{"id":"e879bc6a-59c3-4510-b565-f4e30f9efb0e","entityType":"agent","slug":"clawhub-msaad00-agent-bom-discover-aws","name":"agent-bom discover aws","canonicalUrl":"https://www.xpersona.co/agent/clawhub-msaad00-agent-bom-discover-aws","canonicalPath":"/agent/clawhub-msaad00-agent-bom-discover-aws","generatedAt":"2026-10-09T17:23:17.970Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:26:13.126Z","emptyReason":null},"description":"Discover AWS-hosted AI agent and MCP-relevant assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving agent-bom long-lived cloud credentials. Use when a user asks to inventory AWS Bedrock, ECS, SageMaker, Lambda, EKS, Step Functions, EC2, or agentic AWS infrastructure as canonical inventory. Passing that inventory to agent-bom is optional and operator-chosen.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 4.4K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom-discover-aws","sourceUrl":"https://clawhub.ai/msaad00/agent-bom-discover-aws","homepage":"https://clawhub.ai/msaad00/skills/agent-bom-discover-aws","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/msaad00/agent-bom-discover-aws","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/msaad00/skills/agent-bom-discover-aws","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":73,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"agent-bom discover aws technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:26:13.126Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:26:13.126Z","emptyReason":null},"stars":null,"forks":null,"downloads":4416,"packageName":null,"latestVersion":"0.108.3","tractionLabel":"4.4K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:26:13.125Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T05:26:13.126Z","lastCrawledAt":"2026-10-09T05:26:13.125Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T05:26:13.125Z","lastVerifiedAt":null,"highlights":[{"version":"0.108.3","createdAt":"2026-10-08T22:18:25.675Z","changelog":"Release v0.108.3","fileCount":3,"zipByteSize":3965},{"version":"0.108.2","createdAt":"2026-10-08T05:01:40.874Z","changelog":"Release v0.108.2","fileCount":3,"zipByteSize":3950},{"version":"0.108.1","createdAt":"2026-10-06T17:48:10.017Z","changelog":"Release v0.108.1","fileCount":3,"zipByteSize":3904},{"version":"0.108.0","createdAt":"2026-10-04T07:13:08.187Z","changelog":"Release v0.108.0","fileCount":3,"zipByteSize":3922},{"version":"0.107.2","createdAt":"2026-10-01T23:32:43.358Z","changelog":"Release v0.107.2","fileCount":3,"zipByteSize":3907},{"version":"0.107.0","createdAt":"2026-09-30T20:18:35.175Z","changelog":"Release v0.107.0","fileCount":3,"zipByteSize":3940},{"version":"0.106.1","createdAt":"2026-09-27T00:18:50.100Z","changelog":"Release v0.106.1","fileCount":3,"zipByteSize":3895},{"version":"0.105.0","createdAt":"2026-09-18T11:11:51.484Z","changelog":"Release v0.105.0","fileCount":3,"zipByteSize":4155}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom-discover-aws","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom-discover-aws` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/msaad00/agent-bom-discover-aws before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-aws/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-aws/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-aws/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-aws/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-aws/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-aws/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T17:23:17.969Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-aws/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-aws/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-aws/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-aws/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:26:13.126Z","emptyReason":null},"readme":"Skill: agent-bom discover aws\n\nOwner: msaad00\n\nSummary: Discover AWS-hosted AI agent and MCP-relevant assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving agent-bom long-lived cloud credentials. Use when a user asks to inventory AWS Bedrock, ECS, SageMaker, Lambda, EKS, Step Functions, EC2, or agentic AWS infrastructure as canonical inventory. Passing that inventory to agent-bom is optional and operator-chosen.\n\nTags: latest:0.108.3\n\nVersion history:\n\nv0.108.3 | 2026-10-08T22:18:25.675Z | user\n\nRelease v0.108.3\n\nv0.108.2 | 2026-10-08T05:01:40.874Z | user\n\nRelease v0.108.2\n\nv0.108.1 | 2026-10-06T17:48:10.017Z | user\n\nRelease v0.108.1\n\nv0.108.0 | 2026-10-04T07:13:08.187Z | user\n\nRelease v0.108.0\n\nv0.107.2 | 2026-10-01T23:32:43.358Z | user\n\nRelease v0.107.2\n\nv0.107.0 | 2026-09-30T20:18:35.175Z | user\n\nRelease v0.107.0\n\nv0.106.1 | 2026-09-27T00:18:50.100Z | user\n\nRelease v0.106.1\n\nv0.105.0 | 2026-09-18T11:11:51.484Z | user\n\nRelease v0.105.0\n\nv0.104.0 | 2026-09-09T20:56:37.665Z | user\n\nRelease v0.104.0\n\nv0.103.2 | 2026-09-02T07:24:38.628Z | user\n\nRelease v0.103.2\n\nv0.102.0 | 2026-08-24T04:50:25.940Z | user\n\nRelease v0.102.0\n\nv0.101.0 | 2026-08-16T23:13:36.039Z | user\n\nRelease v0.101.0\n\nv0.100.0 | 2026-08-12T20:55:27.328Z | user\n\nRelease v0.100.0\n\nv0.99.0 | 2026-08-06T00:53:03.576Z | user\n\nRelease v0.99.0\n\nv0.98.3 | 2026-08-03T06:09:23.672Z | user\n\nRelease v0.98.3\n\nv0.98.2 | 2026-07-27T08:50:25.654Z | user\n\nRelease v0.98.2\n\nv0.98.1 | 2026-07-27T02:02:27.343Z | user\n\nRelease v0.98.1\n\nv0.98.0 | 2026-07-25T01:51:41.064Z | user\n\nRelease v0.98.0\n\nv0.97.5 | 2026-07-24T01:43:54.225Z | user\n\nRelease v0.97.5\n\nv0.97.4 | 2026-07-23T00:59:33.721Z | user\n\nRelease v0.97.4\n\nv0.97.2 | 2026-07-21T18:19:30.320Z | user\n\nRelease v0.97.2\n\nv0.97.1 | 2026-07-21T03:31:58.973Z | user\n\nRelease v0.97.1\n\nv0.97.0 | 2026-07-20T18:11:10.509Z | user\n\nRelease v0.97.0\n\nv0.96.4 | 2026-07-20T15:06:05.058Z | user\n\nRelease v0.96.4\n\nv0.96.3 | 2026-07-16T04:05:55.214Z | user\n\nRelease v0.96.3\n\nv0.96.2 | 2026-07-15T23:05:36.401Z | user\n\nRelease v0.96.2\n\nv0.95.0 | 2026-07-13T21:38:48.999Z | user\n\nRelease v0.95.0\n\nv0.94.2 | 2026-07-09T18:24:54.934Z | user\n\nRelease v0.94.2\n\nv0.94.1 | 2026-07-09T05:51:09.575Z | user\n\nRelease v0.94.1\n\nv0.94.0 | 2026-07-08T21:48:23.496Z | user\n\nRelease v0.94.0\n\nv0.93.0 | 2026-07-06T07:43:13.448Z | user\n\nRelease v0.93.0\n\nv0.91.0 | 2026-06-30T23:36:49.699Z | user\n\nRelease v0.91.0\n\nv0.90.0 | 2026-06-30T03:48:05.369Z | user\n\nRelease v0.90.0\n\nv0.89.2 | 2026-06-22T03:18:04.825Z | user\n\nRelease v0.89.2\n\nv0.88.5 | 2026-06-01T06:24:08.328Z | user\n\nRelease v0.88.5\n\nv0.88.4 | 2026-05-26T04:20:33.991Z | user\n\nRelease v0.88.4\n\nv0.88.3 | 2026-05-25T00:57:38.105Z | user\n\nRelease v0.88.3\n\nv0.88.1 | 2026-05-22T04:38:39.752Z | user\n\nRelease v0.88.1\n\nv0.87.1 | 2026-05-18T20:25:56.326Z | user\n\nRelease v0.87.1\n\nv0.87.0 | 2026-05-18T00:37:04.190Z | user\n\nRelease v0.87.0\n\nv0.86.5 | 2026-05-11T16:16:15.072Z | user\n\nRelease v0.86.5\n\nv0.86.2 | 2026-05-07T15:45:26.805Z | user\n\nRelease v0.86.2\n\nv0.86.1 | 2026-05-06T06:42:34.726Z | user\n\nRelease v0.86.1\n\nv0.85.0 | 2026-05-02T22:48:59.703Z | user\n\nRelease v0.85.0\n\nv0.84.6 | 2026-05-02T06:44:22.971Z | user\n\nRelease v0.84.6\n\nv0.84.5 | 2026-05-02T03:29:28.808Z | user\n\nRelease v0.84.5\n\nv0.84.4 | 2026-05-01T19:07:50.337Z | user\n\nRelease v0.84.4\n\nv0.84.0 | 2026-05-01T01:53:44.269Z | user\n\nRelease v0.84.0\n\nv0.83.4 | 2026-04-30T19:33:54.427Z | user\n\nRelease v0.83.4\n\nv0.83.3 | 2026-04-30T05:47:50.455Z | user\n\nRelease v0.83.3\n\nArchive index:\n\nArchive v0.108.3: 3 files, 3965 bytes\n\nFiles: skill-card.md (2057b), SKILL.md (6538b), _meta.json (143b)\n\nFile v0.108.3:SKILL.md\n\n---\nname: agent-bom-discover-aws\ndescription: >-\n  Discover AWS-hosted AI agent and MCP-relevant assets from the operator's\n  environment, emit canonical agent-bom inventory JSON, and scan it without\n  giving agent-bom long-lived cloud credentials. Use when a user asks to\n  inventory AWS Bedrock, ECS, SageMaker, Lambda, EKS, Step Functions, EC2, or\n  agentic AWS infrastructure as canonical inventory. Passing that inventory\n  to agent-bom is optional and operator-chosen.\nversion: 0.108.3\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed from this repository or PyPI, and\n  operator-controlled AWS credentials from AWS SSO, WebIdentity, or STS. Prefer\n  short-lived credentials and read-only IAM policy scope.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: aws-read-only\n    credential_policy: \"Use the operator's existing AWS SDK credential chain. Prefer AWS SSO, WebIdentity, or STS assumed-role credentials. Do not ask users to paste access keys. Do not print credential values.\"\n    optional_env:\n      - AWS_PROFILE\n      - AWS_REGION\n      - AWS_DEFAULT_REGION\n    optional_bins: []\n    emoji: \"\\U0001F50E\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes the AWS SDK locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator AWS account -> read-only AWS SDK calls -> canonical inventory JSON -> agent-bom inventory scan. No agent-bom-hosted service is required. Values matching credential patterns are redacted before persistence/export.\"\n    file_reads: []\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://sts.amazonaws.com\"\n        purpose: \"Caller identity and assumed-role context\"\n        auth: true\n      - url: \"https://bedrock-agent.{region}.amazonaws.com\"\n        purpose: \"Bedrock agent inventory\"\n        auth: true\n      - url: \"https://ecs.{region}.amazonaws.com\"\n        purpose: \"ECS workload inventory when enabled\"\n        auth: true\n      - url: \"https://sagemaker.{region}.amazonaws.com\"\n        purpose: \"SageMaker inventory when enabled\"\n        auth: true\n      - url: \"https://lambda.{region}.amazonaws.com\"\n        purpose: \"Lambda inventory when enabled\"\n        auth: true\n      - url: \"https://eks.{region}.amazonaws.com\"\n        purpose: \"EKS inventory when enabled\"\n        auth: true\n      - url: \"https://states.{region}.amazonaws.com\"\n        purpose: \"Step Functions inventory when enabled\"\n        auth: true\n      - url: \"https://ec2.{region}.amazonaws.com\"\n        purpose: \"EC2 inventory when enabled\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-aws\n\nUse this skill to collect AWS AI and workload inventory from the operator's\nenvironment as canonical inventory. The skill is discover-only by default:\nwrite schema-valid JSON to an operator-selected path and stop. Run\n`agent-bom` only when the operator explicitly wants findings, graph, policy,\nor exports from that inventory.\n\n## Guardrails\n\n- Use only operator-approved AWS profiles, roles, or short-lived STS sessions.\n- Prefer read-only IAM actions listed by `agent-bom trust` or\n  `/v1/discovery/providers`.\n- Do not request or display raw `AWS_ACCESS_KEY_ID`,\n  `AWS_SECRET_ACCESS_KEY`, `AWS_SESSION_TOKEN`, or bearer tokens.\n- Do not modify AWS resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; only the schema-validated\n  inventory JSON is evidence.\n\n## Modes\n\n| Mode | What happens | Data boundary |\n|------|--------------|---------------|\n| `discover-only` | Emit canonical inventory JSON and stop | No agent-bom scan or API handoff |\n| `scan-local` | Run `agent-bom scan --inventory ...