{"id":"7d6f4a1d-2791-4875-9f17-0c67587e72a6","entityType":"agent","slug":"clawhub-msaad00-agent-bom-runtime","name":"agent-bom runtime","canonicalUrl":"https://www.xpersona.co/agent/clawhub-msaad00-agent-bom-runtime","canonicalPath":"/agent/clawhub-msaad00-agent-bom-runtime","generatedAt":"2026-10-09T12:54:55.146Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T03:47:40.422Z","emptyReason":null},"description":"AI runtime security monitoring — context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries. Use when the user mentions runtime monitoring, context graphs, lateral movement analysis, audit log correlation, or vulnerability analytics. Skill: agent-bom runtime Owner: msaad00 Summary: AI runtime security monitoring — context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries. Use when the user mentions runtime monitoring, context graphs, lateral movement analysis, audit log correlation, or vulnerability analytics. Tags: latest:0.108.3 Version history: v0.108.3 | 2026-10-08T22:18:13.720Z | user Releas","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 5.7K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom-runtime","sourceUrl":"https://clawhub.ai/msaad00/agent-bom-runtime","homepage":"https://clawhub.ai/msaad00/skills/agent-bom-runtime","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/msaad00/agent-bom-runtime","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/msaad00/skills/agent-bom-runtime","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":55,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"AI runtime security monitoring — context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries. Use when the user"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T03:47:40.422Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T03:47:40.422Z","emptyReason":null},"stars":null,"forks":null,"downloads":5734,"packageName":null,"latestVersion":"0.108.3","tractionLabel":"5.7K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T03:47:40.421Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T03:47:40.422Z","lastCrawledAt":"2026-10-09T03:47:40.421Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T03:47:40.421Z","lastVerifiedAt":null,"highlights":[{"version":"0.108.3","createdAt":"2026-10-08T22:18:13.720Z","changelog":"Release v0.108.3","fileCount":3,"zipByteSize":2785},{"version":"0.108.2","createdAt":"2026-10-08T05:01:28.097Z","changelog":"Release v0.108.2","fileCount":3,"zipByteSize":2793},{"version":"0.108.1","createdAt":"2026-10-06T17:48:01.316Z","changelog":"Release v0.108.1","fileCount":3,"zipByteSize":2840},{"version":"0.108.0","createdAt":"2026-10-04T07:12:59.234Z","changelog":"Release v0.108.0","fileCount":3,"zipByteSize":2709},{"version":"0.107.2","createdAt":"2026-10-01T23:32:34.146Z","changelog":"Release v0.107.2","fileCount":3,"zipByteSize":2824},{"version":"0.107.0","createdAt":"2026-09-30T20:18:22.872Z","changelog":"Release v0.107.0","fileCount":3,"zipByteSize":2733},{"version":"0.106.1","createdAt":"2026-09-27T00:18:39.186Z","changelog":"Release v0.106.1","fileCount":3,"zipByteSize":2774},{"version":"0.105.0","createdAt":"2026-09-18T11:11:42.784Z","changelog":"Release v0.105.0","fileCount":3,"zipByteSize":2904}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom-runtime","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-runtime/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-runtime/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-runtime/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-runtime/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-runtime/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-runtime/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T12:54:55.145Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-runtime/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-runtime/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-runtime/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-runtime/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T03:47:40.422Z","emptyReason":null},"readme":"Skill: agent-bom runtime\n\nOwner: msaad00\n\nSummary: AI runtime security monitoring — context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries. Use when the user mentions runtime monitoring, context graphs, lateral movement analysis, audit log correlation, or vulnerability analytics.\n\nTags: latest:0.108.3\n\nVersion history:\n\nv0.108.3 | 2026-10-08T22:18:13.720Z | user\n\nRelease v0.108.3\n\nv0.108.2 | 2026-10-08T05:01:28.097Z | user\n\nRelease v0.108.2\n\nv0.108.1 | 2026-10-06T17:48:01.316Z | user\n\nRelease v0.108.1\n\nv0.108.0 | 2026-10-04T07:12:59.234Z | user\n\nRelease v0.108.0\n\nv0.107.2 | 2026-10-01T23:32:34.146Z | user\n\nRelease v0.107.2\n\nv0.107.0 | 2026-09-30T20:18:22.872Z | user\n\nRelease v0.107.0\n\nv0.106.1 | 2026-09-27T00:18:39.186Z | user\n\nRelease v0.106.1\n\nv0.105.0 | 2026-09-18T11:11:42.784Z | user\n\nRelease v0.105.0\n\nv0.104.0 | 2026-09-09T20:56:23.629Z | user\n\nRelease v0.104.0\n\nv0.103.2 | 2026-09-02T07:24:24.168Z | user\n\nRelease v0.103.2\n\nv0.102.0 | 2026-08-24T04:50:09.868Z | user\n\nRelease v0.102.0\n\nv0.101.0 | 2026-08-16T23:13:24.131Z | user\n\nRelease v0.101.0\n\nv0.100.0 | 2026-08-12T20:55:15.284Z | user\n\nRelease v0.100.0\n\nv0.99.0 | 2026-08-06T00:52:50.370Z | user\n\nRelease v0.99.0\n\nv0.98.3 | 2026-08-03T06:09:14.679Z | user\n\nRelease v0.98.3\n\nv0.98.2 | 2026-07-27T08:50:17.803Z | user\n\nRelease v0.98.2\n\nv0.98.1 | 2026-07-27T02:02:19.640Z | user\n\nRelease v0.98.1\n\nv0.98.0 | 2026-07-25T01:51:27.066Z | user\n\nRelease v0.98.0\n\nv0.97.5 | 2026-07-24T01:43:46.299Z | user\n\nRelease v0.97.5\n\nv0.97.4 | 2026-07-23T00:59:25.983Z | user\n\nRelease v0.97.4\n\nv0.97.2 | 2026-07-21T18:19:22.604Z | user\n\nRelease v0.97.2\n\nv0.97.1 | 2026-07-21T03:31:48.672Z | user\n\nRelease v0.97.1\n\nv0.97.0 | 2026-07-20T18:11:03.340Z | user\n\nRelease v0.97.0\n\nv0.96.4 | 2026-07-20T15:05:56.516Z | user\n\nRelease v0.96.4\n\nv0.96.3 | 2026-07-16T04:05:49.207Z | user\n\nRelease v0.96.3\n\nv0.96.2 | 2026-07-15T23:05:29.851Z | user\n\nRelease v0.96.2\n\nv0.95.0 | 2026-07-13T21:38:43.498Z | user\n\nRelease v0.95.0\n\nv0.94.2 | 2026-07-09T18:24:48.179Z | user\n\nRelease v0.94.2\n\nv0.94.1 | 2026-07-09T05:51:03.836Z | user\n\nRelease v0.94.1\n\nv0.94.0 | 2026-07-08T21:48:18.111Z | user\n\nRelease v0.94.0\n\nv0.93.0 | 2026-07-06T07:43:08.427Z | user\n\nRelease v0.93.0\n\nv0.91.0 | 2026-06-30T23:36:44.185Z | user\n\nRelease v0.91.0\n\nv0.90.0 | 2026-06-30T03:47:58.982Z | user\n\nRelease v0.90.0\n\nv0.89.2 | 2026-06-22T03:18:00.611Z | user\n\nRelease v0.89.2\n\nv0.88.5 | 2026-06-01T06:24:05.053Z | user\n\nRelease v0.88.5\n\nv0.88.4 | 2026-05-26T04:20:28.538Z | user\n\nRelease v0.88.4\n\nv0.88.3 | 2026-05-25T00:57:33.670Z | user\n\nRelease v0.88.3\n\nv0.88.1 | 2026-05-22T04:38:36.607Z | user\n\nRelease v0.88.1\n\nv0.87.1 | 2026-05-18T20:25:52.159Z | user\n\nRelease v0.87.1\n\nv0.87.0 | 2026-05-18T00:37:01.038Z | user\n\nRelease v0.87.0\n\nv0.86.5 | 2026-05-11T16:16:12.496Z | user\n\nRelease