{"id":"4120d25e-af2f-4329-af7d-295aed818c92","entityType":"agent","slug":"clawhub-msaad00-agent-bom","name":"agent-bom","canonicalUrl":"https://www.xpersona.co/agent/clawhub-msaad00-agent-bom","canonicalPath":"/agent/clawhub-msaad00-agent-bom","generatedAt":"2026-10-09T15:30:47.377Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T14:12:25.466Z","emptyReason":null},"description":"Open security scanner for agentic infrastructure — agents, MCP, packages, blast radius, runtime, and trust across MCP discovery, CVEs, SBOMs, CIS benchmarks...","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 2.5K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom","sourceUrl":"https://clawhub.ai/msaad00/agent-bom","homepage":"https://clawhub.ai/msaad00/skills/agent-bom","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/msaad00/agent-bom","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/msaad00/skills/agent-bom","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":63,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"agent-bom technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T14:12:25.466Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T14:12:25.466Z","emptyReason":null},"stars":null,"forks":null,"downloads":2507,"packageName":null,"latestVersion":"0.76.4","tractionLabel":"2.5K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T14:12:25.465Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T14:12:25.466Z","lastCrawledAt":"2026-10-09T14:12:25.465Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T14:12:25.465Z","lastVerifiedAt":null,"highlights":[{"version":"0.76.4","createdAt":"2026-04-13T05:42:38.812Z","changelog":"Release v0.76.4","fileCount":13,"zipByteSize":28514},{"version":"0.76.2","createdAt":"2026-04-10T02:13:25.930Z","changelog":"Release v0.76.2","fileCount":12,"zipByteSize":26825},{"version":"0.76.1","createdAt":"2026-04-09T21:54:26.556Z","changelog":"Release v0.76.1","fileCount":12,"zipByteSize":26825},{"version":"0.76.0","createdAt":"2026-04-09T05:01:50.313Z","changelog":"Release v0.76.0","fileCount":12,"zipByteSize":26812},{"version":"0.75.15","createdAt":"2026-04-05T02:52:01.602Z","changelog":"Release v0.75.15","fileCount":12,"zipByteSize":26837},{"version":"0.75.14","createdAt":"2026-04-04T03:27:38.341Z","changelog":"Release v0.75.14","fileCount":12,"zipByteSize":26833},{"version":"0.75.13","createdAt":"2026-04-02T21:12:00.735Z","changelog":"Release v0.75.13","fileCount":12,"zipByteSize":26817},{"version":"0.75.11","createdAt":"2026-03-29T05:23:17.083Z","changelog":"Release v0.75.11","fileCount":12,"zipByteSize":26665}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/msaad00/agent-bom before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T15:30:47.373Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T14:12:25.466Z","emptyReason":null},"readme":"Skill: agent-bom\n\nOwner: msaad00\n\nSummary: Open security scanner for agentic infrastructure — agents, MCP, packages, blast radius, runtime, and trust across MCP discovery, CVEs, SBOMs, CIS benchmarks...\n\nTags: ai-supply-chain:0.28.1, cve:0.28.1, latest:0.76.4, mcp:0.28.1, sbom:0.28.1, security:0.28.1\n\nVersion history:\n\nv0.76.4 | 2026-04-13T05:42:38.812Z | user\n\nRelease v0.76.4\n\nv0.76.2 | 2026-04-10T02:13:25.930Z | user\n\nRelease v0.76.2\n\nv0.76.1 | 2026-04-09T21:54:26.556Z | user\n\nRelease v0.76.1\n\nv0.76.0 | 2026-04-09T05:01:50.313Z | user\n\nRelease v0.76.0\n\nv0.75.15 | 2026-04-05T02:52:01.602Z | user\n\nRelease v0.75.15\n\nv0.75.14 | 2026-04-04T03:27:38.341Z | user\n\nRelease v0.75.14\n\nv0.75.13 | 2026-04-02T21:12:00.735Z | user\n\nRelease v0.75.13\n\nv0.75.11 | 2026-03-29T05:23:17.083Z | user\n\nRelease v0.75.11\n\nv0.75.10 | 2026-03-28T01:04:53.822Z | user\n\nRelease v0.75.10\n\nv0.75.9 | 2026-03-27T15:16:00.416Z | user\n\nRelease v0.75.9\n\nv0.75.8 | 2026-03-26T23:08:09.199Z | user\n\nRelease v0.75.8\n\nv0.75.7 | 2026-03-26T04:46:18.658Z | user\n\nRelease v0.75.7\n\nv0.75.6 | 2026-03-26T02:41:27.417Z | user\n\nRelease v0.75.6\n\nv0.75.3 | 2026-03-23T21:16:24.968Z | user\n\nRelease v0.75.3\n\nv0.75.0 | 2026-03-23T05:18:54.832Z | user\n\nRelease v0.75.0\n\nv0.74.1 | 2026-03-22T04:16:03.570Z | user\n\nRelease v0.74.1\n\nv0.74.0 | 2026-03-21T22:03:35.540Z | user\n\nRelease v0.74.0\n\nv0.72.0 | 2026-03-19T06:08:36.080Z | user\n\nRelease v0.72.0\n\nv0.71.4 | 2026-03-18T20:07:55.613Z | user\n\nRelease v0.71.4\n\nv0.71.3 | 2026-03-18T07:16:05.261Z | user\n\nRelease v0.71.3\n\nv0.71.2 | 2026-03-17T21:03:46.153Z | user\n\nRelease v0.71.2\n\nv0.71.0 | 2026-03-16T07:25:20.508Z | user\n\nRelease v0.71.0\n\nv0.70.12 | 2026-03-15T20:19:14.536Z | user\n\nRelease v0.70.12\n\nv0.70.11 | 2026-03-15T05:31:39.349Z | user\n\nRelease v0.70.11\n\nv0.70.10 | 2026-03-15T04:48:56.279Z | user\n\nRelease v0.70.10\n\nv0.70.9 | 2026-03-15T04:08:20.040Z | user\n\nRelease v0.70.9\n\nv0.70.8 | 2026-03-14T10:01:33.654Z | user\n\nRelease v0.70.8\n\nv0.70.7 | 2026-03-13T19:14:39.209Z | user\n\nRelease v0.70.7\n\nv0.70.6 | 2026-03-12T20:20:26.068Z | user\n\nRelease v0.70.6\n\nv0.62.0 | 2026-03-08T19:25:37.170Z | user\n\nRelease v0.62.0\n\nv0.60.2 | 2026-03-08T04:11:17.361Z | user\n\nRelease v0.60.2\n\nv0.60.1 | 2026-03-08T03:59:22.871Z | user\n\nRelease v0.60.1\n\nv0.60.0 | 2026-03-07T21:44:46.419Z | user\n\nRelease v0.60.0\n\nv0.59.3 | 2026-03-07T06:53:12.243Z | user\n\nRelease v0.59.3\n\nv0.59.2 | 2026-03-07T04:02:32.108Z | user\n\nRelease v0.59.2\n\nv0.59.1 | 2026-03-06T23:07:41.297Z | user\n\nRelease v0.59.1\n\nv0.59.0 | 2026-03-06T22:25:56.544Z | user\n\nRelease v0.59.0\n\nv0.58.1 | 2026-03-06T19:57:06.942Z | user\n\nRelease v0.58.1\n\nv0.57.0 | 2026-03-06T05:20:59.383Z | user\n\nRelease v0.57.0\n\nv0.56.0 | 2026-03-06T00:21:57.298Z | user\n\nRelease v0.56.0\n\nv0.55.0 | 2026-03-05T18:54:35.468Z | user\n\nRelease v0.55.0\n\nv0.54.0 | 2026-03-05T06:51:25.028Z | user\n\nRelease v0.54.0\n\nv0.51.0 | 2026-03-04T18:30:55.080Z | user\n\nRelease v0.51.0\n\nv0.38.1 | 2026-03-02T16:33:03.377Z | user\n\nRelease v0.38.1\n\nv0.38.0 | 2026-03-02T03:59:18.097Z | user\n\nRelease v0.38.0\n\nv0.36.1 | 2026-03-01T03:31:19.703Z | user\n\nRelease v0.36.1\n\nv0.36.0 | 2026-03-01T02:30:02.977Z | user\n\nRelease v0.36.0\n\nv0.35.0 | 2026-02-27T04:58:37.034Z | user\n\nRelease v0.35.0\n\nv0.34.0 | 2026-02-26T07:27:28.229Z | user\n\nRelease v0.34.0\n\nv0.33.0 | 2026-02-26T04:19:11.015Z | user\n\nRelease v0.33.0\n\nArchive index:\n\nArchive v0.76.4: 13 files, 28514 bytes\n\nFiles: analyze/SKILL.md (4208b), compliance/SKILL.md (7524b), discover/SKILL.md (5608b), enforce/SKILL.md (3725b), monitor/SKILL.md (3619b), registry/SKILL.md (4109b), runtime/SKILL.md (2993b), scan-infra/SKILL.md (5922b), scan/SKILL.md (7773b), skill-card.md (3454b), SKILL.md (17813b), troubleshoot/SKILL.md (3461b), _meta.json (129b)\n\nFile v0.76.4:analyze/SKILL.md\n\n---\nname: agent-bom-analyze\ndescription: >-\n  Analyze blast radius, attack paths, and threat landscape across your AI\n  infrastructure. Use when: \"blast radius\", \"threat intel\", \"risk score\",\n  \"attack path\", \"lateral movement\", \"context graph\", \"who can reach what\".\nversion: 0.76.4\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. No credentials required for\n  blast radius and context graph analysis. Threat intelligence lookups query\n  EPSS and CVE databases.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.4\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Blast radius and context graph analysis operate on local scan data. EPSS and CVE lookups send only public CVE IDs — no internal data.\"\n    optional_env: []\n    optional_bins: []\n    emoji: \"\\U0001F4A5\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Blast radius and context graph analysis operate on local scan results in memory. Only public CVE IDs are sent to EPSS and vulnerability databases for threat intelligence enrichment. No internal config data, credentials, or scan results leave the machine.\"\n    file_reads: []\n    file_writes: []\n    network_endpoints:\n      - url: \"https://api.first.org/data/v1/epss\"\n        purpose: \"EPSS exploit probability scores for CVEs found in scan\"\n        auth: false\n      - url: \"https://api.osv.dev/v1\"\n        purpose: \"OSV vulnerability database — CVE detail lookup\"\n        auth: false\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-analyze — Blast Radius & Attack Path Analysis\n\nAnalyzes blast radius, attack paths, and the threat landscape across your AI\ninfrastructure. Maps lateral movement risks, identifies high-impact CVEs, and\nvisualizes agent context graphs.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom agents --verbose   # blast radius detail for each agent\nagent-bom graph              # generate context graph\n```\n\n## When to Use\n\n- \"blast radius\" / \"what's the blast radius\"\n- \"threat intel\" / \"threat intelligence\"\n- \"risk score\" / \"risk scoring\"\n- \"attack path\" / \"attack paths\"\n- \"lateral movement\"\n- \"context graph\" / \"agent graph\"\n- \"who can reach what\"\n\n## Commands\n\n```bash\n# Blast radius detail (verbose)\nagent-bom agents --verbose\n\n# Generate context graph\nagent-bom graph\n```\n\n## Tools\n\n| Tool | Description |\n|------|-------------|\n| `blast_radius` | Map CVE impact chain across agents, servers, and credentials |\n| `context_graph` | Agent context graph with lateral movement analysis |\n| `analytics_query` | Query vulnerability trends, posture history, and risk scores |\n\n## Examples\n\n```\n# Map blast radius of a specific CVE\nblast_radius(cve_id=\"CVE-2024-21538\")\n\n# Build full context graph\ncontext_graph()\n\n# Query top CVEs by blast radius impact\nanalytics_query(query=\"top_blast_radius\", days=30)\n```\n\n**Example blast radius output:**\n```\nCVE-2024-21538 — CRITICAL (CVSS 9.8, EPSS 0.94)\nBlast Radius: 4 agents affected\n\n  filesystem   [direct]  langchain 0.1.0 → CVE-2024-21538\n    └─ github  [indirect] shares filesystem credential scope\n    └─ slack   [indirect] accessible via filesystem tool call\n  postgres     [direct]  langchain 0.1.0 → CVE-2024-21538\n\nRecommended: Update langchain to ≥ 0.1.17\n```\n\n## Guardrails\n\n- Analysis is read-only — no files are modified.\n- Only public CVE IDs are sent externally (to EPSS and vulnerability databases).\n- No internal config data, credentials, or agent details leave the machine.\n- Present blast radius findings clearly and ask the user whether to generate a remediation plan when CRITICAL CVEs are found.\n\nFile v0.76.4:compliance/SKILL.md\n\n---\nname: agent-bom-compliance\ndescription: >-\n  AI compliance and policy engine — evaluate scan results against OWASP, NIST,\n  SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.\n  Generate SBOMs and compliance reports. Use when:\n  \"compliance report\", \"NIST\", \"SOC 2\", \"ISO 27001\", \"OWASP\", \"EU AI Act\",\n  \"AISVS\", \"generate SBOM\", \"policy check\".\nversion: 0.76.4\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. OWASP/NIST/EU AI Act/MITRE\n  evaluation and SBOM generation are fully local with zero credentials. CIS\n  benchmark checks optionally use cloud SDK credentials (AWS/Azure/GCP/Snowflake)\n  and make read-only API calls to cloud providers when explicitly invoked.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.4\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required for OWASP/NIST/EU AI Act compliance and SBOM generation. CIS benchmark checks (AWS, Azure, GCP, Snowflake) optionally accept cloud credentials — only used locally to call cloud APIs, never transmitted elsewhere.\"\n    optional_env:\n      - name: AWS_PROFILE\n        purpose: \"AWS CIS benchmark checks — uses boto3 with your local AWS profile\"\n        required: false\n      - name: AZURE_TENANT_ID\n        purpose: \"Azure CIS benchmark checks (azure-mgmt-* SDK)\"\n        required: false\n      - name: AZURE_CLIENT_ID\n        purpose: \"Azure CIS benchmark checks — service principal client ID\"\n        required: false\n      - name: AZURE_CLIENT_SECRET\n        purpose: \"Azure CIS benchmark checks — service principal secret\"\n        required: false\n      - name: GOOGLE_APPLICATION_CREDENTIALS\n        purpose: \"GCP CIS benchmark checks (google-cloud-* SDK)\"\n        required: false\n      - name: SNOWFLAKE_ACCOUNT\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_USER\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_PRIVATE_KEY_PATH\n        purpose: \"Snowflake key-pair auth (CI/CD)\"\n        required: false\n      - name: SNOWFLAKE_AUTHENTICATOR\n        purpose: \"Snowflake auth method (default: externalbrowser SSO)\"\n        required: false\n    optional_bins: []\n    emoji: \"\\U00002705\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: >-\n      OWASP/NIST/EU AI Act/MITRE/SBOM evaluation is purely local — zero network\n      calls. CIS benchmark checks (optional, user-initiated) call cloud provider\n      APIs (AWS/Azure/GCP/Snowflake) using locally configured credentials. No data\n      is stored or transmitted beyond the cloud provider's own API. File reads are\n      limited to user-provided SBOMs and policy files.\n    file_reads:\n      - \"user-provided SBOM files (CycloneDX/SPDX JSON)\"\n      - \"user-provided policy files (YAML/JSON policy-as-code)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://*.amazonaws.com\"\n        purpose: \"AWS CIS benchmark checks — read-only API calls (IAM, S3, CloudTrail, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://management.azure.com\"\n        purpose: \"Azure CIS benchmark checks — read-only API calls (Azure Resource Manager)\"\n        auth: true\n        optional: true\n      - url: \"https://*.googleapis.com\"\n        purpose: \"GCP CIS benchmark checks — read-only API calls (Cloud Resource Manager, IAM, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake CIS benchmark checks — read-only API calls (ACCOUNT_USAGE views)\"\n        auth: true\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-compliance — AI Compliance & Policy Engine\n\nEvaluate AI infrastructure scan results against 14 security and regulatory\nframeworks. Enforce policy-as-code rules. Generate SBOMs in standard formats.\nRun AISVS v1.0 and CIS benchmark checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom agents -f compliance-export  # run agents scan with compliance export\nagent-bom generate-sbom                # generate CycloneDX SBOM\n```\n\n## When to Use\n\n- \"compliance report\" / \"run compliance\"\n- \"NIST\" / \"NIST AI RMF\" / \"NIST CSF\" / \"NIST 800-53\"\n- \"SOC 2\" / \"SOC2\"\n- \"ISO 27001\"\n- \"OWASP\" / \"OWASP LLM Top 10\" / \"OWASP Agentic Top 10\"\n- \"EU AI Act\"\n- \"AISVS\" / \"AI Security Verification Standard\"\n- \"CMMC\" / \"FedRAMP\"\n- \"generate SBOM\" / \"CycloneDX\" / \"SPDX\"\n- \"policy check\" / \"policy enforcement\"\n\n## Tools (5)\n\n| Tool | Description |\n|------|-------------|\n| `compliance` | OWASP LLM/Agentic Top 10, EU AI Act, MITRE ATLAS, NIST AI RMF |\n| `policy_check` | Evaluate results against custom security policy (17 conditions) |\n| `cis_benchmark` | Run CIS benchmark checks against cloud accounts |\n| `generate_sbom` | Generate SBOM (CycloneDX or SPDX format) |\n| `aisvs_benchmark` | OWASP AISVS v1.0 compliance — 9 AI security checks |\n\n## Supported Frameworks (14)\n\n- **OWASP LLM Top 10** (2025) — prompt injection, supply chain, data leakage\n- **OWASP MCP Top 10** — MCP-specific security risks\n- **OWASP Agentic Top 10** — tool poisoning, rug pulls, credential theft\n- **OWASP AISVS v1.0** — AI Security Verification Standard (9 checks)\n- **MITRE ATLAS** — adversarial ML threat framework\n- **NIST AI RMF** — govern, map, measure, manage lifecycle\n- **NIST CSF 2.0** — identify, protect, detect, respond, recover\n- **NIST 800-53 Rev 5** — federal security controls (CM-8, RA-5, SI-2, SR-3)\n- **FedRAMP Moderate** — derived from NIST 800-53 controls\n- **EU AI Act** — risk classification, transparency, SBOM requirements\n- **ISO 27001:2022** — information security controls (Annex A)\n- **SOC 2** — Trust Services Criteria\n- **CIS Controls v8** — implementation groups IG1/IG2/IG3\n- **CMMC 2.0** — cybersecurity maturity model (Level 1-3)\n\n## Examples\n\n```\n# Run compliance check against multiple frameworks\ncompliance(frameworks=[\"owasp_llm\", \"eu_ai_act\", \"nist_ai_rmf\"])\n\n# Enforce custom policy\npolicy_check(policy={\"max_critical\": 0, \"max_high\": 5})\n\n# Generate SBOM\ngenerate_sbom(format=\"cyclonedx\")\n\n# Run AISVS v1.0 compliance\naisvs_benchmark()\n\n# Run AWS CIS benchmark\ncis_benchmark(provider=\"aws\")\n```\n\n## Privacy & Data Handling\n\n**OWASP, NIST, EU AI Act, MITRE ATLAS, AISVS, SBOM generation, and policy\nchecks** run entirely locally on scan data already in memory. No network calls,\nno credentials needed for these features.