` on the generated file | Local handoff into the scanner |\n| `export` | Write JSON/SARIF or another operator-selected output | Local output only unless the operator routes it elsewhere |\n\nUse `discover-only` unless the operator asks for scan results or an export.\n\n## Workflow\n\n1. Confirm the AWS account/region/profile and intended services.\n2. Generate inventory with the repository adapter and stop:\n\n```bash\npython examples/operator_pull/aws_inventory_adapter.py \\\n  --region us-east-1 \\\n  --profile readonly-audit \\\n  --source aws-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output aws-inventory.json\n```\n\n3. If the operator asks for findings, scan the generated inventory locally:\n\n```bash\nagent-bom scan --inventory aws-inventory.json\n```\n\n4. If the operator asks for an export, write it to an operator-selected path:\n\n```bash\nagent-bom scan --inventory aws-inventory.json --format json --output agent-bom-aws-findings.json\n```\n\n## Optional Service Flags\n\nStart narrow, then expand deliberately:\n\n```bash\npython examples/operator_pull/aws_inventory_adapter.py \\\n  --region us-east-1 \\\n  --profile readonly-audit \\\n  --source aws-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --include-ecs \\\n  --include-lambda \\\n  --include-eks \\\n  --output aws-inventory.json\n```\n\nUse `--no-include-ecs` or similar flags to disable default services when an\noperator wants a smaller scope.\n\n## Evidence Contract\n\nThe inventory emitted by this skill uses:\n\n- `source: aws-skill-invoked`\n- `discovery_provenance.source_type: skill_invoked_pull`\n- `discovery_provenance.observed_via: skill_invoked_pull, aws_sdk`\n- sanitized `metadata.permissions_used`\n- sanitized `cloud_origin`, `cloud_principal`, lifecycle fields, packages, and\n  MCP server launch metadata\n\nIf schema validation fails, stop and fix the inventory instead of scanning a\nbest-effort or prose summary.\n\nThe skill does not push inventory to an API by default. Any push, scan, or\nmanaged control-plane handoff must be a separate operator-approved handoff\ncommand with the destination URL, auth method, and retained evidence classes\nmade explicit.\n\nFile v0.108.3:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-aws\",\n  \"version\": \"0.108.3\",\n  \"publishedAt\": 1791497905675\n}\n\nFile v0.108.3:skill-card.md\n\n## Description:\n\nHelps operators discover AWS-hosted AI agents and related workloads, produce canonical inventory JSON, and optionally scan that inventory with agent-bom.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and cloud operators use this skill to inventory AI agents and workloads in approved AWS accounts and regions. They can optionally request local agent-bom findings or exports after reviewing the generated inventory.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: AWS inventory can expose sensitive cloud architecture when shared or exported.\n\nMitigation: Review inventory before sharing or exporting it and keep generated files at an operator-selected location.\n\nRisk: Broad AWS credentials or unintended account and region selection could expand the inventory scope.\n\nMitigation: Use a read-only profile or short-lived assumed role, and confirm the account, regions, and services before discovery.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/msaad00/skills/agent-bom-discover-aws)\n- [Project homepage (declared in skill metadata; source provenance unavailable)](https://github.com/msaad00/agent-bom)\n- [agent-bom on PyPI](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Guidance, JSON inventory]\n\n**Output Format:** [Markdown guidance and shell commands; canonical JSON inventory file when executed]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Discovery-only by default; local scans and JSON or SARIF exports require operator approval.]\n\n## Skill Version(s):\n\n0.108.3 (source: skill frontmatter and ClawHub release)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.108.2: 3 files, 3950 bytes\n\nFiles: skill-card.md (2064b), SKILL.md (6538b), _meta.json (143b)\n\nFile v0.108.2:SKILL.md\n\n---\nname: agent-bom-discover-aws\ndescription: >-\n  Discover AWS-hosted AI agent and MCP-relevant assets from the operator's\n  environment, emit canonical agent-bom inventory JSON, and scan it without\n  giving agent-bom long-lived cloud credentials. Use when a user asks to\n  inventory AWS Bedrock, ECS, SageMaker, Lambda, EKS, Step Functions, EC2, or\n  agentic AWS infrastructure as canonical inventory. Passing that inventory\n  to agent-bom is optional and operator-chosen.\nversion: 0.108.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed from this repository or PyPI, and\n  operator-controlled AWS credentials from AWS SSO, WebIdentity, or STS. Prefer\n  short-lived credentials and read-only IAM policy scope.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: aws-read-only\n    credential_policy: \"Use the operator's existing AWS SDK credential chain. Prefer AWS SSO, WebIdentity, or STS assumed-role credentials. Do not ask users to paste access keys. Do not print credential values.\"\n    optional_env:\n      - AWS_PROFILE\n      - AWS_REGION\n      - AWS_DEFAULT_REGION\n    optional_bins: []\n    emoji: \"\\U0001F50E\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes the AWS SDK locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator AWS account -> read-only AWS SDK calls -> canonical inventory JSON -> agent-bom inventory scan. No agent-bom-hosted service is required. Values matching credential patterns are redacted before persistence/export.\"\n    file_reads: []\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://sts.amazonaws.com\"\n        purpose: \"Caller identity and assumed-role context\"\n        auth: true\n      - url: \"https://bedrock-agent.{region}.amazonaws.com\"\n        purpose: \"Bedrock agent inventory\"\n        auth: true\n      - url: \"https://ecs.{region}.amazonaws.com\"\n        purpose: \"ECS workload inventory when enabled\"\n        auth: true\n      - url: \"https://sagemaker.{region}.amazonaws.com\"\n        purpose: \"SageMaker inventory when enabled\"\n        auth: true\n      - url: \"https://lambda.{region}.amazonaws.com\"\n        purpose: \"Lambda inventory when enabled\"\n        auth: true\n      - url: \"https://eks.{region}.amazonaws.com\"\n        purpose: \"EKS inventory when enabled\"\n        auth: true\n      - url: \"https://states.{region}.amazonaws.com\"\n        purpose: \"Step Functions inventory when enabled\"\n        auth: true\n      - url: \"https://ec2.{region}.amazonaws.com\"\n        purpose: \"EC2 inventory when enabled\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-aws\n\nUse this skill to collect AWS AI and workload inventory from the operator's\nenvironment as canonical inventory. The skill is discover-only by default:\nwrite schema-valid JSON to an operator-selected path and stop. Run\n`agent-bom` only when the operator explicitly wants findings, graph, policy,\nor exports from that inventory.\n\n## Guardrails\n\n- Use only operator-approved AWS profiles, roles, or short-lived STS sessions.\n- Prefer read-only IAM actions listed by `agent-bom trust` or\n  `/v1/discovery/providers`.\n- Do not request or display raw `AWS_ACCESS_KEY_ID`,\n  `AWS_SECRET_ACCESS_KEY`, `AWS_SESSION_TOKEN`, or bearer tokens.\n- Do not modify AWS resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; only the schema-validated\n  inventory JSON is evidence.\n\n## Modes\n\n| Mode | What happens | Data boundary |\n|------|--------------|---------------|\n| `discover-only` | Emit canonical inventory JSON and stop | No agent-bom scan or API handoff |\n| `scan-local` | Run `agent-bom scan --inventory ...` on the generated file | Local handoff into the scanner |\n| `export` | Write JSON/SARIF or another operator-selected output | Local output only unless the operator routes it elsewhere |\n\nUse `discover-only` unless the operator asks for scan results or an export.\n\n## Workflow\n\n1. Confirm the AWS account/region/profile and intended services.\n2. Generate inventory with the repository adapter and stop:\n\n```bash\npython examples/operator_pull/aws_inventory_adapter.py \\\n  --region us-east-1 \\\n  --profile readonly-audit \\\n  --source aws-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output aws-inventory.json\n```\n\n3. If the operator asks for findings, scan the generated inventory locally:\n\n```bash\nagent-bom scan --inventory aws-inventory.json\n```\n\n4. If the operator asks for an export, write it to an operator-selected path:\n\n```bash\nagent-bom scan --inventory aws-inventory.json --format json --output agent-bom-aws-findings.json\n```\n\n## Optional Service Flags\n\nStart narrow, then expand deliberately:\n\n```bash\npython examples/operator_pull/aws_inventory_adapter.py \\\n  --region us-east-1 \\\n  --profile readonly-audit \\\n  --source aws-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --include-ecs \\\n  --include-lambda \\\n  --include-eks \\\n  --output aws-inventory.json\n```\n\nUse `--no-include-ecs` or similar flags to disable default services when an\noperator wants a smaller scope.\n\n## Evidence Contract\n\nThe inventory emitted by this skill uses:\n\n- `source: aws-skill-invoked`\n- `discovery_provenance.source_type: skill_invoked_pull`\n- `discovery_provenance.observed_via: skill_invoked_pull, aws_sdk`\n- sanitized `metadata.permissions_used`\n- sanitized `cloud_origin`, `cloud_principal`, lifecycle fields, packages, and\n  MCP server launch metadata\n\nIf schema validation fails, stop and fix the inventory instead of scanning a\nbest-effort or prose summary.\n\nThe skill does not push inventory to an API by default. Any push, scan, or\nmanaged control-plane handoff must be a separate operator-approved handoff\ncommand with the destination URL, auth method, and retained evidence classes\nmade explicit.\n\nFile v0.108.2:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-aws\",\n  \"version\": \"0.108.2\",\n  \"publishedAt\": 1791435700874\n}\n\nFile v0.108.2:skill-card.md\n\n## Description:\n\nHelps operators discover AWS-hosted AI agents and related workloads, create canonical agent-bom inventory JSON, and optionally scan the inventory on request.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and cloud operators use this skill to inventory AWS AI agents and associated infrastructure with an approved read-only AWS profile. They can optionally request local scanning or export of the resulting inventory.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: AWS inventory collection exposes infrastructure metadata and requires access to an AWS account.\n\nMitigation: Use an operator-approved, least-privilege read-only profile or short-lived role, and limit collection to the intended account, regions, and services.\n\nRisk: Generated inventory may reveal sensitive infrastructure details if shared or exported.\n\nMitigation: Review the local inventory before sharing it, and separately approve any scan, export, or remote handoff.\n\n## Reference(s):\n\n- [agent-bom project and AWS inventory adapter](https://github.com/msaad00/agent-bom)\n- [agent-bom on PyPI](https://pypi.org/project/agent-bom/)\n- [ClawHub skill release](https://clawhub.ai/msaad00/skills/agent-bom-discover-aws)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Configuration guidance, JSON inventory]\n\n**Output Format:** [Markdown guidance with shell commands; operator-selected inventory JSON file]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Discovery-only by default; local scan and export require separate operator approval.]