{"id":"2f39d3a1-a04d-4040-b37e-781408e9186f","entityType":"agent","slug":"clawhub-msaad00-agent-bom-registry","name":"agent-bom registry","canonicalUrl":"https://www.xpersona.co/agent/clawhub-msaad00-agent-bom-registry","canonicalPath":"/agent/clawhub-msaad00-agent-bom-registry","generatedAt":"2026-10-09T20:22:34.034Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T03:49:04.513Z","emptyReason":null},"description":"MCP server security registry and trust assessment — look up servers in the 1185-entry server security metadata registry, run pre-install marketplace checks, batch fleet risk scoring, assess skill file trust, and run SAST code scans. Use when the user mentions MCP server trust, registry lookup, marketplace check, or skill trust assessment.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 5.7K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom-registry","sourceUrl":"https://clawhub.ai/msaad00/agent-bom-registry","homepage":"https://clawhub.ai/msaad00/skills/agent-bom-registry","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/msaad00/agent-bom-registry","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/msaad00/skills/agent-bom-registry","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":55,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"agent-bom registry technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T03:49:04.513Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T03:49:04.513Z","emptyReason":null},"stars":null,"forks":null,"downloads":5700,"packageName":null,"latestVersion":"0.108.3","tractionLabel":"5.7K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T03:49:04.513Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T03:49:04.513Z","lastCrawledAt":"2026-10-09T03:49:04.513Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T03:49:04.513Z","lastVerifiedAt":null,"highlights":[{"version":"0.108.3","createdAt":"2026-10-08T22:17:58.863Z","changelog":"Release v0.108.3","fileCount":3,"zipByteSize":3177},{"version":"0.108.2","createdAt":"2026-10-08T05:01:12.874Z","changelog":"Release v0.108.2","fileCount":3,"zipByteSize":3232},{"version":"0.108.1","createdAt":"2026-10-06T17:47:52.201Z","changelog":"Release v0.108.1","fileCount":3,"zipByteSize":3151},{"version":"0.108.0","createdAt":"2026-10-04T07:12:50.165Z","changelog":"Release v0.108.0","fileCount":3,"zipByteSize":3128},{"version":"0.107.2","createdAt":"2026-10-01T23:32:25.129Z","changelog":"Release v0.107.2","fileCount":3,"zipByteSize":3198},{"version":"0.107.0","createdAt":"2026-09-30T20:18:10.463Z","changelog":"Release v0.107.0","fileCount":3,"zipByteSize":3253},{"version":"0.106.1","createdAt":"2026-09-27T00:18:27.292Z","changelog":"Release v0.106.1","fileCount":3,"zipByteSize":3283},{"version":"0.105.0","createdAt":"2026-09-18T11:11:33.751Z","changelog":"Release v0.105.0","fileCount":3,"zipByteSize":3303}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom-registry","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom-registry` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/msaad00/agent-bom-registry before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-registry/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-registry/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-registry/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-registry/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-registry/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-registry/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T20:22:34.033Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-registry/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-registry/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-registry/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-registry/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T03:49:04.513Z","emptyReason":null},"readme":"Skill: agent-bom registry\n\nOwner: msaad00\n\nSummary: MCP server security registry and trust assessment — look up servers in the 1185-entry server security metadata registry, run pre-install marketplace checks, batch fleet risk scoring, assess skill file trust, and run SAST code scans. Use when the user mentions MCP server trust, registry lookup, marketplace check, or skill trust assessment.\n\nTags: latest:0.108.3\n\nVersion history:\n\nv0.108.3 | 2026-10-08T22:17:58.863Z | user\n\nRelease v0.108.3\n\nv0.108.2 | 2026-10-08T05:01:12.874Z | user\n\nRelease v0.108.2\n\nv0.108.1 | 2026-10-06T17:47:52.201Z | user\n\nRelease v0.108.1\n\nv0.108.0 | 2026-10-04T07:12:50.165Z | user\n\nRelease v0.108.0\n\nv0.107.2 | 2026-10-01T23:32:25.129Z | user\n\nRelease v0.107.2\n\nv0.107.0 | 2026-09-30T20:18:10.463Z | user\n\nRelease v0.107.0\n\nv0.106.1 | 2026-09-27T00:18:27.292Z | user\n\nRelease v0.106.1\n\nv0.105.0 | 2026-09-18T11:11:33.751Z | user\n\nRelease v0.105.0\n\nv0.104.0 | 2026-09-09T20:56:10.138Z | user\n\nRelease v0.104.0\n\nv0.103.2 | 2026-09-02T07:24:11.091Z | user\n\nRelease v0.103.2\n\nv0.102.0 | 2026-08-24T04:49:53.056Z | user\n\nRelease v0.102.0\n\nv0.101.0 | 2026-08-16T23:13:11.556Z | user\n\nRelease v0.101.0\n\nv0.100.0 | 2026-08-12T20:55:02.671Z | user\n\nRelease v0.100.0\n\nv0.99.0 | 2026-08-06T00:52:37.535Z | user\n\nRelease v0.99.0\n\nv0.98.3 | 2026-08-03T06:09:06.760Z | user\n\nRelease v0.98.3\n\nv0.98.2 | 2026-07-27T08:50:09.828Z | user\n\nRelease v0.98.2\n\nv0.98.1 | 2026-07-27T02:02:12.146Z | user\n\nRelease v0.98.1\n\nv0.98.0 | 2026-07-25T01:51:15.522Z | user\n\nRelease v0.98.0\n\nv0.97.5 | 2026-07-24T01:43:38.584Z | user\n\nRelease v0.97.5\n\nv0.97.4 | 2026-07-23T00:59:17.299Z | user\n\nRelease v0.97.4\n\nv0.97.2 | 2026-07-21T18:19:15.178Z | user\n\nRelease v0.97.2\n\nv0.97.1 | 2026-07-21T03:31:41.545Z | user\n\nRelease v0.97.1\n\nv0.97.0 | 2026-07-20T18:10:55.888Z | user\n\nRelease v0.97.0\n\nv0.96.4 | 2026-07-20T15:05:47.917Z | user\n\nRelease v0.96.4\n\nv0.96.3 | 2026-07-16T04:05:42.991Z | user\n\nRelease v0.96.3\n\nv0.96.2 | 2026-07-15T23:05:23.281Z | user\n\nRelease v0.96.2\n\nv0.95.0 | 2026-07-13T21:38:37.959Z | user\n\nRelease v0.95.0\n\nv0.94.2 | 2026-07-09T18:24:42.259Z | user\n\nRelease v0.94.2\n\nv0.94.1 | 2026-07-09T05:50:58.492Z | user\n\nRelease v0.94.1\n\nv0.94.0 | 2026-07-08T21:48:12.021Z | user\n\nRelease v0.94.0\n\nv0.93.0 | 2026-07-06T07:43:03.427Z | user\n\nRelease v0.93.0\n\nv0.91.0 | 2026-06-30T23:36:39.491Z | user\n\nRelease v0.91.0\n\nv0.90.0 | 2026-06-30T03:47:54.535Z | user\n\nRelease v0.90.0\n\nv0.89.2 | 2026-06-22T03:17:56.600Z | user\n\nRelease v0.89.2\n\nv0.88.5 | 2026-06-01T06:24:01.757Z | user\n\nRelease v0.88.5\n\nv0.88.4 | 2026-05-26T04:20:25.594Z | user\n\nRelease v0.88.4\n\nv0.88.3 | 2026-05-25T00:57:29.624Z | user\n\nRelease v0.88.3\n\nv0.88.1 | 2026-05-22T04:38:31.932Z | user\n\nRelease v0.88.1\n\nv0.87.1 | 2026-05-18T20:25:48.967Z | user\n\nRelease v0.87.1\n\nv0.87.0 | 2026-05-18T00:36:57.333Z | user\n\nRelease v0.87.0\n\nv0.86.5 | 2026-05-11T16:16:10.342Z | user\n\nRelease v0.86.5\n\nv0.86.2 | 2026-05-07T15:45:22.281Z | user\n\nRelease v0.86.2\n\nv0.86.1 | 2026-05-06T06:42:29.651Z | user\n\nRelease v0.86.1\n\nv0.85.0 | 2026-05-02T22:48:55.264Z | user\n\nRelease v0.85.0\n\nv0.84.6 | 2026-05-02T06:44:18.122Z | user\n\nRelease v0.84.6\n\nv0.84.5 | 2026-05-02T03:29:24.493Z | user\n\nRelease v0.84.5\n\nv0.84.4 | 2026-05-01T19:07:46.136Z | user\n\nRelease v0.84.4\n\nv0.84.0 | 2026-05-01T01:53:39.776Z | user\n\nRelease v0.84.0\n\nv0.83.4 | 2026-04-30T19:33:49.277Z | user\n\nRelease v0.83.4\n\nv0.83.3 | 2026-04-30T05:47:46.253Z | user\n\nRelease v0.83.3\n\nArchive index:\n\nArchive v0.108.3: 3 files, 3177 bytes\n\nFiles: skill-card.md (1925b), SKILL.md (4402b), _meta.json (139b)\n\nFile v0.108.3:SKILL.md\n\n---\nname: agent-bom-registry\ndescription: >-\n  MCP server security registry and trust assessment — look up servers in the 1185-entry\n  server security metadata registry, run pre-install marketplace checks, batch\n  fleet risk scoring, assess skill file trust, and run SAST code scans. Use when\n  the user mentions MCP server trust, registry lookup, marketplace check, or\n  skill trust assessment.\nversion: 0.108.3\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: Semgrep for SAST\n  code scanning. No API keys or network access required (registry is bundled).\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Registry data is bundled locally. No network calls needed.