{"id":"68f95cba-c23f-453b-9bc6-b28e55e85d25","entityType":"agent","slug":"clawhub-msaad00-agent-bom-ingest","name":"agent-bom ingest","canonicalUrl":"https://www.xpersona.co/agent/clawhub-msaad00-agent-bom-ingest","canonicalPath":"/agent/clawhub-msaad00-agent-bom-ingest","generatedAt":"2026-10-09T14:20:30.190Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T05:33:10.485Z","emptyReason":null},"description":"Validate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure, GCP, Snowflake, CMDB, or endpoint collectors. Use when a user has canonical inventory JSON and wants local findings, graph, policy, provenance, or auditor-ready exports without giving agent-bom direct cloud credentials. Skill: agent-bom ingest Owner: msaad00 Summary: Validate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure, GCP, Snowflake, CMDB, or endpoint collectors. Use when a user has canonical inventory JSON and wants local findings, graph, policy, provenance, or auditor-ready exports without giving agent-bom direct cloud credentials. Tags: latest:0.108.3 Version history: v0.108.3 | 2026-10-08T22:19:15.016Z","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 4.4K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom-ingest","sourceUrl":"https://clawhub.ai/msaad00/agent-bom-ingest","homepage":"https://clawhub.ai/msaad00/skills/agent-bom-ingest","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/msaad00/agent-bom-ingest","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/msaad00/skills/agent-bom-ingest","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":73,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Validate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure, GCP, Snowflake, CMDB, or endpoint collectors. Use when a user has canonical invent"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:33:10.485Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:33:10.485Z","emptyReason":null},"stars":null,"forks":null,"downloads":4351,"packageName":null,"latestVersion":"0.108.3","tractionLabel":"4.4K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:33:10.484Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T05:33:10.485Z","lastCrawledAt":"2026-10-09T05:33:10.484Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T05:33:10.484Z","lastVerifiedAt":null,"highlights":[{"version":"0.108.3","createdAt":"2026-10-08T22:19:15.016Z","changelog":"Release v0.108.3","fileCount":3,"zipByteSize":3252},{"version":"0.108.2","createdAt":"2026-10-08T05:02:34.330Z","changelog":"Release v0.108.2","fileCount":3,"zipByteSize":3198},{"version":"0.108.1","createdAt":"2026-10-06T17:48:48.141Z","changelog":"Release v0.108.1","fileCount":3,"zipByteSize":3208},{"version":"0.108.0","createdAt":"2026-10-04T07:13:44.740Z","changelog":"Release v0.108.0","fileCount":3,"zipByteSize":3261},{"version":"0.107.2","createdAt":"2026-10-01T23:33:18.567Z","changelog":"Release v0.107.2","fileCount":3,"zipByteSize":3339},{"version":"0.107.0","createdAt":"2026-09-30T20:19:20.835Z","changelog":"Release v0.107.0","fileCount":3,"zipByteSize":3306},{"version":"0.106.1","createdAt":"2026-09-27T00:19:34.665Z","changelog":"Release v0.106.1","fileCount":3,"zipByteSize":3216},{"version":"0.105.0","createdAt":"2026-09-18T11:12:29.914Z","changelog":"Release v0.105.0","fileCount":3,"zipByteSize":3550}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom-ingest","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-ingest/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-ingest/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-ingest/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-ingest/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-ingest/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-ingest/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T14:20:30.188Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-ingest/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-ingest/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-ingest/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-ingest/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T05:33:10.485Z","emptyReason":null},"readme":"Skill: agent-bom ingest\n\nOwner: msaad00\n\nSummary: Validate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure, GCP, Snowflake, CMDB, or endpoint collectors. Use when a user has canonical inventory JSON and wants local findings, graph, policy, provenance, or auditor-ready exports without giving agent-bom direct cloud credentials.\n\nTags: latest:0.108.3\n\nVersion history:\n\nv0.108.3 | 2026-10-08T22:19:15.016Z | user\n\nRelease v0.108.3\n\nv0.108.2 | 2026-10-08T05:02:34.330Z | user\n\nRelease v0.108.2\n\nv0.108.1 | 2026-10-06T17:48:48.141Z | user\n\nRelease v0.108.1\n\nv0.108.0 | 2026-10-04T07:13:44.740Z | user\n\nRelease v0.108.0\n\nv0.107.2 | 2026-10-01T23:33:18.567Z | user\n\nRelease v0.107.2\n\nv0.107.0 | 2026-09-30T20:19:20.835Z | user\n\nRelease v0.107.0\n\nv0.106.1 | 2026-09-27T00:19:34.665Z | user\n\nRelease v0.106.1\n\nv0.105.0 | 2026-09-18T11:12:29.914Z | user\n\nRelease v0.105.0\n\nv0.104.0 | 2026-09-09T20:57:30.471Z | user\n\nRelease v0.104.0\n\nv0.103.2 | 2026-09-02T07:25:33.459Z | user\n\nRelease v0.103.2\n\nv0.102.0 | 2026-08-24T04:51:28.510Z | user\n\nRelease v0.102.0\n\nv0.101.0 | 2026-08-16T23:14:23.798Z | user\n\nRelease v0.101.0\n\nv0.100.0 | 2026-08-12T20:56:21.092Z | user\n\nRelease v0.100.0\n\nv0.99.0 | 2026-08-06T00:53:56.619Z | user\n\nRelease v0.99.0\n\nv0.98.3 | 2026-08-03T06:09:55.890Z | user\n\nRelease v0.98.3\n\nv0.98.2 | 2026-07-27T08:50:58.428Z | user\n\nRelease v0.98.2\n\nv0.98.1 | 2026-07-27T02:02:57.796Z | user\n\nRelease v0.98.1\n\nv0.98.0 | 2026-07-25T01:52:20.366Z | user\n\nRelease v0.98.0\n\nv0.97.5 | 2026-07-24T01:44:23.930Z | user\n\nRelease v0.97.5\n\nv0.97.4 | 2026-07-23T01:00:07.827Z | user\n\nRelease v0.97.4\n\nv0.97.2 | 2026-07-21T18:19:59.296Z | user\n\nRelease v0.97.2\n\nv0.97.1 | 2026-07-21T03:32:31.290Z | user\n\nRelease v0.97.1\n\nv0.97.0 | 2026-07-20T18:11:39.915Z | user\n\nRelease v0.97.0\n\nv0.96.4 | 2026-07-20T15:06:39.804Z | user\n\nRelease v0.96.4\n\nv0.96.3 | 2026-07-16T04:06:19.874Z | user\n\nRelease v0.96.3\n\nv0.96.2 | 2026-07-15T23:06:02.349Z | user\n\nRelease v0.96.2\n\nv0.95.0 | 2026-07-13T21:39:11.857Z | user\n\nRelease v0.95.0\n\nv0.94.2 | 2026-07-09T18:25:18.581Z | user\n\nRelease v0.94.2\n\nv0.94.1 | 2026-07-09T05:51:30.864Z | user\n\nRelease v0.94.1\n\nv0.94.0 | 2026-07-08T21:48:47.301Z | user\n\nRelease v0.94.0\n\nv0.93.0 | 2026-07-06T07:43:35.829Z | user\n\nRelease v0.93.0\n\nv0.91.0 | 2026-06-30T23:37:08.362Z | user\n\nRelease v0.91.0\n\nv0.90.0 | 2026-06-30T03:48:23.864Z | user\n\nRelease v0.90.0\n\nv0.89.2 | 2026-06-22T03:18:22.340Z | user\n\nRelease v0.89.2\n\nv0.88.5 | 2026-06-01T06:24:20.392Z | user\n\nRelease v0.88.5\n\nv0.88.4 | 2026-05-26T04:20:49.991Z | user\n\nRelease v0.88.4\n\nv0.88.3 | 2026-05-25T00:57:58.194Z | user\n\nRelease v0.88.3\n\nv0.88.1 | 2026-05-22T04:38:54.139Z | user\n\nRelease v0.88.1\n\nv0.87.1 | 2026-05-18T20:26:11.959Z | user\n\nRelease v0.87.1\n\nv0.87.0 | 2026-05-18T00:37:17.998Z | user\n\nRelease v0.87.0\n\nv0.86.5 | 2026-05-11T16:16:24.829Z | user\n\nRelease v0.86.5\n\nv0.86.2 | 2026-05-07T15:45:36.085Z | user\n\nRelease v0.86.2\n\nv0.86.1 | 2026-05-06T06:42:45.267Z | user\n\nRelease v0.86.1\n\nv0.85.0 | 2026-05-02T22:49:08.293Z | user\n\nRelease v0.85.0\n\nv0.84.6 | 2026-05-02T06:44:34.428Z | user\n\nRelease v0.84.6\n\nv0.84.5 | 2026-05-02T03:29:37.350Z | user\n\nRelease v0.84.5\n\nv0.84.4 | 2026-05-01T19:08:00.789Z | user\n\nRelease v0.84.4\n\nv0.84.0 | 2026-05-01T01:53:55.375Z | user\n\nRelease v0.84.0\n\nArchive index:\n\nArchive v0.108.3: 3 files, 3252 bytes\n\nFiles: skill-card.md (1960b), SKILL.md (4216b), _meta.json (137b)\n\nFile v0.108.3:SKILL.md\n\n---\nname: agent-bom-ingest\ndescription: >-\n  Validate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure,\n  GCP, Snowflake, CMDB, or endpoint collectors. Use when a user has canonical\n  inventory JSON and wants local findings, graph, policy, provenance, or\n  auditor-ready exports without giving agent-bom direct cloud credentials.\nversion: 0.108.3\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+ and agent-bom 0.84.4+. Inventory must conform to the\n  packaged inventory.schema.json contract.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - agent-bom\n      env: []\n      credentials: none\n    credential_policy: \"No cloud credentials are required. Optional control-plane push uses an operator-provided agent-bom API token; never ask users to paste that token into chat and never print it.\"\n    optional_env:\n      - AGENT_BOM_API_KEY\n      - AGENT_BOM_PUSH_URL\n    optional_bins: []\n    emoji: \"inbox\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Inventory is schema-validated before it is trusted. Env var values, URL credentials, launch arguments, discovery_provenance, permissions_used, and security intelligence pass through the sanitizer/redaction contract before display/export.