v0.86.5\n\nv0.86.2 | 2026-05-07T15:45:24.501Z | user\n\nRelease v0.86.2\n\nv0.86.1 | 2026-05-06T06:42:32.365Z | user\n\nRelease v0.86.1\n\nv0.85.0 | 2026-05-02T22:48:57.547Z | user\n\nRelease v0.85.0\n\nv0.84.6 | 2026-05-02T06:44:20.715Z | user\n\nRelease v0.84.6\n\nv0.84.5 | 2026-05-02T03:29:26.508Z | user\n\nRelease v0.84.5\n\nv0.84.4 | 2026-05-01T19:07:48.345Z | user\n\nRelease v0.84.4\n\nv0.84.0 | 2026-05-01T01:53:41.961Z | user\n\nRelease v0.84.0\n\nv0.83.4 | 2026-04-30T19:33:51.542Z | user\n\nRelease v0.83.4\n\nv0.83.3 | 2026-04-30T05:47:48.386Z | user\n\nRelease v0.83.3\n\nArchive index:\n\nArchive v0.108.3: 3 files, 2785 bytes\n\nFiles: skill-card.md (1920b), SKILL.md (3215b), _meta.json (138b)\n\nFile v0.108.3:SKILL.md\n\n---\nname: agent-bom-runtime\ndescription: >-\n  AI runtime security monitoring — context graph analysis, runtime audit log\n  correlation with CVE findings, and vulnerability analytics queries. Use when\n  the user mentions runtime monitoring, context graphs, lateral movement analysis,\n  audit log correlation, or vulnerability analytics.\nversion: 0.108.3\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: kubectl for\n  Kubernetes context, ClickHouse for analytics storage. No API keys required.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Optional ClickHouse URL enables analytics storage. Never auto-discovered or inferred.\"\n    credential_handling: \"Runtime audit data may include credential environment variable names but must not include raw values. Optional analytics credentials are operator-supplied and must not be displayed or inferred.\"\n    optional_env: []\n    optional_bins:\n      - kubectl\n    emoji: \"\\U0001F4CA\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Operates on scan results in memory and user-provided audit log files. Optional ClickHouse connection for persistent analytics (user-configured, not auto-discovered).\"\n    file_reads:\n      - \"user-provided audit log files (JSONL format from agent-bom proxy)\"\n    file_writes: []\n    network_endpoints: []\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-runtime — AI Runtime Security Monitoring\n\nContext graph analysis, runtime audit log correlation with CVE findings, and\nvulnerability analytics queries.\n\n## Install\n\n```bash\npipx install agent-bom\n```\n\n## Tools (3)\n\n| Tool | Description |\n|------|-------------|\n| `context_graph` | Agent context graph with lateral movement analysis |\n| `analytics_query` | Query vulnerability trends, posture history, and runtime events |\n| `runtime_correlate` | Cross-reference runtime audit logs with CVE findings |\n\n## Example Workflows\n\n```\n# Build context graph from scan results\ncontext_graph()\n\n# Correlate runtime audit with CVE data\nruntime_correlate(audit_file=\"proxy-audit.jsonl\")\n\n# Query analytics\nanalytics_query(query=\"top_cves\", days=30)\n```\n\n## Privacy & Data Handling\n\nOperates on scan results already in memory and user-provided audit log files.\nNo automatic file discovery. No network calls unless you configure an optional\nClickHouse endpoint for persistent analytics.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.108.3:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-runtime\",\n  \"version\": \"0.108.3\",\n  \"publishedAt\": 1791497893720\n}\n\nFile v0.108.3:skill-card.md\n\n## Description:\n\nAnalyzes agent context graphs, correlates runtime audit logs with CVE findings, and queries vulnerability trends.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security teams use this skill to inspect agent context graphs, correlate user-supplied runtime audit logs with CVEs, and review vulnerability trends.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Installing a third-party CLI introduces package supply-chain risk.\n\nMitigation: Review the PyPI package and project before installing, as recommended by the release security guidance.\n\nRisk: Optional ClickHouse or kubectl access can expose analytics data or cluster resources.\n\nMitigation: Configure those connections only when needed and limit access to the intended environment.\n\n## Reference(s):\n\n- [ClawHub skill release](https://clawhub.ai/msaad00/skills/agent-bom-runtime)\n- [Project homepage listed in skill metadata](https://github.com/msaad00/agent-bom)\n- [agent-bom package on PyPI](https://pypi.org/project/agent-bom/)\n- [Project OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Analysis, Guidance]\n\n**Output Format:** [Text or Markdown]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Context graph analysis, audit-to-CVE correlation, and vulnerability trend results; no fixed output schema is specified.]\n\n## Skill Version(s):\n\n0.108.3 (source: release metadata and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.108.2: 3 files, 2793 bytes\n\nFiles: skill-card.md (1935b), SKILL.md (3215b), _meta.json (138b)\n\nFile v0.108.2:SKILL.md\n\n---\nname: agent-bom-runtime\ndescription: >-\n  AI runtime security monitoring — context graph analysis, runtime audit log\n  correlation with CVE findings, and vulnerability analytics queries. Use when\n  the user mentions runtime monitoring, context graphs, lateral movement analysis,\n  audit log correlation, or vulnerability analytics.\nversion: 0.108.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: kubectl for\n  Kubernetes context, ClickHouse for analytics storage. No API keys required.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Optional ClickHouse URL enables analytics storage. Never auto-discovered or inferred.\"\n    credential_handling: \"Runtime audit data may include credential environment variable names but must not include raw values. Optional analytics credentials are operator-supplied and must not be displayed or inferred.\"\n    optional_env: []\n    optional_bins:\n      - kubectl\n    emoji: \"\\U0001F4CA\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Operates on scan results in memory and user-provided audit log files. Optional ClickHouse connection for persistent analytics (user-configured, not auto-discovered).\"\n    file_reads:\n      - \"user-provided audit log files (JSONL format from agent-bom proxy)\"\n    file_writes: []\n    network_endpoints: []\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-runtime — AI Runtime Security Monitoring\n\nContext graph analysis, runtime audit log correlation with CVE findings, and\nvulnerability analytics queries.\n\n## Install\n\n```bash\npipx install agent-bom\n```\n\n## Tools (3)\n\n| Tool | Description |\n|------|-------------|\n| `context_graph` | Agent context graph with lateral movement analysis |\n| `analytics_query` | Query vulnerability trends, posture history, and runtime events |\n| `runtime_correlate` | Cross-reference runtime audit logs with CVE findings |\n\n## Example Workflows\n\n```\n# Build context graph from scan results\ncontext_graph()\n\n# Correlate runtime audit with CVE data\nruntime_correlate(audit_file=\"proxy-audit.jsonl\")\n\n# Query analytics\nanalytics_query(query=\"top_cves\", days=30)\n```\n\n## Privacy & Data Handling\n\nOperates on scan results already in memory and user-provided audit log files.