\n\n## Skill Version(s):\n\n0.108.2 (source: ClawHub release and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.108.1: 3 files, 3904 bytes\n\nFiles: skill-card.md (1963b), SKILL.md (6538b), _meta.json (143b)\n\nFile v0.108.1:SKILL.md\n\n---\nname: agent-bom-discover-aws\ndescription: >-\n  Discover AWS-hosted AI agent and MCP-relevant assets from the operator's\n  environment, emit canonical agent-bom inventory JSON, and scan it without\n  giving agent-bom long-lived cloud credentials. Use when a user asks to\n  inventory AWS Bedrock, ECS, SageMaker, Lambda, EKS, Step Functions, EC2, or\n  agentic AWS infrastructure as canonical inventory. Passing that inventory\n  to agent-bom is optional and operator-chosen.\nversion: 0.108.1\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed from this repository or PyPI, and\n  operator-controlled AWS credentials from AWS SSO, WebIdentity, or STS. Prefer\n  short-lived credentials and read-only IAM policy scope.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: aws-read-only\n    credential_policy: \"Use the operator's existing AWS SDK credential chain. Prefer AWS SSO, WebIdentity, or STS assumed-role credentials. Do not ask users to paste access keys. Do not print credential values.\"\n    optional_env:\n      - AWS_PROFILE\n      - AWS_REGION\n      - AWS_DEFAULT_REGION\n    optional_bins: []\n    emoji: \"\\U0001F50E\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes the AWS SDK locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator AWS account -> read-only AWS SDK calls -> canonical inventory JSON -> agent-bom inventory scan. No agent-bom-hosted service is required. Values matching credential patterns are redacted before persistence/export.\"\n    file_reads: []\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://sts.amazonaws.com\"\n        purpose: \"Caller identity and assumed-role context\"\n        auth: true\n      - url: \"https://bedrock-agent.{region}.amazonaws.com\"\n        purpose: \"Bedrock agent inventory\"\n        auth: true\n      - url: \"https://ecs.{region}.amazonaws.com\"\n        purpose: \"ECS workload inventory when enabled\"\n        auth: true\n      - url: \"https://sagemaker.{region}.amazonaws.com\"\n        purpose: \"SageMaker inventory when enabled\"\n        auth: true\n      - url: \"https://lambda.{region}.amazonaws.com\"\n        purpose: \"Lambda inventory when enabled\"\n        auth: true\n      - url: \"https://eks.{region}.amazonaws.com\"\n        purpose: \"EKS inventory when enabled\"\n        auth: true\n      - url: \"https://states.{region}.amazonaws.com\"\n        purpose: \"Step Functions inventory when enabled\"\n        auth: true\n      - url: \"https://ec2.{region}.amazonaws.com\"\n        purpose: \"EC2 inventory when enabled\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-aws\n\nUse this skill to collect AWS AI and workload inventory from the operator's\nenvironment as canonical inventory. The skill is discover-only by default:\nwrite schema-valid JSON to an operator-selected path and stop. Run\n`agent-bom` only when the operator explicitly wants findings, graph, policy,\nor exports from that inventory.\n\n## Guardrails\n\n- Use only operator-approved AWS profiles, roles, or short-lived STS sessions.\n- Prefer read-only IAM actions listed by `agent-bom trust` or\n  `/v1/discovery/providers`.\n- Do not request or display raw `AWS_ACCESS_KEY_ID`,\n  `AWS_SECRET_ACCESS_KEY`, `AWS_SESSION_TOKEN`, or bearer tokens.\n- Do not modify AWS resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; only the schema-validated\n  inventory JSON is evidence.\n\n## Modes\n\n| Mode | What happens | Data boundary |\n|------|--------------|---------------|\n| `discover-only` | Emit canonical inventory JSON and stop | No agent-bom scan or API handoff |\n| `scan-local` | Run `agent-bom scan --inventory ...` on the generated file | Local handoff into the scanner |\n| `export` | Write JSON/SARIF or another operator-selected output | Local output only unless the operator routes it elsewhere |\n\nUse `discover-only` unless the operator asks for scan results or an export.\n\n## Workflow\n\n1. Confirm the AWS account/region/profile and intended services.\n2. Generate inventory with the repository adapter and stop:\n\n```bash\npython examples/operator_pull/aws_inventory_adapter.py \\\n  --region us-east-1 \\\n  --profile readonly-audit \\\n  --source aws-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output aws-inventory.json\n```\n\n3. If the operator asks for findings, scan the generated inventory locally:\n\n```bash\nagent-bom scan --inventory aws-inventory.json\n```\n\n4. If the operator asks for an export, write it to an operator-selected path:\n\n```bash\nagent-bom scan --inventory aws-inventory.json --format json --output agent-bom-aws-findings.json\n```\n\n## Optional Service Flags\n\nStart narrow, then expand deliberately:\n\n```bash\npython examples/operator_pull/aws_inventory_adapter.py \\\n  --region us-east-1 \\\n  --profile readonly-audit \\\n  --source aws-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --include-ecs \\\n  --include-lambda \\\n  --include-eks \\\n  --output aws-inventory.json\n```\n\nUse `--no-include-ecs` or similar flags to disable default services when an\noperator wants a smaller scope.\n\n## Evidence Contract\n\nThe inventory emitted by this skill uses:\n\n- `source: aws-skill-invoked`\n- `discovery_provenance.source_type: skill_invoked_pull`\n- `discovery_provenance.observed_via: skill_invoked_pull, aws_sdk`\n- sanitized `metadata.permissions_used`\n- sanitized `cloud_origin`, `cloud_principal`, lifecycle fields, packages, and\n  MCP server launch metadata\n\nIf schema validation fails, stop and fix the inventory instead of scanning a\nbest-effort or prose summary.\n\nThe skill does not push inventory to an API by default. Any push, scan, or\nmanaged control-plane handoff must be a separate operator-approved handoff\ncommand with the destination URL, auth method, and retained evidence classes\nmade explicit.\n\nFile v0.108.1:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-aws\",\n  \"version\": \"0.108.1\",\n  \"publishedAt\": 1791308890017\n}\n\nFile v0.108.1:skill-card.md\n\n## Description:\n\nGuides operators through read-only discovery of AWS-hosted AI agents and related workloads, producing canonical agent-bom inventory JSON for optional local scanning.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nApache-2.0\n\n## Use Case:\n\nDevelopers and cloud operators use this skill to inventory Bedrock agents and related AWS workloads in an approved account and region. They may choose to scan or export that inventory locally afterward.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: AWS inventory discovery could access an unintended account, region, or service.\n\nMitigation: Confirm the account, regions, and services before running; use an approved read-only profile or short-lived role.\n\nRisk: Generated inventory could expose sensitive infrastructure details if shared.\n\nMitigation: Keep inventory at an operator-selected local path and review it before sharing or exporting.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/msaad00/skills/agent-bom-discover-aws)\n- [Agent-bom project homepage](https://github.com/msaad00/agent-bom)\n- [Agent-bom package](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Guidance, JSON inventory]\n\n**Output Format:** [Markdown instructions and commands; JSON inventory at an operator-selected path]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Discovery only by default; scanning and exports require an explicit operator request.]\n\n## Skill Version(s):\n\n0.108.1 (source: skill frontmatter and ClawHub release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.108.0: 3 files, 3922 bytes\n\nFiles: skill-card.md (2001b), SKILL.md (6538b), _meta.json (143b)\n\nFile v0.108.0:SKILL.md\n\n---\nname: agent-bom-discover-aws\ndescription: >-\n  Discover AWS-hosted AI agent and MCP-relevant assets from the operator's\n  environment, emit canonical agent-bom inventory JSON, and scan it without\n  giving agent-bom long-lived cloud credentials. Use when a user asks to\n  inventory AWS Bedrock, ECS, SageMaker, Lambda, EKS, Step Functions, EC2, or\n  agentic AWS infrastructure as canonical inventory. Passing that inventory\n  to agent-bom is optional and operator-chosen.\nversion: 0.108.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed from this repository or PyPI, and\n  operator-controlled AWS credentials from AWS SSO, WebIdentity, or STS. Prefer\n  short-lived credentials and read-only IAM policy scope.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: aws-read-only\n    credential_policy: \"Use the operator's existing AWS SDK credential chain. Prefer AWS SSO, WebIdentity, or STS assumed-role credentials. Do not ask users to paste access keys. Do not print credential values.\"\n    optional_env:\n      - AWS_PROFILE\n      - AWS_REGION\n      - AWS_DEFAULT_REGION\n    optional_bins: []\n    emoji: \"\\U0001F50E\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes the AWS SDK locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator AWS account -> read-only AWS SDK calls -> canonical inventory JSON -> agent-bom inventory scan. No agent-bom-hosted service is required. Values matching credential patterns are redacted before persistence/export.\"\n    file_reads: []\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://sts.amazonaws.com\"\n        purpose: \"Caller identity and assumed-role context\"\n        auth: true\n      - url: \"https://bedrock-agent.{region}.amazonaws.com\"\n        purpose: \"Bedrock agent inventory\"\n        auth: true\n      - url: \"https://ecs.{region}.amazonaws.com\"\n        purpose: \"ECS workload inventory when enabled\"\n        auth: true\n      - url: \"https://sagemaker.{region}.amazonaws.com\"\n        purpose: \"SageMaker inventory when enabled\"\n        auth: true\n      - url: \"https://lambda.{region}.amazonaws.com\"\n        purpose: \"Lambda inventory when enabled\"\n        auth: true\n      - url: \"https://eks.{region}.amazonaws.com\"\n        purpose: \"EKS inventory when enabled\"\n        auth: true\n      - url: \"https://states.{region}.amazonaws.com\"\n        purpose: \"Step Functions inventory when enabled\"\n        auth: true\n      - url: \"https://ec2.{region}.amazonaws.com\"\n        purpose: \"EC2 inventory when enabled\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-aws\n\nUse this skill to collect AWS AI and workload inventory from the operator's\nenvironment as canonical inventory. The skill is discover-only by default:\nwrite schema-valid JSON to an operator-selected path and stop. Run\n`agent-bom` only when the operator explicitly wants findings, graph, policy,\nor exports from that inventory.\n\n## Guardrails\n\n- Use only operator-approved AWS profiles, roles, or short-lived STS sessions.\n- Prefer read-only IAM actions listed by `agent-bom trust` or\n  `/v1/discovery/providers`.\n- Do not request or display raw `AWS_ACCESS_KEY_ID`,\n  `AWS_SECRET_ACCESS_KEY`, `AWS_SESSION_TOKEN`, or bearer tokens.\n- Do not modify AWS resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; only the schema-validated\n  inventory JSON is evidence.