{"id":"8847c9b9-48e2-4ae6-8a60-b49c890d9707","entityType":"agent","slug":"clawhub-msaad00-agent-bom-discover-gcp","name":"agent-bom discover gcp","canonicalUrl":"https://www.xpersona.co/agent/clawhub-msaad00-agent-bom-discover-gcp","canonicalPath":"/agent/clawhub-msaad00-agent-bom-discover-gcp","generatedAt":"2026-10-10T02:05:04.055Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:22:48.075Z","emptyReason":null},"description":"Discover GCP-hosted AI agent and MCP-relevant assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving agent-bom long-lived GCP credentials. Use when a user asks to inventory Vertex AI, Cloud Run, Cloud Functions, GKE, or agentic GCP infrastructure as canonical inventory.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 4.5K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom-discover-gcp","sourceUrl":"https://clawhub.ai/msaad00/agent-bom-discover-gcp","homepage":"https://clawhub.ai/msaad00/skills/agent-bom-discover-gcp","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/msaad00/agent-bom-discover-gcp","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/msaad00/skills/agent-bom-discover-gcp","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":73,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"agent-bom discover gcp technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:22:48.075Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:22:48.075Z","emptyReason":null},"stars":null,"forks":null,"downloads":4458,"packageName":null,"latestVersion":"0.108.3","tractionLabel":"4.5K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:22:48.046Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T05:22:48.075Z","lastCrawledAt":"2026-10-09T05:22:48.046Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T05:22:48.046Z","lastVerifiedAt":null,"highlights":[{"version":"0.108.3","createdAt":"2026-10-08T22:18:51.440Z","changelog":"Release v0.108.3","fileCount":3,"zipByteSize":3152},{"version":"0.108.2","createdAt":"2026-10-08T05:02:06.602Z","changelog":"Release v0.108.2","fileCount":3,"zipByteSize":3231},{"version":"0.108.1","createdAt":"2026-10-06T17:48:29.462Z","changelog":"Release v0.108.1","fileCount":3,"zipByteSize":3153},{"version":"0.108.0","createdAt":"2026-10-04T07:13:26.101Z","changelog":"Release v0.108.0","fileCount":3,"zipByteSize":3340},{"version":"0.107.2","createdAt":"2026-10-01T23:33:01.064Z","changelog":"Release v0.107.2","fileCount":3,"zipByteSize":3248},{"version":"0.107.0","createdAt":"2026-09-30T20:18:56.281Z","changelog":"Release v0.107.0","fileCount":3,"zipByteSize":3126},{"version":"0.106.1","createdAt":"2026-09-27T00:19:14.800Z","changelog":"Release v0.106.1","fileCount":3,"zipByteSize":3146},{"version":"0.105.0","createdAt":"2026-09-18T11:12:08.932Z","changelog":"Release v0.105.0","fileCount":3,"zipByteSize":3329}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom-discover-gcp","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom-discover-gcp` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/msaad00/agent-bom-discover-gcp before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-gcp/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-gcp/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-gcp/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-gcp/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-gcp/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-gcp/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T02:05:04.054Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-gcp/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-gcp/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-gcp/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-gcp/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:22:48.075Z","emptyReason":null},"readme":"Skill: agent-bom discover gcp\n\nOwner: msaad00\n\nSummary: Discover GCP-hosted AI agent and MCP-relevant assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving agent-bom long-lived GCP credentials. Use when a user asks to inventory Vertex AI, Cloud Run, Cloud Functions, GKE, or agentic GCP infrastructure as canonical inventory.\n\nTags: latest:0.108.3\n\nVersion history:\n\nv0.108.3 | 2026-10-08T22:18:51.440Z | user\n\nRelease v0.108.3\n\nv0.108.2 | 2026-10-08T05:02:06.602Z | user\n\nRelease v0.108.2\n\nv0.108.1 | 2026-10-06T17:48:29.462Z | user\n\nRelease v0.108.1\n\nv0.108.0 | 2026-10-04T07:13:26.101Z | user\n\nRelease v0.108.0\n\nv0.107.2 | 2026-10-01T23:33:01.064Z | user\n\nRelease v0.107.2\n\nv0.107.0 | 2026-09-30T20:18:56.281Z | user\n\nRelease v0.107.0\n\nv0.106.1 | 2026-09-27T00:19:14.800Z | user\n\nRelease v0.106.1\n\nv0.105.0 | 2026-09-18T11:12:08.932Z | user\n\nRelease v0.105.0\n\nv0.104.0 | 2026-09-09T20:57:03.180Z | user\n\nRelease v0.104.0\n\nv0.103.2 | 2026-09-02T07:25:08.047Z | user\n\nRelease v0.103.2\n\nv0.102.0 | 2026-08-24T04:50:58.450Z | user\n\nRelease v0.102.0\n\nv0.101.0 | 2026-08-16T23:14:00.188Z | user\n\nRelease v0.101.0\n\nv0.100.0 | 2026-08-12T20:55:54.612Z | user\n\nRelease v0.100.0\n\nv0.99.0 | 2026-08-06T00:53:30.562Z | user\n\nRelease v0.99.0\n\nv0.98.3 | 2026-08-03T06:09:40.047Z | user\n\nRelease v0.98.3\n\nv0.98.2 | 2026-07-27T08:50:41.765Z | user\n\nRelease v0.98.2\n\nv0.98.1 | 2026-07-27T02:02:42.863Z | user\n\nRelease v0.98.1\n\nv0.98.0 | 2026-07-25T01:52:01.607Z | user\n\nRelease v0.98.0\n\nv0.97.5 | 2026-07-24T01:44:08.858Z | user\n\nRelease v0.97.5\n\nv0.97.4 | 2026-07-23T00:59:49.240Z | user\n\nRelease v0.97.4\n\nv0.97.2 | 2026-07-21T18:19:44.992Z | user\n\nRelease v0.97.2\n\nv0.97.1 | 2026-07-21T03:32:14.698Z | user\n\nRelease v0.97.1\n\nv0.97.0 | 2026-07-20T18:11:24.738Z | user\n\nRelease v0.97.0\n\nv0.96.4 | 2026-07-20T15:06:21.071Z | user\n\nRelease v0.96.4\n\nv0.96.3 | 2026-07-16T04:06:07.713Z | user\n\nRelease v0.96.3\n\nv0.96.2 | 2026-07-15T23:05:49.396Z | user\n\nRelease v0.96.2\n\nv0.95.0 | 2026-07-13T21:39:00.723Z | user\n\nRelease v0.95.0\n\nv0.94.2 | 2026-07-09T18:25:06.446Z | user\n\nRelease v0.94.2\n\nv0.94.1 | 2026-07-09T05:51:20.522Z | user\n\nRelease v0.94.1\n\nv0.94.0 | 2026-07-08T21:48:35.727Z | user\n\nRelease v0.94.0\n\nv0.93.0 | 2026-07-06T07:43:25.084Z | user\n\nRelease v0.93.0\n\nv0.91.0 | 2026-06-30T23:36:59.200Z | user\n\nRelease v0.91.0\n\nv0.90.0 | 2026-06-30T03:48:14.787Z | user\n\nRelease v0.90.0\n\nv0.89.2 | 2026-06-22T03:18:13.567Z | user\n\nRelease v0.89.2\n\nv0.88.5 | 2026-06-01T06:24:14.356Z | user\n\nRelease v0.88.5\n\nv0.88.4 | 2026-05-26T04:20:41.496Z | user\n\nRelease v0.88.4\n\nv0.88.3 | 2026-05-25T00:57:47.979Z | user\n\nRelease v0.88.3\n\nv0.88.1 | 2026-05-22T04:38:46.257Z | user\n\nRelease v0.88.1\n\nv0.87.1 | 2026-05-18T20:26:03.775Z | user\n\nRelease v0.87.1\n\nv0.87.0 | 2026-05-18T00:37:11.579Z | user\n\nRelease v0.87.0\n\nv0.86.5 | 2026-05-11T16:16:20.004Z | user\n\nRelease v0.86.5\n\nv0.86.2 | 2026-05-07T15:45:31.486Z | user\n\nRelease v0.86.2\n\nv0.86.1 | 2026-05-06T06:42:39.648Z | user\n\nRelease v0.86.1\n\nv0.85.0 | 2026-05-02T22:49:04.002Z | user\n\nRelease v0.85.0\n\nv0.84.6 | 2026-05-02T06:44:27.307Z | user\n\nRelease v0.84.6\n\nv0.84.5 | 2026-05-02T03:29:33.157Z | user\n\nRelease v0.84.5\n\nv0.84.4 | 2026-05-01T19:07:56.868Z | user\n\nRelease v0.84.4\n\nv0.84.0 | 2026-05-01T01:53:49.900Z | user\n\nRelease v0.84.0\n\nArchive index:\n\nArchive v0.108.3: 3 files, 3152 bytes\n\nFiles: skill-card.md (1772b), SKILL.md (4394b), _meta.json (143b)\n\nFile v0.108.3:SKILL.md\n\n---\nname: agent-bom-discover-gcp\ndescription: >-\n  Discover GCP-hosted AI agent and MCP-relevant assets from the operator's\n  environment, emit canonical agent-bom inventory JSON, and scan it without\n  giving agent-bom long-lived GCP credentials. Use when a user asks to\n  inventory Vertex AI, Cloud Run, Cloud Functions, GKE, or agentic GCP\n  infrastructure as canonical inventory.\nversion: 0.108.3\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed from this repository or PyPI, and\n  operator-controlled GCP read-only credentials from ADC, workload identity, or\n  a scoped service account.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: gcp-read-only\n    credential_policy: \"Use the operator's existing Application Default Credentials, workload identity, or short-lived service account credentials. Do not ask users to paste service account JSON into chat. Do not print credential values.