\nNo automatic file discovery. No network calls unless you configure an optional\nClickHouse endpoint for persistent analytics.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.108.2:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-runtime\",\n  \"version\": \"0.108.2\",\n  \"publishedAt\": 1791435688097\n}\n\nFile v0.108.2:skill-card.md\n\n## Description:\n\nHelps agents analyze context graphs, correlate user-provided runtime audit logs with CVE findings, and query vulnerability trends.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security engineers use this skill to assess agent runtime context, correlate provided audit logs with vulnerability findings, and examine security trends.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Installing the external agent-bom package introduces a dependency on its publisher.\n\nMitigation: Confirm you trust the package source before installing it.\n\nRisk: User-provided audit logs may contain sensitive runtime-security information.\n\nMitigation: Provide only intended audit logs and avoid exposing credential values.\n\nRisk: Optional ClickHouse analytics can persist sensitive runtime-security data.\n\nMitigation: Enable it only deliberately and configure storage access and credentials explicitly.\n\n## Reference(s):\n\n- [Project homepage](https://github.com/msaad00/agent-bom)\n- [Python package](https://pypi.org/project/agent-bom/)\n- [OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Analysis, Guidance]\n\n**Output Format:** [Text or Markdown]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Context graphs, runtime-to-CVE correlations, and vulnerability trend summaries depend on supplied scan and audit data.]\n\n## Skill Version(s):\n\n0.108.2 (source: release metadata and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.108.1: 3 files, 2840 bytes\n\nFiles: skill-card.md (2047b), SKILL.md (3215b), _meta.json (138b)\n\nFile v0.108.1:SKILL.md\n\n---\nname: agent-bom-runtime\ndescription: >-\n  AI runtime security monitoring — context graph analysis, runtime audit log\n  correlation with CVE findings, and vulnerability analytics queries. Use when\n  the user mentions runtime monitoring, context graphs, lateral movement analysis,\n  audit log correlation, or vulnerability analytics.\nversion: 0.108.1\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: kubectl for\n  Kubernetes context, ClickHouse for analytics storage. No API keys required.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Optional ClickHouse URL enables analytics storage. Never auto-discovered or inferred.\"\n    credential_handling: \"Runtime audit data may include credential environment variable names but must not include raw values. Optional analytics credentials are operator-supplied and must not be displayed or inferred.\"\n    optional_env: []\n    optional_bins:\n      - kubectl\n    emoji: \"\\U0001F4CA\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Operates on scan results in memory and user-provided audit log files. Optional ClickHouse connection for persistent analytics (user-configured, not auto-discovered).\"\n    file_reads:\n      - \"user-provided audit log files (JSONL format from agent-bom proxy)\"\n    file_writes: []\n    network_endpoints: []\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-runtime — AI Runtime Security Monitoring\n\nContext graph analysis, runtime audit log correlation with CVE findings, and\nvulnerability analytics queries.\n\n## Install\n\n```bash\npipx install agent-bom\n```\n\n## Tools (3)\n\n| Tool | Description |\n|------|-------------|\n| `context_graph` | Agent context graph with lateral movement analysis |\n| `analytics_query` | Query vulnerability trends, posture history, and runtime events |\n| `runtime_correlate` | Cross-reference runtime audit logs with CVE findings |\n\n## Example Workflows\n\n```\n# Build context graph from scan results\ncontext_graph()\n\n# Correlate runtime audit with CVE data\nruntime_correlate(audit_file=\"proxy-audit.jsonl\")\n\n# Query analytics\nanalytics_query(query=\"top_cves\", days=30)\n```\n\n## Privacy & Data Handling\n\nOperates on scan results already in memory and user-provided audit log files.\nNo automatic file discovery. No network calls unless you configure an optional\nClickHouse endpoint for persistent analytics.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.108.1:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-runtime\",\n  \"version\": \"0.108.1\",\n  \"publishedAt\": 1791308881316\n}\n\nFile v0.108.1:skill-card.md\n\n## Description:\n\nAnalyzes agent context graphs, correlates user-provided runtime audit logs with CVE findings, and answers vulnerability analytics queries.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security teams use this skill to inspect agent context graphs, correlate supplied audit logs with vulnerability findings, and review vulnerability trends and runtime events.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: User-supplied runtime audit logs may expose sensitive operational details.\n\nMitigation: Review and minimize logs before sharing them; do not disclose credential values.\n\nRisk: Optional analytics storage can retain runtime data.\n\nMitigation: Configure ClickHouse only when persistent storage is intended and access is appropriately controlled.\n\nRisk: Installing a third-party package requires trusting its distribution source.\n\nMitigation: Confirm the publisher and review the Agent-BOM package source before installation.\n\n## Reference(s):\n\n- [Agent-BOM project homepage (publisher-supplied)](https://github.com/msaad00/agent-bom)\n- [Agent-BOM package on PyPI](https://pypi.org/project/agent-bom/)\n- [Agent-BOM OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands]\n\n**Output Format:** [Markdown with analysis and optional command examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Context graph insights, audit-log/CVE correlations, and vulnerability trend summaries.]\n\n## Skill Version(s):\n\n0.108.1 (source: ClawHub release and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.108.0: 3 files, 2709 bytes\n\nFiles: skill-card.md (1811b), SKILL.md (3215b), _meta.json (138b)\n\nFile v0.108.0:SKILL.md\n\n---\nname: agent-bom-runtime\ndescription: >-\n  AI runtime security monitoring — context graph analysis, runtime audit log\n  correlation with CVE findings, and vulnerability analytics queries. Use when\n  the user mentions runtime monitoring, context graphs, lateral movement analysis,\n  audit log correlation, or vulnerability analytics.\nversion: 0.108.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: kubectl for\n  Kubernetes context, ClickHouse for analytics storage. No API keys required.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Optional ClickHouse URL enables analytics storage. Never auto-discovered or inferred.