\n\n## Modes\n\n| Mode | What happens | Data boundary |\n|------|--------------|---------------|\n| `discover-only` | Emit canonical inventory JSON and stop | No agent-bom scan or API handoff |\n| `scan-local` | Run `agent-bom scan --inventory ...` on the generated file | Local handoff into the scanner |\n| `export` | Write JSON/SARIF or another operator-selected output | Local output only unless the operator routes it elsewhere |\n\nUse `discover-only` unless the operator asks for scan results or an export.\n\n## Workflow\n\n1. Confirm the AWS account/region/profile and intended services.\n2. Generate inventory with the repository adapter and stop:\n\n```bash\npython examples/operator_pull/aws_inventory_adapter.py \\\n  --region us-east-1 \\\n  --profile readonly-audit \\\n  --source aws-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output aws-inventory.json\n```\n\n3. If the operator asks for findings, scan the generated inventory locally:\n\n```bash\nagent-bom scan --inventory aws-inventory.json\n```\n\n4. If the operator asks for an export, write it to an operator-selected path:\n\n```bash\nagent-bom scan --inventory aws-inventory.json --format json --output agent-bom-aws-findings.json\n```\n\n## Optional Service Flags\n\nStart narrow, then expand deliberately:\n\n```bash\npython examples/operator_pull/aws_inventory_adapter.py \\\n  --region us-east-1 \\\n  --profile readonly-audit \\\n  --source aws-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --include-ecs \\\n  --include-lambda \\\n  --include-eks \\\n  --output aws-inventory.json\n```\n\nUse `--no-include-ecs` or similar flags to disable default services when an\noperator wants a smaller scope.\n\n## Evidence Contract\n\nThe inventory emitted by this skill uses:\n\n- `source: aws-skill-invoked`\n- `discovery_provenance.source_type: skill_invoked_pull`\n- `discovery_provenance.observed_via: skill_invoked_pull, aws_sdk`\n- sanitized `metadata.permissions_used`\n- sanitized `cloud_origin`, `cloud_principal`, lifecycle fields, packages, and\n  MCP server launch metadata\n\nIf schema validation fails, stop and fix the inventory instead of scanning a\nbest-effort or prose summary.\n\nThe skill does not push inventory to an API by default. Any push, scan, or\nmanaged control-plane handoff must be a separate operator-approved handoff\ncommand with the destination URL, auth method, and retained evidence classes\nmade explicit.\n\nFile v0.108.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-aws\",\n  \"version\": \"0.108.0\",\n  \"publishedAt\": 1791097988187\n}\n\nFile v0.108.0:skill-card.md\n\n## Description:\n\nDiscovers AWS-hosted AI agents and related workloads and writes canonical inventory JSON for optional local agent-bom analysis.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and cloud operators use this skill to inventory AWS AI agents and related workloads in approved accounts and regions. They can optionally scan or export the resulting inventory on request.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: AWS discovery exposes the selected account's resource inventory to the agent and local output files.\n\nMitigation: Use an operator-approved read-only profile with short-lived credentials; review account, regions, services, and output path before running.\n\nRisk: An inventory scan or handoff could share cloud resource details beyond the intended discovery step.\n\nMitigation: Keep discovery-only as the default and require explicit operator approval for any scan, export, or external handoff.\n\n## Reference(s):\n\n- [ClawHub skill release](https://clawhub.ai/msaad00/skills/agent-bom-discover-aws)\n- [Project homepage (listed in skill metadata)](https://github.com/msaad00/agent-bom)\n- [agent-bom package](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands, JSON inventory files]\n\n**Output Format:** [Markdown guidance and commands; canonical inventory JSON when run]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Discovery only by default; scanning and exports require operator approval.]\n\n## Skill Version(s):\n\n0.108.0 (source: release evidence and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.107.2: 3 files, 3907 bytes\n\nFiles: skill-card.md (1956b), SKILL.md (6538b), _meta.json (143b)\n\nFile v0.107.2:SKILL.md\n\n---\nname: agent-bom-discover-aws\ndescription: >-\n  Discover AWS-hosted AI agent and MCP-relevant assets from the operator's\n  environment, emit canonical agent-bom inventory JSON, and scan it without\n  giving agent-bom long-lived cloud credentials. Use when a user asks to\n  inventory AWS Bedrock, ECS, SageMaker, Lambda, EKS, Step Functions, EC2, or\n  agentic AWS infrastructure as canonical inventory. Passing that inventory\n  to agent-bom is optional and operator-chosen.\nversion: 0.107.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed from this repository or PyPI, and\n  operator-controlled AWS credentials from AWS SSO, WebIdentity, or STS. Prefer\n  short-lived credentials and read-only IAM policy scope.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: aws-read-only\n    credential_policy: \"Use the operator's existing AWS SDK credential chain. Prefer AWS SSO, WebIdentity, or STS assumed-role credentials. Do not ask users to paste access keys. Do not print credential values.\"\n    optional_env:\n      - AWS_PROFILE\n      - AWS_REGION\n      - AWS_DEFAULT_REGION\n    optional_bins: []\n    emoji: \"\\U0001F50E\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes the AWS SDK locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator AWS account -> read-only AWS SDK calls -> canonical inventory JSON -> agent-bom inventory scan. No agent-bom-hosted service is required. Values matching credential patterns are redacted before persistence/export.\"\n    file_reads: []\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://sts.amazonaws.com\"\n        purpose: \"Caller identity and assumed-role context\"\n        auth: true\n      - url: \"https://bedrock-agent.{region}.amazonaws.com\"\n        purpose: \"Bedrock agent inventory\"\n        auth: true\n      - url: \"https://ecs.{region}.amazonaws.com\"\n        purpose: \"ECS workload inventory when enabled\"\n        auth: true\n      - url: \"https://sagemaker.{region}.amazonaws.com\"\n        purpose: \"SageMaker inventory when enabled\"\n        auth: true\n      - url: \"https://lambda.{region}.amazonaws.com\"\n        purpose: \"Lambda inventory when enabled\"\n        auth: true\n      - url: \"https://eks.{region}.amazonaws.com\"\n        purpose: \"EKS inventory when enabled\"\n        auth: true\n      - url: \"https://states.{region}.amazonaws.com\"\n        purpose: \"Step Functions inventory when enabled\"\n        auth: true\n      - url: \"https://ec2.{region}.amazonaws.com\"\n        purpose: \"EC2 inventory when enabled\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-aws\n\nUse this skill to collect AWS AI and workload inventory from the operator's\nenvironment as canonical inventory. The skill is discover-only by default:\nwrite schema-valid JSON to an operator-selected path and stop. Run\n`agent-bom` only when the operator explicitly wants findings, graph, policy,\nor exports from that inventory.\n\n## Guardrails\n\n- Use only operator-approved AWS profiles, roles, or short-lived STS sessions.\n- Prefer read-only IAM actions listed by `agent-bom trust` or\n  `/v1/discovery/providers`.\n- Do not request or display raw `AWS_ACCESS_KEY_ID`,\n  `AWS_SECRET_ACCESS_KEY`, `AWS_SESSION_TOKEN`, or bearer tokens.\n- Do not modify AWS resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; only the schema-validated\n  inventory JSON is evidence.\n\n## Modes\n\n| Mode | What happens | Data boundary |\n|------|--------------|---------------|\n| `discover-only` | Emit canonical inventory JSON and stop | No agent-bom scan or API handoff |\n| `scan-local` | Run `agent-bom scan --inventory ...` on the generated file | Local handoff into the scanner |\n| `export` | Write JSON/SARIF or another operator-selected output | Local output only unless the operator routes it elsewhere |\n\nUse `discover-only` unless the operator asks for scan results or an export.\n\n## Workflow\n\n1. Confirm the AWS account/region/profile and intended services.\n2. Generate inventory with the repository adapter and stop:\n\n```bash\npython examples/operator_pull/aws_inventory_adapter.py \\\n  --region us-east-1 \\\n  --profile readonly-audit \\\n  --source aws-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output aws-inventory.json\n```\n\n3. If the operator asks for findings, scan the generated inventory locally:\n\n```bash\nagent-bom scan --inventory aws-inventory.json\n```\n\n4. If the operator asks for an export, write it to an operator-selected path:\n\n```bash\nagent-bom scan --inventory aws-inventory.json --format json --output agent-bom-aws-findings.json\n```\n\n## Optional Service Flags\n\nStart narrow, then expand deliberately:\n\n```bash\npython examples/operator_pull/aws_inventory_adapter.py \\\n  --region us-east-1 \\\n  --profile readonly-audit \\\n  --source aws-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --include-ecs \\\n  --include-lambda \\\n  --include-eks \\\n  --output aws-inventory.json\n```\n\nUse `--no-include-ecs` or similar flags to disable default services when an\noperator wants a smaller scope.\n\n## Evidence Contract\n\nThe inventory emitted by this skill uses:\n\n- `source: aws-skill-invoked`\n- `discovery_provenance.source_type: skill_invoked_pull`\n- `discovery_provenance.observed_via: skill_invoked_pull, aws_sdk`\n- sanitized `metadata.permissions_used`\n- sanitized `cloud_origin`, `cloud_principal`, lifecycle fields, packages, and\n  MCP server launch metadata\n\nIf schema validation fails, stop and fix the inventory instead of scanning a\nbest-effort or prose summary.\n\nThe skill does not push inventory to an API by default. Any push, scan, or\nmanaged control-plane handoff must be a separate operator-approved handoff\ncommand with the destination URL, auth method, and retained evidence classes\nmade explicit.\n\nFile v0.107.2:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-aws\",\n  \"version\": \"0.107.2\",\n  \"publishedAt\": 1790897563358\n}\n\nFile v0.107.2:skill-card.md\n\n## Description:\n\nDiscovers AWS-hosted AI agent and MCP-relevant assets using operator-approved credentials and creates canonical agent-bom inventory JSON for optional local scanning.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and cloud security teams use this skill to inventory AI agents and related workloads in selected AWS accounts and regions, with optional operator-approved local scanning and export.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: AWS inventory access could exceed the intended account, region, or service scope.\n\nMitigation: Confirm the selected account, regions, and services; use narrowly scoped read-only IAM permissions and short-lived credentials.\n\nRisk: Optional scan, export, or push could share inventory beyond the discovery-only workflow.\n\nMitigation: Review and approve each optional command and its destination before any handoff; keep the default inventory local.