\"\n    credential_handling: \"No credentials are required for bundled registry lookups. Optional enrichment tokens must stay in the operator environment and must not be printed or embedded in skill output.\"\n    optional_env:\n      - name: SNYK_TOKEN\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        required: false\n    optional_bins:\n      - semgrep\n    emoji: \"\\U0001F50D\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Purely local. Registry data (1185 MCP server metadata records) is bundled in the package. Lookups are in-memory string matches. Skill trust analysis parses user-provided SKILL.md content passed as a string argument.\"\n    file_reads:\n      - \"user-provided SKILL.md files (for skill_trust analysis)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://api.snyk.io\"\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-registry — MCP Server Trust & Security Registry\n\nLook up MCP servers in the 1185-entry server security metadata registry, assess skill\nfile trust, and run pre-install marketplace checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom mcp scan @modelcontextprotocol/server-brave-search --ecosystem npm\nagent-bom mcp scan @modelcontextprotocol/server-filesystem --ecosystem npm\n```\n\n## Tools (7)\n\n| Tool | Description |\n|------|-------------|\n| `registry_lookup` | Look up MCP server in the 1185-entry security metadata registry |\n| `marketplace_check` | Pre-install trust check with registry cross-reference |\n| `fleet_scan` | Batch registry lookup + risk scoring for MCP server inventories |\n| `skill_scan` | Scan instruction files for package refs, trust, and findings |\n| `skill_verify` | Verify Sigstore provenance for instruction files |\n| `skill_trust` | Assess skill file trust level (5-category analysis) |\n| `code_scan` | SAST scanning via Semgrep with CWE-based compliance mapping |\n\n## Example Workflows\n\n```\n# Look up a server in the registry\nregistry_lookup(server_name=\"brave-search\")\n\n# Pre-install trust check\nmarketplace_check(package=\"@modelcontextprotocol/server-filesystem\")\n\n# Scan instruction files and then assess a specific skill file\nskill_scan(path=\".\")\nskill_trust(skill_path=\"./SKILL.md\")\n\n# Batch risk scoring\nfleet_scan(servers=[\"brave-search\", \"github\", \"slack\"])\n```\n\n## MCP Resources\n\n| Resource | Description |\n|----------|-------------|\n| `registry://servers` | Browse the 1185-entry MCP server security metadata registry |\n\n## Privacy & Data Handling\n\nRegistry data is **bundled in the package** — lookups are in-memory string\nmatches with zero network calls. Skill trust analysis parses content passed\nas a string argument (no file system access needed).\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.108.3:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-registry\",\n  \"version\": \"0.108.3\",\n  \"publishedAt\": 1791497878863\n}\n\nFile v0.108.3:skill-card.md\n\n## Description:\n\nLooks up MCP server security metadata, checks packages before installation, scores server inventories, assesses skill trust, and supports code scanning.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security teams use this skill to check MCP server registry entries, assess skills and package trust, score server inventories, and request code scans.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Installing the optional third-party agent-bom package adds software to the operator environment.\n\nMitigation: Review the package before installing it with pipx or pip.\n\nRisk: Optional Snyk enrichment uses a token and sends scan data to a third-party service.\n\nMitigation: Keep SNYK_TOKEN in the operator environment, never include it in output, and only scan intended files or repositories.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/msaad00/skills/agent-bom-registry)\n- [Project homepage (listed in skill metadata)](https://github.com/msaad00/agent-bom)\n- [agent-bom on PyPI](https://pypi.org/project/agent-bom/)\n- [OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Guidance]\n\n**Output Format:** [Text or Markdown]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Registry matches, trust assessments, risk scores, and scan findings depend on the requested tool.]\n\n## Skill Version(s):\n\n0.108.3 (source: release metadata and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.108.2: 3 files, 3232 bytes\n\nFiles: skill-card.md (2037b), SKILL.md (4402b), _meta.json (139b)\n\nFile v0.108.2:SKILL.md\n\n---\nname: agent-bom-registry\ndescription: >-\n  MCP server security registry and trust assessment — look up servers in the 1185-entry\n  server security metadata registry, run pre-install marketplace checks, batch\n  fleet risk scoring, assess skill file trust, and run SAST code scans. Use when\n  the user mentions MCP server trust, registry lookup, marketplace check, or\n  skill trust assessment.\nversion: 0.108.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: Semgrep for SAST\n  code scanning. No API keys or network access required (registry is bundled).\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Registry data is bundled locally. No network calls needed.\"\n    credential_handling: \"No credentials are required for bundled registry lookups. Optional enrichment tokens must stay in the operator environment and must not be printed or embedded in skill output.\"\n    optional_env:\n      - name: SNYK_TOKEN\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        required: false\n    optional_bins:\n      - semgrep\n    emoji: \"\\U0001F50D\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Purely local. Registry data (1185 MCP server metadata records) is bundled in the package. Lookups are in-memory string matches. Skill trust analysis parses user-provided SKILL.md content passed as a string argument.\"\n    file_reads:\n      - \"user-provided SKILL.md files (for skill_trust analysis)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://api.snyk.io\"\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-registry — MCP Server Trust & Security Registry\n\nLook up MCP servers in the 1185-entry server security metadata registry, assess skill\nfile trust, and run pre-install marketplace checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom mcp scan @modelcontextprotocol/server-brave-search --ecosystem npm\nagent-bom mcp scan @modelcontextprotocol/server-filesystem --ecosystem npm\n```\n\n## Tools (7)\n\n| Tool | Description |\n|------|-------------|\n| `registry_lookup` | Look up MCP server in the 1185-entry security metadata registry |\n| `marketplace_check` | Pre-install trust check with registry cross-reference |\n| `fleet_scan` | Batch registry lookup + risk scoring for MCP server inventories |\n| `skill_scan` | Scan instruction files for package refs, trust, and findings |\n| `skill_verify` | Verify Sigstore provenance for instruction files |\n| `skill_trust` | Assess skill file trust level (5-category analysis) |\n| `code_scan` | SAST scanning via Semgrep with CWE-based compliance mapping |\n\n## Example Workflows\n\n```\n# Look up a server in the registry\nregistry_lookup(server_name=\"brave-search\")\n\n# Pre-install trust check\nmarketplace_check(package=\"@modelcontextprotocol/server-filesystem\")\n\n# Scan instruction files and then assess a specific skill file\nskill_scan(path=\".\")\nskill_trust(skill_path=\"./SKILL.md\")\n\n# Batch risk scoring\nfleet_scan(servers=[\"brave-search\", \"github\", \"slack\"])\n```\n\n## MCP Resources\n\n| Resource | Description |\n|----------|-------------|\n| `registry://servers` | Browse the 1185-entry MCP server security metadata registry |\n\n## Privacy & Data Handling\n\nRegistry data is **bundled in the package** — lookups are in-memory string\nmatches with zero network calls. Skill trust analysis parses content passed\nas a string argument (no file system access needed).\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.108.2:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-registry\",\n  \"version\": \"0.108.2\",\n  \"publishedAt\": 1791435672874\n}\n\nFile v0.108.2:skill-card.md\n\n## Description:\n\nLooks up MCP server security metadata and helps assess marketplace packages, server fleets, skill files, and source code for trust and security risks.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security teams use this skill to check MCP servers before installation, assess server inventories and skill files, and request code security scans.