\"\n    data_flow: \"Operator-generated inventory JSON -> packaged inventory.schema.json validation -> local agent-bom scan/graph/export. Optional push to an operator-owned control plane goes only to the URL the operator provided.\"\n    file_reads:\n      - \"operator-selected inventory JSON file\"\n      - \"packaged agent_bom/data/inventory.schema.json\"\n    file_writes:\n      - \"operator-selected JSON/SARIF/HTML/Markdown export path\"\n    network_endpoints:\n      - url: \"operator-provided AGENT_BOM_PUSH_URL\"\n        purpose: \"Optional push into the operator-owned agent-bom control plane\"\n        auth: true\n        optional: true\n      - url: \"https://api.osv.dev/v1\"\n        purpose: \"Optional package vulnerability lookup during local scan\"\n        auth: false\n        optional: true\n      - url: \"https://api.github.com/advisories\"\n        purpose: \"Optional GitHub Advisory enrichment during local scan\"\n        auth: false\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-ingest\n\nUse this skill when the operator already produced canonical inventory JSON with\nan operator-pull adapter, endpoint collector, CMDB export, or AI-agent workflow.\nThe default path is local validation plus local scan/export.\n\n## Guardrails\n\n- Validate inventory with the packaged schema before treating it as evidence.\n- Require `discovery_provenance` and `permissions_used` where the source claims\n  cloud/operator-pushed discovery.\n- Require a trustworthy `discovery_provenance.source_type` such as\n  `operator_pushed_inventory` or `skill_invoked_pull`; do not infer it from\n  prose.\n- Do not invent provenance, permissions, cloud scopes, or credential posture.\n- Do not push to a control plane unless the operator provides the destination\n  URL and auth method explicitly.\n- Do not print raw tokens, URL credentials, private keys, or env var values.\n\n## Workflow\n\nValidate first:\n\n```bash\nagent-bom mcp validate inventory.json\n```\n\nScan locally:\n\n```bash\nagent-bom scan --inventory inventory.json --format json --output agent-bom-findings.json\n```\n\nChoose output by consumer:\n\n- SARIF for CI/code-scanning gates\n- JSON for graph, API, and automation\n- HTML or Markdown for human review\n- CycloneDX/SPDX for SBOM consumers\n\n## Evidence Contract\n\nValid inventory preserves `discovery_provenance`, `permissions_used`,\n`cloud_origin`, redaction state, package identity, server identity, tools, and\nsecurity intelligence. If the inventory is malformed or missing required trust\nfields, stop and ask the operator to regenerate it rather than scanning a\nbest-effort summary.\n\nFile v0.108.3:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-ingest\",\n  \"version\": \"0.108.3\",\n  \"publishedAt\": 1791497955016\n}\n\nFile v0.108.3:skill-card.md\n\n## Description:\n\nValidates operator-provided agent inventory JSON and guides local scanning and export without requiring direct cloud credentials.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to validate inventory supplied by their own collectors, scan it locally for findings, and prepare exports for security or audit workflows.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Selected inventory files could contain sensitive data or secrets.\n\nMitigation: Limit access to the intended inventory file, and verify redaction before including secrets or sharing exports.\n\nRisk: Optional advisory lookups or control-plane push can transmit data over the network.\n\nMitigation: Enable network lookups only when appropriate; push only to an operator-approved destination with its designated authentication method.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/msaad00/skills/agent-bom-ingest)\n- [agent-bom project homepage (declared in skill metadata)](https://github.com/msaad00/agent-bom)\n- [agent-bom package (declared in skill metadata)](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Guidance]\n\n**Output Format:** [Markdown with shell commands]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Guides validation and local scanning; the invoked tool can write operator-selected JSON, SARIF, HTML, or Markdown exports.]\n\n## Skill Version(s):\n\n0.108.3 (source: release metadata and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.108.2: 3 files, 3198 bytes\n\nFiles: skill-card.md (1787b), SKILL.md (4216b), _meta.json (137b)\n\nFile v0.108.2:SKILL.md\n\n---\nname: agent-bom-ingest\ndescription: >-\n  Validate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure,\n  GCP, Snowflake, CMDB, or endpoint collectors. Use when a user has canonical\n  inventory JSON and wants local findings, graph, policy, provenance, or\n  auditor-ready exports without giving agent-bom direct cloud credentials.\nversion: 0.108.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+ and agent-bom 0.84.4+. Inventory must conform to the\n  packaged inventory.schema.json contract.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - agent-bom\n      env: []\n      credentials: none\n    credential_policy: \"No cloud credentials are required. Optional control-plane push uses an operator-provided agent-bom API token; never ask users to paste that token into chat and never print it.\"\n    optional_env:\n      - AGENT_BOM_API_KEY\n      - AGENT_BOM_PUSH_URL\n    optional_bins: []\n    emoji: \"inbox\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Inventory is schema-validated before it is trusted. Env var values, URL credentials, launch arguments, discovery_provenance, permissions_used, and security intelligence pass through the sanitizer/redaction contract before display/export.\"\n    data_flow: \"Operator-generated inventory JSON -> packaged inventory.schema.json validation -> local agent-bom scan/graph/export. Optional push to an operator-owned control plane goes only to the URL the operator provided.\"\n    file_reads:\n      - \"operator-selected inventory JSON file\"\n      - \"packaged agent_bom/data/inventory.schema.json\"\n    file_writes:\n      - \"operator-selected JSON/SARIF/HTML/Markdown export path\"\n    network_endpoints:\n      - url: \"operator-provided AGENT_BOM_PUSH_URL\"\n        purpose: \"Optional push into the operator-owned agent-bom control plane\"\n        auth: true\n        optional: true\n      - url: \"https://api.osv.dev/v1\"\n        purpose: \"Optional package vulnerability lookup during local scan\"\n        auth: false\n        optional: true\n      - url: \"https://api.github.com/advisories\"\n        purpose: \"Optional GitHub Advisory enrichment during local scan\"\n        auth: false\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-ingest\n\nUse this skill when the operator already produced canonical inventory JSON with\nan operator-pull adapter, endpoint collector, CMDB export, or AI-agent workflow.\nThe default path is local validation plus local scan/export.\n\n## Guardrails\n\n- Validate inventory with the packaged schema before treating it as evidence.\n- Require `discovery_provenance` and `permissions_used` where the source claims\n  cloud/operator-pushed discovery.\n- Require a trustworthy `discovery_provenance.source_type` such as\n  `operator_pushed_inventory` or `skill_invoked_pull`; do not infer it from\n  prose.\n- Do not invent provenance, permissions, cloud scopes, or credential posture.\n- Do not push to a control plane unless the operator provides the destination\n  URL and auth method explicitly.\n- Do not print raw tokens, URL credentials, private keys, or env var values.\n\n## Workflow\n\nValidate first:\n\n```bash\nagent-bom mcp validate inventory.json\n```\n\nScan locally:\n\n```bash\nagent-bom scan --inventory inventory.json --format json --output agent-bom-findings.json\n```\n\nChoose output by consumer:\n\n- SARIF for CI/code-scanning gates\n- JSON for graph, API, and automation\n- HTML or Markdown for human review\n- CycloneDX/SPDX for SBOM consumers\n\n## Evidence Contract\n\nValid inventory preserves `discovery_provenance`, `permissions_used`,\n`cloud_origin`, redaction state, package identity, server identity, tools, and\nsecurity intelligence. If the inventory is malformed or missing required trust\nfields, stop and ask the operator to regenerate it rather than scanning a\nbest-effort summary.\n\nFile v0.108.2:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-ingest\",\n  \"version\": \"0.108.2\",\n  \"publishedAt\": 1791435754330\n}\n\nFile v0.108.2:skill-card.md\n\n## Description:\n\nValidates operator-provided agent-bom inventory JSON and guides local scanning and export of findings without direct cloud credentials.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security operators use this skill to validate inventory from their collectors, run local agent-bom scans, and prepare findings or auditor-ready exports.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Optional vulnerability lookups may send inventory package details to external advisory services.\n\nMitigation: Confirm the operator accepts OSV or GitHub advisory lookups before enabling them.\n\nRisk: Optional control-plane push can expose inventory or API tokens to an unintended destination.