\"\n    optional_env:\n      - GOOGLE_APPLICATION_CREDENTIALS\n      - GOOGLE_CLOUD_PROJECT\n      - CLOUDSDK_CONFIG\n    optional_bins:\n      - gcloud\n    emoji: \"search\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes GCP SDK discovery locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator GCP project -> read-only Google API calls -> canonical inventory JSON -> optional local agent-bom inventory scan. No agent-bom-hosted service is required. Credential-like values are redacted before persistence/export.\"\n    file_reads:\n      - \"~/.config/gcloud/configurations/config_default\"\n      - \"~/.config/gcloud/application_default_credentials.json\"\n      - \"~/.config/gcloud/credentials.db\"\n      - \"operator-selected service account JSON when GOOGLE_APPLICATION_CREDENTIALS is set\"\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://cloudresourcemanager.googleapis.com\"\n        purpose: \"Project and resource inventory\"\n        auth: true\n      - url: \"https://aiplatform.googleapis.com\"\n        purpose: \"Vertex AI inventory\"\n        auth: true\n      - url: \"https://run.googleapis.com\"\n        purpose: \"Cloud Run inventory\"\n        auth: true\n      - url: \"https://cloudfunctions.googleapis.com\"\n        purpose: \"Cloud Functions inventory\"\n        auth: true\n      - url: \"https://container.googleapis.com\"\n        purpose: \"GKE inventory\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-gcp\n\nUse this skill to collect GCP AI and workload inventory as schema-valid\nagent-bom inventory. Default to discover-only: write JSON to an\noperator-selected path and stop.\n\n## Guardrails\n\n- Use only operator-approved projects and read-only credentials.\n- Do not request or display service account private keys, OAuth refresh tokens,\n  or bearer tokens.\n- Do not modify GCP resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; schema-validated inventory JSON\n  is the evidence.\n\n## Workflow\n\n```bash\npython examples/operator_pull/gcp_inventory_adapter.py \\\n  --project \"$GOOGLE_CLOUD_PROJECT\" \\\n  --region us-central1 \\\n  --source gcp-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output gcp-inventory.json\n```\n\nScan only when the operator asks for findings:\n\n```bash\nagent-bom scan --inventory gcp-inventory.json --format json --output agent-bom-gcp-findings.json\n```\n\n## Evidence Contract\n\nThe emitted inventory carries `discovery_provenance.source_type:\nskill_invoked_pull`, `observed_via: skill_invoked_pull, gcp_sdk`, sanitized\n`metadata.permissions_used`, and redacted credential material. If schema\nvalidation fails, stop and fix the inventory instead of scanning a best-effort\nsummary.\n\nFile v0.108.3:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-gcp\",\n  \"version\": \"0.108.3\",\n  \"publishedAt\": 1791497931440\n}\n\nFile v0.108.3:skill-card.md\n\n## Description:\n\nDiscovers GCP-hosted AI and workload assets and produces canonical agent-bom inventory JSON for optional local scanning.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and cloud operators use this skill to inventory AI agents and related resources in approved GCP projects, then optionally scan that inventory for findings.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: GCP discovery uses the operator's authentication context.\n\nMitigation: Use approved projects and least-privilege read-only credentials; never paste or print credential values.\n\nRisk: Generated inventory may contain sensitive resource metadata.\n\nMitigation: Choose the output path deliberately and review the inventory before sharing it.\n\n## Reference(s):\n\n- [agent-bom project homepage (skill metadata)](https://github.com/msaad00/agent-bom)\n- [agent-bom PyPI package](https://pypi.org/project/agent-bom/)\n- [ClawHub skill release](https://clawhub.ai/msaad00/skills/agent-bom-discover-gcp)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Files]\n\n**Output Format:** [JSON inventory; optional JSON scan findings]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Inventory is saved to an operator-selected path; scanning occurs only on request.]\n\n## Skill Version(s):\n\n0.108.3 (source: release metadata and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.108.2: 3 files, 3231 bytes\n\nFiles: skill-card.md (1944b), SKILL.md (4394b), _meta.json (143b)\n\nFile v0.108.2:SKILL.md\n\n---\nname: agent-bom-discover-gcp\ndescription: >-\n  Discover GCP-hosted AI agent and MCP-relevant assets from the operator's\n  environment, emit canonical agent-bom inventory JSON, and scan it without\n  giving agent-bom long-lived GCP credentials. Use when a user asks to\n  inventory Vertex AI, Cloud Run, Cloud Functions, GKE, or agentic GCP\n  infrastructure as canonical inventory.\nversion: 0.108.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed from this repository or PyPI, and\n  operator-controlled GCP read-only credentials from ADC, workload identity, or\n  a scoped service account.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: gcp-read-only\n    credential_policy: \"Use the operator's existing Application Default Credentials, workload identity, or short-lived service account credentials. Do not ask users to paste service account JSON into chat. Do not print credential values.\"\n    optional_env:\n      - GOOGLE_APPLICATION_CREDENTIALS\n      - GOOGLE_CLOUD_PROJECT\n      - CLOUDSDK_CONFIG\n    optional_bins:\n      - gcloud\n    emoji: \"search\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes GCP SDK discovery locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator GCP project -> read-only Google API calls -> canonical inventory JSON -> optional local agent-bom inventory scan. No agent-bom-hosted service is required. Credential-like values are redacted before persistence/export.\"\n    file_reads:\n      - \"~/.config/gcloud/configurations/config_default\"\n      - \"~/.config/gcloud/application_default_credentials.json\"\n      - \"~/.config/gcloud/credentials.db\"\n      - \"operator-selected service account JSON when GOOGLE_APPLICATION_CREDENTIALS is set\"\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://cloudresourcemanager.googleapis.com\"\n        purpose: \"Project and resource inventory\"\n        auth: true\n      - url: \"https://aiplatform.googleapis.com\"\n        purpose: \"Vertex AI inventory\"\n        auth: true\n      - url: \"https://run.googleapis.com\"\n        purpose: \"Cloud Run inventory\"\n        auth: true\n      - url: \"https://cloudfunctions.googleapis.com\"\n        purpose: \"Cloud Functions inventory\"\n        auth: true\n      - url: \"https://container.googleapis.com\"\n        purpose: \"GKE inventory\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-gcp\n\nUse this skill to collect GCP AI and workload inventory as schema-valid\nagent-bom inventory. Default to discover-only: write JSON to an\noperator-selected path and stop.\n\n## Guardrails\n\n- Use only operator-approved projects and read-only credentials.\n- Do not request or display service account private keys, OAuth refresh tokens,\n  or bearer tokens.\n- Do not modify GCP resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; schema-validated inventory JSON\n  is the evidence.\n\n## Workflow\n\n```bash\npython examples/operator_pull/gcp_inventory_adapter.py \\\n  --project \"$GOOGLE_CLOUD_PROJECT\" \\\n  --region us-central1 \\\n  --source gcp-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output gcp-inventory.json\n```\n\nScan only when the operator asks for findings:\n\n```bash\nagent-bom scan --inventory gcp-inventory.json --format json --output agent-bom-gcp-findings.json\n```\n\n## Evidence Contract\n\nThe emitted inventory carries `discovery_provenance.source_type:\nskill_invoked_pull`, `observed_via: skill_invoked_pull, gcp_sdk`, sanitized\n`metadata.permissions_used`, and redacted credential material. If schema\nvalidation fails, stop and fix the inventory instead of scanning a best-effort\nsummary.\n\nFile v0.108.2:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-gcp\",\n  \"version\": \"0.108.2\",\n  \"publishedAt\": 1791435726602\n}\n\nFile v0.108.2:skill-card.md\n\n## Description:\n\nDiscovers GCP-hosted AI agent and MCP-relevant assets and produces canonical agent-bom inventory JSON for optional scanning.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and cloud operators inventory AI and workload assets in approved GCP projects, then optionally request agent-bom findings from the saved inventory.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Existing GCP authentication can access resources beyond the intended inventory scope.\n\nMitigation: Use read-only credentials limited to operator-approved projects.\n\nRisk: Inventory may be written to an unintended location or shared without review.