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Installing the required Python package introduces third-party code into the operator's environment.\n\nMitigation: Verify that you trust the agent-bom package source before installing it.\n\nRisk: Optional Snyk enrichment may send scan data to a third-party service.\n\nMitigation: Enable SNYK_TOKEN only when third-party enrichment is intended; bundled registry lookups require no credentials or network access.\n\n## Reference(s):\n\n- [ClawHub skill release](https://clawhub.ai/msaad00/skills/agent-bom-registry)\n- [Project homepage (listed in skill metadata; not verified import provenance)](https://github.com/msaad00/agent-bom)\n- [agent-bom package on PyPI](https://pypi.org/project/agent-bom/)\n- [OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Security assessment guidance, Shell commands]\n\n**Output Format:** [Markdown and text with scan results and commands]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Registry lookups use bundled data; optional code scans may use Semgrep and Snyk enrichment.]\n\n## Skill Version(s):\n\n0.108.2 (source: ClawHub release and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.108.1: 3 files, 3151 bytes\n\nFiles: skill-card.md (1855b), SKILL.md (4402b), _meta.json (139b)\n\nFile v0.108.1:SKILL.md\n\n---\nname: agent-bom-registry\ndescription: >-\n  MCP server security registry and trust assessment — look up servers in the 1185-entry\n  server security metadata registry, run pre-install marketplace checks, batch\n  fleet risk scoring, assess skill file trust, and run SAST code scans. Use when\n  the user mentions MCP server trust, registry lookup, marketplace check, or\n  skill trust assessment.\nversion: 0.108.1\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: Semgrep for SAST\n  code scanning. No API keys or network access required (registry is bundled).\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Registry data is bundled locally. No network calls needed.\"\n    credential_handling: \"No credentials are required for bundled registry lookups. Optional enrichment tokens must stay in the operator environment and must not be printed or embedded in skill output.\"\n    optional_env:\n      - name: SNYK_TOKEN\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        required: false\n    optional_bins:\n      - semgrep\n    emoji: \"\\U0001F50D\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Purely local. Registry data (1185 MCP server metadata records) is bundled in the package. Lookups are in-memory string matches. Skill trust analysis parses user-provided SKILL.md content passed as a string argument.\"\n    file_reads:\n      - \"user-provided SKILL.md files (for skill_trust analysis)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://api.snyk.io\"\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-registry — MCP Server Trust & Security Registry\n\nLook up MCP servers in the 1185-entry server security metadata registry, assess skill\nfile trust, and run pre-install marketplace checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom mcp scan @modelcontextprotocol/server-brave-search --ecosystem npm\nagent-bom mcp scan @modelcontextprotocol/server-filesystem --ecosystem npm\n```\n\n## Tools (7)\n\n| Tool | Description |\n|------|-------------|\n| `registry_lookup` | Look up MCP server in the 1185-entry security metadata registry |\n| `marketplace_check` | Pre-install trust check with registry cross-reference |\n| `fleet_scan` | Batch registry lookup + risk scoring for MCP server inventories |\n| `skill_scan` | Scan instruction files for package refs, trust, and findings |\n| `skill_verify` | Verify Sigstore provenance for instruction files |\n| `skill_trust` | Assess skill file trust level (5-category analysis) |\n| `code_scan` | SAST scanning via Semgrep with CWE-based compliance mapping |\n\n## Example Workflows\n\n```\n# Look up a server in the registry\nregistry_lookup(server_name=\"brave-search\")\n\n# Pre-install trust check\nmarketplace_check(package=\"@modelcontextprotocol/server-filesystem\")\n\n# Scan instruction files and then assess a specific skill file\nskill_scan(path=\".\")\nskill_trust(skill_path=\"./SKILL.md\")\n\n# Batch risk scoring\nfleet_scan(servers=[\"brave-search\", \"github\", \"slack\"])\n```\n\n## MCP Resources\n\n| Resource | Description |\n|----------|-------------|\n| `registry://servers` | Browse the 1185-entry MCP server security metadata registry |\n\n## Privacy & Data Handling\n\nRegistry data is **bundled in the package** — lookups are in-memory string\nmatches with zero network calls. Skill trust analysis parses content passed\nas a string argument (no file system access needed).\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.108.1:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-registry\",\n  \"version\": \"0.108.1\",\n  \"publishedAt\": 1791308872201\n}\n\nFile v0.108.1:skill-card.md\n\n## Description:\n\nChecks MCP server registry entries, marketplace packages, skill files, and code for security and trust concerns.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security teams use this skill to look up MCP server trust information, assess skill files, and review code scan findings before installation or deployment.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Installing agent-bom with pip or pipx fetches and runs an external package.\n\nMitigation: Review and approve the package and its dependencies before installation.\n\nRisk: Optional vulnerability enrichment sends requests to a third-party service using SNYK_TOKEN.\n\nMitigation: Enable enrichment only when intended, and keep the token in the operator environment rather than skill output.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/msaad00/skills/agent-bom-registry)\n- [Project homepage](https://github.com/msaad00/agent-bom)\n- [PyPI package](https://pypi.org/project/agent-bom/)\n- [OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Analysis, Text, Shell commands]\n\n**Output Format:** [Text and Markdown]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Registry matches, trust assessments, fleet risk scores, and optional code scan findings.]\n\n## Skill Version(s):\n\n0.108.1 (source: server release and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.108.0: 3 files, 3128 bytes\n\nFiles: skill-card.md (1804b), SKILL.md (4402b), _meta.json (139b)\n\nFile v0.108.0:SKILL.md\n\n---\nname: agent-bom-registry\ndescription: >-\n  MCP server security registry and trust assessment — look up servers in the 1163-entry\n  server security metadata registry, run pre-install marketplace checks, batch\n  fleet risk scoring, assess skill file trust, and run SAST code scans. Use when\n  the user mentions MCP server trust, registry lookup, marketplace check, or\n  skill trust assessment.\nversion: 0.108.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: Semgrep for SAST\n  code scanning. No API keys or network access required (registry is bundled).\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Registry data is bundled locally. No network calls needed.\"\n    credential_handling: \"No credentials are required for bundled registry lookups. Optional enrichment tokens must stay in the operator environment and must not be printed or embedded in skill output.\"\n    optional_env:\n      - name: SNYK_TOKEN\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        required: false\n    optional_bins:\n      - semgrep\n    emoji: \"\\U0001F50D\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Purely local. Registry data (1163 MCP server metadata records) is bundled in the package. Lookups are in-memory string matches. Skill trust analysis parses user-provided SKILL.md content passed as a string argument.