\n\nMitigation: Push only to an operator-provided, operator-owned URL; keep tokens in environment variables and out of chat.\n\n## Reference(s):\n\n- [agent-bom project documentation](https://github.com/msaad00/agent-bom)\n- [agent-bom package](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands, Configuration instructions]\n\n**Output Format:** [Markdown with inline shell commands]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Guides operator-selected local JSON, SARIF, HTML, Markdown, CycloneDX, or SPDX exports.]\n\n## Skill Version(s):\n\n0.108.2 (source: release metadata and frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.108.1: 3 files, 3208 bytes\n\nFiles: skill-card.md (1829b), SKILL.md (4216b), _meta.json (137b)\n\nFile v0.108.1:SKILL.md\n\n---\nname: agent-bom-ingest\ndescription: >-\n  Validate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure,\n  GCP, Snowflake, CMDB, or endpoint collectors. Use when a user has canonical\n  inventory JSON and wants local findings, graph, policy, provenance, or\n  auditor-ready exports without giving agent-bom direct cloud credentials.\nversion: 0.108.1\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+ and agent-bom 0.84.4+. Inventory must conform to the\n  packaged inventory.schema.json contract.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - agent-bom\n      env: []\n      credentials: none\n    credential_policy: \"No cloud credentials are required. Optional control-plane push uses an operator-provided agent-bom API token; never ask users to paste that token into chat and never print it.\"\n    optional_env:\n      - AGENT_BOM_API_KEY\n      - AGENT_BOM_PUSH_URL\n    optional_bins: []\n    emoji: \"inbox\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Inventory is schema-validated before it is trusted. Env var values, URL credentials, launch arguments, discovery_provenance, permissions_used, and security intelligence pass through the sanitizer/redaction contract before display/export.\"\n    data_flow: \"Operator-generated inventory JSON -> packaged inventory.schema.json validation -> local agent-bom scan/graph/export. Optional push to an operator-owned control plane goes only to the URL the operator provided.\"\n    file_reads:\n      - \"operator-selected inventory JSON file\"\n      - \"packaged agent_bom/data/inventory.schema.json\"\n    file_writes:\n      - \"operator-selected JSON/SARIF/HTML/Markdown export path\"\n    network_endpoints:\n      - url: \"operator-provided AGENT_BOM_PUSH_URL\"\n        purpose: \"Optional push into the operator-owned agent-bom control plane\"\n        auth: true\n        optional: true\n      - url: \"https://api.osv.dev/v1\"\n        purpose: \"Optional package vulnerability lookup during local scan\"\n        auth: false\n        optional: true\n      - url: \"https://api.github.com/advisories\"\n        purpose: \"Optional GitHub Advisory enrichment during local scan\"\n        auth: false\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-ingest\n\nUse this skill when the operator already produced canonical inventory JSON with\nan operator-pull adapter, endpoint collector, CMDB export, or AI-agent workflow.\nThe default path is local validation plus local scan/export.\n\n## Guardrails\n\n- Validate inventory with the packaged schema before treating it as evidence.\n- Require `discovery_provenance` and `permissions_used` where the source claims\n  cloud/operator-pushed discovery.\n- Require a trustworthy `discovery_provenance.source_type` such as\n  `operator_pushed_inventory` or `skill_invoked_pull`; do not infer it from\n  prose.\n- Do not invent provenance, permissions, cloud scopes, or credential posture.\n- Do not push to a control plane unless the operator provides the destination\n  URL and auth method explicitly.\n- Do not print raw tokens, URL credentials, private keys, or env var values.\n\n## Workflow\n\nValidate first:\n\n```bash\nagent-bom mcp validate inventory.json\n```\n\nScan locally:\n\n```bash\nagent-bom scan --inventory inventory.json --format json --output agent-bom-findings.json\n```\n\nChoose output by consumer:\n\n- SARIF for CI/code-scanning gates\n- JSON for graph, API, and automation\n- HTML or Markdown for human review\n- CycloneDX/SPDX for SBOM consumers\n\n## Evidence Contract\n\nValid inventory preserves `discovery_provenance`, `permissions_used`,\n`cloud_origin`, redaction state, package identity, server identity, tools, and\nsecurity intelligence. If the inventory is malformed or missing required trust\nfields, stop and ask the operator to regenerate it rather than scanning a\nbest-effort summary.\n\nFile v0.108.1:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-ingest\",\n  \"version\": \"0.108.1\",\n  \"publishedAt\": 1791308928141\n}\n\nFile v0.108.1:skill-card.md\n\n## Description:\n\nValidates operator-provided agent-bom inventory JSON and guides local scanning and export of findings without direct cloud credentials.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security teams use this skill to validate inventory supplied by operators or collectors, then generate local security findings and auditor-ready exports without granting direct cloud access.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Inventory and exported reports may reveal sensitive infrastructure details.\n\nMitigation: Keep scans local and write reports only to intended, access-controlled paths.\n\nRisk: Optional advisory lookups or a control-plane push can transmit data externally.\n\nMitigation: Enable lookups deliberately; push only to an operator-provided destination and keep API tokens out of chat and reports.\n\n## Reference(s):\n\n- [agent-bom project homepage](https://github.com/msaad00/agent-bom)\n- [agent-bom package](https://pypi.org/project/agent-bom/)\n- [ClawHub skill listing](https://clawhub.ai/msaad00/skills/agent-bom-ingest)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Guidance]\n\n**Output Format:** [Markdown with bash commands]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Guides selection of JSON, SARIF, HTML, Markdown, CycloneDX, or SPDX reports.]\n\n## Skill Version(s):\n\n0.108.1 (source: ClawHub release and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.108.0: 3 files, 3261 bytes\n\nFiles: skill-card.md (1984b), SKILL.md (4216b), _meta.json (137b)\n\nFile v0.108.0:SKILL.md\n\n---\nname: agent-bom-ingest\ndescription: >-\n  Validate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure,\n  GCP, Snowflake, CMDB, or endpoint collectors. Use when a user has canonical\n  inventory JSON and wants local findings, graph, policy, provenance, or\n  auditor-ready exports without giving agent-bom direct cloud credentials.\nversion: 0.108.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+ and agent-bom 0.84.4+. Inventory must conform to the\n  packaged inventory.schema.json contract.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - agent-bom\n      env: []\n      credentials: none\n    credential_policy: \"No cloud credentials are required. Optional control-plane push uses an operator-provided agent-bom API token; never ask users to paste that token into chat and never print it.\"\n    optional_env:\n      - AGENT_BOM_API_KEY\n      - AGENT_BOM_PUSH_URL\n    optional_bins: []\n    emoji: \"inbox\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Inventory is schema-validated before it is trusted. Env var values, URL credentials, launch arguments, discovery_provenance, permissions_used, and security intelligence pass through the sanitizer/redaction contract before display/export.\"\n    data_flow: \"Operator-generated inventory JSON -> packaged inventory.schema.json validation -> local agent-bom scan/graph/export. Optional push to an operator-owned control plane goes only to the URL the operator provided.\"\n    file_reads:\n      - \"operator-selected inventory JSON file\"\n      - \"packaged agent_bom/data/inventory.schema.json\"\n    file_writes:\n      - \"operator-selected JSON/SARIF/HTML/Markdown export path\"\n    network_endpoints:\n      - url: \"operator-provided AGENT_BOM_PUSH_URL\"\n        purpose: \"Optional push into the operator-owned agent-bom control plane\"\n        auth: true\n        optional: true\n      - url: \"https://api.osv.dev/v1\"\n        purpose: \"Optional package vulnerability lookup during local scan\"\n        auth: false\n        optional: true\n      - url: \"https://api.github.com/advisories\"\n        purpose: \"Optional GitHub Advisory enrichment during local scan\"\n        auth: false\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-ingest\n\nUse this skill when the operator already produced canonical inventory JSON with\nan operator-pull adapter, endpoint collector, CMDB export, or AI-agent workflow.\nThe default path is local validation plus local scan/export.\n\n## Guardrails\n\n- Validate inventory with the packaged schema before treating it as evidence.\n- Require `discovery_provenance` and `permissions_used` where the source claims\n  cloud/operator-pushed discovery.