\"\n    credential_handling: \"Runtime audit data may include credential environment variable names but must not include raw values. Optional analytics credentials are operator-supplied and must not be displayed or inferred.\"\n    optional_env: []\n    optional_bins:\n      - kubectl\n    emoji: \"\\U0001F4CA\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Operates on scan results in memory and user-provided audit log files. Optional ClickHouse connection for persistent analytics (user-configured, not auto-discovered).\"\n    file_reads:\n      - \"user-provided audit log files (JSONL format from agent-bom proxy)\"\n    file_writes: []\n    network_endpoints: []\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-runtime — AI Runtime Security Monitoring\n\nContext graph analysis, runtime audit log correlation with CVE findings, and\nvulnerability analytics queries.\n\n## Install\n\n```bash\npipx install agent-bom\n```\n\n## Tools (3)\n\n| Tool | Description |\n|------|-------------|\n| `context_graph` | Agent context graph with lateral movement analysis |\n| `analytics_query` | Query vulnerability trends, posture history, and runtime events |\n| `runtime_correlate` | Cross-reference runtime audit logs with CVE findings |\n\n## Example Workflows\n\n```\n# Build context graph from scan results\ncontext_graph()\n\n# Correlate runtime audit with CVE data\nruntime_correlate(audit_file=\"proxy-audit.jsonl\")\n\n# Query analytics\nanalytics_query(query=\"top_cves\", days=30)\n```\n\n## Privacy & Data Handling\n\nOperates on scan results already in memory and user-provided audit log files.\nNo automatic file discovery. No network calls unless you configure an optional\nClickHouse endpoint for persistent analytics.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.108.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-runtime\",\n  \"version\": \"0.108.0\",\n  \"publishedAt\": 1791097979234\n}\n\nFile v0.108.0:skill-card.md\n\n## Description:\n\nHelps analyze agent context graphs, correlate runtime audit logs with CVE findings, and query vulnerability trends.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security teams use this skill to examine agent context graphs, correlate selected runtime audit logs with CVE findings, and review vulnerability trends.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Installing an untrusted package source could expose the operator's environment.\n\nMitigation: Verify that you trust the agent-bom package source before installation.\n\nRisk: Audit logs or optional analytics storage could expose sensitive credential values.\n\nMitigation: Analyze only intended audit logs, avoid storing raw credential values, and configure any ClickHouse endpoint deliberately.\n\n## Reference(s):\n\n- [agent-bom project homepage (skill metadata)](https://github.com/msaad00/agent-bom)\n- [agent-bom package](https://pypi.org/project/agent-bom/)\n- [OpenSSF Scorecard (skill metadata)](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown]\n\n**Output Format:** [Markdown]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Context graph analysis, audit log and CVE correlations, and vulnerability trend summaries.]\n\n## Skill Version(s):\n\n0.108.0 (source: ClawHub release and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.107.2: 3 files, 2824 bytes\n\nFiles: skill-card.md (2030b), SKILL.md (3215b), _meta.json (138b)\n\nFile v0.107.2:SKILL.md\n\n---\nname: agent-bom-runtime\ndescription: >-\n  AI runtime security monitoring — context graph analysis, runtime audit log\n  correlation with CVE findings, and vulnerability analytics queries. Use when\n  the user mentions runtime monitoring, context graphs, lateral movement analysis,\n  audit log correlation, or vulnerability analytics.\nversion: 0.107.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: kubectl for\n  Kubernetes context, ClickHouse for analytics storage. No API keys required.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Optional ClickHouse URL enables analytics storage. Never auto-discovered or inferred.\"\n    credential_handling: \"Runtime audit data may include credential environment variable names but must not include raw values. Optional analytics credentials are operator-supplied and must not be displayed or inferred.\"\n    optional_env: []\n    optional_bins:\n      - kubectl\n    emoji: \"\\U0001F4CA\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Operates on scan results in memory and user-provided audit log files. Optional ClickHouse connection for persistent analytics (user-configured, not auto-discovered).\"\n    file_reads:\n      - \"user-provided audit log files (JSONL format from agent-bom proxy)\"\n    file_writes: []\n    network_endpoints: []\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-runtime — AI Runtime Security Monitoring\n\nContext graph analysis, runtime audit log correlation with CVE findings, and\nvulnerability analytics queries.\n\n## Install\n\n```bash\npipx install agent-bom\n```\n\n## Tools (3)\n\n| Tool | Description |\n|------|-------------|\n| `context_graph` | Agent context graph with lateral movement analysis |\n| `analytics_query` | Query vulnerability trends, posture history, and runtime events |\n| `runtime_correlate` | Cross-reference runtime audit logs with CVE findings |\n\n## Example Workflows\n\n```\n# Build context graph from scan results\ncontext_graph()\n\n# Correlate runtime audit with CVE data\nruntime_correlate(audit_file=\"proxy-audit.jsonl\")\n\n# Query analytics\nanalytics_query(query=\"top_cves\", days=30)\n```\n\n## Privacy & Data Handling\n\nOperates on scan results already in memory and user-provided audit log files.\nNo automatic file discovery. No network calls unless you configure an optional\nClickHouse endpoint for persistent analytics.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.107.2:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-runtime\",\n  \"version\": \"0.107.2\",\n  \"publishedAt\": 1790897554146\n}\n\nFile v0.107.2:skill-card.md\n\n## Description:\n\nHelps analyze agent context graphs, correlate runtime audit logs with CVE findings, and query vulnerability trends.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security teams use this skill to examine agent context graphs, correlate user-provided runtime audit logs with vulnerability findings, and review vulnerability analytics.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Installing an external package from an untrusted source may expose the environment to unwanted code.\n\nMitigation: Confirm that you trust the agent-bom package source before installing it.\n\nRisk: Runtime audit logs may contain sensitive operational information.\n\nMitigation: Provide only audit log files you intend to analyze, and avoid sharing credential values.\n\nRisk: Optional analytics storage or Kubernetes access may involve sensitive data or cluster context.\n\nMitigation: Configure ClickHouse or kubectl only when you trust the selected storage or cluster context.