\"\n    file_reads:\n      - \"user-provided SKILL.md files (for skill_trust analysis)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://api.snyk.io\"\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-registry — MCP Server Trust & Security Registry\n\nLook up MCP servers in the 1163-entry server security metadata registry, assess skill\nfile trust, and run pre-install marketplace checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom mcp scan @modelcontextprotocol/server-brave-search --ecosystem npm\nagent-bom mcp scan @modelcontextprotocol/server-filesystem --ecosystem npm\n```\n\n## Tools (7)\n\n| Tool | Description |\n|------|-------------|\n| `registry_lookup` | Look up MCP server in the 1163-entry security metadata registry |\n| `marketplace_check` | Pre-install trust check with registry cross-reference |\n| `fleet_scan` | Batch registry lookup + risk scoring for MCP server inventories |\n| `skill_scan` | Scan instruction files for package refs, trust, and findings |\n| `skill_verify` | Verify Sigstore provenance for instruction files |\n| `skill_trust` | Assess skill file trust level (5-category analysis) |\n| `code_scan` | SAST scanning via Semgrep with CWE-based compliance mapping |\n\n## Example Workflows\n\n```\n# Look up a server in the registry\nregistry_lookup(server_name=\"brave-search\")\n\n# Pre-install trust check\nmarketplace_check(package=\"@modelcontextprotocol/server-filesystem\")\n\n# Scan instruction files and then assess a specific skill file\nskill_scan(path=\".\")\nskill_trust(skill_path=\"./SKILL.md\")\n\n# Batch risk scoring\nfleet_scan(servers=[\"brave-search\", \"github\", \"slack\"])\n```\n\n## MCP Resources\n\n| Resource | Description |\n|----------|-------------|\n| `registry://servers` | Browse the 1163-entry MCP server security metadata registry |\n\n## Privacy & Data Handling\n\nRegistry data is **bundled in the package** — lookups are in-memory string\nmatches with zero network calls. Skill trust analysis parses content passed\nas a string argument (no file system access needed).\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.108.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-registry\",\n  \"version\": \"0.108.0\",\n  \"publishedAt\": 1791097970165\n}\n\nFile v0.108.0:skill-card.md\n\n## Description:\n\nHelps agents assess MCP server registry entries, pre-install trust, fleet risk, skill trust, and code-scanning findings.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to check MCP servers before installation, assess server inventories and skill files, and review code-scanning results.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Optional code scanning may read user-selected source files.\n\nMitigation: Review and limit the files selected for scanning.\n\nRisk: Optional Snyk enrichment sends requests to a third party and requires a token.\n\nMitigation: Enable enrichment only when intended; keep SNYK_TOKEN in the operator environment and out of skill output.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/msaad00/skills/agent-bom-registry)\n- [Project homepage](https://github.com/msaad00/agent-bom)\n- [agent-bom on PyPI](https://pypi.org/project/agent-bom/)\n- [OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Analysis, Guidance]\n\n**Output Format:** [Text or Markdown]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Registry lookups use bundled data; optional code scans may read selected source files.]\n\n## Skill Version(s):\n\n0.108.0 (source: ClawHub release metadata and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.107.2: 3 files, 3198 bytes\n\nFiles: skill-card.md (1916b), SKILL.md (4402b), _meta.json (139b)\n\nFile v0.107.2:SKILL.md\n\n---\nname: agent-bom-registry\ndescription: >-\n  MCP server security registry and trust assessment — look up servers in the 1163-entry\n  server security metadata registry, run pre-install marketplace checks, batch\n  fleet risk scoring, assess skill file trust, and run SAST code scans. Use when\n  the user mentions MCP server trust, registry lookup, marketplace check, or\n  skill trust assessment.\nversion: 0.107.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: Semgrep for SAST\n  code scanning. No API keys or network access required (registry is bundled).\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Registry data is bundled locally. No network calls needed.\"\n    credential_handling: \"No credentials are required for bundled registry lookups. Optional enrichment tokens must stay in the operator environment and must not be printed or embedded in skill output.\"\n    optional_env:\n      - name: SNYK_TOKEN\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        required: false\n    optional_bins:\n      - semgrep\n    emoji: \"\\U0001F50D\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Purely local. Registry data (1163 MCP server metadata records) is bundled in the package. Lookups are in-memory string matches. Skill trust analysis parses user-provided SKILL.md content passed as a string argument.\"\n    file_reads:\n      - \"user-provided SKILL.md files (for skill_trust analysis)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://api.snyk.io\"\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-registry — MCP Server Trust & Security Registry\n\nLook up MCP servers in the 1163-entry server security metadata registry, assess skill\nfile trust, and run pre-install marketplace checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom mcp scan @modelcontextprotocol/server-brave-search --ecosystem npm\nagent-bom mcp scan @modelcontextprotocol/server-filesystem --ecosystem npm\n```\n\n## Tools (7)\n\n| Tool | Description |\n|------|-------------|\n| `registry_lookup` | Look up MCP server in the 1163-entry security metadata registry |\n| `marketplace_check` | Pre-install trust check with registry cross-reference |\n| `fleet_scan` | Batch registry lookup + risk scoring for MCP server inventories |\n| `skill_scan` | Scan instruction files for package refs, trust, and findings |\n| `skill_verify` | Verify Sigstore provenance for instruction files |\n| `skill_trust` | Assess skill file trust level (5-category analysis) |\n| `code_scan` | SAST scanning via Semgrep with CWE-based compliance mapping |\n\n## Example Workflows\n\n```\n# Look up a server in the registry\nregistry_lookup(server_name=\"brave-search\")\n\n# Pre-install trust check\nmarketplace_check(package=\"@modelcontextprotocol/server-filesystem\")\n\n# Scan instruction files and then assess a specific skill file\nskill_scan(path=\".\")\nskill_trust(skill_path=\"./SKILL.md\")\n\n# Batch risk scoring\nfleet_scan(servers=[\"brave-search\", \"github\", \"slack\"])\n```\n\n## MCP Resources\n\n| Resource | Description |\n|----------|-------------|\n| `registry://servers` | Browse the 1163-entry MCP server security metadata registry |\n\n## Privacy & Data Handling\n\nRegistry data is **bundled in the package** — lookups are in-memory string\nmatches with zero network calls. Skill trust analysis parses content passed\nas a string argument (no file system access needed).\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.107.2:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-registry\",\n  \"version\": \"0.107.2\",\n  \"publishedAt\": 1790897545129\n}\n\nFile v0.107.2:skill-card.md\n\n## Description:\n\nLooks up MCP servers in a security registry and helps assess marketplace packages, skill trust, fleet risk, and code-scan findings.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security reviewers use this skill to check MCP servers before installation, assess skill files and server inventories, and review code-scan findings.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Installation adds a third-party Python package, and requested scans may read local skill files or code.\n\nMitigation: Install only if the package is acceptable to your environment, and scan only files or paths you intend to share with the tool.\n\nRisk: Optional vulnerability enrichment may use an external service and an access token.\n\nMitigation: Enable it only when needed; keep SNYK_TOKEN in the operator environment and out of skill output.\n\n## Reference(s):\n\n- [Project homepage (listed in skill metadata; provenance unavailable)](https://github.com/msaad00/agent-bom)\n- [agent-bom package](https://pypi.org/project/agent-bom/)\n- [Project security scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Analysis, Guidance]\n\n**Output Format:** [Text or Markdown]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Registry matches, trust assessments, risk scores, or scan findings, depending on the requested check.]