\n- Require a trustworthy `discovery_provenance.source_type` such as\n  `operator_pushed_inventory` or `skill_invoked_pull`; do not infer it from\n  prose.\n- Do not invent provenance, permissions, cloud scopes, or credential posture.\n- Do not push to a control plane unless the operator provides the destination\n  URL and auth method explicitly.\n- Do not print raw tokens, URL credentials, private keys, or env var values.\n\n## Workflow\n\nValidate first:\n\n```bash\nagent-bom mcp validate inventory.json\n```\n\nScan locally:\n\n```bash\nagent-bom scan --inventory inventory.json --format json --output agent-bom-findings.json\n```\n\nChoose output by consumer:\n\n- SARIF for CI/code-scanning gates\n- JSON for graph, API, and automation\n- HTML or Markdown for human review\n- CycloneDX/SPDX for SBOM consumers\n\n## Evidence Contract\n\nValid inventory preserves `discovery_provenance`, `permissions_used`,\n`cloud_origin`, redaction state, package identity, server identity, tools, and\nsecurity intelligence. If the inventory is malformed or missing required trust\nfields, stop and ask the operator to regenerate it rather than scanning a\nbest-effort summary.\n\nFile v0.108.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-ingest\",\n  \"version\": \"0.108.0\",\n  \"publishedAt\": 1791098024740\n}\n\nFile v0.108.0:skill-card.md\n\n## Description:\n\nValidates operator-provided agent-bom inventory JSON and guides local scanning and export of findings without requiring direct cloud credentials.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security teams use this skill to validate operator-generated inventory, inspect local findings, and prepare graph, policy, or audit exports without giving the scanner cloud credentials.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Using an untrusted scanning tool or malformed inventory could yield unreliable findings.\n\nMitigation: Confirm you trust agent-bom and validate the inventory against its packaged schema before scanning.\n\nRisk: Optional control-plane push could disclose inventory or expose an API token.\n\nMitigation: Review inventory before pushing, use only an operator-controlled destination, and keep tokens in environment variables rather than chat.\n\n## Reference(s):\n\n- [ClawHub skill release](https://clawhub.ai/msaad00/skills/agent-bom-ingest)\n- [Project homepage (skill metadata)](https://github.com/msaad00/agent-bom)\n- [agent-bom package](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Guidance, Files]\n\n**Output Format:** [Markdown guidance and commands; optional JSON, SARIF, HTML, Markdown, CycloneDX, or SPDX exports]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Requires schema-valid inventory; exports are written only to operator-selected paths.]\n\n## Skill Version(s):\n\n0.108.0 (source: ClawHub release metadata and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.107.2: 3 files, 3339 bytes\n\nFiles: skill-card.md (2127b), SKILL.md (4216b), _meta.json (137b)\n\nFile v0.107.2:SKILL.md\n\n---\nname: agent-bom-ingest\ndescription: >-\n  Validate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure,\n  GCP, Snowflake, CMDB, or endpoint collectors. Use when a user has canonical\n  inventory JSON and wants local findings, graph, policy, provenance, or\n  auditor-ready exports without giving agent-bom direct cloud credentials.\nversion: 0.107.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+ and agent-bom 0.84.4+. Inventory must conform to the\n  packaged inventory.schema.json contract.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - agent-bom\n      env: []\n      credentials: none\n    credential_policy: \"No cloud credentials are required. Optional control-plane push uses an operator-provided agent-bom API token; never ask users to paste that token into chat and never print it.\"\n    optional_env:\n      - AGENT_BOM_API_KEY\n      - AGENT_BOM_PUSH_URL\n    optional_bins: []\n    emoji: \"inbox\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Inventory is schema-validated before it is trusted. Env var values, URL credentials, launch arguments, discovery_provenance, permissions_used, and security intelligence pass through the sanitizer/redaction contract before display/export.\"\n    data_flow: \"Operator-generated inventory JSON -> packaged inventory.schema.json validation -> local agent-bom scan/graph/export. Optional push to an operator-owned control plane goes only to the URL the operator provided.\"\n    file_reads:\n      - \"operator-selected inventory JSON file\"\n      - \"packaged agent_bom/data/inventory.schema.json\"\n    file_writes:\n      - \"operator-selected JSON/SARIF/HTML/Markdown export path\"\n    network_endpoints:\n      - url: \"operator-provided AGENT_BOM_PUSH_URL\"\n        purpose: \"Optional push into the operator-owned agent-bom control plane\"\n        auth: true\n        optional: true\n      - url: \"https://api.osv.dev/v1\"\n        purpose: \"Optional package vulnerability lookup during local scan\"\n        auth: false\n        optional: true\n      - url: \"https://api.github.com/advisories\"\n        purpose: \"Optional GitHub Advisory enrichment during local scan\"\n        auth: false\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-ingest\n\nUse this skill when the operator already produced canonical inventory JSON with\nan operator-pull adapter, endpoint collector, CMDB export, or AI-agent workflow.\nThe default path is local validation plus local scan/export.\n\n## Guardrails\n\n- Validate inventory with the packaged schema before treating it as evidence.\n- Require `discovery_provenance` and `permissions_used` where the source claims\n  cloud/operator-pushed discovery.\n- Require a trustworthy `discovery_provenance.source_type` such as\n  `operator_pushed_inventory` or `skill_invoked_pull`; do not infer it from\n  prose.\n- Do not invent provenance, permissions, cloud scopes, or credential posture.\n- Do not push to a control plane unless the operator provides the destination\n  URL and auth method explicitly.\n- Do not print raw tokens, URL credentials, private keys, or env var values.\n\n## Workflow\n\nValidate first:\n\n```bash\nagent-bom mcp validate inventory.json\n```\n\nScan locally:\n\n```bash\nagent-bom scan --inventory inventory.json --format json --output agent-bom-findings.json\n```\n\nChoose output by consumer:\n\n- SARIF for CI/code-scanning gates\n- JSON for graph, API, and automation\n- HTML or Markdown for human review\n- CycloneDX/SPDX for SBOM consumers\n\n## Evidence Contract\n\nValid inventory preserves `discovery_provenance`, `permissions_used`,\n`cloud_origin`, redaction state, package identity, server identity, tools, and\nsecurity intelligence. If the inventory is malformed or missing required trust\nfields, stop and ask the operator to regenerate it rather than scanning a\nbest-effort summary.\n\nFile v0.107.2:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-ingest\",\n  \"version\": \"0.107.2\",\n  \"publishedAt\": 1790897598567\n}\n\nFile v0.107.2:skill-card.md\n\n## Description:\n\nValidates operator-supplied agent-bom inventory and guides local scanning and auditor-ready exports without requiring direct cloud credentials.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and inventory operators use this skill to validate existing agent inventories, review local security findings, and prepare reports for auditors or automation without granting cloud access to agent-bom.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Optional vulnerability lookups may send package or advisory lookup data to OSV or GitHub.\n\nMitigation: Review what may be shared before enabling external enrichment; keep scans local when external lookup is unnecessary.\n\nRisk: Optional control-plane push can send inventory to an unintended destination or expose an API token.\n\nMitigation: Push only to an operator-approved URL with an operator-managed token; do not paste or print the token.\n\nRisk: Malformed inventory or missing discovery trust fields may produce misleading findings.\n\nMitigation: Validate against the packaged schema and require the claimed discovery provenance and permissions before scanning.\n\n## Reference(s):\n\n- [agent-bom project](https://github.com/msaad00/agent-bom)\n- [agent-bom on PyPI](https://pypi.org/project/agent-bom/)\n- [ClawHub skill listing](https://clawhub.ai/msaad00/skills/agent-bom-ingest)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands]\n\n**Output Format:** [Markdown with shell command examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Guides local exports in JSON, SARIF, HTML, Markdown, CycloneDX, or SPDX formats.]\n\n## Skill Version(s):\n\n0.107.2 (source: release metadata and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.107.0: 3 files, 3306 bytes\n\nFiles: skill-card.md (2098b), SKILL.md (4216b), _meta.json (137b)\n\nFile v0.107.0:SKILL.md\n\n---\nname: agent-bom-ingest\ndescription: >-\n  Validate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure,\n  GCP, Snowflake, CMDB, or endpoint collectors. Use when a user has canonical\n  inventory JSON and wants local findings, graph, policy, provenance, or\n  auditor-ready exports without giving agent-bom direct cloud credentials.