\n\n## Reference(s):\n\n- [Project homepage (listed in skill metadata)](https://github.com/msaad00/agent-bom)\n- [agent-bom package](https://pypi.org/project/agent-bom/)\n- [OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Guidance]\n\n**Output Format:** [Markdown text with findings and tool-call examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Results depend on the available scan findings and user-provided audit logs.]\n\n## Skill Version(s):\n\n0.107.2 (source: release evidence and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.107.0: 3 files, 2733 bytes\n\nFiles: skill-card.md (1837b), SKILL.md (3215b), _meta.json (138b)\n\nFile v0.107.0:SKILL.md\n\n---\nname: agent-bom-runtime\ndescription: >-\n  AI runtime security monitoring — context graph analysis, runtime audit log\n  correlation with CVE findings, and vulnerability analytics queries. Use when\n  the user mentions runtime monitoring, context graphs, lateral movement analysis,\n  audit log correlation, or vulnerability analytics.\nversion: 0.107.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: kubectl for\n  Kubernetes context, ClickHouse for analytics storage. No API keys required.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Optional ClickHouse URL enables analytics storage. Never auto-discovered or inferred.\"\n    credential_handling: \"Runtime audit data may include credential environment variable names but must not include raw values. Optional analytics credentials are operator-supplied and must not be displayed or inferred.\"\n    optional_env: []\n    optional_bins:\n      - kubectl\n    emoji: \"\\U0001F4CA\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Operates on scan results in memory and user-provided audit log files. Optional ClickHouse connection for persistent analytics (user-configured, not auto-discovered).\"\n    file_reads:\n      - \"user-provided audit log files (JSONL format from agent-bom proxy)\"\n    file_writes: []\n    network_endpoints: []\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-runtime — AI Runtime Security Monitoring\n\nContext graph analysis, runtime audit log correlation with CVE findings, and\nvulnerability analytics queries.\n\n## Install\n\n```bash\npipx install agent-bom\n```\n\n## Tools (3)\n\n| Tool | Description |\n|------|-------------|\n| `context_graph` | Agent context graph with lateral movement analysis |\n| `analytics_query` | Query vulnerability trends, posture history, and runtime events |\n| `runtime_correlate` | Cross-reference runtime audit logs with CVE findings |\n\n## Example Workflows\n\n```\n# Build context graph from scan results\ncontext_graph()\n\n# Correlate runtime audit with CVE data\nruntime_correlate(audit_file=\"proxy-audit.jsonl\")\n\n# Query analytics\nanalytics_query(query=\"top_cves\", days=30)\n```\n\n## Privacy & Data Handling\n\nOperates on scan results already in memory and user-provided audit log files.\nNo automatic file discovery. No network calls unless you configure an optional\nClickHouse endpoint for persistent analytics.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.107.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-runtime\",\n  \"version\": \"0.107.0\",\n  \"publishedAt\": 1790799502872\n}\n\nFile v0.107.0:skill-card.md\n\n## Description:\n\nAnalyzes agent context graphs, correlates runtime audit logs with CVE findings, and queries vulnerability trends.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security teams use this skill to investigate agent context graphs, correlate supplied runtime audit logs with CVE findings, and review vulnerability trends.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Installing an untrusted package could expose the user's environment.\n\nMitigation: Confirm you trust the listed PyPI package and project homepage before installing.\n\nRisk: Runtime audit logs and analytics may contain sensitive operational details.\n\nMitigation: Use only intended audit logs and operator-configured ClickHouse endpoints; do not share credential values.\n\n## Reference(s):\n\n- [agent-bom project homepage (listed by publisher; source provenance unavailable)](https://github.com/msaad00/agent-bom)\n- [agent-bom PyPI package](https://pypi.org/project/agent-bom/)\n- [agent-bom OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Analysis]\n\n**Output Format:** [Text]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Results depend on available scan findings, supplied audit logs, and optionally configured analytics storage.]\n\n## Skill Version(s):\n\n0.107.0 (source: ClawHub release and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.106.1: 3 files, 2774 bytes\n\nFiles: skill-card.md (1939b), SKILL.md (3215b), _meta.json (138b)\n\nFile v0.106.1:SKILL.md\n\n---\nname: agent-bom-runtime\ndescription: >-\n  AI runtime security monitoring — context graph analysis, runtime audit log\n  correlation with CVE findings, and vulnerability analytics queries. Use when\n  the user mentions runtime monitoring, context graphs, lateral movement analysis,\n  audit log correlation, or vulnerability analytics.\nversion: 0.106.1\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: kubectl for\n  Kubernetes context, ClickHouse for analytics storage. No API keys required.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Optional ClickHouse URL enables analytics storage. Never auto-discovered or inferred.\"\n    credential_handling: \"Runtime audit data may include credential environment variable names but must not include raw values. Optional analytics credentials are operator-supplied and must not be displayed or inferred.\"\n    optional_env: []\n    optional_bins:\n      - kubectl\n    emoji: \"\\U0001F4CA\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Operates on scan results in memory and user-provided audit log files. Optional ClickHouse connection for persistent analytics (user-configured, not auto-discovered).\"\n    file_reads:\n      - \"user-provided audit log files (JSONL format from agent-bom proxy)\"\n    file_writes: []\n    network_endpoints: []\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-runtime — AI Runtime Security Monitoring\n\nContext graph analysis, runtime audit log correlation with CVE findings, and\nvulnerability analytics queries.\n\n## Install\n\n```bash\npipx install agent-bom\n```\n\n## Tools (3)\n\n| Tool | Description |\n|------|-------------|\n| `context_graph` | Agent context graph with lateral movement analysis |\n| `analytics_query` | Query vulnerability trends, posture history, and runtime events |\n| `runtime_correlate` | Cross-reference runtime audit logs with CVE findings |\n\n## Example Workflows\n\n```\n# Build context graph from scan results\ncontext_graph()\n\n# Correlate runtime audit with CVE data\nruntime_correlate(audit_file=\"proxy-audit.jsonl\")\n\n# Query analytics\nanalytics_query(query=\"top_cves\", days=30)\n```\n\n## Privacy & Data Handling\n\nOperates on scan results already in memory and user-provided audit log files.\nNo automatic file discovery. No network calls unless you configure an optional\nClickHouse endpoint for persistent analytics.