\n\nMitigation: Verify the operator-selected output path and review inventory before sharing it.\n\nRisk: The workflow depends on separately installed agent-bom tooling.\n\nMitigation: Review the agent-bom package or source before installing or running it.\n\n## Reference(s):\n\n- [agent-bom project homepage (skill metadata)](https://github.com/msaad00/agent-bom)\n- [agent-bom on PyPI](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, JSON inventory, JSON findings on request]\n\n**Output Format:** [Markdown guidance and shell commands; canonical JSON inventory and optional JSON findings]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Inventory is schema-validated and credential material is redacted; scanning requires an explicit request.]\n\n## Skill Version(s):\n\n0.108.2 (source: ClawHub release and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.108.1: 3 files, 3153 bytes\n\nFiles: skill-card.md (1805b), SKILL.md (4394b), _meta.json (143b)\n\nFile v0.108.1:SKILL.md\n\n---\nname: agent-bom-discover-gcp\ndescription: >-\n  Discover GCP-hosted AI agent and MCP-relevant assets from the operator's\n  environment, emit canonical agent-bom inventory JSON, and scan it without\n  giving agent-bom long-lived GCP credentials. Use when a user asks to\n  inventory Vertex AI, Cloud Run, Cloud Functions, GKE, or agentic GCP\n  infrastructure as canonical inventory.\nversion: 0.108.1\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed from this repository or PyPI, and\n  operator-controlled GCP read-only credentials from ADC, workload identity, or\n  a scoped service account.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: gcp-read-only\n    credential_policy: \"Use the operator's existing Application Default Credentials, workload identity, or short-lived service account credentials. Do not ask users to paste service account JSON into chat. Do not print credential values.\"\n    optional_env:\n      - GOOGLE_APPLICATION_CREDENTIALS\n      - GOOGLE_CLOUD_PROJECT\n      - CLOUDSDK_CONFIG\n    optional_bins:\n      - gcloud\n    emoji: \"search\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes GCP SDK discovery locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator GCP project -> read-only Google API calls -> canonical inventory JSON -> optional local agent-bom inventory scan. No agent-bom-hosted service is required. Credential-like values are redacted before persistence/export.\"\n    file_reads:\n      - \"~/.config/gcloud/configurations/config_default\"\n      - \"~/.config/gcloud/application_default_credentials.json\"\n      - \"~/.config/gcloud/credentials.db\"\n      - \"operator-selected service account JSON when GOOGLE_APPLICATION_CREDENTIALS is set\"\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://cloudresourcemanager.googleapis.com\"\n        purpose: \"Project and resource inventory\"\n        auth: true\n      - url: \"https://aiplatform.googleapis.com\"\n        purpose: \"Vertex AI inventory\"\n        auth: true\n      - url: \"https://run.googleapis.com\"\n        purpose: \"Cloud Run inventory\"\n        auth: true\n      - url: \"https://cloudfunctions.googleapis.com\"\n        purpose: \"Cloud Functions inventory\"\n        auth: true\n      - url: \"https://container.googleapis.com\"\n        purpose: \"GKE inventory\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-gcp\n\nUse this skill to collect GCP AI and workload inventory as schema-valid\nagent-bom inventory. Default to discover-only: write JSON to an\noperator-selected path and stop.\n\n## Guardrails\n\n- Use only operator-approved projects and read-only credentials.\n- Do not request or display service account private keys, OAuth refresh tokens,\n  or bearer tokens.\n- Do not modify GCP resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; schema-validated inventory JSON\n  is the evidence.\n\n## Workflow\n\n```bash\npython examples/operator_pull/gcp_inventory_adapter.py \\\n  --project \"$GOOGLE_CLOUD_PROJECT\" \\\n  --region us-central1 \\\n  --source gcp-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output gcp-inventory.json\n```\n\nScan only when the operator asks for findings:\n\n```bash\nagent-bom scan --inventory gcp-inventory.json --format json --output agent-bom-gcp-findings.json\n```\n\n## Evidence Contract\n\nThe emitted inventory carries `discovery_provenance.source_type:\nskill_invoked_pull`, `observed_via: skill_invoked_pull, gcp_sdk`, sanitized\n`metadata.permissions_used`, and redacted credential material. If schema\nvalidation fails, stop and fix the inventory instead of scanning a best-effort\nsummary.\n\nFile v0.108.1:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-gcp\",\n  \"version\": \"0.108.1\",\n  \"publishedAt\": 1791308909462\n}\n\nFile v0.108.1:skill-card.md\n\n## Description:\n\nDiscovers GCP-hosted AI agent and MCP-related assets in approved projects and produces canonical agent-bom inventory JSON for optional scanning.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and cloud operators use this skill to inventory AI agents and related workloads across approved GCP projects, then optionally scan the resulting inventory with agent-bom.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Existing GCP credentials may expose resources outside the intended inventory scope.\n\nMitigation: Use scoped, read-only credentials and inventory only operator-approved projects.\n\nRisk: Generated inventory may contain sensitive cloud resource metadata.\n\nMitigation: Choose the output path yourself and review inventory before sharing it.\n\n## Reference(s):\n\n- [agent-bom project homepage (skill metadata)](https://github.com/msaad00/agent-bom)\n- [agent-bom package (skill metadata)](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, JSON inventory, Guidance]\n\n**Output Format:** [Markdown guidance with shell commands; canonical JSON inventory when executed]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Writes inventory to an operator-selected path; produces scan findings only on request.]\n\n## Skill Version(s):\n\n0.108.1 (source: skill frontmatter and ClawHub release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.108.0: 3 files, 3340 bytes\n\nFiles: skill-card.md (2253b), SKILL.md (4394b), _meta.json (143b)\n\nFile v0.108.0:SKILL.md\n\n---\nname: agent-bom-discover-gcp\ndescription: >-\n  Discover GCP-hosted AI agent and MCP-relevant assets from the operator's\n  environment, emit canonical agent-bom inventory JSON, and scan it without\n  giving agent-bom long-lived GCP credentials. Use when a user asks to\n  inventory Vertex AI, Cloud Run, Cloud Functions, GKE, or agentic GCP\n  infrastructure as canonical inventory.\nversion: 0.108.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed from this repository or PyPI, and\n  operator-controlled GCP read-only credentials from ADC, workload identity, or\n  a scoped service account.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: gcp-read-only\n    credential_policy: \"Use the operator's existing Application Default Credentials, workload identity, or short-lived service account credentials. Do not ask users to paste service account JSON into chat. Do not print credential values.\"\n    optional_env:\n      - GOOGLE_APPLICATION_CREDENTIALS\n      - GOOGLE_CLOUD_PROJECT\n      - CLOUDSDK_CONFIG\n    optional_bins:\n      - gcloud\n    emoji: \"search\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes GCP SDK discovery locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator GCP project -> read-only Google API calls -> canonical inventory JSON -> optional local agent-bom inventory scan. No agent-bom-hosted service is required. Credential-like values are redacted before persistence/export.\"\n    file_reads:\n      - \"~/.config/gcloud/configurations/config_default\"\n      - \"~/.config/gcloud/application_default_credentials.json\"\n      - \"~/.config/gcloud/credentials.db\"\n      - \"operator-selected service account JSON when GOOGLE_APPLICATION_CREDENTIALS is set\"\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://cloudresourcemanager.googleapis.com\"\n        purpose: \"Project and resource inventory\"\n        auth: true\n      - url: \"https://aiplatform.googleapis.com\"\n        purpose: \"Vertex AI inventory\"\n        auth: true\n      - url: \"https://run.googleapis.com\"\n        purpose: \"Cloud Run inventory\"\n        auth: true\n      - url: \"https://cloudfunctions.googleapis.com\"\n        purpose: \"Cloud Functions inventory\"\n        auth: true\n      - url: \"https://container.googleapis.com\"\n        purpose: \"GKE inventory\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-gcp\n\nUse this skill to collect GCP AI and workload inventory as schema-valid\nagent-bom inventory. Default to discover-only: write JSON to an\noperator-selected path and stop.