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/msaad00/skills/agent-bom-discover-aws)\n- [agent-bom project](https://github.com/msaad00/agent-bom)\n- [agent-bom on PyPI](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands, JSON inventory]\n\n**Output Format:** [Markdown guidance and canonical JSON inventory file]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Schema-validated inventory at an operator-selected path; local scan and export only on request.]\n\n## Skill Version(s):\n\n0.107.2 (source: frontmatter and ClawHub release)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.107.0: 3 files, 3940 bytes\n\nFiles: skill-card.md (1991b), SKILL.md (6538b), _meta.json (143b)\n\nFile v0.107.0:SKILL.md\n\n---\nname: agent-bom-discover-aws\ndescription: >-\n  Discover AWS-hosted AI agent and MCP-relevant assets from the operator's\n  environment, emit canonical agent-bom inventory JSON, and scan it without\n  giving agent-bom long-lived cloud credentials. Use when a user asks to\n  inventory AWS Bedrock, ECS, SageMaker, Lambda, EKS, Step Functions, EC2, or\n  agentic AWS infrastructure as canonical inventory. Passing that inventory\n  to agent-bom is optional and operator-chosen.\nversion: 0.107.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed from this repository or PyPI, and\n  operator-controlled AWS credentials from AWS SSO, WebIdentity, or STS. Prefer\n  short-lived credentials and read-only IAM policy scope.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: aws-read-only\n    credential_policy: \"Use the operator's existing AWS SDK credential chain. Prefer AWS SSO, WebIdentity, or STS assumed-role credentials. Do not ask users to paste access keys. Do not print credential values.\"\n    optional_env:\n      - AWS_PROFILE\n      - AWS_REGION\n      - AWS_DEFAULT_REGION\n    optional_bins: []\n    emoji: \"\\U0001F50E\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes the AWS SDK locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator AWS account -> read-only AWS SDK calls -> canonical inventory JSON -> agent-bom inventory scan. No agent-bom-hosted service is required. Values matching credential patterns are redacted before persistence/export.\"\n    file_reads: []\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://sts.amazonaws.com\"\n        purpose: \"Caller identity and assumed-role context\"\n        auth: true\n      - url: \"https://bedrock-agent.{region}.amazonaws.com\"\n        purpose: \"Bedrock agent inventory\"\n        auth: true\n      - url: \"https://ecs.{region}.amazonaws.com\"\n        purpose: \"ECS workload inventory when enabled\"\n        auth: true\n      - url: \"https://sagemaker.{region}.amazonaws.com\"\n        purpose: \"SageMaker inventory when enabled\"\n        auth: true\n      - url: \"https://lambda.{region}.amazonaws.com\"\n        purpose: \"Lambda inventory when enabled\"\n        auth: true\n      - url: \"https://eks.{region}.amazonaws.com\"\n        purpose: \"EKS inventory when enabled\"\n        auth: true\n      - url: \"https://states.{region}.amazonaws.com\"\n        purpose: \"Step Functions inventory when enabled\"\n        auth: true\n      - url: \"https://ec2.{region}.amazonaws.com\"\n        purpose: \"EC2 inventory when enabled\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-aws\n\nUse this skill to collect AWS AI and workload inventory from the operator's\nenvironment as canonical inventory. The skill is discover-only by default:\nwrite schema-valid JSON to an operator-selected path and stop. Run\n`agent-bom` only when the operator explicitly wants findings, graph, policy,\nor exports from that inventory.\n\n## Guardrails\n\n- Use only operator-approved AWS profiles, roles, or short-lived STS sessions.\n- Prefer read-only IAM actions listed by `agent-bom trust` or\n  `/v1/discovery/providers`.\n- Do not request or display raw `AWS_ACCESS_KEY_ID`,\n  `AWS_SECRET_ACCESS_KEY`, `AWS_SESSION_TOKEN`, or bearer tokens.\n- Do not modify AWS resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; only the schema-validated\n  inventory JSON is evidence.\n\n## Modes\n\n| Mode | What happens | Data boundary |\n|------|--------------|---------------|\n| `discover-only` | Emit canonical inventory JSON and stop | No agent-bom scan or API handoff |\n| `scan-local` | Run `agent-bom scan --inventory ...` on the generated file | Local handoff into the scanner |\n| `export` | Write JSON/SARIF or another operator-selected output | Local output only unless the operator routes it elsewhere |\n\nUse `discover-only` unless the operator asks for scan results or an export.\n\n## Workflow\n\n1. Confirm the AWS account/region/profile and intended services.\n2. Generate inventory with the repository adapter and stop:\n\n```bash\npython examples/operator_pull/aws_inventory_adapter.py \\\n  --region us-east-1 \\\n  --profile readonly-audit \\\n  --source aws-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output aws-inventory.json\n```\n\n3. If the operator asks for findings, scan the generated inventory locally:\n\n```bash\nagent-bom scan --inventory aws-inventory.json\n```\n\n4. If the operator asks for an export, write it to an operator-selected path:\n\n```bash\nagent-bom scan --inventory aws-inventory.json --format json --output agent-bom-aws-findings.json\n```\n\n## Optional Service Flags\n\nStart narrow, then expand deliberately:\n\n```bash\npython examples/operator_pull/aws_inventory_adapter.py \\\n  --region us-east-1 \\\n  --profile readonly-audit \\\n  --source aws-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --include-ecs \\\n  --include-lambda \\\n  --include-eks \\\n  --output aws-inventory.json\n```\n\nUse `--no-include-ecs` or similar flags to disable default services when an\noperator wants a smaller scope.\n\n## Evidence Contract\n\nThe inventory emitted by this skill uses:\n\n- `source: aws-skill-invoked`\n- `discovery_provenance.source_type: skill_invoked_pull`\n- `discovery_provenance.observed_via: skill_invoked_pull, aws_sdk`\n- sanitized `metadata.permissions_used`\n- sanitized `cloud_origin`, `cloud_principal`, lifecycle fields, packages, and\n  MCP server launch metadata\n\nIf schema validation fails, stop and fix the inventory instead of scanning a\nbest-effort or prose summary.\n\nThe skill does not push inventory to an API by default. Any push, scan, or\nmanaged control-plane handoff must be a separate operator-approved handoff\ncommand with the destination URL, auth method, and retained evidence classes\nmade explicit.\n\nFile v0.107.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-aws\",\n  \"version\": \"0.107.0\",\n  \"publishedAt\": 1790799515175\n}\n\nFile v0.107.0:skill-card.md\n\n## Description:\n\nGuides operators through read-only discovery of AWS-hosted AI agent and workload assets, writing canonical inventory JSON for optional local scanning.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and cloud operators use this skill to inventory AWS agent and MCP-related assets with an approved read-only role. They can optionally scan or export the resulting inventory after choosing the scope and destination.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Broad AWS permissions could expose more cloud metadata than needed.\n\nMitigation: Use an operator-approved, least-privilege read-only role or profile and limit the account, region, and services.\n\nRisk: Generated inventory may contain sensitive cloud metadata that could be shared or retained unintentionally.\n\nMitigation: Choose the output path deliberately, review the inventory before sharing, and approve scans, exports, or handoffs only after confirming the destination and retained evidence.\n\n## Reference(s):\n\n- [agent-bom project (skill metadata)](https://github.com/msaad00/agent-bom)\n- [agent-bom on PyPI (skill metadata)](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands, Files]\n\n**Output Format:** [Markdown instructions and shell commands; optional canonical inventory JSON file]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Inventory is written to an operator-selected path; scanning and export are optional.]\n\n## Skill Version(s):\n\n0.107.0 (source: ClawHub release and SKILL.md frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.106.1: 3 files, 3895 bytes\n\nFiles: skill-card.md (1933b), SKILL.md (6538b), _meta.json (143b)\n\nFile v0.106.1:SKILL.md\n\n---\nname: agent-bom-discover-aws\ndescription: >-\n  Discover AWS-hosted AI agent and MCP-relevant assets from the operator's\n  environment, emit canonical agent-bom inventory JSON, and scan it without\n  giving agent-bom long-lived cloud credentials. Use when a user asks to\n  inventory AWS Bedrock, ECS, SageMaker, Lambda, EKS, Step Functions, EC2, or\n  agentic AWS infrastructure as canonical inventory. Passing that inventory\n  to agent-bom is optional and operator-chosen.\nversion: 0.106.1\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed from this repository or PyPI, and\n  operator-controlled AWS credentials from AWS SSO, WebIdentity, or STS. Prefer\n  short-lived credentials and read-only IAM policy scope.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: aws-read-only\n    credential_policy: \"Use the operator's existing AWS SDK credential chain. Prefer AWS SSO, WebIdentity, or STS assumed-role credentials. Do not ask users to paste access keys. Do not print credential values.\"\n    optional_env:\n      - AWS_PROFILE\n      - AWS_REGION\n      - AWS_DEFAULT_REGION\n    optional_bins: []\n    emoji: \"\\U0001F50E\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes the AWS SDK locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator AWS account -> read-only AWS SDK calls -> canonical inventory JSON -> agent-bom inventory scan. No agent-bom-hosted service is required. Values matching credential patterns are redacted before persistence/export.\"\n    file_reads: []\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://sts.amazonaws.com\"\n        purpose: \"Caller identity and assumed-role context\"\n        auth: true\n      - url: \"https://bedrock-agent.{region}.amazonaws.com\"\n        purpose: \"Bedrock agent inventory\"\n        auth: true\n      - url: \"https://ecs.{region}.amazonaws.com\"\n        purpose: \"ECS workload inventory when enabled\"\n        auth: true\n      - url: \"https://sagemaker.{region}.amazonaws.com\"\n        purpose: \"SageMaker inventory when enabled\"\n        auth: true\n      - url: \"https://lambda.{region}.amazonaws.com\"\n        purpose: \"Lambda inventory when enabled\"\n        auth: true\n      - url: \"https://eks.{region}.amazonaws.com\"\n        purpose: \"EKS inventory when enabled\"\n        auth: true\n      - url: \"https://states.{region}.amazonaws.com\"\n        purpose: \"Step Functions inventory when enabled\"\n        auth: true\n      - url: \"https://ec2.{region}.amazonaws.com\"\n        purpose: \"EC2 inventory when enabled\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-aws\n\nUse this skill to collect AWS AI and workload inventory from the operator's\nenvironment as canonical inventory. The skill is discover-only by default:\nwrite schema-valid JSON to an operator-selected path and stop. Run\n`agent-bom` only when the operator explicitly wants findings, graph, policy,\nor exports from that inventory.\n\n## Guardrails\n\n- Use only operator-approved AWS profiles, roles, or short-lived STS sessions.\n- Prefer read-only IAM actions listed by `agent-bom trust` or\n  `/v1/discovery/providers`.\n- Do not request or display raw `AWS_ACCESS_KEY_ID`,\n  `AWS_SECRET_ACCESS_KEY`, `AWS_SESSION_TOKEN`, or bearer tokens.