\nversion: 0.107.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+ and agent-bom 0.84.4+. Inventory must conform to the\n  packaged inventory.schema.json contract.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - agent-bom\n      env: []\n      credentials: none\n    credential_policy: \"No cloud credentials are required. Optional control-plane push uses an operator-provided agent-bom API token; never ask users to paste that token into chat and never print it.\"\n    optional_env:\n      - AGENT_BOM_API_KEY\n      - AGENT_BOM_PUSH_URL\n    optional_bins: []\n    emoji: \"inbox\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Inventory is schema-validated before it is trusted. Env var values, URL credentials, launch arguments, discovery_provenance, permissions_used, and security intelligence pass through the sanitizer/redaction contract before display/export.\"\n    data_flow: \"Operator-generated inventory JSON -> packaged inventory.schema.json validation -> local agent-bom scan/graph/export. Optional push to an operator-owned control plane goes only to the URL the operator provided.\"\n    file_reads:\n      - \"operator-selected inventory JSON file\"\n      - \"packaged agent_bom/data/inventory.schema.json\"\n    file_writes:\n      - \"operator-selected JSON/SARIF/HTML/Markdown export path\"\n    network_endpoints:\n      - url: \"operator-provided AGENT_BOM_PUSH_URL\"\n        purpose: \"Optional push into the operator-owned agent-bom control plane\"\n        auth: true\n        optional: true\n      - url: \"https://api.osv.dev/v1\"\n        purpose: \"Optional package vulnerability lookup during local scan\"\n        auth: false\n        optional: true\n      - url: \"https://api.github.com/advisories\"\n        purpose: \"Optional GitHub Advisory enrichment during local scan\"\n        auth: false\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-ingest\n\nUse this skill when the operator already produced canonical inventory JSON with\nan operator-pull adapter, endpoint collector, CMDB export, or AI-agent workflow.\nThe default path is local validation plus local scan/export.\n\n## Guardrails\n\n- Validate inventory with the packaged schema before treating it as evidence.\n- Require `discovery_provenance` and `permissions_used` where the source claims\n  cloud/operator-pushed discovery.\n- Require a trustworthy `discovery_provenance.source_type` such as\n  `operator_pushed_inventory` or `skill_invoked_pull`; do not infer it from\n  prose.\n- Do not invent provenance, permissions, cloud scopes, or credential posture.\n- Do not push to a control plane unless the operator provides the destination\n  URL and auth method explicitly.\n- Do not print raw tokens, URL credentials, private keys, or env var values.\n\n## Workflow\n\nValidate first:\n\n```bash\nagent-bom mcp validate inventory.json\n```\n\nScan locally:\n\n```bash\nagent-bom scan --inventory inventory.json --format json --output agent-bom-findings.json\n```\n\nChoose output by consumer:\n\n- SARIF for CI/code-scanning gates\n- JSON for graph, API, and automation\n- HTML or Markdown for human review\n- CycloneDX/SPDX for SBOM consumers\n\n## Evidence Contract\n\nValid inventory preserves `discovery_provenance`, `permissions_used`,\n`cloud_origin`, redaction state, package identity, server identity, tools, and\nsecurity intelligence. If the inventory is malformed or missing required trust\nfields, stop and ask the operator to regenerate it rather than scanning a\nbest-effort summary.\n\nFile v0.107.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-ingest\",\n  \"version\": \"0.107.0\",\n  \"publishedAt\": 1790799560835\n}\n\nFile v0.107.0:skill-card.md\n\n## Description:\n\nValidates operator-provided agent-bom inventory JSON and guides local scanning and export of findings, graphs, policy, and provenance.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security teams use this skill to validate operator-supplied agent inventories and produce local findings and auditor-ready exports without providing cloud credentials to agent-bom.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Inventory and exported findings may contain sensitive information.\n\nMitigation: Scan only intended inventory files and handle exported results as sensitive.\n\nRisk: An optional control-plane push may send inventory data to an unintended destination.\n\nMitigation: Verify the operator-provided destination before pushing and keep API tokens in environment variables, not chat.\n\nRisk: Untrusted or malformed inventory can lead to misleading findings.\n\nMitigation: Validate against the packaged schema and stop if required provenance or permissions fields are missing.\n\n## Reference(s):\n\n- [agent-bom project homepage](https://github.com/msaad00/agent-bom)\n- [agent-bom package](https://pypi.org/project/agent-bom/)\n- [ClawHub skill release](https://clawhub.ai/msaad00/skills/agent-bom-ingest)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Guidance, Files]\n\n**Output Format:** [Markdown guidance and commands; optional JSON, SARIF, HTML, Markdown, CycloneDX, or SPDX exports]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Requires Python 3.11+, agent-bom 0.84.4+, and inventory JSON conforming to the packaged schema.]\n\n## Skill Version(s):\n\n0.107.0 (source: server-resolved release and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.106.1: 3 files, 3216 bytes\n\nFiles: skill-card.md (1825b), SKILL.md (4216b), _meta.json (137b)\n\nFile v0.106.1:SKILL.md\n\n---\nname: agent-bom-ingest\ndescription: >-\n  Validate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure,\n  GCP, Snowflake, CMDB, or endpoint collectors. Use when a user has canonical\n  inventory JSON and wants local findings, graph, policy, provenance, or\n  auditor-ready exports without giving agent-bom direct cloud credentials.\nversion: 0.106.1\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+ and agent-bom 0.84.4+. Inventory must conform to the\n  packaged inventory.schema.json contract.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - agent-bom\n      env: []\n      credentials: none\n    credential_policy: \"No cloud credentials are required. Optional control-plane push uses an operator-provided agent-bom API token; never ask users to paste that token into chat and never print it.\"\n    optional_env:\n      - AGENT_BOM_API_KEY\n      - AGENT_BOM_PUSH_URL\n    optional_bins: []\n    emoji: \"inbox\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Inventory is schema-validated before it is trusted. Env var values, URL credentials, launch arguments, discovery_provenance, permissions_used, and security intelligence pass through the sanitizer/redaction contract before display/export.\"\n    data_flow: \"Operator-generated inventory JSON -> packaged inventory.schema.json validation -> local agent-bom scan/graph/export. Optional push to an operator-owned control plane goes only to the URL the operator provided.\"\n    file_reads:\n      - \"operator-selected inventory JSON file\"\n      - \"packaged agent_bom/data/inventory.schema.json\"\n    file_writes:\n      - \"operator-selected JSON/SARIF/HTML/Markdown export path\"\n    network_endpoints:\n      - url: \"operator-provided AGENT_BOM_PUSH_URL\"\n        purpose: \"Optional push into the operator-owned agent-bom control plane\"\n        auth: true\n        optional: true\n      - url: \"https://api.osv.dev/v1\"\n        purpose: \"Optional package vulnerability lookup during local scan\"\n        auth: false\n        optional: true\n      - url: \"https://api.github.com/advisories\"\n        purpose: \"Optional GitHub Advisory enrichment during local scan\"\n        auth: false\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-ingest\n\nUse this skill when the operator already produced canonical inventory JSON with\nan operator-pull adapter, endpoint collector, CMDB export, or AI-agent workflow.\nThe default path is local validation plus local scan/export.\n\n## Guardrails\n\n- Validate inventory with the packaged schema before treating it as evidence.\n- Require `discovery_provenance` and `permissions_used` where the source claims\n  cloud/operator-pushed discovery.\n- Require a trustworthy `discovery_provenance.source_type` such as\n  `operator_pushed_inventory` or `skill_invoked_pull`; do not infer it from\n  prose.\n- Do not invent provenance, permissions, cloud scopes, or credential posture.\n- Do not push to a control plane unless the operator provides the destination\n  URL and auth method explicitly.\n- Do not print raw tokens, URL credentials, private keys, or env var values.