\n\n## Guardrails\n\n- Use only operator-approved projects and read-only credentials.\n- Do not request or display service account private keys, OAuth refresh tokens,\n  or bearer tokens.\n- Do not modify GCP resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; schema-validated inventory JSON\n  is the evidence.\n\n## Workflow\n\n```bash\npython examples/operator_pull/gcp_inventory_adapter.py \\\n  --project \"$GOOGLE_CLOUD_PROJECT\" \\\n  --region us-central1 \\\n  --source gcp-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output gcp-inventory.json\n```\n\nScan only when the operator asks for findings:\n\n```bash\nagent-bom scan --inventory gcp-inventory.json --format json --output agent-bom-gcp-findings.json\n```\n\n## Evidence Contract\n\nThe emitted inventory carries `discovery_provenance.source_type:\nskill_invoked_pull`, `observed_via: skill_invoked_pull, gcp_sdk`, sanitized\n`metadata.permissions_used`, and redacted credential material. If schema\nvalidation fails, stop and fix the inventory instead of scanning a best-effort\nsummary.\n\nFile v0.108.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-gcp\",\n  \"version\": \"0.108.0\",\n  \"publishedAt\": 1791098006101\n}\n\nFile v0.108.0:skill-card.md\n\n## Description:\n\nDiscovers GCP-hosted AI agent and workload assets using operator-controlled read-only credentials and produces sanitized agent-bom inventory JSON for optional scanning.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and cloud operators use this skill to inventory Vertex AI, Cloud Run, Cloud Functions, GKE, and related agent infrastructure in approved GCP projects, then optionally scan the resulting inventory for findings.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Discovery accesses local GCP credentials and inventories cloud resources.\n\nMitigation: Use only approved projects and scoped, least-privilege read-only credentials; never paste or print credentials.\n\nRisk: Generated inventory may reveal sensitive cloud configuration when shared.\n\nMitigation: Review the sanitized inventory JSON before sharing or scanning it, and write it only to an operator-selected path.\n\nRisk: The example discovery command relies on an external agent-bom installation and project source.\n\nMitigation: Verify the referenced agent-bom dependency and source before running the example command.\n\n## Reference(s):\n\n- [ClawHub skill release](https://clawhub.ai/msaad00/skills/agent-bom-discover-gcp)\n- [agent-bom project homepage (listed in skill metadata; import provenance unavailable)](https://github.com/msaad00/agent-bom)\n- [agent-bom on PyPI](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Guidance, JSON inventory, JSON findings]\n\n**Output Format:** [Markdown instructions and schema-validated JSON files]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Writes sanitized inventory to an operator-selected path; produces JSON scan findings only when requested.]\n\n## Skill Version(s):\n\n0.108.0 (source: ClawHub release and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.107.2: 3 files, 3248 bytes\n\nFiles: skill-card.md (1999b), SKILL.md (4394b), _meta.json (143b)\n\nFile v0.107.2:SKILL.md\n\n---\nname: agent-bom-discover-gcp\ndescription: >-\n  Discover GCP-hosted AI agent and MCP-relevant assets from the operator's\n  environment, emit canonical agent-bom inventory JSON, and scan it without\n  giving agent-bom long-lived GCP credentials. Use when a user asks to\n  inventory Vertex AI, Cloud Run, Cloud Functions, GKE, or agentic GCP\n  infrastructure as canonical inventory.\nversion: 0.107.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed from this repository or PyPI, and\n  operator-controlled GCP read-only credentials from ADC, workload identity, or\n  a scoped service account.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: gcp-read-only\n    credential_policy: \"Use the operator's existing Application Default Credentials, workload identity, or short-lived service account credentials. Do not ask users to paste service account JSON into chat. Do not print credential values.\"\n    optional_env:\n      - GOOGLE_APPLICATION_CREDENTIALS\n      - GOOGLE_CLOUD_PROJECT\n      - CLOUDSDK_CONFIG\n    optional_bins:\n      - gcloud\n    emoji: \"search\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes GCP SDK discovery locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator GCP project -> read-only Google API calls -> canonical inventory JSON -> optional local agent-bom inventory scan. No agent-bom-hosted service is required. Credential-like values are redacted before persistence/export.\"\n    file_reads:\n      - \"~/.config/gcloud/configurations/config_default\"\n      - \"~/.config/gcloud/application_default_credentials.json\"\n      - \"~/.config/gcloud/credentials.db\"\n      - \"operator-selected service account JSON when GOOGLE_APPLICATION_CREDENTIALS is set\"\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://cloudresourcemanager.googleapis.com\"\n        purpose: \"Project and resource inventory\"\n        auth: true\n      - url: \"https://aiplatform.googleapis.com\"\n        purpose: \"Vertex AI inventory\"\n        auth: true\n      - url: \"https://run.googleapis.com\"\n        purpose: \"Cloud Run inventory\"\n        auth: true\n      - url: \"https://cloudfunctions.googleapis.com\"\n        purpose: \"Cloud Functions inventory\"\n        auth: true\n      - url: \"https://container.googleapis.com\"\n        purpose: \"GKE inventory\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-gcp\n\nUse this skill to collect GCP AI and workload inventory as schema-valid\nagent-bom inventory. Default to discover-only: write JSON to an\noperator-selected path and stop.\n\n## Guardrails\n\n- Use only operator-approved projects and read-only credentials.\n- Do not request or display service account private keys, OAuth refresh tokens,\n  or bearer tokens.\n- Do not modify GCP resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; schema-validated inventory JSON\n  is the evidence.\n\n## Workflow\n\n```bash\npython examples/operator_pull/gcp_inventory_adapter.py \\\n  --project \"$GOOGLE_CLOUD_PROJECT\" \\\n  --region us-central1 \\\n  --source gcp-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output gcp-inventory.json\n```\n\nScan only when the operator asks for findings:\n\n```bash\nagent-bom scan --inventory gcp-inventory.json --format json --output agent-bom-gcp-findings.json\n```\n\n## Evidence Contract\n\nThe emitted inventory carries `discovery_provenance.source_type:\nskill_invoked_pull`, `observed_via: skill_invoked_pull, gcp_sdk`, sanitized\n`metadata.permissions_used`, and redacted credential material. If schema\nvalidation fails, stop and fix the inventory instead of scanning a best-effort\nsummary.\n\nFile v0.107.2:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-gcp\",\n  \"version\": \"0.107.2\",\n  \"publishedAt\": 1790897581064\n}\n\nFile v0.107.2:skill-card.md\n\n## Description:\n\nDiscovers GCP-hosted AI agent and MCP-related resources in approved projects and produces canonical agent-bom inventory JSON for optional scanning.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and cloud operators use this skill to inventory AI and workload assets in approved GCP projects, then optionally scan the resulting inventory for findings.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Existing Google Cloud credentials could expose inventory from an unintended project.\n\nMitigation: Use least-privilege read-only credentials and verify the approved project before discovery.\n\nRisk: Generated inventory can contain sensitive resource metadata or be written to the wrong location.\n\nMitigation: Confirm the output path and review the inventory for sensitive metadata before sharing it.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/msaad00/skills/agent-bom-discover-gcp)\n- [Project homepage (listed in skill metadata; import provenance unavailable)](https://github.com/msaad00/agent-bom)\n- [agent-bom on PyPI](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, JSON inventory files, Optional JSON findings]\n\n**Output Format:** [Markdown guidance with shell commands; canonical JSON inventory and optional JSON scan findings]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Discovery only by default; inventory is saved to an operator-selected path and credentials are redacted.]