\n\n## Skill Version(s):\n\n0.107.2 (source: ClawHub release and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.107.0: 3 files, 3253 bytes\n\nFiles: skill-card.md (2033b), SKILL.md (4402b), _meta.json (139b)\n\nFile v0.107.0:SKILL.md\n\n---\nname: agent-bom-registry\ndescription: >-\n  MCP server security registry and trust assessment — look up servers in the 1163-entry\n  server security metadata registry, run pre-install marketplace checks, batch\n  fleet risk scoring, assess skill file trust, and run SAST code scans. Use when\n  the user mentions MCP server trust, registry lookup, marketplace check, or\n  skill trust assessment.\nversion: 0.107.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: Semgrep for SAST\n  code scanning. No API keys or network access required (registry is bundled).\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Registry data is bundled locally. No network calls needed.\"\n    credential_handling: \"No credentials are required for bundled registry lookups. Optional enrichment tokens must stay in the operator environment and must not be printed or embedded in skill output.\"\n    optional_env:\n      - name: SNYK_TOKEN\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        required: false\n    optional_bins:\n      - semgrep\n    emoji: \"\\U0001F50D\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Purely local. Registry data (1163 MCP server metadata records) is bundled in the package. Lookups are in-memory string matches. Skill trust analysis parses user-provided SKILL.md content passed as a string argument.\"\n    file_reads:\n      - \"user-provided SKILL.md files (for skill_trust analysis)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://api.snyk.io\"\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-registry — MCP Server Trust & Security Registry\n\nLook up MCP servers in the 1163-entry server security metadata registry, assess skill\nfile trust, and run pre-install marketplace checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom mcp scan @modelcontextprotocol/server-brave-search --ecosystem npm\nagent-bom mcp scan @modelcontextprotocol/server-filesystem --ecosystem npm\n```\n\n## Tools (7)\n\n| Tool | Description |\n|------|-------------|\n| `registry_lookup` | Look up MCP server in the 1163-entry security metadata registry |\n| `marketplace_check` | Pre-install trust check with registry cross-reference |\n| `fleet_scan` | Batch registry lookup + risk scoring for MCP server inventories |\n| `skill_scan` | Scan instruction files for package refs, trust, and findings |\n| `skill_verify` | Verify Sigstore provenance for instruction files |\n| `skill_trust` | Assess skill file trust level (5-category analysis) |\n| `code_scan` | SAST scanning via Semgrep with CWE-based compliance mapping |\n\n## Example Workflows\n\n```\n# Look up a server in the registry\nregistry_lookup(server_name=\"brave-search\")\n\n# Pre-install trust check\nmarketplace_check(package=\"@modelcontextprotocol/server-filesystem\")\n\n# Scan instruction files and then assess a specific skill file\nskill_scan(path=\".\")\nskill_trust(skill_path=\"./SKILL.md\")\n\n# Batch risk scoring\nfleet_scan(servers=[\"brave-search\", \"github\", \"slack\"])\n```\n\n## MCP Resources\n\n| Resource | Description |\n|----------|-------------|\n| `registry://servers` | Browse the 1163-entry MCP server security metadata registry |\n\n## Privacy & Data Handling\n\nRegistry data is **bundled in the package** — lookups are in-memory string\nmatches with zero network calls. Skill trust analysis parses content passed\nas a string argument (no file system access needed).\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.107.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-registry\",\n  \"version\": \"0.107.0\",\n  \"publishedAt\": 1790799490463\n}\n\nFile v0.107.0:skill-card.md\n\n## Description:\n\nHelps assess MCP server trust through registry lookups, pre-install checks, fleet scoring, skill-file analysis, and code scans.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security teams use this skill to check MCP servers before installation, assess server inventories and skill files, and request code-scan guidance.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Optional vulnerability enrichment may send data to Snyk when configured.\n\nMitigation: Enable it only when appropriate, and keep the optional token in the operator environment rather than skill output.\n\nRisk: Skill-file analysis may read files explicitly supplied by the user.\n\nMitigation: Review file selections before analysis and avoid submitting sensitive files unnecessarily.\n\nRisk: Installing the external agent-bom package introduces supply-chain exposure.\n\nMitigation: Review the package source and pin a trusted release before installation when assurance matters.\n\n## Reference(s):\n\n- [Project homepage (publisher-listed; import provenance unavailable)](https://github.com/msaad00/agent-bom)\n- [agent-bom package](https://pypi.org/project/agent-bom/)\n- [OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Guidance]\n\n**Output Format:** [Text or Markdown with optional shell commands]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Registry matches, trust assessments, risk scores, and scan findings vary by input.]\n\n## Skill Version(s):\n\n0.107.0 (source: frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.106.1: 3 files, 3283 bytes\n\nFiles: skill-card.md (2158b), SKILL.md (4402b), _meta.json (139b)\n\nFile v0.106.1:SKILL.md\n\n---\nname: agent-bom-registry\ndescription: >-\n  MCP server security registry and trust assessment — look up servers in the 1151-entry\n  server security metadata registry, run pre-install marketplace checks, batch\n  fleet risk scoring, assess skill file trust, and run SAST code scans. Use when\n  the user mentions MCP server trust, registry lookup, marketplace check, or\n  skill trust assessment.\nversion: 0.106.1\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: Semgrep for SAST\n  code scanning. No API keys or network access required (registry is bundled).\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Registry data is bundled locally. No network calls needed.\"\n    credential_handling: \"No credentials are required for bundled registry lookups. Optional enrichment tokens must stay in the operator environment and must not be printed or embedded in skill output.\"\n    optional_env:\n      - name: SNYK_TOKEN\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        required: false\n    optional_bins:\n      - semgrep\n    emoji: \"\\U0001F50D\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Purely local. Registry data (1151 MCP server metadata records) is bundled in the package. Lookups are in-memory string matches. Skill trust analysis parses user-provided SKILL.md content passed as a string argument.\"\n    file_reads:\n      - \"user-provided SKILL.md files (for skill_trust analysis)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://api.snyk.io\"\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-registry — MCP Server Trust & Security Registry\n\nLook up MCP servers in the 1151-entry server security metadata registry, assess skill\nfile trust, and run pre-install marketplace checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom mcp scan @modelcontextprotocol/server-brave-search --ecosystem npm\nagent-bom mcp scan @modelcontextprotocol/server-filesystem --ecosystem npm\n```\n\n## Tools (7)\n\n| Tool | Description |\n|------|-------------|\n| `registry_lookup` | Look up MCP server in the 1151-entry security metadata registry |\n| `marketplace_check` | Pre-install trust check with registry cross-reference |\n| `fleet_scan` | Batch registry lookup + risk scoring for MCP server inventories |\n| `skill_scan` | Scan instruction files for package refs, trust, and findings |\n| `skill_verify` | Verify Sigstore provenance for instruction files |\n| `skill_trust` | Assess skill file trust level (5-category analysis) |\n| `code_scan` | SAST scanning via Semgrep with CWE-based compliance mapping |\n\n## Example Workflows\n\n```\n# Look up a server in the registry\nregistry_lookup(server_name=\"brave-search\")\n\n# Pre-install trust check\nmarketplace_check(package=\"@modelcontextprotocol/server-filesystem\")\n\n# Scan instruction files and then assess a specific skill file\nskill_scan(path=\".\")\nskill_trust(skill_path=\"./SKILL.md\")\n\n# Batch risk scoring\nfleet_scan(servers=[\"brave-search\", \"github\", \"slack\"])\n```\n\n## MCP Resources\n\n| Resource | Description |\n|----------|-------------|\n| `registry://servers` | Browse the 1151-entry MCP server security metadata registry |\n\n## Privacy & Data Handling\n\nRegistry data is **bundled in the package** — lookups are in-memory string\nmatches with zero network calls. Skill trust analysis parses content passed\nas a string argument (no file system access needed).