\n\n**CIS benchmark checks** (optional, user-initiated) call cloud provider APIs\nusing your locally configured credentials. These are read-only API calls to\nAWS, Azure, GCP, or Snowflake. You must explicitly run `cis_benchmark(provider=...)`\nand confirm before any cloud API calls are made.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.76.4:discover/SKILL.md\n\n---\nname: agent-bom-discover\ndescription: >-\n  Discover AI agents, MCP servers, and configurations on this machine or\n  environment. Use when: \"find agents\", \"what's configured\", \"doctor\",\n  \"what MCP servers\", \"show me what's installed\", \"mcp inventory\".\nversion: 0.76.4\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. No credentials required.\n  Registry data (427+ MCP servers) is bundled in-package with zero network calls.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.4\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Discovery reads only structural config data (server names, commands, args, URLs). Env var values are replaced with ***REDACTED*** by sanitize_env_vars() before any processing.\"\n    optional_env: []\n    optional_bins: []\n    emoji: \"\\U0001F50E\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Env var values are NEVER extracted from config files. sanitize_env_vars() replaces all env values with ***REDACTED*** BEFORE any config data is processed or stored. Source: https://github.com/msaad00/agent-bom/blob/main/src/agent_bom/security.py#L159\"\n    data_flow: \"Purely local. Reads MCP client config files across 22+ AI tools. Only structural data (server names, commands, URLs) is extracted. Env var values are redacted before processing. No data leaves the machine.\"\n    file_reads:\n      # Claude Desktop\n      - \"~/Library/Application Support/Claude/claude_desktop_config.json\"\n      - \"~/.config/Claude/claude_desktop_config.json\"\n      # Claude Code\n      - \"~/.claude/settings.json\"\n      - \"~/.claude.json\"\n      # Cursor\n      - \"~/.cursor/mcp.json\"\n      - \"~/Library/Application Support/Cursor/User/globalStorage/cursor.mcp/mcp.json\"\n      # Windsurf\n      - \"~/.windsurf/mcp.json\"\n      # Cline\n      - \"~/Library/Application Support/Code/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.json\"\n      # VS Code Copilot\n      - \"~/Library/Application Support/Code/User/mcp.json\"\n      # Codex CLI\n      - \"~/.codex/config.toml\"\n      # Gemini CLI\n      - \"~/.gemini/settings.json\"\n      # Goose\n      - \"~/.config/goose/config.yaml\"\n      # Continue\n      - \"~/.continue/config.json\"\n      # Zed\n      - \"~/.config/zed/settings.json\"\n      # Roo Code\n      - \"~/Library/Application Support/Code/User/globalStorage/rooveterinaryinc.roo-cline/settings/cline_mcp_settings.json\"\n      # Amazon Q\n      - \"~/Library/Application Support/Code/User/globalStorage/amazonwebservices.amazon-q-vscode/mcp.json\"\n      # JetBrains AI\n      - \"~/Library/Application Support/JetBrains/*/mcp.json\"\n      - \"~/.config/github-copilot/intellij/mcp.json\"\n      # Junie\n      - \"~/.junie/mcp/mcp.json\"\n      # GitHub Copilot CLI\n      - \"~/.copilot/mcp-config.json\"\n      # Tabnine\n      - \"~/.tabnine/mcp_servers.json\"\n      # Cortex Code (Snowflake)\n      - \"~/.snowflake/cortex/mcp.json\"\n      - \"~/.snowflake/cortex/settings.json\"\n      # Snowflake CLI\n      - \"~/.snowflake/connections.toml\"\n      - \"~/.snowflake/config.toml\"\n      # Project-level configs\n      - \".mcp.json\"\n      - \".vscode/mcp.json\"\n      - \".cursor/mcp.json\"\n    file_writes: []\n    network_endpoints: []\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover — AI Agent & MCP Server Discovery\n\nDiscovers AI agents, MCP servers, and their configurations across 22+ AI tools\non this machine. Shows what's installed, configured, and registered in the\nbundled 427+ MCP server registry.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom agents             # discover all AI agents and MCP servers\nagent-bom doctor             # check prerequisites and configuration health\nagent-bom mcp inventory      # list all discovered MCP servers\nagent-bom where              # show all discovery paths\n```\n\n## When to Use\n\n- \"find agents\" / \"what agents are configured\"\n- \"what MCP servers do I have\"\n- \"what's configured on this machine\"\n- \"mcp inventory\"\n- \"doctor\" / \"check my setup\"\n- \"show me what's installed\"\n\n## Commands\n\n```bash\n# Discover all AI agents and MCP servers\nagent-bom agents\n\n# Check configuration health and prerequisites\nagent-bom doctor\n\n# List MCP server inventory\nagent-bom mcp inventory\n\n# Show all discovery paths\nagent-bom where\n```\n\n## Examples\n\n```\n# Discover all agents\nagents()\n\n# Run health check\ndoctor()\n\n# List MCP inventory\ninventory()\n```\n\n**Example output:**\n```\nDiscovered 3 MCP clients:\n  Claude Desktop  — 4 servers configured\n  Cursor          — 2 servers configured\n  VS Code         — 1 server configured\n\nServers: filesystem, brave-search, github, slack, postgres, linear, notion\nRegistry: 5/7 servers found in registry (427+ entries)\n```\n\n## Guardrails\n\n- Discovery is read-only — no files are modified, no packages installed.\n- Env var values in config files are always replaced with `***REDACTED***` before processing.\n- Only structural data (server names, commands, URLs) is extracted.\n- Confirm with user before scanning paths outside the home directory.\n\nFile v0.76.4:enforce/SKILL.md\n\n---\nname: agent-bom-enforce\ndescription: >-\n  Enforce security policies on MCP tool calls and block dangerous operations at\n  runtime. Use when: \"block risky calls\", \"apply policy\", \"proxy\",\n  \"runtime protection\", \"policy enforcement\", \"intercept MCP calls\".\nversion: 0.76.4\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. No credentials required.\n  Policy files are user-provided YAML/JSON. Proxy runs locally.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.4\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Policy evaluation is local. Proxy operates on local network only. Policy files are user-provided and never transmitted.\"\n    optional_env: []\n    optional_bins: []\n    emoji: \"\\U0001F6AB\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Purely local. Policy evaluation runs on scan results in memory. Proxy intercepts MCP calls on local network only. Audit logs are written locally (JSONL). No data leaves the machine.\"\n    file_reads:\n      - \"user-provided policy files (YAML/JSON policy-as-code)\"\n      - \"user-provided audit log files (JSONL from agent-bom proxy)\"\n    file_writes:\n      - \"proxy-audit.jsonl (local audit log, only when proxy is running)\"\n    network_endpoints: []\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n    disable-model-invocation: true\n---\n\n# agent-bom-enforce — Runtime Policy Enforcement\n\nEnforces security policies on MCP tool calls and blocks dangerous operations\nat runtime. Runs a local proxy that intercepts MCP calls and evaluates them\nagainst policy-as-code rules.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom proxy              # start enforcement proxy\nagent-bom policy apply policy.yaml  # apply a policy file\nagent-bom policy check       # check current policy status\n```\n\n## When to Use\n\n- \"block risky calls\" / \"block dangerous MCP calls\"\n- \"apply policy\" / \"enforce policy\"\n- \"proxy\" / \"MCP proxy\"\n- \"runtime protection\"\n- \"policy enforcement\"\n- \"intercept MCP calls\"\n\n## Commands\n\n```bash\n# Start the enforcement proxy\nagent-bom proxy\n\n# Apply a policy file\nagent-bom policy apply policy.yaml\n\n# Check current policy status\nagent-bom policy check\n```\n\n## Example Policy File\n\n```yaml\n# policy.yaml\nrules:\n  - id: block-shell-exec\n    description: Block shell execution tool calls\n    match:\n      tool: \"bash|shell|exec|run_command\"\n    action: block\n    severity: critical\n\n  - id: require-path-allowlist\n    description: Restrict filesystem access to allowed paths\n    match:\n      tool: \"read_file|write_file|list_directory\"\n      args.path:\n        not_starts_with: [\"/home/\", \"/tmp/\"]\n    action: block\n    severity: high\n```\n\n## Guardrails\n\n- IMPORTANT: Do not start the proxy or apply policies without explicit user confirmation — enforcement changes how MCP calls are processed.\n- Confirm the policy file contents with the user before applying.\n- Do not enable proxy mode autonomously — always ask the user first.\n- Audit logs are written locally only; no data is transmitted externally.\n- This skill has `disable-model-invocation: true` — do not auto-run enforcement actions.\n\nFile v0.76.4:monitor/SKILL.md\n\n---\nname: agent-bom-monitor\ndescription: >-\n  Monitor agent fleet, track trust scores, and manage lifecycle states. Use\n  when: \"fleet\", \"watch agents\", \"runtime status\", \"trust scores\",\n  \"fleet sync\", \"agent lifecycle\", \"serve dashboard\".\nversion: 0.76.4\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. No credentials required for\n  fleet listing and trust score tracking. Optional server dashboard available\n  via agent-bom serve.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.4\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required for fleet listing and trust score tracking. Fleet sync reads local scan state. Dashboard server (agent-bom serve) runs on localhost only.\"\n    optional_env: []\n    optional_bins: []\n    emoji: \"\\U0001F4CA\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Purely local. Fleet data is read from local scan state. Dashboard server (agent-bom serve) runs on localhost and exposes no data externally. No data leaves the machine.\"\n    file_reads:\n      - \"local scan state and fleet registry (managed by agent-bom)\"\n    file_writes: []\n    network_endpoints: []\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-monitor — Agent Fleet Monitor\n\nMonitor agent fleet health, track trust scores, and manage agent lifecycle\nstates across your AI infrastructure. Start a local dashboard server for\ncontinuous monitoring.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom fleet sync         # sync fleet state with latest scan\nagent-bom fleet list         # list all agents and trust scores\nagent-bom serve              # start local monitoring dashboard\n```\n\n## When to Use\n\n- \"fleet\" / \"agent fleet\"\n- \"watch agents\" / \"monitor agents\"\n- \"runtime status\"\n- \"trust scores\"\n- \"fleet sync\"\n- \"agent lifecycle\"\n- \"serve dashboard\" / \"start dashboard\"\n\n## Commands\n\n```bash\n# Sync fleet state with latest scan\nagent-bom fleet sync\n\n# List all agents with trust scores\nagent-bom fleet list\n\n# Start local monitoring dashboard\nagent-bom serve\n```\n\n## Examples\n\n```\n# Sync fleet\nfleet_sync()\n\n# List agents and trust scores\nfleet_list()\n\n# Start dashboard server\nserve()\n```\n\n**Example fleet list output:**\n```\nAgent Fleet — 7 agents tracked\n  filesystem   trust: 92  status: healthy   last-scan: 2m ago\n  brave-search trust: 88  status: healthy   last-scan: 2m ago\n  github       trust: 95  status: healthy   last-scan: 2m ago\n  slack        trust: 71  status: warning   last-scan: 2m ago  [2 CVEs]\n  postgres     trust: 84  status: healthy   last-scan: 2m ago\n  linear       trust: 90  status: healthy   last-scan: 2m ago\n  notion       trust: 67  status: at-risk   last-scan: 2m ago  [CRITICAL]\n```\n\n## Guardrails\n\n- Fleet monitoring is read-only — no agents are modified.\n- The dashboard server runs on localhost only — no external exposure.\n- Confirm with the user before starting `agent-bom serve` — it binds a local port.\n- Trust scores are derived from local scan data; they do not contact external services.\n\nFile v0.76.4:registry/SKILL.md\n\n---\nname: agent-bom-registry\ndescription: >-\n  MCP server security registry and trust assessment — look up servers in the 427+\n  server security metadata registry, run pre-install marketplace checks, batch\n  fleet risk scoring, assess skill file trust, and run SAST code scans. Use when\n  the user mentions MCP server trust, registry lookup, marketplace check, or\n  skill trust assessment.\nversion: 0.76.4\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: Semgrep for SAST\n  code scanning. No API keys or network access required (registry is bundled).\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Registry data is bundled locally. No network calls needed.\"\n    optional_env:\n      - name: SNYK_TOKEN\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        required: false\n    optional_bins:\n      - semgrep\n    emoji: \"\\U0001F50D\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Purely local. Registry data (427+ MCP server metadata) is bundled in the package. Lookups are in-memory string matches. Skill trust analysis parses user-provided SKILL.md content passed as a string argument.\"\n    file_reads:\n      - \"user-provided SKILL.md files (for skill_trust analysis)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://api.snyk.io\"\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-registry — MCP Server Trust & Security Registry\n\nLook up MCP servers in the 427+ server security metadata registry, assess skill\nfile trust, and run pre-install marketplace checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom registry-lookup brave-search\nagent-bom marketplace-check @anthropic/server-filesystem\n```\n\n## Tools (7)\n\n| Tool | Description |\n|------|-------------|\n| `registry_lookup` | Look up MCP server in 427+ server security metadata registry |\n| `marketplace_check` | Pre-install trust check with registry cross-reference |\n| `fleet_scan` | Batch registry lookup + risk scoring for MCP server inventories |\n| `skill_scan` | Scan instruction files for package refs, trust, and findings |\n| `skill_verify` | Verify Sigstore provenance for instruction files |\n| `skill_trust` | Assess skill file trust level (5-category analysis) |\n| `code_scan` | SAST scanning via Semgrep with CWE-based compliance mapping |\n\n## Example Workflows\n\n```\n# Look up a server in the registry\nregistry_lookup(server_name=\"brave-search\")\n\n# Pre-install trust check\nmarketplace_check(package=\"@modelcontextprotocol/server-filesystem\")\n\n# Scan instruction files and then assess a specific skill file\nskill_scan(path=\".\")\nskill_trust(skill_path=\"./SKILL.md\")\n\n# Batch risk scoring\nfleet_scan(servers=[\"brave-search\", \"github\", \"slack\"])\n```\n\n## MCP Resources\n\n| Resource | Description |\n|----------|-------------|\n| `registry://servers` | Browse 427+ MCP server security metadata registry |\n\n## Privacy & Data Handling\n\nRegistry data is **bundled in the package** — lookups are in-memory string\nmatches with zero network calls. Skill trust analysis parses content passed\nas a string argument (no file system access needed).