\n\n## Workflow\n\nValidate first:\n\n```bash\nagent-bom mcp validate inventory.json\n```\n\nScan locally:\n\n```bash\nagent-bom scan --inventory inventory.json --format json --output agent-bom-findings.json\n```\n\nChoose output by consumer:\n\n- SARIF for CI/code-scanning gates\n- JSON for graph, API, and automation\n- HTML or Markdown for human review\n- CycloneDX/SPDX for SBOM consumers\n\n## Evidence Contract\n\nValid inventory preserves `discovery_provenance`, `permissions_used`,\n`cloud_origin`, redaction state, package identity, server identity, tools, and\nsecurity intelligence. If the inventory is malformed or missing required trust\nfields, stop and ask the operator to regenerate it rather than scanning a\nbest-effort summary.\n\nFile v0.106.1:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-ingest\",\n  \"version\": \"0.106.1\",\n  \"publishedAt\": 1790468374665\n}\n\nFile v0.106.1:skill-card.md\n\n## Description:\n\nValidates operator-provided agent-bom inventory JSON and guides local scanning and export without requiring direct cloud credentials.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security teams use this skill to validate operator-generated agent inventories, scan them locally, and prepare findings or auditor-ready exports.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Optional vulnerability enrichment can share package or advisory query data with OSV or GitHub.\n\nMitigation: Review the data-sharing implications before enabling network enrichment.\n\nRisk: An optional control-plane push sends inventory to an operator-selected endpoint.\n\nMitigation: Enable push only after explicitly specifying and trusting the destination URL and authentication method; do not disclose tokens in chat or output.\n\n## Reference(s):\n\n- [agent-bom project](https://github.com/msaad00/agent-bom)\n- [agent-bom on PyPI](https://pypi.org/project/agent-bom/)\n- [agent-bom ingest release](https://clawhub.ai/msaad00/skills/agent-bom-ingest)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Guidance]\n\n**Output Format:** [Markdown with shell commands and export guidance]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Guides JSON, SARIF, HTML, Markdown, CycloneDX, or SPDX exports.]\n\n## Skill Version(s):\n\n0.106.1 (source: server release and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.105.0: 3 files, 3550 bytes\n\nFiles: skill-card.md (2597b), SKILL.md (4216b), _meta.json (137b)\n\nFile v0.105.0:SKILL.md\n\n---\nname: agent-bom-ingest\ndescription: >-\n  Validate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure,\n  GCP, Snowflake, CMDB, or endpoint collectors. Use when a user has canonical\n  inventory JSON and wants local findings, graph, policy, provenance, or\n  auditor-ready exports without giving agent-bom direct cloud credentials.\nversion: 0.105.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+ and agent-bom 0.84.4+. Inventory must conform to the\n  packaged inventory.schema.json contract.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - agent-bom\n      env: []\n      credentials: none\n    credential_policy: \"No cloud credentials are required. Optional control-plane push uses an operator-provided agent-bom API token; never ask users to paste that token into chat and never print it.\"\n    optional_env:\n      - AGENT_BOM_API_KEY\n      - AGENT_BOM_PUSH_URL\n    optional_bins: []\n    emoji: \"inbox\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Inventory is schema-validated before it is trusted. Env var values, URL credentials, launch arguments, discovery_provenance, permissions_used, and security intelligence pass through the sanitizer/redaction contract before display/export.\"\n    data_flow: \"Operator-generated inventory JSON -> packaged inventory.schema.json validation -> local agent-bom scan/graph/export. Optional push to an operator-owned control plane goes only to the URL the operator provided.\"\n    file_reads:\n      - \"operator-selected inventory JSON file\"\n      - \"packaged agent_bom/data/inventory.schema.json\"\n    file_writes:\n      - \"operator-selected JSON/SARIF/HTML/Markdown export path\"\n    network_endpoints:\n      - url: \"operator-provided AGENT_BOM_PUSH_URL\"\n        purpose: \"Optional push into the operator-owned agent-bom control plane\"\n        auth: true\n        optional: true\n      - url: \"https://api.osv.dev/v1\"\n        purpose: \"Optional package vulnerability lookup during local scan\"\n        auth: false\n        optional: true\n      - url: \"https://api.github.com/advisories\"\n        purpose: \"Optional GitHub Advisory enrichment during local scan\"\n        auth: false\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-ingest\n\nUse this skill when the operator already produced canonical inventory JSON with\nan operator-pull adapter, endpoint collector, CMDB export, or AI-agent workflow.\nThe default path is local validation plus local scan/export.\n\n## Guardrails\n\n- Validate inventory with the packaged schema before treating it as evidence.\n- Require `discovery_provenance` and `permissions_used` where the source claims\n  cloud/operator-pushed discovery.\n- Require a trustworthy `discovery_provenance.source_type` such as\n  `operator_pushed_inventory` or `skill_invoked_pull`; do not infer it from\n  prose.\n- Do not invent provenance, permissions, cloud scopes, or credential posture.\n- Do not push to a control plane unless the operator provides the destination\n  URL and auth method explicitly.\n- Do not print raw tokens, URL credentials, private keys, or env var values.\n\n## Workflow\n\nValidate first:\n\n```bash\nagent-bom mcp validate inventory.json\n```\n\nScan locally:\n\n```bash\nagent-bom scan --inventory inventory.json --format json --output agent-bom-findings.json\n```\n\nChoose output by consumer:\n\n- SARIF for CI/code-scanning gates\n- JSON for graph, API, and automation\n- HTML or Markdown for human review\n- CycloneDX/SPDX for SBOM consumers\n\n## Evidence Contract\n\nValid inventory preserves `discovery_provenance`, `permissions_used`,\n`cloud_origin`, redaction state, package identity, server identity, tools, and\nsecurity intelligence. If the inventory is malformed or missing required trust\nfields, stop and ask the operator to regenerate it rather than scanning a\nbest-effort summary.\n\nFile v0.105.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-ingest\",\n  \"version\": \"0.105.0\",\n  \"publishedAt\": 1789729949914\n}\n\nFile v0.105.0:skill-card.md\n\n## Description:\n\nValidate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure, GCP, Snowflake, CMDB, or endpoint collectors for local findings, graph, policy, provenance, and auditor-ready exports without giving agent-bom direct cloud credentials.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nApache-2.0\n\n## Use Case:\n\nDevelopers, security engineers, and auditors use this skill when they already have canonical inventory JSON and need schema validation, local scanning, policy review, provenance checks, and exports for CI, graph, automation, or human review.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Optional enrichment can send selected inventory data to OSV or GitHub Advisory endpoints, and optional push can send data to an operator-provided control-plane URL.\n\nMitigation: Enable those network flows only when the operator has approved the destination and understands what inventory data will be used.\n\nRisk: API tokens or URL credentials could be exposed if handled through chat or printed in logs.\n\nMitigation: Provide AGENT_BOM_API_KEY and push URLs through normal secret handling, and do not paste tokens into chat or display raw credentials.\n\nRisk: Malformed inventory or missing trust fields can produce unreliable scan and provenance results.\n\nMitigation: Validate inventory against the packaged schema and require discovery_provenance and permissions_used before scanning.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/msaad00/skills/agent-bom-ingest)\n- [agent-bom project homepage](https://github.com/msaad00/agent-bom)\n- [agent-bom PyPI package](https://pypi.org/project/agent-bom/)\n- [OSV vulnerability API](https://api.osv.dev/v1)\n- [GitHub Advisory Database API](https://api.github.com/advisories)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Configuration, JSON, Markdown, Code]\n\n**Output Format:** [Markdown guidance with bash commands and export format choices]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May produce operator-selected JSON, SARIF, HTML, Markdown, CycloneDX, or SPDX export files through agent-bom.]\n\n## Skill Version(s):\n\n0.105.0 (source: frontmatter and server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.104.0: 3 files, 3571 bytes\n\nFiles: skill-card.md (2675b), SKILL.md (4216b), _meta.json (137b)\n\nFile v0.104.0:SKILL.md\n\n---\nname: agent-bom-ingest\ndescription: >-\n  Validate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure,\n  GCP, Snowflake, CMDB, or endpoint collectors. Use when a user has canonical\n  inventory JSON and wants local findings, graph, policy, provenance, or\n  auditor-ready exports without giving agent-bom direct cloud credentials.\nversion: 0.104.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+ and agent-bom 0.84.4+. Inventory must conform to the\n  packaged inventory.schema.json contract.