\n\n## Skill Version(s):\n\n0.107.2 (source: ClawHub release and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.107.0: 3 files, 3126 bytes\n\nFiles: skill-card.md (1703b), SKILL.md (4394b), _meta.json (143b)\n\nFile v0.107.0:SKILL.md\n\n---\nname: agent-bom-discover-gcp\ndescription: >-\n  Discover GCP-hosted AI agent and MCP-relevant assets from the operator's\n  environment, emit canonical agent-bom inventory JSON, and scan it without\n  giving agent-bom long-lived GCP credentials. Use when a user asks to\n  inventory Vertex AI, Cloud Run, Cloud Functions, GKE, or agentic GCP\n  infrastructure as canonical inventory.\nversion: 0.107.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed from this repository or PyPI, and\n  operator-controlled GCP read-only credentials from ADC, workload identity, or\n  a scoped service account.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: gcp-read-only\n    credential_policy: \"Use the operator's existing Application Default Credentials, workload identity, or short-lived service account credentials. Do not ask users to paste service account JSON into chat. Do not print credential values.\"\n    optional_env:\n      - GOOGLE_APPLICATION_CREDENTIALS\n      - GOOGLE_CLOUD_PROJECT\n      - CLOUDSDK_CONFIG\n    optional_bins:\n      - gcloud\n    emoji: \"search\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes GCP SDK discovery locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator GCP project -> read-only Google API calls -> canonical inventory JSON -> optional local agent-bom inventory scan. No agent-bom-hosted service is required. Credential-like values are redacted before persistence/export.\"\n    file_reads:\n      - \"~/.config/gcloud/configurations/config_default\"\n      - \"~/.config/gcloud/application_default_credentials.json\"\n      - \"~/.config/gcloud/credentials.db\"\n      - \"operator-selected service account JSON when GOOGLE_APPLICATION_CREDENTIALS is set\"\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://cloudresourcemanager.googleapis.com\"\n        purpose: \"Project and resource inventory\"\n        auth: true\n      - url: \"https://aiplatform.googleapis.com\"\n        purpose: \"Vertex AI inventory\"\n        auth: true\n      - url: \"https://run.googleapis.com\"\n        purpose: \"Cloud Run inventory\"\n        auth: true\n      - url: \"https://cloudfunctions.googleapis.com\"\n        purpose: \"Cloud Functions inventory\"\n        auth: true\n      - url: \"https://container.googleapis.com\"\n        purpose: \"GKE inventory\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-gcp\n\nUse this skill to collect GCP AI and workload inventory as schema-valid\nagent-bom inventory. Default to discover-only: write JSON to an\noperator-selected path and stop.\n\n## Guardrails\n\n- Use only operator-approved projects and read-only credentials.\n- Do not request or display service account private keys, OAuth refresh tokens,\n  or bearer tokens.\n- Do not modify GCP resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; schema-validated inventory JSON\n  is the evidence.\n\n## Workflow\n\n```bash\npython examples/operator_pull/gcp_inventory_adapter.py \\\n  --project \"$GOOGLE_CLOUD_PROJECT\" \\\n  --region us-central1 \\\n  --source gcp-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output gcp-inventory.json\n```\n\nScan only when the operator asks for findings:\n\n```bash\nagent-bom scan --inventory gcp-inventory.json --format json --output agent-bom-gcp-findings.json\n```\n\n## Evidence Contract\n\nThe emitted inventory carries `discovery_provenance.source_type:\nskill_invoked_pull`, `observed_via: skill_invoked_pull, gcp_sdk`, sanitized\n`metadata.permissions_used`, and redacted credential material. If schema\nvalidation fails, stop and fix the inventory instead of scanning a best-effort\nsummary.\n\nFile v0.107.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-gcp\",\n  \"version\": \"0.107.0\",\n  \"publishedAt\": 1790799536281\n}\n\nFile v0.107.0:skill-card.md\n\n## Description:\n\nGuides discovery of GCP-hosted AI and workload assets into agent-bom inventory JSON, with optional local scanning for findings.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and cloud operators use this skill to inventory AI agents and related services in approved GCP projects, then optionally scan the resulting inventory for findings.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Inventory may expose sensitive cloud metadata even after credential values are redacted.\n\nMitigation: Confirm the project, region, credential scope, and output path; use only approved projects and existing read-only credentials, and control access to the inventory file.\n\n## Reference(s):\n\n- [ClawHub skill release](https://clawhub.ai/msaad00/skills/agent-bom-discover-gcp)\n- [agent-bom project homepage](https://github.com/msaad00/agent-bom)\n- [agent-bom on PyPI](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Guidance]\n\n**Output Format:** [Markdown with bash commands]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Discovery writes inventory JSON to an operator-selected path; an optional scan writes findings JSON.]\n\n## Skill Version(s):\n\n0.107.0 (source: skill frontmatter and server release)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.106.1: 3 files, 3146 bytes\n\nFiles: skill-card.md (1780b), SKILL.md (4394b), _meta.json (143b)\n\nFile v0.106.1:SKILL.md\n\n---\nname: agent-bom-discover-gcp\ndescription: >-\n  Discover GCP-hosted AI agent and MCP-relevant assets from the operator's\n  environment, emit canonical agent-bom inventory JSON, and scan it without\n  giving agent-bom long-lived GCP credentials. Use when a user asks to\n  inventory Vertex AI, Cloud Run, Cloud Functions, GKE, or agentic GCP\n  infrastructure as canonical inventory.\nversion: 0.106.1\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed from this repository or PyPI, and\n  operator-controlled GCP read-only credentials from ADC, workload identity, or\n  a scoped service account.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: gcp-read-only\n    credential_policy: \"Use the operator's existing Application Default Credentials, workload identity, or short-lived service account credentials. Do not ask users to paste service account JSON into chat. Do not print credential values.\"\n    optional_env:\n      - GOOGLE_APPLICATION_CREDENTIALS\n      - GOOGLE_CLOUD_PROJECT\n      - CLOUDSDK_CONFIG\n    optional_bins:\n      - gcloud\n    emoji: \"search\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes GCP SDK discovery locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator GCP project -> read-only Google API calls -> canonical inventory JSON -> optional local agent-bom inventory scan. No agent-bom-hosted service is required. Credential-like values are redacted before persistence/export.\"\n    file_reads:\n      - \"~/.config/gcloud/configurations/config_default\"\n      - \"~/.config/gcloud/application_default_credentials.json\"\n      - \"~/.config/gcloud/credentials.db\"\n      - \"operator-selected service account JSON when GOOGLE_APPLICATION_CREDENTIALS is set\"\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://cloudresourcemanager.googleapis.com\"\n        purpose: \"Project and resource inventory\"\n        auth: true\n      - url: \"https://aiplatform.googleapis.com\"\n        purpose: \"Vertex AI inventory\"\n        auth: true\n      - url: \"https://run.googleapis.com\"\n        purpose: \"Cloud Run inventory\"\n        auth: true\n      - url: \"https://cloudfunctions.googleapis.com\"\n        purpose: \"Cloud Functions inventory\"\n        auth: true\n      - url: \"https://container.googleapis.com\"\n        purpose: \"GKE inventory\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-gcp\n\nUse this skill to collect GCP AI and workload inventory as schema-valid\nagent-bom inventory. Default to discover-only: write JSON to an\noperator-selected path and stop.\n\n## Guardrails\n\n- Use only operator-approved projects and read-only credentials.\n- Do not request or display service account private keys, OAuth refresh tokens,\n  or bearer tokens.\n- Do not modify GCP resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; schema-validated inventory JSON\n  is the evidence.