\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.76.4:runtime/SKILL.md\n\n---\nname: agent-bom-runtime\ndescription: >-\n  AI runtime security monitoring — context graph analysis, runtime audit log\n  correlation with CVE findings, and vulnerability analytics queries. Use when\n  the user mentions runtime monitoring, context graphs, lateral movement analysis,\n  audit log correlation, or vulnerability analytics.\nversion: 0.76.4\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: kubectl for\n  Kubernetes context, ClickHouse for analytics storage. No API keys required.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Optional ClickHouse URL enables analytics storage. Never auto-discovered or inferred.\"\n    optional_env: []\n    optional_bins:\n      - kubectl\n    emoji: \"\\U0001F4CA\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Operates on scan results in memory and user-provided audit log files. Optional ClickHouse connection for persistent analytics (user-configured, not auto-discovered).\"\n    file_reads:\n      - \"user-provided audit log files (JSONL format from agent-bom proxy)\"\n    file_writes: []\n    network_endpoints: []\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-runtime — AI Runtime Security Monitoring\n\nContext graph analysis, runtime audit log correlation with CVE findings, and\nvulnerability analytics queries.\n\n## Install\n\n```bash\npipx install agent-bom\n```\n\n## Tools (3)\n\n| Tool | Description |\n|------|-------------|\n| `context_graph` | Agent context graph with lateral movement analysis |\n| `analytics_query` | Query vulnerability trends, posture history, and runtime events |\n| `runtime_correlate` | Cross-reference runtime audit logs with CVE findings |\n\n## Example Workflows\n\n```\n# Build context graph from scan results\ncontext_graph()\n\n# Correlate runtime audit with CVE data\nruntime_correlate(audit_file=\"proxy-audit.jsonl\")\n\n# Query analytics\nanalytics_query(query=\"top_cves\", days=30)\n```\n\n## Privacy & Data Handling\n\nOperates on scan results already in memory and user-provided audit log files.\nNo automatic file discovery. No network calls unless you configure an optional\nClickHouse endpoint for persistent analytics.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.76.4:scan-infra/SKILL.md\n\n---\nname: agent-bom-scan-infra\ndescription: >-\n  Scan infrastructure-as-code, cloud configurations, and find secrets. Use when:\n  \"check terraform\", \"scan kubernetes\", \"IaC\", \"find secrets\",\n  \"scan dockerfile\", \"cloud security\", \"misconfigurations\".\nversion: 0.76.4\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: kubectl for\n  Kubernetes checks. Cloud checks use locally configured credentials\n  (AWS/Azure/GCP/Snowflake) when explicitly invoked.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.4\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required for IaC and secrets scanning. Cloud checks (AWS/Azure/GCP/Snowflake) optionally accept cloud credentials — only used locally to call cloud APIs, never transmitted elsewhere.\"\n    optional_env:\n      - name: AWS_PROFILE\n        purpose: \"AWS CIS benchmark checks — uses boto3 with your local AWS profile\"\n        required: false\n      - name: AZURE_TENANT_ID\n        purpose: \"Azure CIS benchmark checks (azure-mgmt-* SDK)\"\n        required: false\n      - name: AZURE_CLIENT_ID\n        purpose: \"Azure CIS benchmark checks — service principal client ID\"\n        required: false\n      - name: AZURE_CLIENT_SECRET\n        purpose: \"Azure CIS benchmark checks — service principal secret\"\n        required: false\n      - name: GOOGLE_APPLICATION_CREDENTIALS\n        purpose: \"GCP CIS benchmark checks (google-cloud-* SDK)\"\n        required: false\n      - name: SNOWFLAKE_ACCOUNT\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_USER\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_PRIVATE_KEY_PATH\n        purpose: \"Snowflake key-pair auth (CI/CD)\"\n        required: false\n      - name: SNOWFLAKE_AUTHENTICATOR\n        purpose: \"Snowflake auth method (default: externalbrowser SSO)\"\n        required: false\n    optional_bins:\n      - kubectl\n    emoji: \"\\U0001F3D7\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: >-\n      IaC and secrets scanning is purely local — no network calls. Cloud\n      benchmark checks (optional, user-initiated) call cloud provider APIs\n      (AWS/Azure/GCP/Snowflake) using locally configured credentials. No data\n      is stored or transmitted beyond the cloud provider's own API.\n    file_reads:\n      - \"user-specified IaC directories (Terraform, CloudFormation, Kubernetes YAML)\"\n      - \"user-specified Dockerfiles\"\n      - \"user-specified cloud configuration files\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://*.amazonaws.com\"\n        purpose: \"AWS CIS benchmark checks — read-only API calls (IAM, S3, CloudTrail, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://management.azure.com\"\n        purpose: \"Azure CIS benchmark checks — read-only API calls (Azure Resource Manager)\"\n        auth: true\n        optional: true\n      - url: \"https://*.googleapis.com\"\n        purpose: \"GCP CIS benchmark checks — read-only API calls (Cloud Resource Manager, IAM, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake CIS benchmark checks — read-only API calls (ACCOUNT_USAGE views)\"\n        auth: true\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-scan-infra — Infrastructure & Cloud Security Scanner\n\nScans infrastructure-as-code (Terraform, CloudFormation, Kubernetes), finds\nsecrets in config files, and runs cloud CIS benchmarks against AWS, Azure,\nGCP, and Snowflake.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom iac infra/         # scan Terraform/CloudFormation/K8s\nagent-bom cloud aws          # AWS CIS benchmark\nagent-bom cloud azure        # Azure CIS benchmark\nagent-bom cloud gcp          # GCP CIS benchmark\nagent-bom secrets .          # find secrets in current directory\n```\n\n## When to Use\n\n- \"check terraform\" / \"scan terraform\"\n- \"scan kubernetes\" / \"K8s security\"\n- \"IaC\" / \"infrastructure as code\"\n- \"find secrets\" / \"secret scanning\"\n- \"scan dockerfile\"\n- \"cloud security\" / \"CIS benchmark\"\n- \"misconfigurations\"\n\n## Commands\n\n```bash\n# Scan IaC directory\nagent-bom iac infra/\n\n# Run cloud CIS benchmark\nagent-bom cloud aws\nagent-bom cloud azure\nagent-bom cloud gcp\nagent-bom cloud snowflake\n\n# Find secrets in files\nagent-bom secrets .\n```\n\n## Tools\n\n| Tool | Description |\n|------|-------------|\n| `iac` | Scan Terraform, CloudFormation, Kubernetes YAML for misconfigurations |\n| `cloud` | CIS benchmark checks (AWS, Azure v3.0, GCP v3.0, Snowflake) |\n| `secrets` | Find secrets and credentials in files and directories |\n\n## Examples\n\n```\n# Scan IaC directory for misconfigurations\niac(path=\"infra/\")\n\n# Run AWS CIS benchmark\ncloud(provider=\"aws\")\n\n# Find secrets in project\nsecrets(path=\".\")\n```\n\n## Guardrails\n\n- Confirm with the user before running cloud CIS benchmarks — these make live read-only API calls to AWS/Azure/GCP using the user's locally configured credentials.\n- IaC and secrets scanning is purely local — no network calls.\n- Do not modify any infrastructure files.\n- Ask the user before scanning paths outside their home or project directory.\n- Cloud credentials are used only to call the cloud provider's own APIs and are never transmitted elsewhere.\n\nFile v0.76.4:scan/SKILL.md\n\n---\nname: agent-bom-scan\ndescription: >-\n  Open security scanner for agentic infrastructure — agents, MCP, packages,\n  blast radius, runtime, and trust for package CVEs (OSV, NVD, EPSS,\n  KEV), container images, provenance, filesystems, and SBOMs. Use\n  when: \"check package\", \"scan image\", \"verify\", \"is this safe\",\n  \"scan dependencies\", \"CVE lookup\", \"blast radius\".\nversion: 0.76.4\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Native container image\n  scanning — no external scanner required. No API keys required for basic\n  operation.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.4\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Optional env vars below increase rate limits. They are never auto-discovered, inferred, or transmitted.\"\n    optional_env: []\n    optional_bins:\n      - semgrep\n      - kubectl\n    emoji: \"\\U0001F6E1\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Env var values are NEVER extracted from config files. sanitize_env_vars() replaces all env values with ***REDACTED*** BEFORE any config data is processed or stored. Only structural data (server names, commands, URLs) passes through. Source: https://github.com/msaad00/agent-bom/blob/main/src/agent_bom/security.py#L159\"\n    data_flow: \"All scanning is local-first. Only public package names and CVE IDs are sent to vulnerability databases (OSV, NVD, EPSS, GitHub Advisories). No credentials, config file contents, or scan results leave the machine.\"\n    file_reads:\n      # Claude Desktop\n      - \"~/Library/Application Support/Claude/claude_desktop_config.json\"\n      - \"~/.config/Claude/claude_desktop_config.json\"\n      # Claude Code\n      - \"~/.claude/settings.json\"\n      - \"~/.claude.json\"\n      # Cursor\n      - \"~/.cursor/mcp.json\"\n      - \"~/Library/Application Support/Cursor/User/globalStorage/cursor.mcp/mcp.json\"\n      # Windsurf\n      - \"~/.windsurf/mcp.json\"\n      # Cline\n      - \"~/Library/Application Support/Code/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.json\"\n      # VS Code Copilot\n      - \"~/Library/Application Support/Code/User/mcp.json\"\n      # Codex CLI\n      - \"~/.codex/config.toml\"\n      # Gemini CLI\n      - \"~/.gemini/settings.json\"\n      # Goose\n      - \"~/.config/goose/config.yaml\"\n      # Continue\n      - \"~/.continue/config.json\"\n      # Zed\n      - \"~/.config/zed/settings.json\"\n      # Roo Code\n      - \"~/Library/Application Support/Code/User/globalStorage/rooveterinaryinc.roo-cline/settings/cline_mcp_settings.json\"\n      # Amazon Q\n      - \"~/Library/Application Support/Code/User/globalStorage/amazonwebservices.amazon-q-vscode/mcp.json\"\n      # JetBrains AI\n      - \"~/Library/Application Support/JetBrains/*/mcp.json\"\n      - \"~/.config/github-copilot/intellij/mcp.json\"\n      # Junie\n      - \"~/.junie/mcp/mcp.json\"\n      # GitHub Copilot CLI\n      - \"~/.copilot/mcp-config.json\"\n      # Tabnine\n      - \"~/.tabnine/mcp_servers.json\"\n      # Cortex Code (Snowflake)\n      - \"~/.snowflake/cortex/mcp.json\"\n      - \"~/.snowflake/cortex/settings.json\"\n      - \"~/.snowflake/cortex/permissions.json\"\n      - \"~/.snowflake/cortex/hooks.json\"\n      # Snowflake CLI\n      - \"~/.snowflake/connections.toml\"\n      - \"~/.snowflake/config.toml\"\n      # Project-level configs\n      - \".mcp.json\"\n      - \".vscode/mcp.json\"\n      - \".cursor/mcp.json\"\n      # User-provided files\n      - \"user-provided SBOM files (CycloneDX/SPDX JSON)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://api.osv.dev/v1\"\n        purpose: \"OSV vulnerability database — batch CVE lookup for packages\"\n        auth: false\n      - url: \"https://services.nvd.nist.gov/rest/json/cves/2.0\"\n        purpose: \"NVD CVSS v4 enrichment — optional API key increases rate limit\"\n        auth: false\n      - url: \"https://api.first.org/data/v1/epss\"\n        purpose: \"EPSS exploit probability scores\"\n        auth: false\n      - url: \"https://api.github.com/advisories\"\n        purpose: \"GitHub Security Advisories — supplemental CVE lookup\"\n        auth: false\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-scan — AI Supply Chain Vulnerability Scanner\n\nChecks packages for CVEs, scans container images natively, verifies package\nprovenance via Sigstore, scans filesystems, and generates SBOMs.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom agents             # discover agents and scan dependencies\nagent-bom check langchain==0.1.0  # check a specific package with version\nagent-bom image nginx:1.25   # scan container image (native)\nagent-bom fs .               # scan filesystem packages\nagent-bom sbom .             # generate SBOM\nagent-bom verify agent-bom   # verify Sigstore provenance\nagent-bom where              # show all discovery paths\n```\n\n### As an MCP Server\n\n```json\n{\n  \"mcpServers\": {\n    \"agent-bom\": {\n      \"command\": \"uvx\",\n      \"args\": [\"agent-bom\", \"mcp\", \"server\"]\n    }\n  }\n}\n```\n\n## When to Use\n\n- \"check package\" / \"is this package safe\"\n- \"scan image\" / \"scan container\"\n- \"verify\" / \"check provenance\"\n- \"is this safe\" / \"CVE lookup\"\n- \"scan dependencies\"\n- \"blast radius\"\n- \"generate SBOM\"\n\n## Tools (8)\n\n| Tool | Description |\n|------|-------------|\n| `check` | Check a package for CVEs (OSV, NVD, EPSS, KEV) |\n| `scan` | Full discovery + vulnerability scan pipeline |\n| `blast_radius` | Map CVE impact chain across agents, servers, credentials |\n| `remediate` | Prioritized remediation plan for vulnerabilities |\n| `verify` | Package integrity + SLSA provenance check |\n| `diff` | Compare two scan reports (new/resolved/persistent) |\n| `where` | Show MCP client config discovery paths |\n| `inventory` | List discovered agents, servers, packages |\n\n## Examples\n\n```\n# Check a package before installing\ncheck(package=\"langchain\", version=\"0.1.0\", ecosystem=\"pypi\")\n\n# Map blast radius of a CVE\nblast_radius(cve_id=\"CVE-2024-21538\")\n\n# Full scan\nscan()\n\n# Verify package provenance\nverify(package=\"agent-bom\")\n```\n\n## Guardrails\n\n- Show CVEs even when NVD analysis is pending or severity is `unknown` — a CVE ID is still a real finding.\n- Treat `UNKNOWN` severity as unresolved, not benign — it means data is not yet available.\n- Do not modify any files, install packages, or change system configuration.\n- Only public package names and CVE IDs leave the machine for vulnerability database lookups.\n- Ask before scanning paths outside the user's home directory.\n\n## Privacy & Data Handling\n\n```bash\n# Step 1: Install\npip install agent-bom\n\n# Step 2: Review redaction logic BEFORE scanning\n# sanitize_env_vars() replaces ALL env var values with ***REDACTED***\n# BEFORE any config data is processed or stored:\n# https://github.com/msaad00/agent-bom/blob/main/src/agent_bom/security.py#L159\n\n# Step 3: Verify package provenance (Sigstore)\nagent-bom verify agent-bom\n\n# Step 4: Only then run scans\nagent-bom agents\n```\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **Sigstore signed**: `agent-bom verify agent-bom@0.76.4`\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.76.4:SKILL.md\n\n---\nname: agent-bom\ndescription: >-\n  Open security scanner for agentic infrastructure — agents, MCP, packages,\n  blast radius, runtime, and trust across MCP discovery, CVEs, SBOMs,\n  CIS benchmarks (AWS, Azure, GCP, Snowflake), OWASP/NIST/MITRE\n  compliance, AISVS v1.0, MAESTRO layer tagging, and vector database\n  security checks. Use when the user mentions vulnerability scanning,\n  MCP server trust, compliance, SBOM generation, CIS benchmarks, blast\n  radius, or AI supply chain risk.\nversion: 0.76.4\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. No credentials required for\n  basic scanning. Native container image scanning — no external scanner required.\n  CIS benchmark checks optionally use cloud SDK credentials\n  (AWS/Azure/GCP/Snowflake).