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - agent-bom\n      env: []\n      credentials: none\n    credential_policy: \"No cloud credentials are required. Optional control-plane push uses an operator-provided agent-bom API token; never ask users to paste that token into chat and never print it.\"\n    optional_env:\n      - AGENT_BOM_API_KEY\n      - AGENT_BOM_PUSH_URL\n    optional_bins: []\n    emoji: \"inbox\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Inventory is schema-validated before it is trusted. Env var values, URL credentials, launch arguments, discovery_provenance, permissions_used, and security intelligence pass through the sanitizer/redaction contract before display/export.\"\n    data_flow: \"Operator-generated inventory JSON -> packaged inventory.schema.json validation -> local agent-bom scan/graph/export. Optional push to an operator-owned control plane goes only to the URL the operator provided.\"\n    file_reads:\n      - \"operator-selected inventory JSON file\"\n      - \"packaged agent_bom/data/inventory.schema.json\"\n    file_writes:\n      - \"operator-selected JSON/SARIF/HTML/Markdown export path\"\n    network_endpoints:\n      - url: \"operator-provided AGENT_BOM_PUSH_URL\"\n        purpose: \"Optional push into the operator-owned agent-bom control plane\"\n        auth: true\n        optional: true\n      - url: \"https://api.osv.dev/v1\"\n        purpose: \"Optional package vulnerability lookup during local scan\"\n        auth: false\n        optional: true\n      - url: \"https://api.github.com/advisories\"\n        purpose: \"Optional GitHub Advisory enrichment during local scan\"\n        auth: false\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-ingest\n\nUse this skill when the operator already produced canonical inventory JSON with\nan operator-pull adapter, endpoint collector, CMDB export, or AI-agent workflow.\nThe default path is local validation plus local scan/export.\n\n## Guardrails\n\n- Validate inventory with the packaged schema before treating it as evidence.\n- Require `discovery_provenance` and `permissions_used` where the source claims\n  cloud/operator-pushed discovery.\n- Require a trustworthy `discovery_provenance.source_type` such as\n  `operator_pushed_inventory` or `skill_invoked_pull`; do not infer it from\n  prose.\n- Do not invent provenance, permissions, cloud scopes, or credential posture.\n- Do not push to a control plane unless the operator provides the destination\n  URL and auth method explicitly.\n- Do not print raw tokens, URL credentials, private keys, or env var values.\n\n## Workflow\n\nValidate first:\n\n```bash\nagent-bom mcp validate inventory.json\n```\n\nScan locally:\n\n```bash\nagent-bom scan --inventory inventory.json --format json --output agent-bom-findings.json\n```\n\nChoose output by consumer:\n\n- SARIF for CI/code-scanning gates\n- JSON for graph, API, and automation\n- HTML or Markdown for human review\n- CycloneDX/SPDX for SBOM consumers\n\n## Evidence Contract\n\nValid inventory preserves `discovery_provenance`, `permissions_used`,\n`cloud_origin`, redaction state, package identity, server identity, tools, and\nsecurity intelligence. If the inventory is malformed or missing required trust\nfields, stop and ask the operator to regenerate it rather than scanning a\nbest-effort summary.\n\nFile v0.104.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-ingest\",\n  \"version\": \"0.104.0\",\n  \"publishedAt\": 1788987450471\n}\n\nFile v0.104.0:skill-card.md\n\n## Description:\n\nValidate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure, GCP, Snowflake, CMDB, or endpoint collectors to produce local findings, graph, policy, provenance, or auditor-ready exports without giving agent-bom direct cloud credentials.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, operators, and auditors use this skill to validate canonical inventory JSON, run local agent-bom scans, and export results for CI, graph analysis, policy review, or human audit workflows.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill requires the external agent-bom command-line tool, so a compromised or unexpected installation could affect scan behavior.\n\nMitigation: Install agent-bom only from a trusted source and confirm the expected version before relying on findings or exports.\n\nRisk: Inventory files and exports may contain sensitive operational details, credentials, or security intelligence.\n\nMitigation: Validate inventory against the packaged schema, keep scans to intentionally selected files, and apply the documented sanitizer and redaction contract before displaying or exporting data.\n\nRisk: Optional advisory lookups and control-plane pushes may contact OSV, GitHub, or an operator-provided endpoint.\n\nMitigation: Use optional network features only when the operator approves them, and set AGENT_BOM_PUSH_URL or AGENT_BOM_API_KEY only for a control plane the operator operates or trusts.\n\n## Reference(s):\n\n- [agent-bom GitHub repository](https://github.com/msaad00/agent-bom)\n- [agent-bom PyPI package](https://pypi.org/project/agent-bom/)\n- [OSV API](https://api.osv.dev/v1)\n- [GitHub Advisory Database API](https://api.github.com/advisories)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance, Files]\n\n**Output Format:** [Markdown guidance with inline shell commands and optional JSON, SARIF, HTML, Markdown, CycloneDX, or SPDX export files.]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Outputs depend on an operator-selected inventory JSON file, local agent-bom scan options, and optional advisory lookup or control-plane push settings.]\n\n## Skill Version(s):\n\n0.104.0 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.103.2: 3 files, 3485 bytes\n\nFiles: skill-card.md (2395b), SKILL.md (4216b), _meta.json (137b)\n\nFile v0.103.2:SKILL.md\n\n---\nname: agent-bom-ingest\ndescription: >-\n  Validate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure,\n  GCP, Snowflake, CMDB, or endpoint collectors. Use when a user has canonical\n  inventory JSON and wants local findings, graph, policy, provenance, or\n  auditor-ready exports without giving agent-bom direct cloud credentials.\nversion: 0.103.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+ and agent-bom 0.84.4+. Inventory must conform to the\n  packaged inventory.schema.json contract.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - agent-bom\n      env: []\n      credentials: none\n    credential_policy: \"No cloud credentials are required. Optional control-plane push uses an operator-provided agent-bom API token; never ask users to paste that token into chat and never print it.\"\n    optional_env:\n      - AGENT_BOM_API_KEY\n      - AGENT_BOM_PUSH_URL\n    optional_bins: []\n    emoji: \"inbox\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Inventory is schema-validated before it is trusted. Env var values, URL credentials, launch arguments, discovery_provenance, permissions_used, and security intelligence pass through the sanitizer/redaction contract before display/export.\"\n    data_flow: \"Operator-generated inventory JSON -> packaged inventory.schema.json validation -> local agent-bom scan/graph/export. Optional push to an operator-owned control plane goes only to the URL the operator provided.\"\n    file_reads:\n      - \"operator-selected inventory JSON file\"\n      - \"packaged agent_bom/data/inventory.schema.json\"\n    file_writes:\n      - \"operator-selected JSON/SARIF/HTML/Markdown export path\"\n    network_endpoints:\n      - url: \"operator-provided AGENT_BOM_PUSH_URL\"\n        purpose: \"Optional push into the operator-owned agent-bom control plane\"\n        auth: true\n        optional: true\n      - url: \"https://api.osv.dev/v1\"\n        purpose: \"Optional package vulnerability lookup during local scan\"\n        auth: false\n        optional: true\n      - url: \"https://api.github.com/advisories\"\n        purpose: \"Optional GitHub Advisory enrichment during local scan\"\n        auth: false\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-ingest\n\nUse this skill when the operator already produced canonical inventory JSON with\nan operator-pull adapter, endpoint collector, CMDB export, or AI-agent workflow.\nThe default path is local validation plus local scan/export.\n\n## Guardrails\n\n- Validate inventory with the packaged schema before treating it as evidence.\n- Require `discovery_provenance` and `permissions_used` where the source claims\n  cloud/operator-pushed discovery.\n- Require a trustworthy `discovery_provenance.source_type` such as\n  `operator_pushed_inventory` or `skill_invoked_pull`; do not infer it from\n  prose.\n- Do not invent provenance, permissions, cloud scopes, or credential posture.\n- Do not push to a control plane unless the operator provides the destination\n  URL and auth method explicitly.\n- Do not print raw tokens, URL credentials, private keys, or env var values.