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.106.1:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-runtime\",\n  \"version\": \"0.106.1\",\n  \"publishedAt\": 1790468319186\n}\n\nFile v0.106.1:skill-card.md\n\n## Description:\n\nAnalyzes agent context graphs, correlates runtime audit logs with CVE findings, and queries vulnerability trends.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nApache-2.0\n\n## Use Case:\n\nDevelopers and security teams use this skill to examine agent context graphs, correlate user-provided runtime audit logs with CVE findings, and review vulnerability trends.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Installing an untrusted package could expose the local environment.\n\nMitigation: Confirm you trust the agent-bom package on PyPI and its linked project before installation.\n\nRisk: Runtime audit logs may contain sensitive operational details.\n\nMitigation: Review logs before sharing or processing them, and avoid exposing credential values.\n\nRisk: Optional persistent analytics storage can retain vulnerability and runtime data.\n\nMitigation: Configure ClickHouse only when persistent storage is intended.\n\n## Reference(s):\n\n- [Agent-BOM project homepage](https://github.com/msaad00/agent-bom)\n- [Agent-BOM package on PyPI](https://pypi.org/project/agent-bom/)\n- [Agent-BOM OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Analysis, Guidance]\n\n**Output Format:** [Text]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Findings depend on available scan results, user-provided audit logs, and optionally configured analytics storage.]\n\n## Skill Version(s):\n\n0.106.1 (source: ClawHub release and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.105.0: 3 files, 2904 bytes\n\nFiles: skill-card.md (2231b), SKILL.md (3215b), _meta.json (138b)\n\nFile v0.105.0:SKILL.md\n\n---\nname: agent-bom-runtime\ndescription: >-\n  AI runtime security monitoring — context graph analysis, runtime audit log\n  correlation with CVE findings, and vulnerability analytics queries. Use when\n  the user mentions runtime monitoring, context graphs, lateral movement analysis,\n  audit log correlation, or vulnerability analytics.\nversion: 0.105.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: kubectl for\n  Kubernetes context, ClickHouse for analytics storage. No API keys required.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Optional ClickHouse URL enables analytics storage. Never auto-discovered or inferred.\"\n    credential_handling: \"Runtime audit data may include credential environment variable names but must not include raw values. Optional analytics credentials are operator-supplied and must not be displayed or inferred.\"\n    optional_env: []\n    optional_bins:\n      - kubectl\n    emoji: \"\\U0001F4CA\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Operates on scan results in memory and user-provided audit log files. Optional ClickHouse connection for persistent analytics (user-configured, not auto-discovered).\"\n    file_reads:\n      - \"user-provided audit log files (JSONL format from agent-bom proxy)\"\n    file_writes: []\n    network_endpoints: []\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-runtime — AI Runtime Security Monitoring\n\nContext graph analysis, runtime audit log correlation with CVE findings, and\nvulnerability analytics queries.\n\n## Install\n\n```bash\npipx install agent-bom\n```\n\n## Tools (3)\n\n| Tool | Description |\n|------|-------------|\n| `context_graph` | Agent context graph with lateral movement analysis |\n| `analytics_query` | Query vulnerability trends, posture history, and runtime events |\n| `runtime_correlate` | Cross-reference runtime audit logs with CVE findings |\n\n## Example Workflows\n\n```\n# Build context graph from scan results\ncontext_graph()\n\n# Correlate runtime audit with CVE data\nruntime_correlate(audit_file=\"proxy-audit.jsonl\")\n\n# Query analytics\nanalytics_query(query=\"top_cves\", days=30)\n```\n\n## Privacy & Data Handling\n\nOperates on scan results already in memory and user-provided audit log files.\nNo automatic file discovery. No network calls unless you configure an optional\nClickHouse endpoint for persistent analytics.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.105.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-runtime\",\n  \"version\": \"0.105.0\",\n  \"publishedAt\": 1789729902784\n}\n\nFile v0.105.0:skill-card.md\n\n## Description:\n\nAI runtime security monitoring for context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security engineers use this skill to inspect runtime context graphs, correlate agent audit logs with CVE findings, and query vulnerability trends for agent deployments.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Installing a third-party package can introduce supply-chain risk.\n\nMitigation: Confirm trust in the publisher and package before installation, and review the linked package and scorecard evidence before deployment.\n\nRisk: Runtime audit logs may contain sensitive operational details or credential environment variable names.\n\nMitigation: Only provide audit logs intended for analysis, avoid raw secret values, and handle the resulting analysis under the same data controls as the source logs.\n\nRisk: Optional ClickHouse use creates persistent analytics and runtime-event storage.\n\nMitigation: Configure ClickHouse intentionally with appropriate access controls, retention, and storage location before enabling persistence.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/msaad00/skills/agent-bom-runtime)\n- [Project homepage](https://github.com/msaad00/agent-bom)\n- [PyPI package](https://pypi.org/project/agent-bom/)\n- [OpenSSF Scorecard report](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown with inline shell commands and tool-call guidance]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [None]\n\n## Skill Version(s):\n\n0.105.0 (source: evidence release and SKILL.md frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.104.0: 3 files, 2826 bytes\n\nFiles: skill-card.md (2073b), SKILL.md (3215b), _meta.json (138b)\n\nFile v0.104.0:SKILL.md\n\n---\nname: agent-bom-runtime\ndescription: >-\n  AI runtime security monitoring — context graph analysis, runtime audit log\n  correlation with CVE findings, and vulnerability analytics queries. Use when\n  the user mentions runtime monitoring, context graphs, lateral movement analysis,\n  audit log correlation, or vulnerability analytics.\nversion: 0.104.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: kubectl for\n  Kubernetes context, ClickHouse for analytics storage. No API keys required.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Optional ClickHouse URL enables analytics storage. Never auto-discovered or inferred.\"\n    credential_handling: \"Runtime audit data may include credential environment variable names but must not include raw values. Optional analytics credentials are operator-supplied and must not be displayed or inferred.