\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.4\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: >-\n      Zero credentials required for CVE scanning, blast radius, compliance\n      evaluation, SBOM generation, and MCP registry lookups. Optional env vars\n      below increase rate limits or enable cloud CIS checks. Env var values in\n      discovered config files are replaced with ***REDACTED*** by\n      sanitize_env_vars() in the installed code — verify at\n      https://github.com/msaad00/agent-bom/blob/main/src/agent_bom/security.py#L159\n    optional_env:\n      - name: SNYK_TOKEN\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        required: false\n      - name: AWS_PROFILE\n        purpose: \"AWS CIS benchmark checks — uses boto3 with local AWS profile\"\n        required: false\n      - name: AZURE_TENANT_ID\n        purpose: \"Azure CIS benchmark checks (azure-mgmt-* SDK)\"\n        required: false\n      - name: AZURE_CLIENT_ID\n        purpose: \"Azure CIS benchmark checks — service principal client ID\"\n        required: false\n      - name: AZURE_CLIENT_SECRET\n        purpose: \"Azure CIS benchmark checks — service principal secret\"\n        required: false\n      - name: GOOGLE_APPLICATION_CREDENTIALS\n        purpose: \"GCP CIS benchmark checks (google-cloud-* SDK)\"\n        required: false\n      - name: SNOWFLAKE_ACCOUNT\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_USER\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_PRIVATE_KEY_PATH\n        purpose: \"Snowflake key-pair auth (CI/CD)\"\n        required: false\n      - name: SNOWFLAKE_AUTHENTICATOR\n        purpose: \"Snowflake auth method (default: externalbrowser SSO)\"\n        required: false\n    optional_bins:\n      - semgrep\n      - kubectl\n    emoji: \"\\U0001F6E1\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    install_verification: >-\n      VERIFY BEFORE running with any config files: (1) pip install agent-bom;\n      (2) Review sanitize_env_vars() at security.py#L159 — confirms env value\n      redaction; (3) Review discovery/__init__.py — confirms only structural\n      config data extracted; (4) agent-bom verify agent-bom — Sigstore\n      provenance check; (5) Only then run agent-bom agents\n    credential_handling: >-\n      Env var values are NEVER extracted from config files. sanitize_env_vars()\n      replaces all env values with ***REDACTED*** BEFORE any config data is\n      processed or stored. Only structural data (server names, commands, URLs)\n      passes through. Source:\n      https://github.com/msaad00/agent-bom/blob/main/src/agent_bom/security.py#L159\n    data_flow: >-\n      Scanning is local-first. What leaves the machine: (1) public package names\n      and CVE IDs sent to vulnerability databases (OSV, NVD, EPSS, GitHub\n      Advisories) for CVE lookup; (2) CIS benchmark checks make read-only API\n      calls to cloud providers (AWS/Azure/GCP/Snowflake) using your locally\n      configured credentials, only when explicitly invoked. What stays local:\n      all config file contents, env var values, credentials, scan results,\n      compliance tags, and SBOM data. Registry lookups (427+ MCP servers) are\n      bundled in-package with zero network calls. Env var values in discovered\n      config files are replaced with ***REDACTED*** by sanitize_env_vars() in\n      the installed code.\n    file_reads:\n      # Claude Desktop\n      - \"~/Library/Application Support/Claude/claude_desktop_config.json\"\n      - \"~/.config/Claude/claude_desktop_config.json\"\n      # Claude Code\n      - \"~/.claude/settings.json\"\n      - \"~/.claude.json\"\n      # Cursor\n      - \"~/.cursor/mcp.json\"\n      - \"~/Library/Application Support/Cursor/User/globalStorage/cursor.mcp/mcp.json\"\n      # Windsurf\n      - \"~/.windsurf/mcp.json\"\n      # Cline\n      - \"~/Library/Application Support/Code/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.json\"\n      # VS Code Copilot\n      - \"~/Library/Application Support/Code/User/mcp.json\"\n      # Codex CLI\n      - \"~/.codex/config.toml\"\n      # Gemini CLI\n      - \"~/.gemini/settings.json\"\n      # Goose\n      - \"~/.config/goose/config.yaml\"\n      # Continue\n      - \"~/.continue/config.json\"\n      # Zed\n      - \"~/.config/zed/settings.json\"\n      # Roo Code\n      - \"~/Library/Application Support/Code/User/globalStorage/rooveterinaryinc.roo-cline/settings/cline_mcp_settings.json\"\n      # Amazon Q\n      - \"~/Library/Application Support/Code/User/globalStorage/amazonwebservices.amazon-q-vscode/mcp.json\"\n      # JetBrains AI\n      - \"~/Library/Application Support/JetBrains/*/mcp.json\"\n      - \"~/.config/github-copilot/intellij/mcp.json\"\n      # Junie\n      - \"~/.junie/mcp/mcp.json\"\n      # GitHub Copilot CLI\n      - \"~/.copilot/mcp-config.json\"\n      # Tabnine\n      - \"~/.tabnine/mcp_servers.json\"\n      # Cortex Code (Snowflake)\n      - \"~/.snowflake/cortex/mcp.json\"\n      - \"~/.snowflake/cortex/settings.json\"\n      - \"~/.snowflake/cortex/permissions.json\"\n      - \"~/.snowflake/cortex/hooks.json\"\n      # Snowflake CLI\n      - \"~/.snowflake/connections.toml\"\n      - \"~/.snowflake/config.toml\"\n      # Project-level configs\n      - \".mcp.json\"\n      - \".vscode/mcp.json\"\n      - \".cursor/mcp.json\"\n      # User-provided files\n      - \"user-provided SBOM files (CycloneDX/SPDX JSON)\"\n      - \"user-provided policy files (YAML/JSON policy-as-code)\"\n      - \"user-provided audit log files (JSONL from agent-bom proxy)\"\n      - \"user-provided SKILL.md files (for skill_trust analysis)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://api.osv.dev/v1\"\n        purpose: \"OSV vulnerability database — batch CVE lookup for packages\"\n        auth: false\n      - url: \"https://services.nvd.nist.gov/rest/json/cves/2.0\"\n        purpose: \"NVD secondary enrichment — adds CWE IDs, dates, references (no key required)\"\n        auth: false\n      - url: \"https://api.first.org/data/v1/epss\"\n        purpose: \"EPSS exploit probability scores\"\n        auth: false\n      - url: \"https://api.github.com/advisories\"\n        purpose: \"GitHub Security Advisories — supplemental CVE lookup\"\n        auth: false\n      - url: \"https://api.snyk.io\"\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        auth: true\n      - url: \"https://*.amazonaws.com\"\n        purpose: \"AWS CIS benchmark checks — read-only API calls (optional, user-initiated)\"\n        auth: true\n        optional: true\n      - url: \"https://management.azure.com\"\n        purpose: \"Azure CIS benchmark checks — read-only API calls (optional, user-initiated)\"\n        auth: true\n        optional: true\n      - url: \"https://*.googleapis.com\"\n        purpose: \"GCP CIS benchmark checks — read-only API calls (optional, user-initiated)\"\n        auth: true\n        optional: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake CIS benchmark checks — read-only API calls (optional, user-initiated)\"\n        auth: true\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom — AI Agent Infrastructure Security Scanner\n\nDiscovers MCP clients and servers across 22 AI tools, scans for CVEs, maps\nblast radius, runs cloud CIS benchmarks, checks OWASP/NIST/MITRE compliance,\ngenerates SBOMs, and assesses AI infrastructure against AISVS v1.0 and MAESTRO\nframework layers.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom agents            # auto-discover + scan\nagent-bom check langchain==0.1.0  # check a specific package with version\nagent-bom fs .              # scan filesystem packages\nagent-bom image nginx:1.25  # scan container image (native)\nagent-bom cloud aws         # AWS CIS benchmark\nagent-bom iac infra/        # scan Terraform/CloudFormation\nagent-bom where             # show all discovery paths\n```\n\n### As an MCP Server\n\n```json\n{\n  \"mcpServers\": {\n    \"agent-bom\": {\n      \"command\": \"uvx\",\n      \"args\": [\"agent-bom\", \"mcp\", \"server\"]\n    }\n  }\n}\n```\n\n## Sub-Skills (8)\n\n| Sub-Skill | Purpose | Triggers |\n|-----------|---------|---------|\n| [discover](discover/SKILL.md) | Find agents, MCP servers, configurations | \"find agents\", \"what's configured\", \"mcp inventory\" |\n| [scan](scan/SKILL.md) | CVE scanning, image scanning, SBOM, provenance | \"check package\", \"scan image\", \"verify\", \"blast radius\" |\n| [scan-infra](scan-infra/SKILL.md) | IaC, cloud config, secrets scanning | \"check terraform\", \"scan kubernetes\", \"find secrets\" |\n| [enforce](enforce/SKILL.md) | Runtime policy enforcement, MCP proxy | \"block risky calls\", \"apply policy\", \"proxy\" |\n| [compliance](compliance/SKILL.md) | 14-framework compliance, SBOM generation | \"compliance report\", \"NIST\", \"SOC 2\", \"OWASP\" |\n| [monitor](monitor/SKILL.md) | Fleet monitoring, trust scores, lifecycle | \"fleet\", \"watch agents\", \"trust scores\" |\n| [analyze](analyze/SKILL.md) | Blast radius, attack paths, context graph | \"blast radius\", \"threat intel\", \"attack path\" |\n| [troubleshoot](troubleshoot/SKILL.md) | Diagnostics, doctor, config validation | \"doctor\", \"debug\", \"why failing\", \"validate config\" |\n\n## Tools\n\n### Vulnerability Scanning\n| Tool | Description |\n|------|-------------|\n| `scan` | Full discovery + vulnerability scan pipeline |\n| `check` | Check a package for CVEs (OSV, NVD, EPSS, KEV) |\n| `blast_radius` | Map CVE impact chain across agents, servers, credentials |\n| `remediate` | Prioritized remediation plan for vulnerabilities |\n| `verify` | Package integrity + SLSA provenance check |\n| `diff` | Compare two scan reports (new/resolved/persistent) |\n| `where` | Show MCP client config discovery paths |\n| `inventory` | List discovered agents, servers, packages |\n\n### Compliance & Policy\n| Tool | Description |\n|------|-------------|\n| `compliance` | OWASP LLM/Agentic Top 10, EU AI Act, MITRE ATLAS, NIST AI RMF |\n| `policy_check` | Evaluate results against custom security policy (17 conditions) |\n| `cis_benchmark` | CIS benchmark checks (AWS, Azure v3.0, GCP v3.0, Snowflake) |\n| `generate_sbom` | Generate SBOM (CycloneDX or SPDX format) |\n| `aisvs_benchmark` | OWASP AISVS v1.0 compliance — 9 AI security checks |\n\n### Registry & Trust\n| Tool | Description |\n|------|-------------|\n| `registry_lookup` | Look up MCP server in 427+ server security metadata registry |\n| `marketplace_check` | Pre-install trust check with registry cross-reference |\n| `fleet_scan` | Batch registry lookup + risk scoring for MCP server inventories |\n| `skill_scan` | Scan instruction files for package refs, trust, and findings |\n| `skill_verify` | Verify Sigstore provenance for instruction files |\n| `skill_trust` | Assess skill file trust level (5-category analysis) |\n| `code_scan` | SAST scanning via Semgrep with CWE-based compliance mapping |\n\n### Runtime & Analytics\n| Tool | Description |\n|------|-------------|\n| `context_graph` | Agent context graph with lateral movement analysis |\n| `analytics_query` | Query vulnerability trends, posture history, and runtime events |\n| `runtime_correlate` | Cross-reference proxy audit JSONL with CVE findings, risk amplification |\n| `vector_db_scan` | Probe Qdrant/Weaviate/Chroma/Milvus for auth and exposure |\n| `gpu_infra_scan` | GPU container and K8s node inventory + unauthenticated DCGM probe (MAESTRO KC6) |\n\n### Specialized Scans\n| Tool | Description |\n|------|-------------|\n| `dataset_card_scan` | Scan dataset cards for bias, licensing, and provenance issues |\n| `training_pipeline_scan` | Scan training pipeline configs for security risks |\n| `browser_extension_scan` | Scan browser extensions for risky permissions and AI domain access |\n| `model_provenance_scan` | Verify model provenance and supply chain integrity |\n| `prompt_scan` | Scan prompt templates for injection and data leakage risks |\n| `model_file_scan` | Scan model files for unsafe serialization (pickle, etc.) |\n| `license_compliance_scan` | Full SPDX license catalog scan with copyleft and network-copyleft detection |\n| `ingest_external_scan` | Import external scan results (CycloneDX/SPDX/JSON) and merge into agent-bom findings |\n\n### Resources\n| Resource | Description |\n|----------|-------------|\n| `registry://servers` | Browse 427+ MCP server security metadata registry |\n\n## Example Workflows\n\n```\n# Check a package before installing\ncheck(package=\"@modelcontextprotocol/server-filesystem\", ecosystem=\"npm\")\n\n# Map blast radius of a CVE\nblast_radius(cve_id=\"CVE-2024-21538\")\n\n# Full agent discovery + scan\nagents()\n\n# Run CIS benchmark\ncis_benchmark(provider=\"aws\")\n\n# Run AISVS v1.0 compliance\naisvs_benchmark()\n\n# Scan vector databases for auth misconfigurations\nvector_db_scan()\n\n# Discover GPU containers, K8s GPU nodes, and unauthenticated DCGM endpoints\ngpu_infra_scan()\n\n# Scan instruction files and then inspect trust\nskill_scan(path=\".\")\nskill_trust(skill_path=\"./SKILL.md\")\n```\n\n## Guardrails\n\n**Always do:**\n- Show CVEs even when NVD analysis is pending or severity is `unknown` — a CVE ID with no details is still a real finding. Report what is known; mark severity as `unknown` explicitly.\n- Confirm with the user before scanning cloud environments (`cis_benchmark`) — these make live API calls to AWS/Azure/GCP using the user's credentials.\n- Treat `UNKNOWN` severity as unresolved, not benign — it means data is not yet available, not that the issue is minor.\n\n**Never do:**\n- Do not modify any files, install packages, or change system configuration. This skill is read-only.\n- Do not transmit env var values, credentials, or file contents to any external service. Only package names and CVE IDs leave the machine.\n- Do not invoke `agents()` autonomously on sensitive environments without user confirmation. The `autonomous_invocation` policy is `restricted`.\n\n**Stop and ask the user when:**\n- The user requests a cloud CIS benchmark and no cloud credentials are configured.\n- A scan finds `CRITICAL` CVEs — present findings and ask whether to generate a remediation plan.\n- The user asks to scan a path outside their home directory.\n\n## Supported Frameworks (14)\n\n- **OWASP LLM Top 10** (2025) — prompt injection, supply chain, data leakage\n- **OWASP MCP Top 10** — MCP-specific security risks\n- **OWASP Agentic Top 10** — tool poisoning, rug pulls, credential theft\n- **OWASP AISVS v1.0** — AI Security Verification Standard (9 checks)\n- **MITRE ATLAS** — adversarial ML threat framework\n- **NIST AI RMF** — govern, map, measure, manage lifecycle\n- **NIST CSF 2.0** — identify, protect, detect, respond, recover\n- **NIST 800-53 Rev 5** — federal security controls (CM-8, RA-5, SI-2, SR-3)\n- **FedRAMP Moderate** — derived from NIST 800-53 controls\n- **EU AI Act** — risk classification, transparency, SBOM requirements\n- **ISO 27001:2022** — information security controls (Annex A)\n- **SOC 2** — Trust Services Criteria\n- **CIS Controls v8** — implementation groups IG1/IG2/IG3\n- **CMMC 2.0** — cybersecurity maturity model (Level 1-3)\n\n## Privacy & Data Handling\n\nThis skill installs agent-bom from PyPI. **Verify the redaction behavior\nbefore running with any config files:**\n\n```bash\n# Step 1: Install\npip install agent-bom\n\n# Step 2: Review redaction logic BEFORE scanning\n# sanitize_env_vars() replaces ALL env var values with ***REDACTED***\n# BEFORE any config data is processed or stored:\n# https://github.com/msaad00/agent-bom/blob/main/src/agent_bom/security.py#L159\n\n# Step 3: Review config parsing — only structural data extracted:\n# https://github.com/msaad00/agent-bom/blob/main/src/agent_bom/discovery/__init__.py\n\n# Step 4: Verify package provenance (Sigstore)\nagent-bom verify agent-bom\n\n# Step 5: Only then run scans\nagent-bom agents\n```\n\n**What is extracted**: Server names, commands, args, and URLs from MCP client\nconfig files across 22 AI tools. **What is NOT extracted**: Env var values are\nreplaced with `***REDACTED***` by `sanitize_env_vars()` before any processing.\nOnly public package names and CVE IDs are sent to vulnerability databases.\nCloud CIS checks use locally configured credentials and call only the cloud\nprovider's own APIs.