\n- Do not modify AWS resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; only the schema-validated\n  inventory JSON is evidence.\n\n## Modes\n\n| Mode | What happens | Data boundary |\n|------|--------------|---------------|\n| `discover-only` | Emit canonical inventory JSON and stop | No agent-bom scan or API handoff |\n| `scan-local` | Run `agent-bom scan --inventory ...` on the generated file | Local handoff into the scanner |\n| `export` | Write JSON/SARIF or another operator-selected output | Local output only unless the operator routes it elsewhere |\n\nUse `discover-only` unless the operator asks for scan results or an export.\n\n## Workflow\n\n1. Confirm the AWS account/region/profile and intended services.\n2. Generate inventory with the repository adapter and stop:\n\n```bash\npython examples/operator_pull/aws_inventory_adapter.py \\\n  --region us-east-1 \\\n  --profile readonly-audit \\\n  --source aws-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output aws-inventory.json\n```\n\n3. If the operator asks for findings, scan the generated inventory locally:\n\n```bash\nagent-bom scan --inventory aws-inventory.json\n```\n\n4. If the operator asks for an export, write it to an operator-selected path:\n\n```bash\nagent-bom scan --inventory aws-inventory.json --format json --output agent-bom-aws-findings.json\n```\n\n## Optional Service Flags\n\nStart narrow, then expand deliberately:\n\n```bash\npython examples/operator_pull/aws_inventory_adapter.py \\\n  --region us-east-1 \\\n  --profile readonly-audit \\\n  --source aws-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --include-ecs \\\n  --include-lambda \\\n  --include-eks \\\n  --output aws-inventory.json\n```\n\nUse `--no-include-ecs` or similar flags to disable default services when an\noperator wants a smaller scope.\n\n## Evidence Contract\n\nThe inventory emitted by this skill uses:\n\n- `source: aws-skill-invoked`\n- `discovery_provenance.source_type: skill_invoked_pull`\n- `discovery_provenance.observed_via: skill_invoked_pull, aws_sdk`\n- sanitized `metadata.permissions_used`\n- sanitized `cloud_origin`, `cloud_principal`, lifecycle fields, packages, and\n  MCP server launch metadata\n\nIf schema validation fails, stop and fix the inventory instead of scanning a\nbest-effort or prose summary.\n\nThe skill does not push inventory to an API by default. Any push, scan, or\nmanaged control-plane handoff must be a separate operator-approved handoff\ncommand with the destination URL, auth method, and retained evidence classes\nmade explicit.\n\nFile v0.106.1:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-aws\",\n  \"version\": \"0.106.1\",\n  \"publishedAt\": 1790468330100\n}\n\nFile v0.106.1:skill-card.md\n\n## Description:\n\nDiscovers AWS-hosted AI agents and related workloads using operator-controlled credentials and writes canonical agent-bom inventory JSON for optional local scanning.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nApache-2.0\n\n## Use Case:\n\nDevelopers and cloud operators use this skill to inventory AWS AI agents and workloads in approved accounts and regions, then optionally scan or export findings from the local inventory.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Access to an AWS profile or role can reveal cloud resource inventory.\n\nMitigation: Use an operator-approved, short-lived read-only role limited to the intended accounts, regions, and services.\n\nRisk: Generated inventory files may expose details of cloud infrastructure if shared.\n\nMitigation: Write only to an operator-selected path and review inventory before sharing or exporting it.\n\n## Reference(s):\n\n- [agent-bom project (listed in skill metadata)](https://github.com/msaad00/agent-bom)\n- [agent-bom on PyPI](https://pypi.org/project/agent-bom/)\n- [ClawHub skill listing](https://clawhub.ai/msaad00/skills/agent-bom-discover-aws)\n\n## Skill Output:\n\n**Output Type(s):** [JSON inventory, Shell commands, Guidance]\n\n**Output Format:** [JSON inventory file and Markdown guidance with shell commands]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Optional local scan findings and JSON/SARIF exports when requested by the operator.]\n\n## Skill Version(s):\n\n0.106.1 (source: skill frontmatter and server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.105.0: 3 files, 4155 bytes\n\nFiles: skill-card.md (2431b), SKILL.md (6538b), _meta.json (143b)\n\nFile v0.105.0:SKILL.md\n\n---\nname: agent-bom-discover-aws\ndescription: >-\n  Discover AWS-hosted AI agent and MCP-relevant assets from the operator's\n  environment, emit canonical agent-bom inventory JSON, and scan it without\n  giving agent-bom long-lived cloud credentials. Use when a user asks to\n  inventory AWS Bedrock, ECS, SageMaker, Lambda, EKS, Step Functions, EC2, or\n  agentic AWS infrastructure as canonical inventory. Passing that inventory\n  to agent-bom is optional and operator-chosen.\nversion: 0.105.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed from this repository or PyPI, and\n  operator-controlled AWS credentials from AWS SSO, WebIdentity, or STS. Prefer\n  short-lived credentials and read-only IAM policy scope.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: aws-read-only\n    credential_policy: \"Use the operator's existing AWS SDK credential chain. Prefer AWS SSO, WebIdentity, or STS assumed-role credentials. Do not ask users to paste access keys. Do not print credential values.\"\n    optional_env:\n      - AWS_PROFILE\n      - AWS_REGION\n      - AWS_DEFAULT_REGION\n    optional_bins: []\n    emoji: \"\\U0001F50E\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes the AWS SDK locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator AWS account -> read-only AWS SDK calls -> canonical inventory JSON -> agent-bom inventory scan. No agent-bom-hosted service is required. Values matching credential patterns are redacted before persistence/export.\"\n    file_reads: []\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://sts.amazonaws.com\"\n        purpose: \"Caller identity and assumed-role context\"\n        auth: true\n      - url: \"https://bedrock-agent.{region}.amazonaws.com\"\n        purpose: \"Bedrock agent inventory\"\n        auth: true\n      - url: \"https://ecs.{region}.amazonaws.com\"\n        purpose: \"ECS workload inventory when enabled\"\n        auth: true\n      - url: \"https://sagemaker.{region}.amazonaws.com\"\n        purpose: \"SageMaker inventory when enabled\"\n        auth: true\n      - url: \"https://lambda.{region}.amazonaws.com\"\n        purpose: \"Lambda inventory when enabled\"\n        auth: true\n      - url: \"https://eks.{region}.amazonaws.com\"\n        purpose: \"EKS inventory when enabled\"\n        auth: true\n      - url: \"https://states.{region}.amazonaws.com\"\n        purpose: \"Step Functions inventory when enabled\"\n        auth: true\n      - url: \"https://ec2.{region}.amazonaws.com\"\n        purpose: \"EC2 inventory when enabled\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-aws\n\nUse this skill to collect AWS AI and workload inventory from the operator's\nenvironment as canonical inventory. The skill is discover-only by default:\nwrite schema-valid JSON to an operator-selected path and stop. Run\n`agent-bom` only when the operator explicitly wants findings, graph, policy,\nor exports from that inventory.\n\n## Guardrails\n\n- Use only operator-approved AWS profiles, roles, or short-lived STS sessions.\n- Prefer read-only IAM actions listed by `agent-bom trust` or\n  `/v1/discovery/providers`.\n- Do not request or display raw `AWS_ACCESS_KEY_ID`,\n  `AWS_SECRET_ACCESS_KEY`, `AWS_SESSION_TOKEN`, or bearer tokens.\n- Do not modify AWS resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; only the schema-validated\n  inventory JSON is evidence.\n\n## Modes\n\n| Mode | What happens | Data boundary |\n|------|--------------|---------------|\n| `discover-only` | Emit canonical inventory JSON and stop | No agent-bom scan or API handoff |\n| `scan-local` | Run `agent-bom scan --inventory ...` on the generated file | Local handoff into the scanner |\n| `export` | Write JSON/SARIF or another operator-selected output | Local output only unless the operator routes it elsewhere |\n\nUse `discover-only` unless the operator asks for scan results or an export.\n\n## Workflow\n\n1. Confirm the AWS account/region/profile and intended services.\n2. Generate inventory with the repository adapter and stop:\n\n```bash\npython examples/operator_pull/aws_inventory_adapter.py \\\n  --region us-east-1 \\\n  --profile readonly-audit \\\n  --source aws-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output aws-inventory.json\n```\n\n3. If the operator asks for findings, scan the generated inventory locally:\n\n```bash\nagent-bom scan --inventory aws-inventory.json\n```\n\n4. If the operator asks for an export, write it to an operator-selected path:\n\n```bash\nagent-bom scan --inventory aws-inventory.json --format json --output agent-bom-aws-findings.json\n```\n\n## Optional Service Flags\n\nStart narrow, then expand deliberately:\n\n```bash\npython examples/operator_pull/aws_inventory_adapter.py \\\n  --region us-east-1 \\\n  --profile readonly-audit \\\n  --source aws-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --include-ecs \\\n  --include-lambda \\\n  --include-eks \\\n  --output aws-inventory.json\n```\n\nUse `--no-include-ecs` or similar flags to disable default services when an\noperator wants a smaller scope.\n\n## Evidence Contract\n\nThe inventory emitted by this skill uses:\n\n- `source: aws-skill-invoked`\n- `discovery_provenance.source_type: skill_invoked_pull`\n- `discovery_provenance.observed_via: skill_invoked_pull, aws_sdk`\n- sanitized `metadata.permissions_used`\n- sanitized `cloud_origin`, `cloud_principal`, lifecycle fields, packages, and\n  MCP server launch metadata\n\nIf schema validation fails, stop and fix the inventory instead of scanning a\nbest-effort or prose summary.\n\nThe skill does not push inventory to an API by default. Any push, scan, or\nmanaged control-plane handoff must be a separate operator-approved handoff\ncommand with the destination URL, auth method, and retained evidence classes\nmade explicit.\n\nFile v0.105.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-aws\",\n  \"version\": \"0.105.0\",\n  \"publishedAt\": 1789729911484\n}\n\nFile v0.105.0:skill-card.md\n\n## Description:\n\nDiscover AWS-hosted AI agent and MCP-relevant assets from the operator's environment, emit canonical agent-bom inventory JSON, and optionally scan that inventory without giving agent-bom long-lived cloud credentials.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, security engineers, and cloud operators use this skill to inventory AWS Bedrock, ECS, SageMaker, Lambda, EKS, Step Functions, EC2, and agentic AWS infrastructure as canonical agent-bom inventory. It supports discovery-only operation by default, with local scanning or export only when the operator asks for those follow-on steps.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can enumerate AWS resources using operator-approved cloud credentials, and generated inventory may contain sensitive infrastructure data.\n\nMitigation: Confirm the AWS profile, region, service scope, and output path before execution; prefer short-lived read-only credentials and protect generated inventory as sensitive data.