\"\n    optional_env: []\n    optional_bins:\n      - kubectl\n    emoji: \"\\U0001F4CA\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Operates on scan results in memory and user-provided audit log files. Optional ClickHouse connection for persistent analytics (user-configured, not auto-discovered).\"\n    file_reads:\n      - \"user-provided audit log files (JSONL format from agent-bom proxy)\"\n    file_writes: []\n    network_endpoints: []\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-runtime — AI Runtime Security Monitoring\n\nContext graph analysis, runtime audit log correlation with CVE findings, and\nvulnerability analytics queries.\n\n## Install\n\n```bash\npipx install agent-bom\n```\n\n## Tools (3)\n\n| Tool | Description |\n|------|-------------|\n| `context_graph` | Agent context graph with lateral movement analysis |\n| `analytics_query` | Query vulnerability trends, posture history, and runtime events |\n| `runtime_correlate` | Cross-reference runtime audit logs with CVE findings |\n\n## Example Workflows\n\n```\n# Build context graph from scan results\ncontext_graph()\n\n# Correlate runtime audit with CVE data\nruntime_correlate(audit_file=\"proxy-audit.jsonl\")\n\n# Query analytics\nanalytics_query(query=\"top_cves\", days=30)\n```\n\n## Privacy & Data Handling\n\nOperates on scan results already in memory and user-provided audit log files.\nNo automatic file discovery. No network calls unless you configure an optional\nClickHouse endpoint for persistent analytics.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.104.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-runtime\",\n  \"version\": \"0.104.0\",\n  \"publishedAt\": 1788987383629\n}\n\nFile v0.104.0:skill-card.md\n\n## Description:\n\nAI runtime security monitoring for context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nApache-2.0\n\n## Use Case:\n\nDevelopers and security engineers use this skill to inspect AI runtime context graphs, correlate agent audit logs with CVE findings, and query vulnerability trends or posture history.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The documented package install is not pinned to the reviewed version.\n\nMitigation: Install the reviewed release explicitly, for example `agent-bom==0.104.0`, before relying on this card.\n\nRisk: Runtime audit logs and optional analytics configuration can contain sensitive operational context or credential environment variable names.\n\nMitigation: Provide only audit logs and optional ClickHouse configuration that are approved for analysis, and do not include raw credential values.\n\n## Reference(s):\n\n- [agent-bom GitHub project](https://github.com/msaad00/agent-bom)\n- [agent-bom PyPI package](https://pypi.org/project/agent-bom/)\n- [OpenSSF Scorecard report](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n- [ClawHub skill page](https://clawhub.ai/msaad00/skills/agent-bom-runtime)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, guidance]\n\n**Output Format:** [Markdown with inline tool-call and shell-command examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May reference user-provided audit log paths and optional analytics configuration.]\n\n## Skill Version(s):\n\n0.104.0 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.103.2: 3 files, 2881 bytes\n\nFiles: skill-card.md (2146b), SKILL.md (3215b), _meta.json (138b)\n\nFile v0.103.2:SKILL.md\n\n---\nname: agent-bom-runtime\ndescription: >-\n  AI runtime security monitoring — context graph analysis, runtime audit log\n  correlation with CVE findings, and vulnerability analytics queries. Use when\n  the user mentions runtime monitoring, context graphs, lateral movement analysis,\n  audit log correlation, or vulnerability analytics.\nversion: 0.103.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: kubectl for\n  Kubernetes context, ClickHouse for analytics storage. No API keys required.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Optional ClickHouse URL enables analytics storage. Never auto-discovered or inferred.\"\n    credential_handling: \"Runtime audit data may include credential environment variable names but must not include raw values. Optional analytics credentials are operator-supplied and must not be displayed or inferred.\"\n    optional_env: []\n    optional_bins:\n      - kubectl\n    emoji: \"\\U0001F4CA\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Operates on scan results in memory and user-provided audit log files. Optional ClickHouse connection for persistent analytics (user-configured, not auto-discovered).\"\n    file_reads:\n      - \"user-provided audit log files (JSONL format from agent-bom proxy)\"\n    file_writes: []\n    network_endpoints: []\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-runtime — AI Runtime Security Monitoring\n\nContext graph analysis, runtime audit log correlation with CVE findings, and\nvulnerability analytics queries.\n\n## Install\n\n```bash\npipx install agent-bom\n```\n\n## Tools (3)\n\n| Tool | Description |\n|------|-------------|\n| `context_graph` | Agent context graph with lateral movement analysis |\n| `analytics_query` | Query vulnerability trends, posture history, and runtime events |\n| `runtime_correlate` | Cross-reference runtime audit logs with CVE findings |\n\n## Example Workflows\n\n```\n# Build context graph from scan results\ncontext_graph()\n\n# Correlate runtime audit with CVE data\nruntime_correlate(audit_file=\"proxy-audit.jsonl\")\n\n# Query analytics\nanalytics_query(query=\"top_cves\", days=30)\n```\n\n## Privacy & Data Handling\n\nOperates on scan results already in memory and user-provided audit log files.\nNo automatic file discovery. No network calls unless you configure an optional\nClickHouse endpoint for persistent analytics.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.103.2:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-runtime\",\n  \"version\": \"0.103.2\",\n  \"publishedAt\": 1788333864168\n}\n\nFile v0.103.2:skill-card.md\n\n## Description:\n\nAI runtime security monitoring for context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nApache-2.0\n\n## Use Case:\n\nDevelopers and security engineers use this skill to analyze agent runtime context, correlate user-provided audit logs with CVE findings, and query vulnerability trends or posture history.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: User-provided audit logs may contain sensitive operational details such as credential environment variable names.\n\nMitigation: Review audit logs before use, avoid including raw credential values, and share only the minimum data needed for the analysis.\n\nRisk: Optional ClickHouse or kubectl use can expose analytics data or cluster context if configured unintentionally.\n\nMitigation: Configure optional ClickHouse and kubectl access deliberately, using least-privilege credentials and operator-approved endpoints.