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **Sigstore signed**: `agent-bom verify agent-bom@0.76.4`\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.76.4:troubleshoot/SKILL.md\n\n---\nname: agent-bom-troubleshoot\ndescription: >-\n  Diagnose issues, check prerequisites, and validate configurations. Use when:\n  \"doctor\", \"debug\", \"why failing\", \"validate config\", \"check prerequisites\",\n  \"something is broken\", \"db status\", \"fix my setup\".\nversion: 0.76.4\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. No credentials required.\n  Doctor checks run locally against the installed environment.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.4\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. All diagnostic checks run locally against the installed environment. No data leaves the machine.\"\n    optional_env: []\n    optional_bins: []\n    emoji: \"\\U0001F527\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Purely local. Doctor checks inspect installed packages, config files, and environment settings. No data leaves the machine.\"\n    file_reads:\n      - \"local agent-bom configuration and state files\"\n    file_writes: []\n    network_endpoints: []\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-troubleshoot — Diagnostics & Configuration Validator\n\nDiagnoses issues, checks prerequisites, validates configurations, and reports\non the health of the agent-bom installation and connected database.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom doctor             # check prerequisites and installation health\nagent-bom validate           # validate configuration files\nagent-bom db status          # check database connection status\n```\n\n## When to Use\n\n- \"doctor\" / \"run doctor\"\n- \"debug\" / \"help me debug\"\n- \"why failing\" / \"something's broken\"\n- \"validate config\" / \"check configuration\"\n- \"check prerequisites\"\n- \"db status\" / \"database status\"\n- \"fix my setup\"\n\n## Commands\n\n```bash\n# Run full diagnostic check\nagent-bom doctor\n\n# Validate configuration\nagent-bom validate\n\n# Check database status\nagent-bom db status\n```\n\n## Examples\n\n```\n# Run diagnostics\ndoctor()\n\n# Validate config\nvalidate()\n\n# Check DB\ndb_status()\n```\n\n**Example doctor output:**\n```\nagent-bom doctor\n\n  Python        3.12.2   OK\n  agent-bom     0.75.9   OK\n  pip           24.0     OK\n  semgrep       not found  (optional — SAST scanning unavailable)\n  kubectl       not found  (optional — K8s context unavailable)\n\n  Config files found:\n    Claude Desktop  ~/.config/Claude/claude_desktop_config.json  OK\n    Cursor          ~/.cursor/mcp.json                           OK\n\n  Database:      SQLite  ~/.agent-bom/db.sqlite  OK\n  Last scan:     2 hours ago\n\n  Status: Ready\n```\n\n## Guardrails\n\n- Diagnostics are read-only — no configuration files are modified.\n- Doctor checks do not transmit any data externally.\n- If the user is experiencing an error, show the full diagnostic output before suggesting fixes.\n- Validate configuration files before recommending changes.\n\nFile v0.76.4:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom\",\n  \"version\": \"0.76.4\",\n  \"publishedAt\": 1776058958812\n}\n\nArchive v0.76.2: 12 files, 26825 bytes\n\nFiles: analyze/SKILL.md (4208b), compliance/SKILL.md (7524b), discover/SKILL.md (5608b), enforce/SKILL.md (3725b), monitor/SKILL.md (3619b), registry/SKILL.md (4109b), runtime/SKILL.md (2993b), scan-infra/SKILL.md (5922b), scan/SKILL.md (7773b), SKILL.md (17813b), troubleshoot/SKILL.md (3461b), _meta.json (129b)\n\nFile v0.76.2:analyze/SKILL.md\n\n---\nname: agent-bom-analyze\ndescription: >-\n  Analyze blast radius, attack paths, and threat landscape across your AI\n  infrastructure. Use when: \"blast radius\", \"threat intel\", \"risk score\",\n  \"attack path\", \"lateral movement\", \"context graph\", \"who can reach what\".\nversion: 0.76.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. No credentials required for\n  blast radius and context graph analysis. Threat intelligence lookups query\n  EPSS and CVE databases.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.2\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Blast radius and context graph analysis operate on local scan data. EPSS and CVE lookups send only public CVE IDs — no internal data.\"\n    optional_env: []\n    optional_bins: []\n    emoji: \"\\U0001F4A5\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Blast radius and context graph analysis operate on local scan results in memory. Only public CVE IDs are sent to EPSS and vulnerability databases for threat intelligence enrichment. No internal config data, credentials, or scan results leave the machine.\"\n    file_reads: []\n    file_writes: []\n    network_endpoints:\n      - url: \"https://api.first.org/data/v1/epss\"\n        purpose: \"EPSS exploit probability scores for CVEs found in scan\"\n        auth: false\n      - url: \"https://api.osv.dev/v1\"\n        purpose: \"OSV vulnerability database — CVE detail lookup\"\n        auth: false\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-analyze — Blast Radius & Attack Path Analysis\n\nAnalyzes blast radius, attack paths, and the threat landscape across your AI\ninfrastructure. Maps lateral movement risks, identifies high-impact CVEs, and\nvisualizes agent context graphs.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom agents --verbose   # blast radius detail for each agent\nagent-bom graph              # generate context graph\n```\n\n## When to Use\n\n- \"blast radius\" / \"what's the blast radius\"\n- \"threat intel\" / \"threat intelligence\"\n- \"risk score\" / \"risk scoring\"\n- \"attack path\" / \"attack paths\"\n- \"lateral movement\"\n- \"context graph\" / \"agent graph\"\n- \"who can reach what\"\n\n## Commands\n\n```bash\n# Blast radius detail (verbose)\nagent-bom agents --verbose\n\n# Generate context graph\nagent-bom graph\n```\n\n## Tools\n\n| Tool | Description |\n|------|-------------|\n| `blast_radius` | Map CVE impact chain across agents, servers, and credentials |\n| `context_graph` | Agent context graph with lateral movement analysis |\n| `analytics_query` | Query vulnerability trends, posture history, and risk scores |\n\n## Examples\n\n```\n# Map blast radius of a specific CVE\nblast_radius(cve_id=\"CVE-2024-21538\")\n\n# Build full context graph\ncontext_graph()\n\n# Query top CVEs by blast radius impact\nanalytics_query(query=\"top_blast_radius\", days=30)\n```\n\n**Example blast radius output:**\n```\nCVE-2024-21538 — CRITICAL (CVSS 9.8, EPSS 0.94)\nBlast Radius: 4 agents affected\n\n  filesystem   [direct]  langchain 0.1.0 → CVE-2024-21538\n    └─ github  [indirect] shares filesystem credential scope\n    └─ slack   [indirect] accessible via filesystem tool call\n  postgres     [direct]  langchain 0.1.0 → CVE-2024-21538\n\nRecommended: Update langchain to ≥ 0.1.17\n```\n\n## Guardrails\n\n- Analysis is read-only — no files are modified.\n- Only public CVE IDs are sent externally (to EPSS and vulnerability databases).\n- No internal config data, credentials, or agent details leave the machine.\n- Present blast radius findings clearly and ask the user whether to generate a remediation plan when CRITICAL CVEs are found.\n\nFile v0.76.2:compliance/SKILL.md\n\n---\nname: agent-bom-compliance\ndescription: >-\n  AI compliance and policy engine — evaluate scan results against OWASP, NIST,\n  SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.\n  Generate SBOMs and compliance reports. Use when:\n  \"compliance report\", \"NIST\", \"SOC 2\", \"ISO 27001\", \"OWASP\", \"EU AI Act\",\n  \"AISVS\", \"generate SBOM\", \"policy check\".\nversion: 0.76.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. OWASP/NIST/EU AI Act/MITRE\n  evaluation and SBOM generation are fully local with zero credentials. CIS\n  benchmark checks optionally use cloud SDK credentials (AWS/Azure/GCP/Snowflake)\n  and make read-only API calls to cloud providers when explicitly invoked.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.2\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required for OWASP/NIST/EU AI Act compliance and SBOM generation. CIS benchmark checks (AWS, Azure, GCP, Snowflake) optionally accept cloud credentials — only used locally to call cloud APIs, never transmitted elsewhere.\"\n    optional_env:\n      - name: AWS_PROFILE\n        purpose: \"AWS CIS benchmark checks — uses boto3 with your local AWS profile\"\n        required: false\n      - name: AZURE_TENANT_ID\n        purpose: \"Azure CIS benchmark checks (azure-mgmt-* SDK)\"\n        required: false\n      - name: AZURE_CLIENT_ID\n        purpose: \"Azure CIS benchmark checks — service principal client ID\"\n        required: false\n      - name: AZURE_CLIENT_SECRET\n        purpose: \"Azure CIS benchmark checks — service principal secret\"\n        required: false\n      - name: GOOGLE_APPLICATION_CREDENTIALS\n        purpose: \"GCP CIS benchmark checks (google-cloud-* SDK)\"\n        required: false\n      - name: SNOWFLAKE_ACCOUNT\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_USER\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_PRIVATE_KEY_PATH\n        purpose: \"Snowflake key-pair auth (CI/CD)\"\n        required: false\n      - name: SNOWFLAKE_AUTHENTICATOR\n        purpose: \"Snowflake auth method (default: externalbrowser SSO)\"\n        required: false\n    optional_bins: []\n    emoji: \"\\U00002705\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: >-\n      OWASP/NIST/EU AI Act/MITRE/SBOM evaluation is purely local — zero network\n      calls. CIS benchmark checks (optional, user-initiated) call cloud provider\n      APIs (AWS/Azure/GCP/Snowflake) using locally configured credentials. No data\n      is stored or transmitted beyond the cloud provider's own API. File reads are\n      limited to user-provided SBOMs and policy files.\n    file_reads:\n      - \"user-provided SBOM files (CycloneDX/SPDX JSON)\"\n      - \"user-provided policy files (YAML/JSON policy-as-code)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://*.amazonaws.com\"\n        purpose: \"AWS CIS benchmark checks — read-only API calls (IAM, S3, CloudTrail, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://management.azure.com\"\n        purpose: \"Azure CIS benchmark checks — read-only API calls (Azure Resource Manager)\"\n        auth: true\n        optional: true\n      - url: \"https://*.googleapis.com\"\n        purpose: \"GCP CIS benchmark checks — read-only API calls (Cloud Resource Manager, IAM, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake CIS benchmark checks — read-only API calls (ACCOUNT_USAGE views)\"\n        auth: true\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-compliance — AI Compliance & Policy Engine\n\nEvaluate AI infrastructure scan results against 14 security and regulatory\nframeworks. Enforce policy-as-code rules. Generate SBOMs in standard formats.\nRun AISVS v1.0 and CIS benchmark checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom agents -f compliance-export  # run agents scan with compliance export\nagent-bom generate-sbom                # generate CycloneDX SBOM\n```\n\n## When to Use\n\n- \"compliance report\" / \"run compliance\"\n- \"NIST\" / \"NIST AI RMF\" / \"NIST CSF\" / \"NIST 800-53\"\n- \"SOC 2\" / \"SOC2\"\n- \"ISO 27001\"\n- \"OWASP\" / \"OWASP LLM Top 10\" / \"OWASP Agentic Top 10\"\n- \"EU AI Act\"\n- \"AISVS\" / \"AI Security Verification Standard\"\n- \"CMMC\" / \"FedRAMP\"\n- \"generate SBOM\" / \"CycloneDX\" / \"SPDX\"\n- \"policy check\" / \"policy enforcement\"\n\n## Tools (5)\n\n| Tool | Description |\n|------|-------------|\n| `compliance` | OWASP LLM/Agentic Top 10, EU AI Act, MITRE ATLAS, NIST AI RMF |\n| `policy_check` | Evaluate results against custom security policy (17 conditions) |\n| `cis_benchmark` | Run CIS benchmark checks against cloud accounts |\n| `generate_sbom` | Generate SBOM (CycloneDX or SPDX format) |\n| `aisvs_benchmark` | OWASP AISVS v1.0 compliance — 9 AI security checks |\n\n## Supported Frameworks (14)\n\n- **OWASP LLM Top 10** (2025) — prompt injection, supply chain, data leakage\n- **OWASP MCP Top 10** — MCP-specific security risks\n- **OWASP Agentic Top 10** — tool poisoning, rug pulls, credential theft\n- **OWASP AISVS v1.0** — AI Security Verification Standard (9 checks)\n- **MITRE ATLAS** — adversarial ML threat framework\n- **NIST AI RMF** — govern, map, measure, manage lifecycle\n- **NIST CSF 2.0** — identify, protect, detect, respond, recover\n- **NIST 800-53 Rev 5** — federal security controls (CM-8, RA-5, SI-2, SR-3)\n- **FedRAMP Moderate** — derived from NIST 800-53 controls\n- **EU AI Act** — risk classification, transparency, SBOM requirements\n- **ISO 27001:2022** — information security controls (Annex A)\n- **SOC 2** — Trust Services Criteria\n- **CIS Controls v8** — implementation groups IG1/IG2/IG3\n- **CMMC 2.0** — cybersecurity maturity model (Level 1-3)\n\n## Examples\n\n```\n# Run compliance check against multiple frameworks\ncompliance(frameworks=[\"owasp_llm\", \"eu_ai_act\", \"nist_ai_rmf\"])\n\n# Enforce custom policy\npolicy_check(policy={\"max_critical\": 0, \"max_high\": 5})\n\n# Generate SBOM\ngenerate_sbom(format=\"cyclonedx\")\n\n# Run AISVS v1.0 compliance\naisvs_benchmark()\n\n# Run AWS CIS benchmark\ncis_benchmark(provider=\"aws\")\n```\n\n## Privacy & Data Handling\n\n**OWASP, NIST, EU AI Act, MITRE ATLAS, AISVS, SBOM generation, and policy\nchecks** run entirely locally on scan data already in memory. No network calls,\nno credentials needed for these features.\n\n**CIS benchmark checks** (optional, user-initiated) call cloud provider APIs\nusing your locally configured credentials. These are read-only API calls to\nAWS, Azure, GCP, or Snowflake. You must explicitly run `cis_benchmark(provider=...)`\nand confirm before any cloud API calls are made.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.76.2:discover/SKILL.md\n\n---\nname: agent-bom-discover\ndescription: >-\n  Discover AI agents, MCP servers, and configurations on this machine or\n  environment. Use when: \"find agents\", \"what's configured\", \"doctor\",\n  \"what MCP servers\", \"show me what's installed\", \"mcp inventory\".\nversion: 0.76.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. No credentials required.\n  Registry data (427+ MCP servers) is bundled in-package with zero network calls.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.2\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Discovery reads only structural config data (server names, commands, args, URLs). Env var values are replaced with ***REDACTED*** by sanitize_env_vars() before any processing.\"\n    optional_env: []\n    optional_bins: []\n    emoji: \"\\U0001F50E\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Env var values are NEVER extracted from config files. sanitize_env_vars() replaces all env values with ***REDACTED*** BEFORE any config data is processed or stored. Source: https://github.com/msaad00/agent-bom/blob/main/src/agent_bom/security.py#L159\"\n    data_flow: \"Purely local. Reads MCP client config files across 22+ AI tools. Only structural data (server names, commands, URLs) is extracted. Env var values are redacted before processing. No data leaves the machine.