\n\n## Workflow\n\n```bash\npython examples/operator_pull/gcp_inventory_adapter.py \\\n  --project \"$GOOGLE_CLOUD_PROJECT\" \\\n  --region us-central1 \\\n  --source gcp-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output gcp-inventory.json\n```\n\nScan only when the operator asks for findings:\n\n```bash\nagent-bom scan --inventory gcp-inventory.json --format json --output agent-bom-gcp-findings.json\n```\n\n## Evidence Contract\n\nThe emitted inventory carries `discovery_provenance.source_type:\nskill_invoked_pull`, `observed_via: skill_invoked_pull, gcp_sdk`, sanitized\n`metadata.permissions_used`, and redacted credential material. If schema\nvalidation fails, stop and fix the inventory instead of scanning a best-effort\nsummary.\n\nFile v0.106.1:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-gcp\",\n  \"version\": \"0.106.1\",\n  \"publishedAt\": 1790468354800\n}\n\nFile v0.106.1:skill-card.md\n\n## Description:\n\nDiscovers GCP-hosted AI agent and MCP-relevant assets in approved projects and produces canonical agent-bom inventory JSON for optional scanning.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and cloud operators use this skill to inventory AI agents and related workloads in approved GCP projects, then optionally scan the inventory with agent-bom.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Existing GCP authentication can expose inventory from unintended projects.\n\nMitigation: Use scoped read-only credentials and confirm the approved project before discovery.\n\nRisk: Generated inventory may contain sensitive resource details if shared.\n\nMitigation: Confirm the output path and review the sanitized inventory before sharing it outside the environment.\n\n## Reference(s):\n\n- [agent-bom project](https://github.com/msaad00/agent-bom)\n- [agent-bom on PyPI](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Files, Shell commands, Guidance]\n\n**Output Format:** [Canonical JSON inventory file and Markdown guidance; optional JSON scan findings]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Inventory is schema-validated and sanitizes credential-like values; scanning requires operator approval.]\n\n## Skill Version(s):\n\n0.106.1 (source: release metadata and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.105.0: 3 files, 3329 bytes\n\nFiles: skill-card.md (2225b), SKILL.md (4394b), _meta.json (143b)\n\nFile v0.105.0:SKILL.md\n\n---\nname: agent-bom-discover-gcp\ndescription: >-\n  Discover GCP-hosted AI agent and MCP-relevant assets from the operator's\n  environment, emit canonical agent-bom inventory JSON, and scan it without\n  giving agent-bom long-lived GCP credentials. Use when a user asks to\n  inventory Vertex AI, Cloud Run, Cloud Functions, GKE, or agentic GCP\n  infrastructure as canonical inventory.\nversion: 0.105.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed from this repository or PyPI, and\n  operator-controlled GCP read-only credentials from ADC, workload identity, or\n  a scoped service account.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: gcp-read-only\n    credential_policy: \"Use the operator's existing Application Default Credentials, workload identity, or short-lived service account credentials. Do not ask users to paste service account JSON into chat. Do not print credential values.\"\n    optional_env:\n      - GOOGLE_APPLICATION_CREDENTIALS\n      - GOOGLE_CLOUD_PROJECT\n      - CLOUDSDK_CONFIG\n    optional_bins:\n      - gcloud\n    emoji: \"search\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes GCP SDK discovery locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator GCP project -> read-only Google API calls -> canonical inventory JSON -> optional local agent-bom inventory scan. No agent-bom-hosted service is required. Credential-like values are redacted before persistence/export.\"\n    file_reads:\n      - \"~/.config/gcloud/configurations/config_default\"\n      - \"~/.config/gcloud/application_default_credentials.json\"\n      - \"~/.config/gcloud/credentials.db\"\n      - \"operator-selected service account JSON when GOOGLE_APPLICATION_CREDENTIALS is set\"\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://cloudresourcemanager.googleapis.com\"\n        purpose: \"Project and resource inventory\"\n        auth: true\n      - url: \"https://aiplatform.googleapis.com\"\n        purpose: \"Vertex AI inventory\"\n        auth: true\n      - url: \"https://run.googleapis.com\"\n        purpose: \"Cloud Run inventory\"\n        auth: true\n      - url: \"https://cloudfunctions.googleapis.com\"\n        purpose: \"Cloud Functions inventory\"\n        auth: true\n      - url: \"https://container.googleapis.com\"\n        purpose: \"GKE inventory\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-gcp\n\nUse this skill to collect GCP AI and workload inventory as schema-valid\nagent-bom inventory. Default to discover-only: write JSON to an\noperator-selected path and stop.\n\n## Guardrails\n\n- Use only operator-approved projects and read-only credentials.\n- Do not request or display service account private keys, OAuth refresh tokens,\n  or bearer tokens.\n- Do not modify GCP resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; schema-validated inventory JSON\n  is the evidence.\n\n## Workflow\n\n```bash\npython examples/operator_pull/gcp_inventory_adapter.py \\\n  --project \"$GOOGLE_CLOUD_PROJECT\" \\\n  --region us-central1 \\\n  --source gcp-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output gcp-inventory.json\n```\n\nScan only when the operator asks for findings:\n\n```bash\nagent-bom scan --inventory gcp-inventory.json --format json --output agent-bom-gcp-findings.json\n```\n\n## Evidence Contract\n\nThe emitted inventory carries `discovery_provenance.source_type:\nskill_invoked_pull`, `observed_via: skill_invoked_pull, gcp_sdk`, sanitized\n`metadata.permissions_used`, and redacted credential material. If schema\nvalidation fails, stop and fix the inventory instead of scanning a best-effort\nsummary.\n\nFile v0.105.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-gcp\",\n  \"version\": \"0.105.0\",\n  \"publishedAt\": 1789729928932\n}\n\nFile v0.105.0:skill-card.md\n\n## Description:\n\nDiscover GCP-hosted AI agent and MCP-relevant assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving agent-bom long-lived GCP credentials.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nApache-2.0\n\n## Use Case:\n\nDevelopers and cloud security engineers use this skill to inventory approved GCP projects for Vertex AI, Cloud Run, Cloud Functions, GKE, and related agentic infrastructure. It produces canonical agent-bom inventory for local review and optional scanning.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can use existing local GCP credentials to enumerate approved projects.\n\nMitigation: Run it only with scoped read-only credentials for operator-approved projects.\n\nRisk: Generated inventory may contain sensitive details about cloud resources.\n\nMitigation: Write inventory only to an operator-selected local path and review it before sharing or scanning.\n\nRisk: The workflow depends on the agent-bom package and adapter script used in the operator environment.\n\nMitigation: Verify the installed package and adapter source before execution.\n\n## Reference(s):\n\n- [agent-bom source repository](https://github.com/msaad00/agent-bom)\n- [agent-bom PyPI package](https://pypi.org/project/agent-bom/)\n- [ClawHub skill page](https://clawhub.ai/msaad00/skills/agent-bom-discover-gcp)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with bash commands and JSON inventory outputs]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Writes canonical inventory JSON to an operator-selected path and can optionally produce JSON scan findings.]\n\n## Skill Version(s):\n\n0.105.0 (source: server release evidence and SKILL.md frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.104.0: 3 files, 3420 bytes\n\nFiles: skill-card.md (2356b), SKILL.md (4394b), _meta.json (143b)\n\nFile v0.104.0:SKILL.md\n\n---\nname: agent-bom-discover-gcp\ndescription: >-\n  Discover GCP-hosted AI agent and MCP-relevant assets from the operator's\n  environment, emit canonical agent-bom inventory JSON, and scan it without\n  giving agent-bom long-lived GCP credentials. Use when a user asks to\n  inventory Vertex AI, Cloud Run, Cloud Functions, GKE, or agentic GCP\n  infrastructure as canonical inventory.\nversion: 0.104.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed from this repository or PyPI, and\n  operator-controlled GCP read-only credentials from ADC, workload identity, or\n  a scoped service account.