\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.106.1:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-registry\",\n  \"version\": \"0.106.1\",\n  \"publishedAt\": 1790468307292\n}\n\nFile v0.106.1:skill-card.md\n\n## Description:\n\nLooks up MCP server security metadata, checks packages before installation, scores server inventories, assesses skill trust, and helps run code scans.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security teams use this skill to evaluate MCP servers and skill files before installation or deployment, review fleet risks, and inspect source code for security findings.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Security checks may read skill files or source code selected by the user.\n\nMitigation: Review the scan scope and avoid supplying sensitive files unnecessarily.\n\nRisk: Optional Snyk enrichment may send scan information to a third party and use SNYK_TOKEN.\n\nMitigation: Enable enrichment only when approved; keep the token in the operator environment and out of skill output.\n\nRisk: The skill's broad privacy claims may not describe optional network-based enrichment or file reads accurately.\n\nMitigation: Confirm data handling for the selected operation before running it.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/msaad00/skills/agent-bom-registry)\n- [Project homepage listed in skill metadata](https://github.com/msaad00/agent-bom)\n- [agent-bom on PyPI](https://pypi.org/project/agent-bom/)\n- [OpenSSF Scorecard listed in skill metadata](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Guidance]\n\n**Output Format:** [Text and structured tool results]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include registry matches, risk scores, skill trust assessments, and code scan findings.]\n\n## Skill Version(s):\n\n0.106.1 (source: release metadata and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.105.0: 3 files, 3303 bytes\n\nFiles: skill-card.md (2235b), SKILL.md (4402b), _meta.json (139b)\n\nFile v0.105.0:SKILL.md\n\n---\nname: agent-bom-registry\ndescription: >-\n  MCP server security registry and trust assessment — look up servers in the 1142-entry\n  server security metadata registry, run pre-install marketplace checks, batch\n  fleet risk scoring, assess skill file trust, and run SAST code scans. Use when\n  the user mentions MCP server trust, registry lookup, marketplace check, or\n  skill trust assessment.\nversion: 0.105.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: Semgrep for SAST\n  code scanning. No API keys or network access required (registry is bundled).\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Registry data is bundled locally. No network calls needed.\"\n    credential_handling: \"No credentials are required for bundled registry lookups. Optional enrichment tokens must stay in the operator environment and must not be printed or embedded in skill output.\"\n    optional_env:\n      - name: SNYK_TOKEN\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        required: false\n    optional_bins:\n      - semgrep\n    emoji: \"\\U0001F50D\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Purely local. Registry data (1142 MCP server metadata records) is bundled in the package. Lookups are in-memory string matches. Skill trust analysis parses user-provided SKILL.md content passed as a string argument.\"\n    file_reads:\n      - \"user-provided SKILL.md files (for skill_trust analysis)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://api.snyk.io\"\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-registry — MCP Server Trust & Security Registry\n\nLook up MCP servers in the 1142-entry server security metadata registry, assess skill\nfile trust, and run pre-install marketplace checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom mcp scan @modelcontextprotocol/server-brave-search --ecosystem npm\nagent-bom mcp scan @modelcontextprotocol/server-filesystem --ecosystem npm\n```\n\n## Tools (7)\n\n| Tool | Description |\n|------|-------------|\n| `registry_lookup` | Look up MCP server in the 1142-entry security metadata registry |\n| `marketplace_check` | Pre-install trust check with registry cross-reference |\n| `fleet_scan` | Batch registry lookup + risk scoring for MCP server inventories |\n| `skill_scan` | Scan instruction files for package refs, trust, and findings |\n| `skill_verify` | Verify Sigstore provenance for instruction files |\n| `skill_trust` | Assess skill file trust level (5-category analysis) |\n| `code_scan` | SAST scanning via Semgrep with CWE-based compliance mapping |\n\n## Example Workflows\n\n```\n# Look up a server in the registry\nregistry_lookup(server_name=\"brave-search\")\n\n# Pre-install trust check\nmarketplace_check(package=\"@modelcontextprotocol/server-filesystem\")\n\n# Scan instruction files and then assess a specific skill file\nskill_scan(path=\".\")\nskill_trust(skill_path=\"./SKILL.md\")\n\n# Batch risk scoring\nfleet_scan(servers=[\"brave-search\", \"github\", \"slack\"])\n```\n\n## MCP Resources\n\n| Resource | Description |\n|----------|-------------|\n| `registry://servers` | Browse the 1142-entry MCP server security metadata registry |\n\n## Privacy & Data Handling\n\nRegistry data is **bundled in the package** — lookups are in-memory string\nmatches with zero network calls. Skill trust analysis parses content passed\nas a string argument (no file system access needed).\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.105.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-registry\",\n  \"version\": \"0.105.0\",\n  \"publishedAt\": 1789729893751\n}\n\nFile v0.105.0:skill-card.md\n\n## Description:\n\nMCP server security registry and trust assessment: look up servers in the 1142-entry server security metadata registry, run pre-install marketplace checks, batch fleet risk scoring, assess skill file trust, and run SAST code scans.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security reviewers use this skill to check MCP server trust signals, evaluate marketplace packages before installation, scan fleets of MCP servers, assess skill files, and run optional static code analysis.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Optional code scanning or Snyk enrichment may share scan metadata with Snyk when enabled.\n\nMitigation: Confirm the operator is comfortable with that sharing before enrichment, and keep SNYK_TOKEN in the environment rather than prompts or outputs.\n\nRisk: Skill trust analysis depends on user-provided SKILL.md content and registry metadata.\n\nMitigation: Review analysis results before deployment and use the bundled security guidance as decision support rather than automatic approval.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/msaad00/skills/agent-bom-registry)\n- [Project homepage](https://github.com/msaad00/agent-bom)\n- [PyPI package](https://pypi.org/project/agent-bom/)\n- [OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown with inline shell commands and structured analysis]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include registry lookup results, trust assessments, risk scoring, SAST findings, and installation or configuration guidance.]\n\n## Skill Version(s):\n\n0.105.0 (source: server release metadata and frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.104.0: 3 files, 3373 bytes\n\nFiles: skill-card.md (2412b), SKILL.md (4402b), _meta.json (139b)\n\nFile v0.104.0:SKILL.md\n\n---\nname: agent-bom-registry\ndescription: >-\n  MCP server security registry and trust assessment — look up servers in the 1133-entry\n  server security metadata registry, run pre-install marketplace checks, batch\n  fleet risk scoring, assess skill file trust, and run SAST code scans. Use when\n  the user mentions MCP server trust, registry lookup, marketplace check, or\n  skill trust assessment.\nversion: 0.104.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: Semgrep for SAST\n  code scanning. No API keys or network access required (registry is bundled).\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Registry data is bundled locally. No network calls needed.