\"\n    file_reads:\n      # Claude Desktop\n      - \"~/Library/Application Support/Claude/claude_desktop_config.json\"\n      - \"~/.config/Claude/claude_desktop_config.json\"\n      # Claude Code\n      - \"~/.claude/settings.json\"\n      - \"~/.claude.json\"\n      # Cursor\n      - \"~/.cursor/mcp.json\"\n      - \"~/Library/Application Support/Cursor/User/globalStorage/cursor.mcp/mcp.json\"\n      # Windsurf\n      - \"~/.windsurf/mcp.json\"\n      # Cline\n      - \"~/Library/Application Support/Code/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.json\"\n      # VS Code Copilot\n      - \"~/Library/Application Support/Code/User/mcp.json\"\n      # Codex CLI\n      - \"~/.codex/config.toml\"\n      # Gemini CLI\n      - \"~/.gemini/settings.json\"\n      # Goose\n      - \"~/.config/goose/config.yaml\"\n      # Continue\n      - \"~/.continue/config.json\"\n      # Zed\n      - \"~/.config/zed/settings.json\"\n      # Roo Code\n      - \"~/Library/Application Support/Code/User/globalStorage/rooveterinaryinc.roo-cline/settings/cline_mcp_settings.json\"\n      # Amazon Q\n      - \"~/Library/Application Support/Code/User/globalStorage/amazonwebservices.amazon-q-vscode/mcp.json\"\n      # JetBrains AI\n      - \"~/Library/Application Support/JetBrains/*/mcp.json\"\n      - \"~/.config/github-copilot/intellij/mcp.json\"\n      # Junie\n      - \"~/.junie/mcp/mcp.json\"\n      # GitHub Copilot CLI\n      - \"~/.copilot/mcp-config.json\"\n      # Tabnine\n      - \"~/.tabnine/mcp_servers.json\"\n      # Cortex Code (Snowflake)\n      - \"~/.snowflake/cortex/mcp.json\"\n      - \"~/.snowflake/cortex/settings.json\"\n      # Snowflake CLI\n      - \"~/.snowflake/connections.toml\"\n      - \"~/.snowflake/config.toml\"\n      # Project-level configs\n      - \".mcp.json\"\n      - \".vscode/mcp.json\"\n      - \".cursor/mcp.json\"\n    file_writes: []\n    network_endpoints: []\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover — AI Agent & MCP Server Discovery\n\nDiscovers AI agents, MCP servers, and their configurations across 22+ AI tools\non this machine. Shows what's installed, configured, and registered in the\nbundled 427+ MCP server registry.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom agents             # discover all AI agents and MCP servers\nagent-bom doctor             # check prerequisites and configuration health\nagent-bom mcp inventory      # list all discovered MCP servers\nagent-bom where              # show all discovery paths\n```\n\n## When to Use\n\n- \"find agents\" / \"what agents are configured\"\n- \"what MCP servers do I have\"\n- \"what's configured on this machine\"\n- \"mcp inventory\"\n- \"doctor\" / \"check my setup\"\n- \"show me what's installed\"\n\n## Commands\n\n```bash\n# Discover all AI agents and MCP servers\nagent-bom agents\n\n# Check configuration health and prerequisites\nagent-bom doctor\n\n# List MCP server inventory\nagent-bom mcp inventory\n\n# Show all discovery paths\nagent-bom where\n```\n\n## Examples\n\n```\n# Discover all agents\nagents()\n\n# Run health check\ndoctor()\n\n# List MCP inventory\ninventory()\n```\n\n**Example output:**\n```\nDiscovered 3 MCP clients:\n  Claude Desktop  — 4 servers configured\n  Cursor          — 2 servers configured\n  VS Code         — 1 server configured\n\nServers: filesystem, brave-search, github, slack, postgres, linear, notion\nRegistry: 5/7 servers found in registry (427+ entries)\n```\n\n## Guardrails\n\n- Discovery is read-only — no files are modified, no packages installed.\n- Env var values in config files are always replaced with `***REDACTED***` before processing.\n- Only structural data (server names, commands, URLs) is extracted.\n- Confirm with user before scanning paths outside the home directory.\n\nFile v0.76.2:enforce/SKILL.md\n\n---\nname: agent-bom-enforce\ndescription: >-\n  Enforce security policies on MCP tool calls and block dangerous operations at\n  runtime. Use when: \"block risky calls\", \"apply policy\", \"proxy\",\n  \"runtime protection\", \"policy enforcement\", \"intercept MCP calls\".\nversion: 0.76.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. No credentials required.\n  Policy files are user-provided YAML/JSON. Proxy runs locally.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.2\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Policy evaluation is local. Proxy operates on local network only. Policy files are user-provided and never transmitted.\"\n    optional_env: []\n    optional_bins: []\n    emoji: \"\\U0001F6AB\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Purely local. Policy evaluation runs on scan results in memory. Proxy intercepts MCP calls on local network only. Audit logs are written locally (JSONL). No data leaves the machine.\"\n    file_reads:\n      - \"user-provided policy files (YAML/JSON policy-as-code)\"\n      - \"user-provided audit log files (JSONL from agent-bom proxy)\"\n    file_writes:\n      - \"proxy-audit.jsonl (local audit log, only when proxy is running)\"\n    network_endpoints: []\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n    disable-model-invocation: true\n---\n\n# agent-bom-enforce — Runtime Policy Enforcement\n\nEnforces security policies on MCP tool calls and blocks dangerous operations\nat runtime. Runs a local proxy that intercepts MCP calls and evaluates them\nagainst policy-as-code rules.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom proxy              # start enforcement proxy\nagent-bom policy apply policy.yaml  # apply a policy file\nagent-bom policy check       # check current policy status\n```\n\n## When to Use\n\n- \"block risky calls\" / \"block dangerous MCP calls\"\n- \"apply policy\" / \"enforce policy\"\n- \"proxy\" / \"MCP proxy\"\n- \"runtime protection\"\n- \"policy enforcement\"\n- \"intercept MCP calls\"\n\n## Commands\n\n```bash\n# Start the enforcement proxy\nagent-bom proxy\n\n# Apply a policy file\nagent-bom policy apply policy.yaml\n\n# Check current policy status\nagent-bom policy check\n```\n\n## Example Policy File\n\n```yaml\n# policy.yaml\nrules:\n  - id: block-shell-exec\n    description: Block shell execution tool calls\n    match:\n      tool: \"bash|shell|exec|run_command\"\n    action: block\n    severity: critical\n\n  - id: require-path-allowlist\n    description: Restrict filesystem access to allowed paths\n    match:\n      tool: \"read_file|write_file|list_directory\"\n      args.path:\n        not_starts_with: [\"/home/\", \"/tmp/\"]\n    action: block\n    severity: high\n```\n\n## Guardrails\n\n- IMPORTANT: Do not start the proxy or apply policies without explicit user confirmation — enforcement changes how MCP calls are processed.\n- Confirm the policy file contents with the user before applying.\n- Do not enable proxy mode autonomously — always ask the user first.\n- Audit logs are written locally only; no data is transmitted externally.\n- This skill has `disable-model-invocation: true` — do not auto-run enforcement actions.\n\nFile v0.76.2:monitor/SKILL.md\n\n---\nname: agent-bom-monitor\ndescription: >-\n  Monitor agent fleet, track trust scores, and manage lifecycle states. Use\n  when: \"fleet\", \"watch agents\", \"runtime status\", \"trust scores\",\n  \"fleet sync\", \"agent lifecycle\", \"serve dashboard\".\nversion: 0.76.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. No credentials required for\n  fleet listing and trust score tracking. Optional server dashboard available\n  via agent-bom serve.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.2\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required for fleet listing and trust score tracking. Fleet sync reads local scan state. Dashboard server (agent-bom serve) runs on localhost only.\"\n    optional_env: []\n    optional_bins: []\n    emoji: \"\\U0001F4CA\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Purely local. Fleet data is read from local scan state. Dashboard server (agent-bom serve) runs on localhost and exposes no data externally. No data leaves the machine.\"\n    file_reads:\n      - \"local scan state and fleet registry (managed by agent-bom)\"\n    file_writes: []\n    network_endpoints: []\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-monitor — Agent Fleet Monitor\n\nMonitor agent fleet health, track trust scores, and manage agent lifecycle\nstates across your AI infrastructure. Start a local dashboard server for\ncontinuous monitoring.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom fleet sync         # sync fleet state with latest scan\nagent-bom fleet list         # list all agents and trust scores\nagent-bom serve              # start local monitoring dashboard\n```\n\n## When to Use\n\n- \"fleet\" / \"agent fleet\"\n- \"watch agents\" / \"monitor agents\"\n- \"runtime status\"\n- \"trust scores\"\n- \"fleet sync\"\n- \"agent lifecycle\"\n- \"serve dashboard\" / \"start dashboard\"\n\n## Commands\n\n```bash\n# Sync fleet state with latest scan\nagent-bom fleet sync\n\n# List all agents with trust scores\nagent-bom fleet list\n\n# Start local monitoring dashboard\nagent-bom serve\n```\n\n## Examples\n\n```\n# Sync fleet\nfleet_sync()\n\n# List agents and trust scores\nfleet_list()\n\n# Start dashboard server\nserve()\n```\n\n**Example fleet list output:**\n```\nAgent Fleet — 7 agents tracked\n  filesystem   trust: 92  status: healthy   last-scan: 2m ago\n  brave-search trust: 88  status: healthy   last-scan: 2m ago\n  github       trust: 95  status: healthy   last-scan: 2m ago\n  slack        trust: 71  status: warning   last-scan: 2m ago  [2 CVEs]\n  postgres     trust: 84  status: healthy   last-scan: 2m ago\n  linear       trust: 90  status: healthy   last-scan: 2m ago\n  notion       trust: 67  status: at-risk   last-scan: 2m ago  [CRITICAL]\n```\n\n## Guardrails\n\n- Fleet monitoring is read-only — no agents are modified.\n- The dashboard server runs on localhost only — no external exposure.\n- Confirm with the user before starting `agent-bom serve` — it binds a local port.\n- Trust scores are derived from local scan data; they do not contact external services.\n\nFile v0.76.2:registry/SKILL.md\n\n---\nname: agent-bom-registry\ndescription: >-\n  MCP server security registry and trust assessment — look up servers in the 427+\n  server security metadata registry, run pre-install marketplace checks, batch\n  fleet risk scoring, assess skill file trust, and run SAST code scans. Use when\n  the user mentions MCP server trust, registry lookup, marketplace check, or\n  skill trust assessment.\nversion: 0.76.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: Semgrep for SAST\n  code scanning. No API keys or network access required (registry is bundled).\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Registry data is bundled locally. No network calls needed.\"\n    optional_env:\n      - name: SNYK_TOKEN\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        required: false\n    optional_bins:\n      - semgrep\n    emoji: \"\\U0001F50D\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Purely local. Registry data (427+ MCP server metadata) is bundled in the package. Lookups are in-memory string matches. Skill trust analysis parses user-provided SKILL.md content passed as a string argument.\"\n    file_reads:\n      - \"user-provided SKILL.md files (for skill_trust analysis)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://api.snyk.io\"\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-registry — MCP Server Trust & Security Registry\n\nLook up MCP servers in the 427+ server security metadata registry, assess skill\nfile trust, and run pre-install marketplace checks.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom registry-lookup brave-search\nagent-bom marketplace-check @anthropic/server-filesystem\n```\n\n## Tools (7)\n\n| Tool | Description |\n|------|-------------|\n| `registry_lookup` | Look up MCP server in 427+ server security metadata registry |\n| `marketplace_check` | Pre-install trust check with registry cross-reference |\n| `fleet_scan` | Batch registry lookup + risk scoring for MCP server inventories |\n| `skill_scan` | Scan instruction files for package refs, trust, and findings |\n| `skill_verify` | Verify Sigstore provenance for instruction files |\n| `skill_trust` | Assess skill file trust level (5-category analysis) |\n| `code_scan` | SAST scanning via Semgrep with CWE-based compliance mapping |\n\n## Example Workflows\n\n```\n# Look up a server in the registry\nregistry_lookup(server_name=\"brave-search\")\n\n# Pre-install trust check\nmarketplace_check(package=\"@modelcontextprotocol/server-filesystem\")\n\n# Scan instruction files and then assess a specific skill file\nskill_scan(path=\".\")\nskill_trust(skill_path=\"./SKILL.md\")\n\n# Batch risk scoring\nfleet_scan(servers=[\"brave-search\", \"github\", \"slack\"])\n```\n\n## MCP Resources\n\n| Resource | Description |\n|----------|-------------|\n| `registry://servers` | Browse 427+ MCP server security metadata registry |\n\n## Privacy & Data Handling\n\nRegistry data is **bundled in the package** — lookups are in-memory string\nmatches with zero network calls. Skill trust analysis parses content passed\nas a string argument (no file system access needed).\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.76.2:runtime/SKILL.md\n\n---\nname: agent-bom-runtime\ndescription: >-\n  AI runtime security monitoring — context graph analysis, runtime audit log\n  correlation with CVE findings, and vulnerability analytics queries. Use when\n  the user mentions runtime monitoring, context graphs, lateral movement analysis,\n  audit log correlation, or vulnerability analytics.\nversion: 0.76.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: kubectl for\n  Kubernetes context, ClickHouse for analytics storage. No API keys required.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Optional ClickHouse URL enables analytics storage. Never auto-discovered or inferred.\"\n    optional_env: []\n    optional_bins:\n      - kubectl\n    emoji: \"\\U0001F4CA\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Operates on scan results in memory and user-provided audit log files. Optional ClickHouse connection for persistent analytics (user-configured, not auto-discovered).\"\n    file_reads:\n      - \"user-provided audit log files (JSONL format from agent-bom proxy)\"\n    file_writes: []\n    network_endpoints: []\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-runtime — AI Runtime Security Monitoring\n\nContext graph analysis, runtime audit log correlation with CVE findings, and\nvulnerability analytics queries.\n\n## Install\n\n```bash\npipx install agent-bom\n```\n\n## Tools (3)\n\n| Tool | Description |\n|------|-------------|\n| `context_graph` | Agent context graph with lateral movement analysis |\n| `analytics_query` | Query vulnerability trends, posture history, and runtime events |\n| `runtime_correlate` | Cross-reference runtime audit logs with CVE findings |\n\n## Example Workflows\n\n```\n# Build context graph from scan results\ncontext_graph()\n\n# Correlate runtime audit with CVE data\nruntime_correlate(audit_file=\"proxy-audit.jsonl\")\n\n# Query analytics\nanalytics_query(query=\"top_cves\", days=30)\n```\n\n## Privacy & Data Handling\n\nOperates on scan results already in memory and user-provided audit log files.\nNo automatic file discovery. No network calls unless you configure an optional\nClickHouse endpoint for persistent analytics.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.76.2:scan-infra/SKILL.md\n\n---\nname: agent-bom-scan-infra\ndescription: >-\n  Scan infrastructure-as-code, cloud configurations, and find secrets. Use when:\n  \"check terraform\", \"scan kubernetes\", \"IaC\", \"find secrets\",\n  \"scan dockerfile\", \"cloud security\", \"misconfigurations\".\nversion: 0.76.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Optional: kubectl for\n  Kubernetes checks. Cloud checks use locally configured credentials\n  (AWS/Azure/GCP/Snowflake) when explicitly invoked.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.2\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required for IaC and secrets scanning. Cloud checks (AWS/Azure/GCP/Snowflake) optionally accept cloud credentials — only used locally to call cloud APIs, never transmitted elsewhere.