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: gcp-read-only\n    credential_policy: \"Use the operator's existing Application Default Credentials, workload identity, or short-lived service account credentials. Do not ask users to paste service account JSON into chat. Do not print credential values.\"\n    optional_env:\n      - GOOGLE_APPLICATION_CREDENTIALS\n      - GOOGLE_CLOUD_PROJECT\n      - CLOUDSDK_CONFIG\n    optional_bins:\n      - gcloud\n    emoji: \"search\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes GCP SDK discovery locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator GCP project -> read-only Google API calls -> canonical inventory JSON -> optional local agent-bom inventory scan. No agent-bom-hosted service is required. Credential-like values are redacted before persistence/export.\"\n    file_reads:\n      - \"~/.config/gcloud/configurations/config_default\"\n      - \"~/.config/gcloud/application_default_credentials.json\"\n      - \"~/.config/gcloud/credentials.db\"\n      - \"operator-selected service account JSON when GOOGLE_APPLICATION_CREDENTIALS is set\"\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://cloudresourcemanager.googleapis.com\"\n        purpose: \"Project and resource inventory\"\n        auth: true\n      - url: \"https://aiplatform.googleapis.com\"\n        purpose: \"Vertex AI inventory\"\n        auth: true\n      - url: \"https://run.googleapis.com\"\n        purpose: \"Cloud Run inventory\"\n        auth: true\n      - url: \"https://cloudfunctions.googleapis.com\"\n        purpose: \"Cloud Functions inventory\"\n        auth: true\n      - url: \"https://container.googleapis.com\"\n        purpose: \"GKE inventory\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-gcp\n\nUse this skill to collect GCP AI and workload inventory as schema-valid\nagent-bom inventory. Default to discover-only: write JSON to an\noperator-selected path and stop.\n\n## Guardrails\n\n- Use only operator-approved projects and read-only credentials.\n- Do not request or display service account private keys, OAuth refresh tokens,\n  or bearer tokens.\n- Do not modify GCP resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; schema-validated inventory JSON\n  is the evidence.\n\n## Workflow\n\n```bash\npython examples/operator_pull/gcp_inventory_adapter.py \\\n  --project \"$GOOGLE_CLOUD_PROJECT\" \\\n  --region us-central1 \\\n  --source gcp-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output gcp-inventory.json\n```\n\nScan only when the operator asks for findings:\n\n```bash\nagent-bom scan --inventory gcp-inventory.json --format json --output agent-bom-gcp-findings.json\n```\n\n## Evidence Contract\n\nThe emitted inventory carries `discovery_provenance.source_type:\nskill_invoked_pull`, `observed_via: skill_invoked_pull, gcp_sdk`, sanitized\n`metadata.permissions_used`, and redacted credential material. If schema\nvalidation fails, stop and fix the inventory instead of scanning a best-effort\nsummary.\n\nFile v0.104.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-gcp\",\n  \"version\": \"0.104.0\",\n  \"publishedAt\": 1788987423180\n}\n\nFile v0.104.0:skill-card.md\n\n## Description:\n\nDiscover GCP-hosted AI agent and MCP-relevant assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving agent-bom long-lived GCP credentials.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, cloud platform engineers, and security reviewers use this skill to collect read-only inventory for Vertex AI, Cloud Run, Cloud Functions, GKE, and other agentic GCP infrastructure. The resulting canonical inventory can be reviewed locally and scanned with agent-bom when findings are requested.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can use local GCP credential stores during discovery.\n\nMitigation: Run it only with operator-approved GCP authentication, preferably a dedicated project-scoped, read-only, short-lived service account or workload identity.\n\nRisk: The release relies on runtime agent-bom adapter code that is not included in the artifact.\n\nMitigation: Inspect and pin the referenced agent-bom package or repository version before use.\n\nRisk: Inventory output may describe sensitive cloud resources.\n\nMitigation: Write inventory only to a controlled local path and avoid broad shared GCloud credential stores where possible.\n\n## Reference(s):\n\n- [agent-bom GitHub repository](https://github.com/msaad00/agent-bom)\n- [agent-bom PyPI package](https://pypi.org/project/agent-bom/)\n- [ClawHub skill page](https://clawhub.ai/msaad00/skills/agent-bom-discover-gcp)\n\n## Skill Output:\n\n**Output Type(s):** [guidance, shell commands, configuration]\n\n**Output Format:** [Markdown guidance with shell command blocks and JSON inventory file outputs]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Discovery output is written to an operator-selected local JSON path; optional findings are written as agent-bom JSON when scanning is requested.]\n\n## Skill Version(s):\n\n0.104.0 (source: server release metadata and frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.103.2: 3 files, 3525 bytes\n\nFiles: skill-card.md (2778b), SKILL.md (4394b), _meta.json (143b)\n\nFile v0.103.2:SKILL.md\n\n---\nname: agent-bom-discover-gcp\ndescription: >-\n  Discover GCP-hosted AI agent and MCP-relevant assets from the operator's\n  environment, emit canonical agent-bom inventory JSON, and scan it without\n  giving agent-bom long-lived GCP credentials. Use when a user asks to\n  inventory Vertex AI, Cloud Run, Cloud Functions, GKE, or agentic GCP\n  infrastructure as canonical inventory.\nversion: 0.103.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed from this repository or PyPI, and\n  operator-controlled GCP read-only credentials from ADC, workload identity, or\n  a scoped service account.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: gcp-read-only\n    credential_policy: \"Use the operator's existing Application Default Credentials, workload identity, or short-lived service account credentials. Do not ask users to paste service account JSON into chat. Do not print credential values.\"\n    optional_env:\n      - GOOGLE_APPLICATION_CREDENTIALS\n      - GOOGLE_CLOUD_PROJECT\n      - CLOUDSDK_CONFIG\n    optional_bins:\n      - gcloud\n    emoji: \"search\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes GCP SDK discovery locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator GCP project -> read-only Google API calls -> canonical inventory JSON -> optional local agent-bom inventory scan. No agent-bom-hosted service is required. Credential-like values are redacted before persistence/export.\"\n    file_reads:\n      - \"~/.config/gcloud/configurations/config_default\"\n      - \"~/.config/gcloud/application_default_credentials.json\"\n      - \"~/.config/gcloud/credentials.db\"\n      - \"operator-selected service account JSON when GOOGLE_APPLICATION_CREDENTIALS is set\"\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://cloudresourcemanager.googleapis.com\"\n        purpose: \"Project and resource inventory\"\n        auth: true\n      - url: \"https://aiplatform.googleapis.com\"\n        purpose: \"Vertex AI inventory\"\n        auth: true\n      - url: \"https://run.googleapis.com\"\n        purpose: \"Cloud Run inventory\"\n        auth: true\n      - url: \"https://cloudfunctions.googleapis.com\"\n        purpose: \"Cloud Functions inventory\"\n        auth: true\n      - url: \"https://container.googleapis.com\"\n        purpose: \"GKE inventory\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-gcp\n\nUse this skill to collect GCP AI and workload inventory as schema-valid\nagent-bom inventory. Default to discover-only: write JSON to an\noperator-selected path and stop.\n\n## Guardrails\n\n- Use only operator-approved projects and read-only credentials.\n- Do not request or display service account private keys, OAuth refresh tokens,\n  or bearer tokens.\n- Do not modify GCP resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; schema-validated inventory JSON\n  is the evidence.\n\n## Workflow\n\n```bash\npython examples/operator_pull/gcp_inventory_adapter.py \\\n  --project \"$GOOGLE_CLOUD_PROJECT\" \\\n  --region us-central1 \\\n  --source gcp-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output gcp-inventory.json\n```\n\nScan only when the operator asks for findings:\n\n```bash\nagent-bom scan --inventory gcp-inventory.json --format json --output agent-bom-gcp-findings.json\n```\n\n## Evidence Contract\n\nThe emitted inventory carries `discovery_provenance.source_type:\nskill_invoked_pull`, `observed_via: skill_invoked_pull, gcp_sdk`, sanitized\n`metadata.permissions_used`, and redacted credential material. If schema\nvalidation fails, stop and fix the inventory instead of scanning a best-effort\nsummary.