\"\n    credential_handling: \"No credentials are required for bundled registry lookups. Optional enrichment tokens must stay in the operator environment and must not be printed or embedded in skill output.\"\n    optional_env:\n      - name: SNYK_TOKEN\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        required: false\n    optional_bins:\n      - semgrep\n    emoji: \"\\U0001F50D\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Purely local. Registry data (1133 MCP server metadata records) is bundled in the package. Lookups are in-memory string matches. Skill trust analysis parses user-provided SKILL.md content passed as a string argument.\"\n    file_reads:\n      - \"user-provided SKILL.md files (for skill_trust analysis)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://api.snyk.io\"\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-registry — MCP Server Trust & Security Registry\n\nLook up MCP servers in the 1133-entry server security metadata registry, assess skill\nfile trust, and run pre-install marketplace checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom mcp scan @modelcontextprotocol/server-brave-search --ecosystem npm\nagent-bom mcp scan @modelcontextprotocol/server-filesystem --ecosystem npm\n```\n\n## Tools (7)\n\n| Tool | Description |\n|------|-------------|\n| `registry_lookup` | Look up MCP server in the 1133-entry security metadata registry |\n| `marketplace_check` | Pre-install trust check with registry cross-reference |\n| `fleet_scan` | Batch registry lookup + risk scoring for MCP server inventories |\n| `skill_scan` | Scan instruction files for package refs, trust, and findings |\n| `skill_verify` | Verify Sigstore provenance for instruction files |\n| `skill_trust` | Assess skill file trust level (5-category analysis) |\n| `code_scan` | SAST scanning via Semgrep with CWE-based compliance mapping |\n\n## Example Workflows\n\n```\n# Look up a server in the registry\nregistry_lookup(server_name=\"brave-search\")\n\n# Pre-install trust check\nmarketplace_check(package=\"@modelcontextprotocol/server-filesystem\")\n\n# Scan instruction files and then assess a specific skill file\nskill_scan(path=\".\")\nskill_trust(skill_path=\"./SKILL.md\")\n\n# Batch risk scoring\nfleet_scan(servers=[\"brave-search\", \"github\", \"slack\"])\n```\n\n## MCP Resources\n\n| Resource | Description |\n|----------|-------------|\n| `registry://servers` | Browse the 1133-entry MCP server security metadata registry |\n\n## Privacy & Data Handling\n\nRegistry data is **bundled in the package** — lookups are in-memory string\nmatches with zero network calls. Skill trust analysis parses content passed\nas a string argument (no file system access needed).\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.104.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-registry\",\n  \"version\": \"0.104.0\",\n  \"publishedAt\": 1788987370138\n}\n\nFile v0.104.0:skill-card.md\n\n## Description:\n\nProvides MCP server security registry lookup and trust assessment for server metadata, marketplace checks, fleet risk scoring, skill-file trust checks, and SAST code scans.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nApache-2.0\n\n## Use Case:\n\nDevelopers and security engineers use this skill to check MCP server trust, scan skill files, and review package or fleet risk before installation or deployment.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Installing the agent-bom Python package from PyPI runs third-party package code in the local environment.\n\nMitigation: Pin a reviewed version and install with pipx or another isolated environment before use.\n\nRisk: Optional Snyk enrichment requires an authenticated SNYK_TOKEN and may contact a third-party API.\n\nMitigation: Provide SNYK_TOKEN only when Snyk enrichment is intended, keep it in the operator environment, and avoid printing or embedding token values in outputs.\n\nRisk: Security registry lookups and SAST results can be incomplete or stale.\n\nMitigation: Treat findings as decision support and review high-impact installation or deployment decisions before acting.\n\n## Reference(s):\n\n- [agent-bom project homepage](https://github.com/msaad00/agent-bom)\n- [agent-bom PyPI package](https://pypi.org/project/agent-bom/)\n- [OpenSSF Scorecard for agent-bom](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n- [ClawHub skill page](https://clawhub.ai/msaad00/skills/agent-bom-registry)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown or text responses with commands, configuration guidance, and structured security findings.]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May reference bundled registry data, user-provided SKILL.md content, optional Semgrep findings, and optional Snyk enrichment when explicitly configured.]\n\n## Skill Version(s):\n\n0.104.0 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.103.2: 3 files, 3332 bytes\n\nFiles: skill-card.md (2251b), SKILL.md (4402b), _meta.json (139b)\n\nFile v0.103.2:SKILL.md\n\n---\nname: agent-bom-registry\ndescription: >-\n  MCP server security registry and trust assessment — look up servers in the 1123-entry\n  server security metadata registry, run pre-install marketplace checks, batch\n  fleet risk scoring, assess skill file trust, and run SAST code scans. Use when\n  the user mentions MCP server trust, registry lookup, marketplace check, or\n  skill trust assessment.\nversion: 0.103.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: Semgrep for SAST\n  code scanning. No API keys or network access required (registry is bundled).\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Registry data is bundled locally. No network calls needed.\"\n    credential_handling: \"No credentials are required for bundled registry lookups. Optional enrichment tokens must stay in the operator environment and must not be printed or embedded in skill output.\"\n    optional_env:\n      - name: SNYK_TOKEN\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        required: false\n    optional_bins:\n      - semgrep\n    emoji: \"\\U0001F50D\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Purely local. Registry data (1123 MCP server metadata records) is bundled in the package. Lookups are in-memory string matches. Skill trust analysis parses user-provided SKILL.md content passed as a string argument.\"\n    file_reads:\n      - \"user-provided SKILL.md files (for skill_trust analysis)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://api.snyk.io\"\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-registry — MCP Server Trust & Security Registry\n\nLook up MCP servers in the 1123-entry server security metadata registry, assess skill\nfile trust, and run pre-install marketplace checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom mcp scan @modelcontextprotocol/server-brave-search --ecosystem npm\nagent-bom mcp scan @modelcontextprotocol/server-filesystem --ecosystem npm\n```\n\n## Tools (7)\n\n| Tool | Description |\n|------|-------------|\n| `registry_lookup` | Look up MCP server in the 1123-entry security metadata registry |\n| `marketplace_check` | Pre-install trust check with registry cross-reference |\n| `fleet_scan` | Batch registry lookup + risk scoring for MCP server inventories |\n| `skill_scan` | Scan instruction files for package refs, trust, and findings |\n| `skill_verify` | Verify Sigstore provenance for instruction files |\n| `skill_trust` | Assess skill file trust level (5-category analysis) |\n| `code_scan` | SAST scanning via Semgrep with CWE-based compliance mapping |\n\n## Example Workflows\n\n```\n# Look up a server in the registry\nregistry_lookup(server_name=\"brave-search\")\n\n# Pre-install trust check\nmarketplace_check(package=\"@modelcontextprotocol/server-filesystem\")\n\n# Scan instruction files and then assess a specific skill file\nskill_scan(path=\".\")\nskill_trust(skill_path=\"./SKILL.md\")\n\n# Batch risk scoring\nfleet_scan(servers=[\"brave-search\", \"github\", \"slack\"])\n```\n\n## MCP Resources\n\n| Resource | Description |\n|----------|-------------|\n| `registry://servers` | Browse the 1123-entry MCP server security metadata registry |\n\n## Privacy & Data Handling\n\nRegistry data is **bundled in the package** — lookups are in-memory string\nmatches with zero network calls. Skill trust analysis parses content passed\nas a string argument (no file system access needed).