\"\n    optional_env:\n      - name: AWS_PROFILE\n        purpose: \"AWS CIS benchmark checks — uses boto3 with your local AWS profile\"\n        required: false\n      - name: AZURE_TENANT_ID\n        purpose: \"Azure CIS benchmark checks (azure-mgmt-* SDK)\"\n        required: false\n      - name: AZURE_CLIENT_ID\n        purpose: \"Azure CIS benchmark checks — service principal client ID\"\n        required: false\n      - name: AZURE_CLIENT_SECRET\n        purpose: \"Azure CIS benchmark checks — service principal secret\"\n        required: false\n      - name: GOOGLE_APPLICATION_CREDENTIALS\n        purpose: \"GCP CIS benchmark checks (google-cloud-* SDK)\"\n        required: false\n      - name: SNOWFLAKE_ACCOUNT\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_USER\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_PRIVATE_KEY_PATH\n        purpose: \"Snowflake key-pair auth (CI/CD)\"\n        required: false\n      - name: SNOWFLAKE_AUTHENTICATOR\n        purpose: \"Snowflake auth method (default: externalbrowser SSO)\"\n        required: false\n    optional_bins:\n      - kubectl\n    emoji: \"\\U0001F3D7\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: >-\n      IaC and secrets scanning is purely local — no network calls. Cloud\n      benchmark checks (optional, user-initiated) call cloud provider APIs\n      (AWS/Azure/GCP/Snowflake) using locally configured credentials. No data\n      is stored or transmitted beyond the cloud provider's own API.\n    file_reads:\n      - \"user-specified IaC directories (Terraform, CloudFormation, Kubernetes YAML)\"\n      - \"user-specified Dockerfiles\"\n      - \"user-specified cloud configuration files\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://*.amazonaws.com\"\n        purpose: \"AWS CIS benchmark checks — read-only API calls (IAM, S3, CloudTrail, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://management.azure.com\"\n        purpose: \"Azure CIS benchmark checks — read-only API calls (Azure Resource Manager)\"\n        auth: true\n        optional: true\n      - url: \"https://*.googleapis.com\"\n        purpose: \"GCP CIS benchmark checks — read-only API calls (Cloud Resource Manager, IAM, etc.)\"\n        auth: true\n        optional: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake CIS benchmark checks — read-only API calls (ACCOUNT_USAGE views)\"\n        auth: true\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-scan-infra — Infrastructure & Cloud Security Scanner\n\nScans infrastructure-as-code (Terraform, CloudFormation, Kubernetes), finds\nsecrets in config files, and runs cloud CIS benchmarks against AWS, Azure,\nGCP, and Snowflake.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom iac infra/         # scan Terraform/CloudFormation/K8s\nagent-bom cloud aws          # AWS CIS benchmark\nagent-bom cloud azure        # Azure CIS benchmark\nagent-bom cloud gcp          # GCP CIS benchmark\nagent-bom secrets .          # find secrets in current directory\n```\n\n## When to Use\n\n- \"check terraform\" / \"scan terraform\"\n- \"scan kubernetes\" / \"K8s security\"\n- \"IaC\" / \"infrastructure as code\"\n- \"find secrets\" / \"secret scanning\"\n- \"scan dockerfile\"\n- \"cloud security\" / \"CIS benchmark\"\n- \"misconfigurations\"\n\n## Commands\n\n```bash\n# Scan IaC directory\nagent-bom iac infra/\n\n# Run cloud CIS benchmark\nagent-bom cloud aws\nagent-bom cloud azure\nagent-bom cloud gcp\nagent-bom cloud snowflake\n\n# Find secrets in files\nagent-bom secrets .\n```\n\n## Tools\n\n| Tool | Description |\n|------|-------------|\n| `iac` | Scan Terraform, CloudFormation, Kubernetes YAML for misconfigurations |\n| `cloud` | CIS benchmark checks (AWS, Azure v3.0, GCP v3.0, Snowflake) |\n| `secrets` | Find secrets and credentials in files and directories |\n\n## Examples\n\n```\n# Scan IaC directory for misconfigurations\niac(path=\"infra/\")\n\n# Run AWS CIS benchmark\ncloud(provider=\"aws\")\n\n# Find secrets in project\nsecrets(path=\".\")\n```\n\n## Guardrails\n\n- Confirm with the user before running cloud CIS benchmarks — these make live read-only API calls to AWS/Azure/GCP using the user's locally configured credentials.\n- IaC and secrets scanning is purely local — no network calls.\n- Do not modify any infrastructure files.\n- Ask the user before scanning paths outside their home or project directory.\n- Cloud credentials are used only to call the cloud provider's own APIs and are never transmitted elsewhere.\n\nFile v0.76.2:scan/SKILL.md\n\n---\nname: agent-bom-scan\ndescription: >-\n  Open security scanner for agentic infrastructure — agents, MCP, packages,\n  blast radius, runtime, and trust for package CVEs (OSV, NVD, EPSS,\n  KEV), container images, provenance, filesystems, and SBOMs. Use\n  when: \"check package\", \"scan image\", \"verify\", \"is this safe\",\n  \"scan dependencies\", \"CVE lookup\", \"blast radius\".\nversion: 0.76.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. Native container image\n  scanning — no external scanner required. No API keys required for basic\n  operation.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.2\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Optional env vars below increase rate limits. They are never auto-discovered, inferred, or transmitted.\"\n    optional_env: []\n    optional_bins:\n      - semgrep\n      - kubectl\n    emoji: \"\\U0001F6E1\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Env var values are NEVER extracted from config files. sanitize_env_vars() replaces all env values with ***REDACTED*** BEFORE any config data is processed or stored. Only structural data (server names, commands, URLs) passes through. Source: https://github.com/msaad00/agent-bom/blob/main/src/agent_bom/security.py#L159\"\n    data_flow: \"All scanning is local-first. Only public package names and CVE IDs are sent to vulnerability databases (OSV, NVD, EPSS, GitHub Advisories). No credentials, config file contents, or scan results leave the machine.\"\n    file_reads:\n      # Claude Desktop\n      - \"~/Library/Application Support/Claude/claude_desktop_config.json\"\n      - \"~/.config/Claude/claude_desktop_config.json\"\n      # Claude Code\n      - \"~/.claude/settings.json\"\n      - \"~/.claude.json\"\n      # Cursor\n      - \"~/.cursor/mcp.json\"\n      - \"~/Library/Application Support/Cursor/User/globalStorage/cursor.mcp/mcp.json\"\n      # Windsurf\n      - \"~/.windsurf/mcp.json\"\n      # Cline\n      - \"~/Library/Application Support/Code/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.json\"\n      # VS Code Copilot\n      - \"~/Library/Application Support/Code/User/mcp.json\"\n      # Codex CLI\n      - \"~/.codex/config.toml\"\n      # Gemini CLI\n      - \"~/.gemini/settings.json\"\n      # Goose\n      - \"~/.config/goose/config.yaml\"\n      # Continue\n      - \"~/.continue/config.json\"\n      # Zed\n      - \"~/.config/zed/settings.json\"\n      # Roo Code\n      - \"~/Library/Application Support/Code/User/globalStorage/rooveterinaryinc.roo-cline/settings/cline_mcp_settings.json\"\n      # Amazon Q\n      - \"~/Library/Application Support/Code/User/globalStorage/amazonwebservices.amazon-q-vscode/mcp.json\"\n      # JetBrains AI\n      - \"~/Library/Application Support/JetBrains/*/mcp.json\"\n      - \"~/.config/github-copilot/intellij/mcp.json\"\n      # Junie\n      - \"~/.junie/mcp/mcp.json\"\n      # GitHub Copilot CLI\n      - \"~/.copilot/mcp-config.json\"\n      # Tabnine\n      - \"~/.tabnine/mcp_servers.json\"\n      # Cortex Code (Snowflake)\n      - \"~/.snowflake/cortex/mcp.json\"\n      - \"~/.snowflake/cortex/settings.json\"\n      - \"~/.snowflake/cortex/permissions.json\"\n      - \"~/.snowflake/cortex/hooks.json\"\n      # Snowflake CLI\n      - \"~/.snowflake/connections.toml\"\n      - \"~/.snowflake/config.toml\"\n      # Project-level configs\n      - \".mcp.json\"\n      - \".vscode/mcp.json\"\n      - \".cursor/mcp.json\"\n      # User-provided files\n      - \"user-provided SBOM files (CycloneDX/SPDX JSON)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://api.osv.dev/v1\"\n        purpose: \"OSV vulnerability database — batch CVE lookup for packages\"\n        auth: false\n      - url: \"https://services.nvd.nist.gov/rest/json/cves/2.0\"\n        purpose: \"NVD CVSS v4 enrichment — optional API key increases rate limit\"\n        auth: false\n      - url: \"https://api.first.org/data/v1/epss\"\n        purpose: \"EPSS exploit probability scores\"\n        auth: false\n      - url: \"https://api.github.com/advisories\"\n        purpose: \"GitHub Security Advisories — supplemental CVE lookup\"\n        auth: false\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-scan — AI Supply Chain Vulnerability Scanner\n\nChecks packages for CVEs, scans container images natively, verifies package\nprovenance via Sigstore, scans filesystems, and generates SBOMs.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom agents             # discover agents and scan dependencies\nagent-bom check langchain==0.1.0  # check a specific package with version\nagent-bom image nginx:1.25   # scan container image (native)\nagent-bom fs .               # scan filesystem packages\nagent-bom sbom .             # generate SBOM\nagent-bom verify agent-bom   # verify Sigstore provenance\nagent-bom where              # show all discovery paths\n```\n\n### As an MCP Server\n\n```json\n{\n  \"mcpServers\": {\n    \"agent-bom\": {\n      \"command\": \"uvx\",\n      \"args\": [\"agent-bom\", \"mcp\", \"server\"]\n    }\n  }\n}\n```\n\n## When to Use\n\n- \"check package\" / \"is this package safe\"\n- \"scan image\" / \"scan container\"\n- \"verify\" / \"check provenance\"\n- \"is this safe\" / \"CVE lookup\"\n- \"scan dependencies\"\n- \"blast radius\"\n- \"generate SBOM\"\n\n## Tools (8)\n\n| Tool | Description |\n|------|-------------|\n| `check` | Check a package for CVEs (OSV, NVD, EPSS, KEV) |\n| `scan` | Full discovery + vulnerability scan pipeline |\n| `blast_radius` | Map CVE impact chain across agents, servers, credentials |\n| `remediate` | Prioritized remediation plan for vulnerabilities |\n| `verify` | Package integrity + SLSA provenance check |\n| `diff` | Compare two scan reports (new/resolved/persistent) |\n| `where` | Show MCP client config discovery paths |\n| `inventory` | List discovered agents, servers, packages |\n\n## Examples\n\n```\n# Check a package before installing\ncheck(package=\"langchain\", version=\"0.1.0\", ecosystem=\"pypi\")\n\n# Map blast radius of a CVE\nblast_radius(cve_id=\"CVE-2024-21538\")\n\n# Full scan\nscan()\n\n# Verify package provenance\nverify(package=\"agent-bom\")\n```\n\n## Guardrails\n\n- Show CVEs even when NVD analysis is pending or severity is `unknown` — a CVE ID is still a real finding.\n- Treat `UNKNOWN` severity as unresolved, not benign — it means data is not yet available.\n- Do not modify any files, install packages, or change system configuration.\n- Only public package names and CVE IDs leave the machine for vulnerability database lookups.\n- Ask before scanning paths outside the user's home directory.\n\n## Privacy & Data Handling\n\n```bash\n# Step 1: Install\npip install agent-bom\n\n# Step 2: Review redaction logic BEFORE scanning\n# sanitize_env_vars() replaces ALL env var values with ***REDACTED***\n# BEFORE any config data is processed or stored:\n# https://github.com/msaad00/agent-bom/blob/main/src/agent_bom/security.py#L159\n\n# Step 3: Verify package provenance (Sigstore)\nagent-bom verify agent-bom\n\n# Step 4: Only then run scans\nagent-bom agents\n```\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **Sigstore signed**: `agent-bom verify agent-bom@0.76.2`\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.76.2:SKILL.md\n\n---\nname: agent-bom\ndescription: >-\n  Open security scanner for agentic infrastructure — agents, MCP, packages,\n  blast radius, runtime, and trust across MCP discovery, CVEs, SBOMs,\n  CIS benchmarks (AWS, Azure, GCP, Snowflake), OWASP/NIST/MITRE\n  compliance, AISVS v1.0, MAESTRO layer tagging, and vector database\n  security checks. Use when the user mentions vulnerability scanning,\n  MCP server trust, compliance, SBOM generation, CIS benchmarks, blast\n  radius, or AI supply chain risk.\nversion: 0.76.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. No credentials required for\n  basic scanning. Native container image scanning — no external scanner required.\n  CIS benchmark checks optionally use cloud SDK credentials\n  (AWS/Azure/GCP/Snowflake).\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.2\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: >-\n      Zero credentials required for CVE scanning, blast radius, compliance\n      evaluation, SBOM generation, and MCP registry lookups. Optional env vars\n      below increase rate limits or enable cloud CIS checks. Env var values in\n      discovered config files are replaced with ***REDACTED*** by\n      sanitize_env_vars() in the installed code — verify at\n      https://github.com/msaad00/agent-bom/blob/main/src/agent_bom/security.py#L159\n    optional_env:\n      - name: SNYK_TOKEN\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        required: false\n      - name: AWS_PROFILE\n        purpose: \"AWS CIS benchmark checks — uses boto3 with local AWS profile\"\n        required: false\n      - name: AZURE_TENANT_ID\n        purpose: \"Azure CIS benchmark checks (azure-mgmt-* SDK)\"\n        required: false\n      - name: AZURE_CLIENT_ID\n        purpose: \"Azure CIS benchmark checks — service principal client ID\"\n        required: false\n      - name: AZURE_CLIENT_SECRET\n        purpose: \"Azure CIS benchmark checks — service principal secret\"\n        required: false\n      - name: GOOGLE_APPLICATION_CREDENTIALS\n        purpose: \"GCP CIS benchmark checks (google-cloud-* SDK)\"\n        required: false\n      - name: SNOWFLAKE_ACCOUNT\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_USER\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_PRIVATE_KEY_PATH\n        purpose: \"Snowflake key-pair auth (CI/CD)\"\n        required: false\n      - name: SNOWFLAKE_AUTHENTICATOR\n        purpose: \"Snowflake auth method (default: externalbrowser SSO)\"\n        required: false\n    optional_bins:\n      - semgrep\n      - kubectl\n    emoji: \"\\U0001F6E1\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    install_verification: >-\n      VERIFY BEFORE running with any config files: (1) pip install agent-bom;\n      (2) Review sanitize_env_vars() at security.py#L159 — confirms env value\n      redaction; (3) Review discovery/__init__.py — confirms only structural\n      config data extracted; (4) agent-bom verify agent-bom — Sigstore\n      provenance check; (5) Only then run agent-bom agents\n    credential_handling: >-\n      Env var values are NEVER extracted from config files. sanitize_env_vars()\n      replaces all env values with ***REDACTED*** BEFORE any config data is\n      processed or stored. Only structural data (server names, commands, URLs)\n      passes through. Source:\n      https://github.com/msaad00/agent-bom/blob/main/src/agent_bom/security.py#L159\n    data_flow: >-\n      Scanning is local-first. What leaves the machine: (1) public package names\n      and CVE IDs sent to vulnerability databases (OSV, NVD, EPSS, GitHub\n      Advisories) for CVE lookup; (2) CIS benchmark checks make read-only API\n      calls to cloud providers (AWS/Azure/GCP/Snowflake) using your locally\n      configured credentials, only when explicitly invoked. What stays local:\n      all config file contents, env var values, credentials, scan results,\n      compliance tags, and SBOM data. Registry lookups (427+ MCP servers) are\n      bundled in-package with zero network calls. Env var values in discovered\n      config files are replaced with ***REDACTED*** by sanitize_env_vars() in\n      the installed code.