\n\nFile v0.103.2:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-gcp\",\n  \"version\": \"0.103.2\",\n  \"publishedAt\": 1788333908047\n}\n\nFile v0.103.2:skill-card.md\n\n## Description:\n\nDiscover GCP-hosted AI agent and MCP-relevant assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving agent-bom long-lived GCP credentials.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and cloud security engineers use this skill to discover Vertex AI, Cloud Run, Cloud Functions, GKE, and related GCP assets as canonical agent-bom inventory, then optionally scan that inventory for findings.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The workflow may use local GCP authentication context, including Application Default Credentials or configured credential files, for read-only inventory discovery.\n\nMitigation: Use narrowly scoped read-only ADC, workload identity, or short-lived service account credentials, and do not paste service account keys or token values into chat.\n\nRisk: Generated inventory JSON can contain cloud resource details that may be sensitive outside the operator's environment.\n\nMitigation: Write inventory only to an operator-selected path and review the JSON before sharing, scanning, or exporting it.\n\nRisk: Running discovery against broad projects can expose more resource metadata than intended.\n\nMitigation: Limit use to operator-approved GCP projects and credentials with the minimum read-only permissions needed for the inventory task.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/msaad00/skills/agent-bom-discover-gcp)\n- [agent-bom repository](https://github.com/msaad00/agent-bom)\n- [agent-bom PyPI package](https://pypi.org/project/agent-bom/)\n- [Cloud Resource Manager API endpoint](https://cloudresourcemanager.googleapis.com)\n- [Vertex AI API endpoint](https://aiplatform.googleapis.com)\n- [Cloud Run API endpoint](https://run.googleapis.com)\n- [Cloud Functions API endpoint](https://cloudfunctions.googleapis.com)\n- [Google Kubernetes Engine API endpoint](https://container.googleapis.com)\n\n## Skill Output:\n\n**Output Type(s):** [JSON, Shell commands, Guidance]\n\n**Output Format:** [Markdown guidance with bash commands; generated artifacts are JSON inventory and findings files.]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Default workflow is discover-only and writes inventory to an operator-selected path.]\n\n## Skill Version(s):\n\n0.103.2 (source: server release and SKILL.md frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.","readmeExcerpt":"Skill: agent-bom discover gcp Owner: msaad00 Summary: Discover GCP-hosted AI agent and MCP-relevant assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving agent-bom long-lived GCP credentials. Use when a user asks to inventory Vertex AI, Cloud Run, Cloud Functions, GKE, or agentic GCP infrastructure as canonical inventory. Tags: latest:0.108.3 Version history: v0.1","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"python examples/operator_pull/gcp_inventory_adapter.py \\\n  --project \"$GOOGLE_CLOUD_PROJECT\" \\\n  --region us-central1 \\\n  --source gcp-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output gcp-inventory.json"},{"language":"bash","snippet":"agent-bom scan --inventory gcp-inventory.json --format json --output agent-bom-gcp-findings.json"},{"language":"bash","snippet":"python examples/operator_pull/gcp_inventory_adapter.py \\\n  --project \"$GOOGLE_CLOUD_PROJECT\" \\\n  --region us-central1 \\\n  --source gcp-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output gcp-inventory.json"},{"language":"bash","snippet":"agent-bom scan --inventory gcp-inventory.json --format json --output agent-bom-gcp-findings.json"},{"language":"bash","snippet":"python examples/operator_pull/gcp_inventory_adapter.py \\\n  --project \"$GOOGLE_CLOUD_PROJECT\" \\\n  --region us-central1 \\\n  --source gcp-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output gcp-inventory.json"},{"language":"bash","snippet":"agent-bom scan --inventory gcp-inventory.json --format json --output agent-bom-gcp-findings.json"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: agent-bom-discover-gcp\ndescription: >-\n  Discover GCP-hosted AI agent and MCP-relevant assets from the operator's\n  environment, emit canonical agent-bom inventory JSON, and scan it without\n  giving agent-bom long-lived GCP credentials. Use when a user asks to\n  inventory Vertex AI, Cloud Run, Cloud Functions, GKE, or agentic GCP\n  infrastructure as canonical inventory.\nversion: 0.108.3\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed from this repository or PyPI, and\n  operator-controlled GCP read-only credentials from ADC, workload identity, or\n  a scoped service account.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: gcp-read-only\n    credential_policy: \"Use the operator's existing Application Default Credentials, workload identity, or short-lived service account credentials. Do not ask users to paste service account JSON into chat. Do not print credential values.\"\n    optional_env:\n      - GOOGLE_APPLICATION_CREDENTIALS\n      - GOOGLE_CLOUD_PROJECT\n      - CLOUDSDK_CONFIG\n    optional_bins:\n      - gcloud\n    emoji: \"search\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes GCP SDK discovery locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator GCP project -> read-only Google API calls -> canonical inventory JSON -> optional local agent-bom inventory scan. No agent-bom-hosted service is required. Credential-like values are redacted before persistence/export.\"\n    file_reads:\n      - \"~/.config/gcloud/configurations/config_default\"\n      - \"~/.config/gcloud/application_default_credentials.json\"\n      - \"~/.config/gcloud/credentials.db\"\n      - \"operator-selected service account JSON when GOOGLE_APPLICATION_CREDENTIALS is set\"\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://cloudresourcemanager.googleapis.com\"\n        purpose: \"Project and resource inventory\"\n        auth: true\n      - url: \"https://aiplatform.googleapis.com\"\n        purpose: \"Vertex AI inventory\"\n        auth: true\n      - url: \"https://run.googleapis.com\"\n        purpose: \"Cloud Run inventory\"\n        auth: true\n      - url: \"https://cloudfunctions.googleapis.com\"\n        purpose: \"Cloud Functions inventory\"\n        auth: true\n      - url: \"https://container.googleapis.com\"\n        purpose: \"GKE inventory\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-gcp\",\n  \"version\": \"0.108.3\",\n  \"publishedAt\": 1791497931440\n}"},{"path":"skill-card.md","content":"## Description:\n\nDiscovers GCP-hosted AI and workload assets and produces canonical agent-bom inventory JSON for optional local scanning.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and cloud operators use this skill to inventory AI agents and related resources in approved GCP projects, then optionally scan that inventory for findings.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: GCP discovery uses the operator's authentication context.\n\nMitigation: Use approved projects and least-privilege read-only credentials; never paste or print credential values.\n\nRisk: Generated inventory may contain sensitive resource metadata.\n\nMitigation: Choose the output path deliberately and review the inventory before sharing it.\n\n## Reference(s):\n\n- [agent-bom project homepage (skill metadata)](https://github.com/msaad00/agent-bom)\n- [agent-bom PyPI package](https://pypi.org/project/agent-bom/)\n- [ClawHub skill release](https://clawhub.ai/msaad00/skills/agent-bom-discover-gcp)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Files]\n\n**Output Format:** [JSON inventory; optional JSON scan findings]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Inventory is saved to an operator-selected path; scanning occurs only on request.]\n\n## Skill Version(s):\n\n0.108.3 (source: release metadata and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1062,"uniquenessScore":43,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T05:22:48.075Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T05:22:48.075Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T02:05:04.055Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}