\n\nRisk: Authenticated AWS API calls are required for discovery across enabled services.\n\nMitigation: Use the existing AWS SDK credential chain with AWS SSO, WebIdentity, or STS assumed-role credentials, and avoid pasting or printing raw access keys or tokens.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/msaad00/skills/agent-bom-discover-aws)\n- [Agent BOM source repository](https://github.com/msaad00/agent-bom)\n- [agent-bom PyPI package](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with bash commands and operator-selected JSON inventory outputs]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Uses operator-approved AWS credentials, writes inventory to an operator-selected path, and only scans or exports inventory when explicitly requested.]\n\n## Skill Version(s):\n\n0.105.0 (source: server release metadata and SKILL.md frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.104.0: 3 files, 4022 bytes\n\nFiles: skill-card.md (2216b), SKILL.md (6538b), _meta.json (143b)\n\nFile v0.104.0:SKILL.md\n\n---\nname: agent-bom-discover-aws\ndescription: >-\n  Discover AWS-hosted AI agent and MCP-relevant assets from the operator's\n  environment, emit canonical agent-bom inventory JSON, and scan it without\n  giving agent-bom long-lived cloud credentials. Use when a user asks to\n  inventory AWS Bedrock, ECS, SageMaker, Lambda, EKS, Step Functions, EC2, or\n  agentic AWS infrastructure as canonical inventory. Passing that inventory\n  to agent-bom is optional and operator-chosen.\nversion: 0.104.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed from this repository or PyPI, and\n  operator-controlled AWS credentials from AWS SSO, WebIdentity, or STS. Prefer\n  short-lived credentials and read-only IAM policy scope.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: aws-read-only\n    credential_policy: \"Use the operator's existing AWS SDK credential chain. Prefer AWS SSO, WebIdentity, or STS assumed-role credentials. Do not ask users to paste access keys. Do not print credential values.\"\n    optional_env:\n      - AWS_PROFILE\n      - AWS_REGION\n      - AWS_DEFAULT_REGION\n    optional_bins: []\n    emoji: \"\\U0001F50E\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes the AWS SDK locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator AWS account -> read-only AWS SDK calls -> canonical inventory JSON -> agent-bom inventory scan. No agent-bom-hosted service is required. Values matching credential patterns are redacted before persistence/export.\"\n    file_reads: []\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://sts.amazonaws.com\"\n        purpose: \"Caller identity and assumed-role context\"\n        auth: true\n      - url: \"https://bedrock-agent.{region}.amazonaws.com\"\n        purpose: \"Bedrock agent inventory\"\n        auth: true\n      - url: \"https://ecs.{region}.amazonaws.com\"\n        purpose: \"ECS workload inventory when enabled\"\n        auth: true\n      - url: \"https://sagemaker.{region}.amazonaws.com\"\n        purpose: \"SageMaker inventory when enabled\"\n        auth: true\n      - url: \"https://lambda.{region}.amazonaws.com\"\n        purpose: \"Lambda inventory when enabled\"\n        auth: true\n      - url: \"https://eks.{region}.amazonaws.com\"\n        purpose: \"EKS inventory when enabled\"\n        auth: true\n      - url: \"https://states.{region}.amazonaws.com\"\n        purpose: \"Step Functions inventory when enabled\"\n        auth: true\n      - url: \"https://ec2.{region}.amazonaws.com\"\n        purpose: \"EC2 inventory when enabled\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-aws\n\nUse this skill to collect AWS AI and workload inventory from the operator's\nenvironment as canonical inventory. The skill is discover-only by default:\nwrite schema-valid JSON to an operator-selected path and stop. Run\n`agent-bom` only when the operator explicitly wants findings, graph, policy,\nor exports from that inventory.\n\n## Guardrails\n\n- Use only operator-approved AWS profiles, roles, or short-lived STS sessions.\n- Prefer read-only IAM actions listed by `agent-bom trust` or\n  `/v1/discovery/providers`.\n- Do not request or display raw `AWS_ACCESS_KEY_ID`,\n  `AWS_SECRET_ACCESS_KEY`, `AWS_SESSION_TOKEN`, or bearer tokens.\n- Do not modify AWS resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; only the schema-validated\n  inventory JSON is evidence.\n\n## Modes\n\n| Mode | What happens | Data boundary |\n|------|--------------|---------------|\n| `discover-only` | Emit canonical inventory JSON and stop | No agent-bom scan or API handoff |\n| `scan-local` | Run `agent-bom scan --inventory ...` on the generated file | Local handoff into the scanner |\n| `export` | Write JSON/SARIF or another operator-selected output | Local output only unless the operator routes it elsewhere |\n\nUse `discover-only` unless the operator asks for scan results or an export.\n\n## Workflow\n\n1. Confirm the AWS account/region/profile and intended services.\n2. Generate inventory with the repository adapter and stop:\n\n```bash\npython examples/operator_pull/aws_inventory_adapter.py \\\n  --region us-east-1 \\\n  --profile readonly-audit \\\n  --source aws-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output aws-inventory.json\n```\n\n3. If the operator asks for findings, scan the generated inventory locally:\n\n```bash\nagent-bom scan --inventory aws-inventory.json\n```\n\n4. If the operator asks for an export, write it to an operator-selected path:\n\n```bash\nagent-bom scan --inventory aws-inventory.json --format json --output agent-bom-aws-findings.json\n```\n\n## Optional Service Flags\n\nStart narrow, then expand deliberately:\n\n```bash\npython examples/operator_pull/aws_inventory_adapter.py \\\n  --region us-east-1 \\\n  --profile readonly-audit \\\n  --source aws-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --include-ecs \\\n  --include-lambda \\\n  --include-eks \\\n  --output aws-inventory.json\n```\n\nUse `--no-include-ecs` or similar flags to disable default services when an\noperator wants a smaller scope.\n\n## Evidence Contract\n\nThe inventory emitted by this skill uses:\n\n- `source: aws-skill-invoked`\n- `discovery_provenance.source_type: skill_invoked_pull`\n- `discovery_provenance.observed_via: skill_invoked_pull, aws_sdk`\n- sanitized `metadata.permissions_used`\n- sanitized `cloud_origin`, `cloud_principal`, lifecycle fields, packages, and\n  MCP server launch metadata\n\nIf schema validation fails, stop and fix the inventory instead of scanning a\nbest-effort or prose summary.\n\nThe skill does not push inventory to an API by default. Any push, scan, or\nmanaged control-plane handoff must be a separate operator-approved handoff\ncommand with the destination URL, auth method, and retained evidence classes\nmade explicit.\n\nFile v0.104.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-aws\",\n  \"version\": \"0.104.0\",\n  \"publishedAt\": 1788987397665\n}\n\nFile v0.104.0:skill-card.md\n\n## Description:\n\nDiscover AWS-hosted AI agent and MCP-relevant assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving agent-bom long-lived cloud credentials.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and cloud security engineers use this skill to inventory AWS-hosted agentic infrastructure with operator-approved AWS credentials, then optionally scan the generated local inventory with agent-bom.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill uses local AWS credentials to inventory cloud resources, so an overly broad profile or role can expose more account metadata than intended.\n\nMitigation: Use a genuinely read-only AWS profile or short-lived role scoped to the intended accounts, regions, and services before running discovery.\n\nRisk: Generated inventory can contain sensitive cloud resource names and metadata even when credential-like values are redacted.\n\nMitigation: Review generated inventory before sharing it or passing it to a scanner, export, or managed service.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/msaad00/skills/agent-bom-discover-aws)\n- [agent-bom project homepage](https://github.com/msaad00/agent-bom)\n- [agent-bom PyPI package](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, json, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with shell commands and JSON inventory file paths]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Produces operator-scoped discovery guidance and local inventory or scan commands; generated inventory is written only to an operator-selected path.]\n\n## Skill Version(s):\n\n0.104.0 (source: server release metadata and SKILL.md frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.103.2: 3 files, 4166 bytes\n\nFiles: skill-card.md (2525b), SKILL.md (6538b), _meta.json (143b)\n\nFile v0.103.2:SKILL.md\n\n---\nname: agent-bom-discover-aws\ndescription: >-\n  Discover AWS-hosted AI agent and MCP-relevant assets from the operator's\n  environment, emit canonical agent-bom inventory JSON, and scan it without\n  giving agent-bom long-lived cloud credentials. Use when a user asks to\n  inventory AWS Bedrock, ECS, SageMaker, Lambda, EKS, Step Functions, EC2, or\n  agentic AWS infrastructure as canonical inventory. Passing that inventory\n  to agent-bom is optional and operator-chosen.\nversion: 0.103.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed from this repository or PyPI, and\n  operator-controlled AWS credentials from AWS SSO, WebIdentity, or STS. Prefer\n  short-lived credentials and read-only IAM policy scope.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: aws-read-only\n    credential_policy: \"Use the operator's existing AWS SDK credential chain. Prefer AWS SSO, WebIdentity, or STS assumed-role credentials. Do not ask users to paste access keys. Do not print credential values.\"\n    optional_env:\n      - AWS_PROFILE\n      - AWS_REGION\n      - AWS_DEFAULT_REGION\n    optional_bins: []\n    emoji: \"\\U0001F50E\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes the AWS SDK locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator AWS account -> read-only AWS SDK calls -> canonical inventory JSON -> agent-bom inventory scan. No agent-bom-hosted service is required. Values matching credential patterns are redacted before persistence/export.\"\n    file_reads: []\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://sts.amazonaws.com\"\n        purpose: \"Caller identity and assumed-role context\"\n        auth: true\n      - url: \"https://bedrock-agent.{region}.amazonaws.com\"\n        purpose: \"Bedrock agent inventory\"\n        auth: true\n      - url: \"https://ecs.{region}.amazonaws.com\"\n        purpose: \"ECS workload inventory when enabled\"\n        auth: true\n      - url: \"https://sagemaker.{region}.amazonaws.com\"\n        purpose: \"SageMaker inventory when enabled\"\n        auth: true\n      - url: \"https://lambda.{region}.amazonaws.com\"\n        purpose: \"Lambda inventory when enabled\"\n        auth: true\n      - url: \"https://eks.{region}.amazonaws.com\"\n        purpose: \"EKS inventory when enabled\"\n        auth: true\n      - url: \"https://states.{region}.amazonaws.com\"\n        purpose: \"Step Functions inventory when enabled\"\n        auth: true\n      - url: \"https://ec2.