\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.103.2:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-registry\",\n  \"version\": \"0.103.2\",\n  \"publishedAt\": 1788333851091\n}\n\nFile v0.103.2:skill-card.md\n\n## Description:\n\nMCP server security registry and trust assessment - look up servers in the 1123-entry server security metadata registry, run pre-install marketplace checks, batch fleet risk scoring, assess skill file trust, and run SAST code scans.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nApache-2.0\n\n## Use Case:\n\nDevelopers and engineers use this skill to assess MCP server trust, check marketplace packages before installation, score MCP server inventories, evaluate skill files, and run optional SAST scans.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Code and skill scanning requires the operator to point the tool at files or directories.\n\nMitigation: Scan only intended paths and review findings before using the results to make installation or deployment decisions.\n\nRisk: Optional Snyk enrichment sends requests to a third-party service and requires SNYK_TOKEN.\n\nMitigation: Use Snyk enrichment only when approved for the environment, keep the token in the operator environment, and avoid including it in prompts, files, or output.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/msaad00/skills/agent-bom-registry)\n- [Source repository](https://github.com/msaad00/agent-bom)\n- [PyPI package](https://pypi.org/project/agent-bom/)\n- [OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown and text with inline shell commands and structured scan findings]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Registry lookup data is bundled locally; optional code scanning may use Semgrep, and optional Snyk enrichment requires SNYK_TOKEN.]\n\n## Skill Version(s):\n\n0.103.2 (source: artifact/SKILL.md frontmatter and server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.","readmeExcerpt":"Skill: agent-bom registry Owner: msaad00 Summary: MCP server security registry and trust assessment — look up servers in the 1185-entry server security metadata registry, run pre-install marketplace checks, batch fleet risk scoring, assess skill file trust, and run SAST code scans. Use when the user mentions MCP server trust, registry lookup, marketplace check, or skill trust assessment. Tags: latest:0.108.3 Version ","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"pipx install agent-bom\nagent-bom mcp scan @modelcontextprotocol/server-brave-search --ecosystem npm\nagent-bom mcp scan @modelcontextprotocol/server-filesystem --ecosystem npm"},{"language":"text","snippet":"# Look up a server in the registry\nregistry_lookup(server_name=\"brave-search\")\n\n# Pre-install trust check\nmarketplace_check(package=\"@modelcontextprotocol/server-filesystem\")\n\n# Scan instruction files and then assess a specific skill file\nskill_scan(path=\".\")\nskill_trust(skill_path=\"./SKILL.md\")\n\n# Batch risk scoring\nfleet_scan(servers=[\"brave-search\", \"github\", \"slack\"])"},{"language":"bash","snippet":"pipx install agent-bom\nagent-bom mcp scan @modelcontextprotocol/server-brave-search --ecosystem npm\nagent-bom mcp scan @modelcontextprotocol/server-filesystem --ecosystem npm"},{"language":"text","snippet":"# Look up a server in the registry\nregistry_lookup(server_name=\"brave-search\")\n\n# Pre-install trust check\nmarketplace_check(package=\"@modelcontextprotocol/server-filesystem\")\n\n# Scan instruction files and then assess a specific skill file\nskill_scan(path=\".\")\nskill_trust(skill_path=\"./SKILL.md\")\n\n# Batch risk scoring\nfleet_scan(servers=[\"brave-search\", \"github\", \"slack\"])"},{"language":"bash","snippet":"pipx install agent-bom\nagent-bom mcp scan @modelcontextprotocol/server-brave-search --ecosystem npm\nagent-bom mcp scan @modelcontextprotocol/server-filesystem --ecosystem npm"},{"language":"text","snippet":"# Look up a server in the registry\nregistry_lookup(server_name=\"brave-search\")\n\n# Pre-install trust check\nmarketplace_check(package=\"@modelcontextprotocol/server-filesystem\")\n\n# Scan instruction files and then assess a specific skill file\nskill_scan(path=\".\")\nskill_trust(skill_path=\"./SKILL.md\")\n\n# Batch risk scoring\nfleet_scan(servers=[\"brave-search\", \"github\", \"slack\"])"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: agent-bom-registry\ndescription: >-\n  MCP server security registry and trust assessment — look up servers in the 1185-entry\n  server security metadata registry, run pre-install marketplace checks, batch\n  fleet risk scoring, assess skill file trust, and run SAST code scans. Use when\n  the user mentions MCP server trust, registry lookup, marketplace check, or\n  skill trust assessment.\nversion: 0.108.3\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: Semgrep for SAST\n  code scanning. No API keys or network access required (registry is bundled).\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Registry data is bundled locally. No network calls needed.\"\n    credential_handling: \"No credentials are required for bundled registry lookups. Optional enrichment tokens must stay in the operator environment and must not be printed or embedded in skill output.\"\n    optional_env:\n      - name: SNYK_TOKEN\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        required: false\n    optional_bins:\n      - semgrep\n    emoji: \"\\U0001F50D\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Purely local. Registry data (1185 MCP server metadata records) is bundled in the package. Lookups are in-memory string matches. Skill trust analysis parses user-provided SKILL.md content passed as a string argument.\"\n    file_reads:\n      - \"user-provided SKILL.md files (for skill_trust analysis)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://api.snyk.io\"\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-registry — MCP Server Trust & Security Registry\n\nLook up MCP servers in the 1185-entry server security metadata registry, assess skill\nfile trust, and run pre-install marketplace checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom mcp scan @modelcontextprotocol/server-brave-search --ecosystem npm\nagent-bom mcp scan @modelcontextprotocol/server-filesystem --ecosystem npm\n```\n\n## Tools (7)\n\n| Tool | Description |\n|------|-------------|\n| `registry_lookup` | Look up MCP server in the 1185-entry security metadata registry |\n| `marketplace_check` | Pre-install trust check with registry cross-reference |\n|"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-registry\",\n  \"version\": \"0.108.3\",\n  \"publishedAt\": 1791497878863\n}"},{"path":"skill-card.md","content":"## Description:\n\nLooks up MCP server security metadata, checks packages before installation, scores server inventories, assesses skill trust, and supports code scanning.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security teams use this skill to check MCP server registry entries, assess skills and package trust, score server inventories, and request code scans.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Installing the optional third-party agent-bom package adds software to the operator environment.\n\nMitigation: Review the package before installing it with pipx or pip.\n\nRisk: Optional Snyk enrichment uses a token and sends scan data to a third-party service.\n\nMitigation: Keep SNYK_TOKEN in the operator environment, never include it in output, and only scan intended files or repositories.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/msaad00/skills/agent-bom-registry)\n- [Project homepage (listed in skill metadata)](https://github.com/msaad00/agent-bom)\n- [agent-bom on PyPI](https://pypi.org/project/agent-bom/)\n- [OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Guidance]\n\n**Output Format:** [Text or Markdown]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Registry matches, trust assessments, risk scores, and scan findings depend on the requested tool.]\n\n## Skill Version(s):\n\n0.108.3 (source: release metadata and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1066,"uniquenessScore":44,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T03:49:04.513Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T03:49:04.513Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T20:22:34.034Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}