\n\n## Reference(s):\n\n- [Project homepage](https://github.com/msaad00/agent-bom)\n- [PyPI package](https://pypi.org/project/agent-bom/)\n- [OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n- [ClawHub skill page](https://clawhub.ai/msaad00/skills/agent-bom-runtime)\n\n## Skill Output:\n\n**Output Type(s):** [Analysis, Markdown, Shell commands, Guidance]\n\n**Output Format:** [Markdown with inline shell commands and structured analysis]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May reference user-provided JSONL audit logs, in-memory scan results, optional kubectl context, and optional ClickHouse analytics storage.]\n\n## Skill Version(s):\n\n0.103.2 (source: frontmatter and server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.","readmeExcerpt":"Skill: agent-bom runtime Owner: msaad00 Summary: AI runtime security monitoring — context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries. Use when the user mentions runtime monitoring, context graphs, lateral movement analysis, audit log correlation, or vulnerability analytics. Tags: latest:0.108.3 Version history: v0.108.3 | 2026-10-08T22:18:13.720Z | user Releas","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"pipx install agent-bom"},{"language":"text","snippet":"# Build context graph from scan results\ncontext_graph()\n\n# Correlate runtime audit with CVE data\nruntime_correlate(audit_file=\"proxy-audit.jsonl\")\n\n# Query analytics\nanalytics_query(query=\"top_cves\", days=30)"},{"language":"bash","snippet":"pipx install agent-bom"},{"language":"text","snippet":"# Build context graph from scan results\ncontext_graph()\n\n# Correlate runtime audit with CVE data\nruntime_correlate(audit_file=\"proxy-audit.jsonl\")\n\n# Query analytics\nanalytics_query(query=\"top_cves\", days=30)"},{"language":"bash","snippet":"pipx install agent-bom"},{"language":"text","snippet":"# Build context graph from scan results\ncontext_graph()\n\n# Correlate runtime audit with CVE data\nruntime_correlate(audit_file=\"proxy-audit.jsonl\")\n\n# Query analytics\nanalytics_query(query=\"top_cves\", days=30)"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: agent-bom-runtime\ndescription: >-\n  AI runtime security monitoring — context graph analysis, runtime audit log\n  correlation with CVE findings, and vulnerability analytics queries. Use when\n  the user mentions runtime monitoring, context graphs, lateral movement analysis,\n  audit log correlation, or vulnerability analytics.\nversion: 0.108.3\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: kubectl for\n  Kubernetes context, ClickHouse for analytics storage. No API keys required.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Optional ClickHouse URL enables analytics storage. Never auto-discovered or inferred.\"\n    credential_handling: \"Runtime audit data may include credential environment variable names but must not include raw values. Optional analytics credentials are operator-supplied and must not be displayed or inferred.\"\n    optional_env: []\n    optional_bins:\n      - kubectl\n    emoji: \"\\U0001F4CA\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Operates on scan results in memory and user-provided audit log files. Optional ClickHouse connection for persistent analytics (user-configured, not auto-discovered).\"\n    file_reads:\n      - \"user-provided audit log files (JSONL format from agent-bom proxy)\"\n    file_writes: []\n    network_endpoints: []\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-runtime — AI Runtime Security Monitoring\n\nContext graph analysis, runtime audit log correlation with CVE findings, and\nvulnerability analytics queries.\n\n## Install\n\n```bash\npipx install agent-bom\n```\n\n## Tools (3)\n\n| Tool | Description |\n|------|-------------|\n| `context_graph` | Agent context graph with lateral movement analysis |\n| `analytics_query` | Query vulnerability trends, posture history, and runtime events |\n| `runtime_correlate` | Cross-reference runtime audit logs with CVE findings |\n\n## Example Workflows\n\n```\n# Build context graph from scan results\ncontext_graph()\n\n# Correlate runtime audit with CVE data\nruntime_correlate(audit_file=\"proxy-audit.jsonl\")\n\n# Query analytics\nanalytics_query(query=\"top_cves\", days=30)\n```\n\n## Privacy & Data Handling\n\nOperates on scan results already in memory and user-provided audit log files.\nNo automatic file discovery. No network calls unless you configure an optional\nClickHouse endpoint for persistent analytics.\n\n## "},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-runtime\",\n  \"version\": \"0.108.3\",\n  \"publishedAt\": 1791497893720\n}"},{"path":"skill-card.md","content":"## Description:\n\nAnalyzes agent context graphs, correlates runtime audit logs with CVE findings, and queries vulnerability trends.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security teams use this skill to inspect agent context graphs, correlate user-supplied runtime audit logs with CVEs, and review vulnerability trends.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Installing a third-party CLI introduces package supply-chain risk.\n\nMitigation: Review the PyPI package and project before installing, as recommended by the release security guidance.\n\nRisk: Optional ClickHouse or kubectl access can expose analytics data or cluster resources.\n\nMitigation: Configure those connections only when needed and limit access to the intended environment.\n\n## Reference(s):\n\n- [ClawHub skill release](https://clawhub.ai/msaad00/skills/agent-bom-runtime)\n- [Project homepage listed in skill metadata](https://github.com/msaad00/agent-bom)\n- [agent-bom package on PyPI](https://pypi.org/project/agent-bom/)\n- [Project OpenSSF Scorecard](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Analysis, Guidance]\n\n**Output Format:** [Text or Markdown]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Context graph analysis, audit-to-CVE correlation, and vulnerability trend results; no fixed output schema is specified.]\n\n## Skill Version(s):\n\n0.108.3 (source: release metadata and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"AI runtime security monitoring — context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries. Use when the user mentions runtime monitoring, context graphs, lateral movement analysis, audit log correlation, or vulnerability analytics. Skill: agent-bom runtime Owner: msaad00 Summary: AI runtime security monitoring — context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries. Use when the user mentions runtime monitoring, context graphs, lateral movement analysis, audit log correlation, or vulnerability analytics. Tags: latest:0.108.3 Version history: v0.108.3 | 2026-10-08T22:18:13.720Z | user Releas","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1010,"uniquenessScore":48,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T03:47:40.422Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T03:47:40.422Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T12:54:55.146Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}