{"id":"a6e48009-2bb8-4be3-960a-b287e1c9e19a","slug":"clawhub-msaad00-agent-bom-scan","name":"agent-bom scan","description":"Check vulnerabilities in a specified package/version, repository, container image, or SBOM, or inspect a specified CVE. Discover local MCP clients only when the user explicitly requests that discovery. Ask for the target when a request such as \"verify\" or \"is this safe\" does not identify one.","canonicalUrl":"https://www.xpersona.co/agent/clawhub-msaad00-agent-bom-scan","sourceUrl":"https://clawhub.ai/msaad00/agent-bom-scan","homepage":"https://clawhub.ai/msaad00/skills/agent-bom-scan","source":"CLAWHUB","vendor":{"slug":"clawhub","label":"Clawhub","url":"https://clawhub.ai/msaad00/skills/agent-bom-scan"},"protocols":["OPENCLEW"],"capabilities":[],"trustScore":null,"trustConfidence":"unknown","artifactCount":0,"benchmarkCount":0,"lastRelease":"0.108.3","freshnessAt":"2026-10-09T04:30:28.296Z","freshnessLabel":"Oct 9, 2026","securityReviewed":true,"openapiReady":false,"stats":[{"label":"Trust score","value":"Unknown"},{"label":"Compatibility","value":"OpenClaw"},{"label":"Freshness","value":"Oct 9, 2026"},{"label":"Vendor","value":"Clawhub"},{"label":"Artifacts","value":"0"},{"label":"Benchmarks","value":"0"},{"label":"Last release","value":"0.108.3"}],"factsPreview":[{"factKey":"vendor","category":"vendor","label":"Vendor","value":"Clawhub","href":"https://clawhub.ai/msaad00/skills/agent-bom-scan","sourceUrl":"https://clawhub.ai/msaad00/skills/agent-bom-scan","sourceType":"profile","confidence":"medium","observedAt":"2026-10-09T04:30:28.296Z","isPublic":true},{"factKey":"protocols","category":"compatibility","label":"Protocol compatibility","value":"OpenClaw","href":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-scan/contract","sourceUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-scan/contract","sourceType":"contract","confidence":"medium","observedAt":"2026-10-09T04:30:28.296Z","isPublic":true},{"factKey":"traction","category":"adoption","label":"Adoption signal","value":"5K downloads","href":"https://clawhub.ai/msaad00/agent-bom-scan","sourceUrl":"https://clawhub.ai/msaad00/agent-bom-scan","sourceType":"profile","confidence":"medium","observedAt":"2026-10-09T04:30:28.296Z","isPublic":true},{"factKey":"latest_release","category":"release","label":"Latest release","value":"0.108.3","href":"https://clawhub.ai/msaad00/agent-bom-scan","sourceUrl":"https://clawhub.ai/msaad00/agent-bom-scan","sourceType":"release","confidence":"medium","observedAt":"2026-10-08T22:17:30.509Z","isPublic":true},{"factKey":"handshake_status","category":"security","label":"Handshake status","value":"UNKNOWN","href":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-scan/trust","sourceUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-scan/trust","sourceType":"trust","confidence":"medium","observedAt":null,"isPublic":true}],"highlights":["5K downloads","Trust evidence available"],"agentCard":{"name":"agent-bom scan","description":"Check vulnerabilities in a specified package/version, repository, container image, or SBOM, or inspect a specified CVE. Discover local MCP clients only when the user explicitly requests that discovery. Ask for the target when a request such as \"verify\" or \"is this safe\" does not identify one.","source":"CLAWHUB","sourceId":"clawhub:s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom-scan","homepage":"https://clawhub.ai/msaad00/skills/agent-bom-scan","repository":"https://clawhub.ai/msaad00/agent-bom-scan","documentation":"https://www.xpersona.co/agent/clawhub-msaad00-agent-bom-scan","protocols":["OPENCLEW"],"examples":[{"kind":"example","language":"bash","snippet":"pipx install agent-bom\nagent-bom check langchain==0.1.0  # check a specific package with version\nagent-bom scan --project . --no-discover  # scan the requested project\nagent-bom scan --image nginx:1.25 --no-discover  # scan the requested image\nagent-bom scan --sbom sbom.json --no-discover  # scan a supplied SBOM\nagent-bom scan --project . --no-discover -f cyclonedx -o sbom.json  # requested output\nagent-bom verify agent-bom   # verify Sigstore provenance"},{"kind":"example","language":"json","snippet":"{\n  \"mcpServers\": {\n    \"agent-bom\": {\n      \"command\": \"uvx\",\n      \"args\": [\"agent-bom\", \"mcp\", \"server\"]\n    }\n  }\n}"}]}}