{region}.amazonaws.com\"\n        purpose: \"EC2 inventory when enabled\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-aws\n\nUse this skill to collect AWS AI and workload inventory from the operator's\nenvironment as canonical inventory. The skill is discover-only by default:\nwrite schema-valid JSON to an operator-selected path and stop. Run\n`agent-bom` only when the operator explicitly wants findings, graph, policy,\nor exports from that inventory.\n\n## Guardrails\n\n- Use only operator-approved AWS profiles, roles, or short-lived STS sessions.\n- Prefer read-only IAM actions listed by `agent-bom trust` or\n  `/v1/discovery/providers`.\n- Do not request or display raw `AWS_ACCESS_KEY_ID`,\n  `AWS_SECRET_ACCESS_KEY`, `AWS_SESSION_TOKEN`, or bearer tokens.\n- Do not modify AWS resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; only the schema-validated\n  inventory JSON is evidence.\n\n## Modes\n\n| Mode | What happens | Data boundary |\n|------|--------------|---------------|\n| `discover-only` | Emit canonical inventory JSON and stop | No agent-bom scan or API handoff |\n| `scan-local` | Run `agent-bom scan --inventory ...` on the generated file | Local handoff into the scanner |\n| `export` | Write JSON/SARIF or another operator-selected output | Local output only unless the operator routes it elsewhere |\n\nUse `discover-only` unless the operator asks for scan results or an export.\n\n## Workflow\n\n1. Confirm the AWS account/region/profile and intended services.\n2. Generate inventory with the repository adapter and stop:\n\n```bash\npython examples/operator_pull/aws_inventory_adapter.py \\\n  --region us-east-1 \\\n  --profile readonly-audit \\\n  --source aws-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output aws-inventory.json\n```\n\n3. If the operator asks for findings, scan the generated inventory locally:\n\n```bash\nagent-bom scan --inventory aws-inventory.json\n```\n\n4. If the operator asks for an export, write it to an operator-selected path:\n\n```bash\nagent-bom scan --inventory aws-inventory.json --format json --output agent-bom-aws-findings.json\n```\n\n## Optional Service Flags\n\nStart narrow, then expand deliberately:\n\n```bash\npython examples/operator_pull/aws_inventory_adapter.py \\\n  --region us-east-1 \\\n  --profile readonly-audit \\\n  --source aws-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --include-ecs \\\n  --include-lambda \\\n  --include-eks \\\n  --output aws-inventory.json\n```\n\nUse `--no-include-ecs` or similar flags to disable default services when an\noperator wants a smaller scope.\n\n## Evidence Contract\n\nThe inventory emitted by this skill uses:\n\n- `source: aws-skill-invoked`\n- `discovery_provenance.source_type: skill_invoked_pull`\n- `discovery_provenance.observed_via: skill_invoked_pull, aws_sdk`\n- sanitized `metadata.permissions_used`\n- sanitized `cloud_origin`, `cloud_principal`, lifecycle fields, packages, and\n  MCP server launch metadata\n\nIf schema validation fails, stop and fix the inventory instead of scanning a\nbest-effort or prose summary.\n\nThe skill does not push inventory to an API by default. Any push, scan, or\nmanaged control-plane handoff must be a separate operator-approved handoff\ncommand with the destination URL, auth method, and retained evidence classes\nmade explicit.\n\nFile v0.103.2:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-aws\",\n  \"version\": \"0.103.2\",\n  \"publishedAt\": 1788333878628\n}\n\nFile v0.103.2:skill-card.md\n\n## Description:\n\nDiscover AWS-hosted AI agent and MCP-relevant assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving agent-bom long-lived cloud credentials.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, security engineers, and cloud operators use this skill to inventory AWS Bedrock, ECS, SageMaker, Lambda, EKS, Step Functions, EC2, and related agentic infrastructure as canonical agent-bom JSON. The workflow supports local scanning and exports only when the operator explicitly asks for those follow-on actions.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can inventory AWS environments through authenticated AWS SDK calls.\n\nMitigation: Use only operator-approved read-only short-lived AWS profiles or assumed roles for AWS accounts and regions the operator intends to inventory.\n\nRisk: Generated inventory can contain sensitive infrastructure details even when credential-like values are redacted.\n\nMitigation: Write inventory only to an operator-selected path, review it before sharing, and require explicit approval before any scan export or remote handoff.\n\nRisk: Optional local scans and exports can broaden where inventory evidence is stored.\n\nMitigation: Default to discover-only mode and run scan, export, push, or managed handoff commands only after the operator explicitly requests them.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/msaad00/skills/agent-bom-discover-aws)\n- [agent-bom source](https://github.com/msaad00/agent-bom)\n- [agent-bom PyPI package](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [guidance, shell commands, configuration, json]\n\n**Output Format:** [Markdown guidance with bash command examples and operator-selected JSON inventory or scan output files]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Requires Python 3.11+, agent-bom, and operator-controlled AWS credentials; inventory files are written only to operator-selected paths.]\n\n## Skill Version(s):\n\n0.103.2 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.","readmeExcerpt":"Skill: agent-bom discover aws Owner: msaad00 Summary: Discover AWS-hosted AI agent and MCP-relevant assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving agent-bom long-lived cloud credentials. Use when a user asks to inventory AWS Bedrock, ECS, SageMaker, Lambda, EKS, Step Functions, EC2, or agentic AWS infrastructure as canonical inventory. Passing that inventor","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"python examples/operator_pull/aws_inventory_adapter.py \\\n  --region us-east-1 \\\n  --profile readonly-audit \\\n  --source aws-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output aws-inventory.json"},{"language":"bash","snippet":"agent-bom scan --inventory aws-inventory.json"},{"language":"bash","snippet":"agent-bom scan --inventory aws-inventory.json --format json --output agent-bom-aws-findings.json"},{"language":"bash","snippet":"python examples/operator_pull/aws_inventory_adapter.py \\\n  --region us-east-1 \\\n  --profile readonly-audit \\\n  --source aws-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --include-ecs \\\n  --include-lambda \\\n  --include-eks \\\n  --output aws-inventory.json"},{"language":"bash","snippet":"python examples/operator_pull/aws_inventory_adapter.py \\\n  --region us-east-1 \\\n  --profile readonly-audit \\\n  --source aws-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output aws-inventory.json"},{"language":"bash","snippet":"agent-bom scan --inventory aws-inventory.json"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: agent-bom-discover-aws\ndescription: >-\n  Discover AWS-hosted AI agent and MCP-relevant assets from the operator's\n  environment, emit canonical agent-bom inventory JSON, and scan it without\n  giving agent-bom long-lived cloud credentials. Use when a user asks to\n  inventory AWS Bedrock, ECS, SageMaker, Lambda, EKS, Step Functions, EC2, or\n  agentic AWS infrastructure as canonical inventory. Passing that inventory\n  to agent-bom is optional and operator-chosen.\nversion: 0.108.3\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed from this repository or PyPI, and\n  operator-controlled AWS credentials from AWS SSO, WebIdentity, or STS. Prefer\n  short-lived credentials and read-only IAM policy scope.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: aws-read-only\n    credential_policy: \"Use the operator's existing AWS SDK credential chain. Prefer AWS SSO, WebIdentity, or STS assumed-role credentials. Do not ask users to paste access keys. Do not print credential values.\"\n    optional_env:\n      - AWS_PROFILE\n      - AWS_REGION\n      - AWS_DEFAULT_REGION\n    optional_bins: []\n    emoji: \"\\U0001F50E\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes the AWS SDK locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator AWS account -> read-only AWS SDK calls -> canonical inventory JSON -> agent-bom inventory scan. No agent-bom-hosted service is required. Values matching credential patterns are redacted before persistence/export.\"\n    file_reads: []\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://sts.amazonaws.com\"\n        purpose: \"Caller identity and assumed-role context\"\n        auth: true\n      - url: \"https://bedrock-agent.{region}.amazonaws.com\"\n        purpose: \"Bedrock agent inventory\"\n        auth: true\n      - url: \"https://ecs.{region}.amazonaws.com\"\n        purpose: \"ECS workload inventory when enabled\"\n        auth: true\n      - url: \"https://sagemaker.{region}.amazonaws.com\"\n        purpose: \"SageMaker inventory when enabled\"\n        auth: true\n      - url: \"https://lambda.{region}.amazonaws.com\"\n        purpose: \"Lambda inventory when enabled\"\n        auth: true\n      - url: \"https://eks.{region}.amazonaws.com\"\n        purpose: \"EKS inventory when enabled\"\n        auth: true\n      - url: \"https://states.{region}.amazonaws.com\"\n        purpose: \"Step Functions invento"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-aws\",\n  \"version\": \"0.108.3\",\n  \"publishedAt\": 1791497905675\n}"},{"path":"skill-card.md","content":"## Description:\n\nHelps operators discover AWS-hosted AI agents and related workloads, produce canonical inventory JSON, and optionally scan that inventory with agent-bom.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and cloud operators use this skill to inventory AI agents and workloads in approved AWS accounts and regions. They can optionally request local agent-bom findings or exports after reviewing the generated inventory.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: AWS inventory can expose sensitive cloud architecture when shared or exported.\n\nMitigation: Review inventory before sharing or exporting it and keep generated files at an operator-selected location.\n\nRisk: Broad AWS credentials or unintended account and region selection could expand the inventory scope.\n\nMitigation: Use a read-only profile or short-lived assumed role, and confirm the account, regions, and services before discovery.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/msaad00/skills/agent-bom-discover-aws)\n- [Project homepage (declared in skill metadata; source provenance unavailable)](https://github.com/msaad00/agent-bom)\n- [agent-bom on PyPI](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Guidance, JSON inventory]\n\n**Output Format:** [Markdown guidance and shell commands; canonical JSON inventory file when executed]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Discovery-only by default; local scans and JSON or SARIF exports require operator approval.]\n\n## Skill Version(s):\n\n0.108.3 (source: skill frontmatter and ClawHub release)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1134,"uniquenessScore":42,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T05:26:13.126Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T05:26:13.126Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T17:23:17.970Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}