\n\n## Workflow\n\nValidate first:\n\n```bash\nagent-bom mcp validate inventory.json\n```\n\nScan locally:\n\n```bash\nagent-bom scan --inventory inventory.json --format json --output agent-bom-findings.json\n```\n\nChoose output by consumer:\n\n- SARIF for CI/code-scanning gates\n- JSON for graph, API, and automation\n- HTML or Markdown for human review\n- CycloneDX/SPDX for SBOM consumers\n\n## Evidence Contract\n\nValid inventory preserves `discovery_provenance`, `permissions_used`,\n`cloud_origin`, redaction state, package identity, server identity, tools, and\nsecurity intelligence. If the inventory is malformed or missing required trust\nfields, stop and ask the operator to regenerate it rather than scanning a\nbest-effort summary.\n\nFile v0.103.2:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-ingest\",\n  \"version\": \"0.103.2\",\n  \"publishedAt\": 1788333933459\n}\n\nFile v0.103.2:skill-card.md\n\n## Description:\n\nValidates and ingests operator-pushed agent-bom inventory JSON from AWS, Azure, GCP, Snowflake, CMDB, or endpoint collectors for local findings, graph, policy, provenance, and auditor-ready exports without direct cloud credentials.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nApache-2.0\n\n## Use Case:\n\nDevelopers and engineers use this skill when they already have canonical inventory JSON and need to validate, scan, graph, or export local agent-bom findings without granting direct cloud credentials.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Inventory files can contain sensitive infrastructure details.\n\nMitigation: Review inventory content before scanning and rely on schema validation plus redaction before display or export.\n\nRisk: Optional push behavior can send results to an operator-provided control plane.\n\nMitigation: Set AGENT_BOM_PUSH_URL and AGENT_BOM_API_KEY only for an operator-owned destination and never expose token values in chat or output.\n\nRisk: Malformed or incomplete inventory can misrepresent provenance, permissions, or credential posture.\n\nMitigation: Stop and ask the operator to regenerate canonical inventory when required trust fields are missing instead of scanning a best-effort summary.\n\n## Reference(s):\n\n- [agent-bom repository](https://github.com/msaad00/agent-bom)\n- [agent-bom PyPI project](https://pypi.org/project/agent-bom/)\n- [OSV vulnerability API](https://api.osv.dev/v1)\n- [GitHub Advisory API](https://api.github.com/advisories)\n- [ClawHub skill page](https://clawhub.ai/msaad00/skills/agent-bom-ingest)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands, Configuration, Markdown]\n\n**Output Format:** [Markdown with inline bash code blocks]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May guide JSON, SARIF, HTML, Markdown, CycloneDX, or SPDX exports through the agent-bom CLI.]\n\n## Skill Version(s):\n\n0.103.2 (source: artifact/SKILL.md frontmatter and evidence.release.version)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.","readmeExcerpt":"Skill: agent-bom ingest Owner: msaad00 Summary: Validate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure, GCP, Snowflake, CMDB, or endpoint collectors. Use when a user has canonical inventory JSON and wants local findings, graph, policy, provenance, or auditor-ready exports without giving agent-bom direct cloud credentials. Tags: latest:0.108.3 Version history: v0.108.3 | 2026-10-08T22:19:15.016Z ","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"agent-bom mcp validate inventory.json"},{"language":"bash","snippet":"agent-bom scan --inventory inventory.json --format json --output agent-bom-findings.json"},{"language":"bash","snippet":"agent-bom mcp validate inventory.json"},{"language":"bash","snippet":"agent-bom scan --inventory inventory.json --format json --output agent-bom-findings.json"},{"language":"bash","snippet":"agent-bom mcp validate inventory.json"},{"language":"bash","snippet":"agent-bom scan --inventory inventory.json --format json --output agent-bom-findings.json"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: agent-bom-ingest\ndescription: >-\n  Validate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure,\n  GCP, Snowflake, CMDB, or endpoint collectors. Use when a user has canonical\n  inventory JSON and wants local findings, graph, policy, provenance, or\n  auditor-ready exports without giving agent-bom direct cloud credentials.\nversion: 0.108.3\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+ and agent-bom 0.84.4+. Inventory must conform to the\n  packaged inventory.schema.json contract.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - agent-bom\n      env: []\n      credentials: none\n    credential_policy: \"No cloud credentials are required. Optional control-plane push uses an operator-provided agent-bom API token; never ask users to paste that token into chat and never print it.\"\n    optional_env:\n      - AGENT_BOM_API_KEY\n      - AGENT_BOM_PUSH_URL\n    optional_bins: []\n    emoji: \"inbox\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Inventory is schema-validated before it is trusted. Env var values, URL credentials, launch arguments, discovery_provenance, permissions_used, and security intelligence pass through the sanitizer/redaction contract before display/export.\"\n    data_flow: \"Operator-generated inventory JSON -> packaged inventory.schema.json validation -> local agent-bom scan/graph/export. Optional push to an operator-owned control plane goes only to the URL the operator provided.\"\n    file_reads:\n      - \"operator-selected inventory JSON file\"\n      - \"packaged agent_bom/data/inventory.schema.json\"\n    file_writes:\n      - \"operator-selected JSON/SARIF/HTML/Markdown export path\"\n    network_endpoints:\n      - url: \"operator-provided AGENT_BOM_PUSH_URL\"\n        purpose: \"Optional push into the operator-owned agent-bom control plane\"\n        auth: true\n        optional: true\n      - url: \"https://api.osv.dev/v1\"\n        purpose: \"Optional package vulnerability lookup during local scan\"\n        auth: false\n        optional: true\n      - url: \"https://api.github.com/advisories\"\n        purpose: \"Optional GitHub Advisory enrichment during local scan\"\n        auth: false\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-ingest\n\nUse this skill when the operator already produced canonical inventory JSON with\nan operator-pull adapter, endpoint collector, CMDB export, or AI-agent workflow.\nThe default path is local validation plus local scan/export.\n\n## Guardrails\n\n- Validate inventory with the packaged schema before treating it as evidence.\n- Require `discovery_provenance` and"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-ingest\",\n  \"version\": \"0.108.3\",\n  \"publishedAt\": 1791497955016\n}"},{"path":"skill-card.md","content":"## Description:\n\nValidates operator-provided agent inventory JSON and guides local scanning and export without requiring direct cloud credentials.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to validate inventory supplied by their own collectors, scan it locally for findings, and prepare exports for security or audit workflows.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Selected inventory files could contain sensitive data or secrets.\n\nMitigation: Limit access to the intended inventory file, and verify redaction before including secrets or sharing exports.\n\nRisk: Optional advisory lookups or control-plane push can transmit data over the network.\n\nMitigation: Enable network lookups only when appropriate; push only to an operator-approved destination with its designated authentication method.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/msaad00/skills/agent-bom-ingest)\n- [agent-bom project homepage (declared in skill metadata)](https://github.com/msaad00/agent-bom)\n- [agent-bom package (declared in skill metadata)](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Guidance]\n\n**Output Format:** [Markdown with shell commands]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Guides validation and local scanning; the invoked tool can write operator-selected JSON, SARIF, HTML, or Markdown exports.]\n\n## Skill Version(s):\n\n0.108.3 (source: release metadata and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Validate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure, GCP, Snowflake, CMDB, or endpoint collectors. Use when a user has canonical inventory JSON and wants local findings, graph, policy, provenance, or auditor-ready exports without giving agent-bom direct cloud credentials. Skill: agent-bom ingest Owner: msaad00 Summary: Validate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure, GCP, Snowflake, CMDB, or endpoint collectors. Use when a user has canonical inventory JSON and wants local findings, graph, policy, provenance, or auditor-ready exports without giving agent-bom direct cloud credentials. Tags: latest:0.108.3 Version history: v0.108.3 | 2026-10-08T22:19:15.016Z","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1089,"uniquenessScore":46,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T05:33:10.485Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T05:33:10.485Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T14:20:30.190Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}