108.3 | 2026-10","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"pipx install agent-bom\nagent-bom scan --compliance --compliance-export nist-ai-rmf\nagent-bom scan -f cyclonedx -o sbom.json"},{"language":"text","snippet":"# Run compliance check against multiple frameworks\ncompliance(frameworks=[\"owasp_llm\", \"eu_ai_act\", \"nist_ai_rmf\"])\n\n# Enforce custom policy\npolicy_check(policy={\"max_critical\": 0, \"max_high\": 5})\n\n# Generate SBOM\ngenerate_sbom(format=\"cyclonedx\")\n\n# Run AISVS v1.0 compliance\naisvs_benchmark()\n\n# Run AWS CIS benchmark\ncis_benchmark(provider=\"aws\")"},{"language":"bash","snippet":"pipx install agent-bom\nagent-bom scan --compliance --compliance-export nist-ai-rmf\nagent-bom scan -f cyclonedx -o sbom.json"},{"language":"text","snippet":"# Run compliance check against multiple frameworks\ncompliance(frameworks=[\"owasp_llm\", \"eu_ai_act\", \"nist_ai_rmf\"])\n\n# Enforce custom policy\npolicy_check(policy={\"max_critical\": 0, \"max_high\": 5})\n\n# Generate SBOM\ngenerate_sbom(format=\"cyclonedx\")\n\n# Run AISVS v1.0 compliance\naisvs_benchmark()\n\n# Run AWS CIS benchmark\ncis_benchmark(provider=\"aws\")"},{"language":"bash","snippet":"pipx install agent-bom\nagent-bom scan --compliance --compliance-export nist-ai-rmf\nagent-bom scan -f cyclonedx -o sbom.json"},{"language":"text","snippet":"# Run compliance check against multiple frameworks\ncompliance(frameworks=[\"owasp_llm\", \"eu_ai_act\", \"nist_ai_rmf\"])\n\n# Enforce custom policy\npolicy_check(policy={\"max_critical\": 0, \"max_high\": 5})\n\n# Generate SBOM\ngenerate_sbom(format=\"cyclonedx\")\n\n# Run AISVS v1.0 compliance\naisvs_benchmark()\n\n# Run AWS CIS benchmark\ncis_benchmark(provider=\"aws\")"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: agent-bom-compliance\ndescription: >-\n  AI compliance and policy engine — evaluate scan results against OWASP, NIST,\n  SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.\n  Generate SBOMs and compliance reports. Use when:\n  \"compliance report\", \"NIST\", \"SOC 2\", \"ISO 27001\", \"OWASP\", \"EU AI Act\",\n  \"AISVS\", \"generate SBOM\", \"policy check\".\nversion: 0.108.3\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. OWASP/NIST/EU AI Act/MITRE\n  evaluation and SBOM generation are fully local with zero credentials. CIS\n  benchmark checks optionally use cloud SDK credentials (AWS/Azure/GCP/Snowflake)\n  and make read-only API calls to cloud providers when explicitly invoked.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.108.3\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required for OWASP/NIST/EU AI Act compliance and SBOM generation. CIS benchmark checks (AWS, Azure, GCP, Snowflake) optionally accept cloud credentials — only used locally to call cloud APIs, never transmitted elsewhere.\"\n    credential_handling: \"Use only operator-configured cloud SDK credentials for explicitly requested CIS checks. Do not ask users to paste secrets, and never print cloud tokens, private keys, passwords, or connection strings.\"\n    optional_env:\n      - name: AWS_PROFILE\n        purpose: \"AWS CIS benchmark checks — uses boto3 with your local AWS profile\"\n        required: false\n      - name: AZURE_TENANT_ID\n        purpose: \"Azure CIS benchmark checks (azure-mgmt-* SDK)\"\n        required: false\n      - name: AZURE_CLIENT_ID\n        purpose: \"Azure CIS benchmark checks — service principal client ID\"\n        required: false\n      - name: AZURE_CLIENT_SECRET\n        purpose: \"Azure CIS benchmark checks — service principal secret\"\n        required: false\n      - name: GOOGLE_APPLICATION_CREDENTIALS\n        purpose: \"GCP CIS benchmark checks (google-cloud-* SDK)\"\n        required: false\n      - name: SNOWFLAKE_ACCOUNT\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_USER\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_PRIVATE_KEY_PATH\n        purpose: \"Snowflake key-pair auth (CI/CD)\"\n        required: false\n      - name: SNOWFLAKE_AUTHENTICATOR\n        purpose: \"Snowflake auth method (default: externalbrowser SSO)\"\n        required: false\n    optional_bins: []\n    emoji: \"\\U00002705\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-compliance\",\n  \"version\": \"0.108.3\",\n  \"publishedAt\": 1791497866772\n}"},{"path":"skill-card.md","content":"## Description:\n\nHelps agents evaluate AI security and compliance findings against common frameworks, check policies, and generate SBOMs and compliance reports.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security teams use this skill to request compliance and policy checks on AI infrastructure scan results, generate SBOMs, and optionally run cloud CIS benchmark checks.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Optional CIS checks access cloud provider APIs using configured credentials and may expose more account information than needed.\n\nMitigation: Run CIS checks only after explicit confirmation and use a minimally privileged cloud profile.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/msaad00/skills/agent-bom-compliance)\n- [Project homepage](https://github.com/msaad00/agent-bom)\n- [Python package](https://pypi.org/project/agent-bom/)\n- [OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Guidance]\n\n**Output Format:** [Markdown with compliance guidance and example commands]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Can guide generation of CycloneDX or SPDX SBOMs and compliance reports.]\n\n## Skill Version(s):\n\n0.108.3 (source: release metadata and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks. Generate SBOMs and compliance reports. Use when: \"compliance report\", \"NIST\", \"SOC 2\", \"ISO 27001\", \"OWASP\", \"EU AI Act\", \"AISVS\", \"generate SBOM\", \"policy check\". Skill: agent-bom compliance Owner: msaad00 Summary: AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks. Generate SBOMs and compliance reports. Use when: \"compliance report\", \"NIST\", \"SOC 2\", \"ISO 27001\", \"OWASP\", \"EU AI Act\", \"AISVS\", \"generate SBOM\", \"policy check\". Tags: latest:0.108.3 Version history: v0.108.3 | 2026-10","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1041,"uniquenessScore":47,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T04:24:17.496Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T04:24:17.496Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T01:14:22.397Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}