\n    file_reads:\n      # Claude Desktop\n      - \"~/Library/Application Support/Claude/claude_desktop_config.json\"\n      - \"~/.config/Claude/claude_desktop_config.json\"\n      # Claude Code\n      - \"~/.claude/settings.json\"\n      - \"~/.claude.json\"\n      # Cursor\n      - \"~/.cursor/mcp.json\"\n      - \"~/Library/Application Support/Cursor/User/globalStorage/cursor.mcp/mcp.json\"\n      # Windsurf\n      - \"~/.windsurf/mcp.json\"\n      # Cline\n      - \"~/Library/Application Support/Code/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.json\"\n      # VS Code Copilot\n      - \"~/Library/Application Support/Code/User/mcp.json\"\n      # Codex CLI\n      - \"~/.codex/config.toml\"\n      # Gemini CLI\n      - \"~/.gemini/settings.json\"\n      # Goose\n      - \"~/.config/goose/config.yaml\"\n      # Continue\n      - \"~/.continue/config.json\"\n      # Zed\n      - \"~/.config/zed/settings.json\"\n      # Roo Code\n      - \"~/Library/Application Support/Code/User/globalStorage/rooveterinaryinc.roo-cline/settings/cline_mcp_settings.json\"\n      # Amazon Q\n      - \"~/Library/Application Support/Code/User/globalStorage/amazonwebservices.amazon-q-vscode/mcp.json\"\n      # JetBrains AI\n      - \"~/Library/Application Support/JetBrains/*/mcp.json\"\n      - \"~/.config/github-copilot/intellij/mcp.json\"\n      # Junie\n      - \"~/.junie/mcp/mcp.json\"\n      # GitHub Copilot CLI\n      - \"~/.copilot/mcp-config.json\"\n      # Tabnine\n      - \"~/.tabnine/mcp_servers.json\"\n      # Cortex Code (Snowflake)\n      - \"~/.snowflake/cortex/mcp.json\"\n      - \"~/.snowflake/cortex/settings.json\"\n      - \"~/.snowflake/cortex/permissions.json\"\n      - \"~/.snowflake/cortex/hooks.json\"\n      # Snowflake CLI\n      - \"~/.snowflake/connections.toml\"\n      - \"~/.snowflake/config.toml\"\n      # Project-level configs\n      - \".mcp.json\"\n      - \".vscode/mcp.json\"\n      - \".cursor/mcp.json\"\n      # User-provided files\n      - \"user-provided SBOM files (CycloneDX/SPDX JSON)\"\n      - \"user-provided policy files (YAML/JSON policy-as-code)\"\n      - \"user-provided audit log files (JSONL from agent-bom proxy)\"\n      - \"user-provided SKILL.md files (for skill_trust analysis)\"\n    file_writes: []\n    network_endpoints:\n      - url: \"https://api.osv.dev/v1\"\n        purpose: \"OSV vulnerability database — batch CVE lookup for packages\"\n        auth: false\n      - url: \"https://services.nvd.nist.gov/rest/json/cves/2.0\"\n        purpose: \"NVD secondary enrichment — adds CWE IDs, dates, references (no key required)\"\n        auth: false\n      - url: \"https://api.first.org/data/v1/epss\"\n        purpose: \"EPSS exploit probability scores\"\n        auth: false\n      - url: \"https://api.github.com/advisories\"\n        purpose: \"GitHub Security Advisories — supplemental CVE lookup\"\n        auth: false\n      - url: \"https://api.snyk.io\"\n        purpose: \"Optional third-party vulnerability enrichment for code_scan (requires SNYK_TOKEN)\"\n        auth: true\n      - url: \"https://*.amazonaws.com\"\n        purpose: \"AWS CIS benchmark checks — read-only API calls (optional, user-initiated)\"\n        auth: true\n        optional: true\n      - url: \"https://management.azure.com\"\n        purpose: \"Azure CIS benchmark checks — read-only API calls (optional, user-initiated)\"\n        auth: true\n        optional: true\n      - url: \"https://*.googleapis.com\"\n        purpose: \"GCP CIS benchmark checks — read-only API calls (optional, user-initiated)\"\n        auth: true\n        optional: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake CIS benchmark checks — read-only API calls (optional, user-initiated)\"\n        auth: true\n        optional: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom — AI Agent Infrastructure Security Scanner\n\nDiscovers MCP clients and servers across 22 AI tools, scans for CVEs, maps\nblast radius, runs cloud CIS benchmarks, checks OWASP/NIST/MITRE compliance,\ngenerates SBOMs, and assesses AI infrastructure against AISVS v1.0 and MAESTRO\nframework layers.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom agents            # auto-discover + scan\nagent-bom check langchain==0.1.0  # check a specific package with version\nagent-bom fs .              # scan filesystem packages\nagent-bom image nginx:1.25  # scan container image (native)\nagent-bom cloud aws         # AWS CIS benchmark\nagent-bom iac infra/        # scan Terraform/CloudFormation\nagent-bom where             # show all discovery paths\n```\n\n### As an MCP Server\n\n```json\n{\n  \"mcpServers\": {\n    \"agent-bom\": {\n      \"command\": \"uvx\",\n      \"args\": [\"agent-bom\", \"mcp\", \"server\"]\n    }\n  }\n}\n```\n\n## Sub-Skills (8)\n\n| Sub-Skill | Purpose | Triggers |\n|-----------|---------|---------|\n| [discover](discover/SKILL.md) | Find agents, MCP servers, configurations | \"find agents\", \"what's configured\", \"mcp inventory\" |\n| [scan](scan/SKILL.md) | CVE scanning, image scanning, SBOM, provenance | \"check package\", \"scan image\", \"verify\", \"blast radius\" |\n| [scan-infra](scan-infra/SKILL.md) | IaC, cloud config, secrets scanning | \"check terraform\", \"scan kubernetes\", \"find secrets\" |\n| [enforce](enforce/SKILL.md) | Runtime policy enforcement, MCP proxy | \"block risky calls\", \"apply policy\", \"proxy\" |\n| [compliance](compliance/SKILL.md) | 14-framework compliance, SBOM generation | \"compliance report\", \"NIST\", \"SOC 2\", \"OWASP\" |\n| [monitor](monitor/SKILL.md) | Fleet monitoring, trust scores, lifecycle | \"fleet\", \"watch agents\", \"trust scores\" |\n| [analyze](analyze/SKILL.md) | Blast radius, attack paths, context graph | \"blast radius\", \"threat intel\", \"attack path\" |\n| [troubleshoot](troubleshoot/SKILL.md) | Diagnostics, doctor, config validation | \"doctor\", \"debug\", \"why failing\", \"validate config\" |\n\n## Tools\n\n### Vulnerability Scanning\n| Tool | Description |\n|------|-------------|\n| `scan` | Full discovery + vulnerability scan pipeline |\n| `check` | Check a package for CVEs (OSV, NVD, EPSS, KEV) |\n| `blast_radius` | Map CVE impact chain across agents, servers, credentials |\n| `remediate` | Prioritized remediation plan for vulnerabilities |\n| `verify` | Package integrity + SLSA provenance check |\n| `diff` | Compare two scan reports (new/resolved/persistent) |\n| `where` | Show MCP client config discovery paths |\n| `inventory` | List discovered agents, servers, packages |\n\n### Compliance & Policy\n| Tool | Description |\n|------|-------------|\n| `compliance` | OWASP LLM/Agentic Top 10, EU AI Act, MITRE ATLAS, NIST AI RMF |\n| `policy_check` | Evaluate results against custom security policy (17 conditions) |\n| `cis_benchmark` | CIS benchmark checks (AWS, Azure v3.0, GCP v3.0, Snowflake) |\n| `generate_sbom` | Generate SBOM (CycloneDX or SPDX format) |\n| `aisvs_benchmark` | OWASP AISVS v1.0 compliance — 9 AI security checks |\n\n### Registry & Trust\n| Tool | Description |\n|------|-------------|\n| `registry_lookup` | Look up MCP server in 427+ server security metadata registry |\n| `marketplace_check` | Pre-install trust check with registry cross-reference |\n| `fleet_scan` | Batch registry lookup + risk scoring for MCP server inventories |\n| `skill_scan` | Scan instruction files for package refs, trust, and findings |\n| `skill_verify` | Verify Sigstore provenance for instruction files |\n| `skill_trust` | Assess skill file trust level (5-category analysis) |\n| `code_scan` | SAST scanning via Semgrep with CWE-based compliance mapping |\n\n### Runtime & Analytics\n| Tool | Description |\n|------|-------------|\n| `context_graph` | Agent context graph with lateral movement analysis |\n| `analytics_query` | Query vulnerability trends, posture history, and runtime events |\n| `runtime_correlate` | Cross-reference proxy audit JSONL with CVE findings, risk amplification |\n| `vector_db_scan` | Probe Qdrant/Weaviate/Chroma/Milvus for auth and exposure |\n| `gpu_infra_scan` | GPU container and K8s node inventory + unauthenticated DCGM probe (MAESTRO KC6) |\n\n### Specialized Scans\n| Tool | Description |\n|------|-------------|\n| `dataset_card_scan` | Scan dataset cards for bias, licensing, and provenance issues |\n| `training_pipeline_scan` | Scan training pipeline configs for security risks |\n| `browser_extension_scan` | Scan browser extensions for risky permissions and AI domain access |\n| `model_provenance_scan` | Verify model provenance and supply chain integrity |\n| `prompt_scan` | Scan prompt templates for injection and data leakage risks |\n| `model_file_scan` | Scan model files for unsafe serialization (pickle, etc.) |\n| `license_compliance_scan` | Full SPDX license catalog scan with copyleft and network-copyleft detection |\n| `ingest_external_scan` | Import external scan results (CycloneDX/SPDX/JSON) and merge into agent-bom findings |\n\n### Resources\n| Resource | Description |\n|----------|-------------|\n| `registry://servers` | Browse 427+ MCP server security metadata registry |\n\n## Example Workflows\n\n```\n# Check a package before installing\ncheck(package=\"@modelcontextprotocol/server-filesystem\", ecosystem=\"npm\")\n\n# Map blast radius of a CVE\nblast_radius(cve_id=\"CVE-2024-21538\")\n\n# Full agent discovery + scan\nagents()\n\n# Run CIS benchmark\ncis_benchmark(provider=\"aws\")\n\n# Run AISVS v1.0 compliance\naisvs_benchmark()\n\n# Scan vector databases for auth misconfigurations\nvector_db_scan()\n\n# Discover GPU containers, K8s GPU nodes, and unauthenticated DCGM endpoints\ngpu_infra_scan()\n\n# Scan instruction files and then inspect trust\nskill_scan(path=\".\")\nskill_trust(skill_path=\"./SKILL.md\")\n```\n\n## Guardrails\n\n**Always do:**\n- Show CVEs even when NVD analysis is pending or severity is `unknown` — a CVE ID with no details is still a real finding. Report what is known; mark severity as `unknown` explicitly.\n- Confirm with the user before scanning cloud environments (`cis_benchmark`) — these make live API calls to AWS/Azure/GCP using the user's credentials.\n- Treat `UNKNOWN` severity as unresolved, not benign — it means data is not yet available, not that the issue is minor.\n\n**Never do:**\n- Do not modify any files, install packages, or change system configuration. This skill is read-only.\n- Do not transmit env var values, credentials, or file contents to any external service. Only package names and CVE IDs leave the machine.\n- Do not invoke `agents()` autonomously on sensitive environments without user confirmation. The `autonomous_invocation` policy is `restricted`.\n\n**Stop and ask the user when:**\n- The user requests a cloud CIS benchmark and no cloud credentials are configured.\n- A scan finds `CRITICAL` CVEs — present findings and ask whether to generate a remediation plan.\n- The user asks to scan a path outside their home directory.\n\n## Supported Frameworks (14)\n\n- **OWASP LLM Top 10** (2025) — prompt injection, supply chain, data leakage\n- **OWASP MCP Top 10** — MCP-specific security risks\n- **OWASP Agentic Top 10** — tool poisoning, rug pulls, credential theft\n- **OWASP AISVS v1.0** — AI Security Verification Standard (9 checks)\n- **MITRE ATLAS** — adversarial ML threat framework\n- **NIST AI RMF** — govern, map, measure, manage lifecycle\n- **NIST CSF 2.0** — identify, protect, detect, respond, recover\n- **NIST 800-53 Rev 5** — federal security controls (CM-8, RA-5, SI-2, SR-3)\n- **FedRAMP Moderate** — derived from NIST 800-53 controls\n- **EU AI Act** — risk classification, transparency, SBOM requirements\n- **ISO 27001:2022** — information security controls (Annex A)\n- **SOC 2** — Trust Services Criteria\n- **CIS Controls v8** — implementation groups IG1/IG2/IG3\n- **CMMC 2.0** — cybersecurity maturity model (Level 1-3)\n\n## Privacy & Data Handling\n\nThis skill installs agent-bom from PyPI. **Verify the redaction behavior\nbefore running with any config files:**\n\n```bash\n# Step 1: Install\npip install agent-bom\n\n# Step 2: Review redaction logic BEFORE scanning\n# sanitize_env_vars() replaces ALL env var values with ***REDACTED***\n# BEFORE any config data is processed or stored:\n# https://github.com/msaad00/agent-bom/blob/main/src/agent_bom/security.py#L159\n\n# Step 3: Review config parsing — only structural data extracted:\n# https://github.com/msaad00/agent-bom/blob/main/src/agent_bom/discovery/__init__.py\n\n# Step 4: Verify package provenance (Sigstore)\nagent-bom verify agent-bom\n\n# Step 5: Only then run scans\nagent-bom agents\n```\n\n**What is extracted**: Server names, commands, args, and URLs from MCP client\nconfig files across 22 AI tools. **What is NOT extracted**: Env var values are\nreplaced with `***REDACTED***` by `sanitize_env_vars()` before any processing.\nOnly public package names and CVE IDs are sent to vulnerability databases.\nCloud CIS checks use locally configured credentials and call only the cloud\nprovider's own APIs.\n\n## Verification\n\n- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)\n- **Sigstore signed**: `agent-bom verify agent-bom@0.76.2`\n- **7,100+ tests** with CodeQL + OpenSSF Scorecard\n- **No telemetry**: Zero tracking, zero analytics\n\nFile v0.76.2:troubleshoot/SKILL.md\n\n---\nname: agent-bom-troubleshoot\ndescription: >-\n  Diagnose issues, check prerequisites, and validate configurations. Use when:\n  \"doctor\", \"debug\", \"why failing\", \"validate config\", \"check prerequisites\",\n  \"something is broken\", \"db status\", \"fix my setup\".\nversion: 0.76.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. No credentials required.\n  Doctor checks run locally against the installed environment.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.2\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. All diagnostic checks run locally against the installed environment. No data leaves the machine.\"\n    optional_env: []\n    optional_bins: []\n    emoji: \"\\U0001F527\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Purely local. Doctor checks inspect installed packages, config files, and environment settings. No data leaves the machine.\"\n    file_reads:\n      - \"local agent-bom configuration and state files\"\n    file_writes: []\n    network_endpoints: []\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-troubleshoot — Diagnostics & Configuration Validator\n\nDiagnoses issues, checks prerequisites, validates configurations, and reports\non the health of the agent-bom installation and connected database.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom doctor             # check prerequisites and installation health\nagent-bom validate           # validate configuration files\nagent-bom db status          # check database connection status\n```\n\n## When to Use\n\n- \"doctor\" / \"run doctor\"\n- \"debug\" / \"help me debug\"\n- \"why failing\" / \"something's broken\"\n- \"validate config\" / \"check configuration\"\n- \"check prerequisites\"\n- \"db status\" / \"database status\"\n- \"fix my setup\"\n\n## Commands\n\n```bash\n# Run full diagnostic check\nagent-bom doctor\n\n# Validate configuration\nagent-bom validate\n\n# Check database status\nagent-bom db status\n```\n\n## Examples\n\n```\n# Run diagnostics\ndoctor()\n\n# Validate config\nvalidate()\n\n# Check DB\ndb_status()\n```\n\n**Example doctor output:**\n```\nagent-bom doctor\n\n  Python        3.12.2   OK\n  agent-bom     0.75.9   OK\n  pip           24.0     OK\n  semgrep       not found  (optional — SAST scanning unavailable)\n  kubectl       not found  (optional — K8s context unavailable)\n\n  Config files found:\n    Claude Desktop  ~/.config/Claude/claude_desktop_config.json  OK\n    Cursor          ~/.cursor/mcp.json                           OK\n\n  Database:      SQLite  ~/.agent-bom/db.sqlite  OK\n  Last scan:     2 hours ago\n\n  Status: Ready\n```\n\n## Guardrails\n\n- Diagnostics are read-only — no configuration files are modified.\n- Doctor checks do not transmit any data externally.\n- If the user is experiencing an error, show the full diagnostic output before suggesting fixes.\n- Validate configuration files before recommending changes.\n\nFile v0.76.2:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom\",\n  \"version\": \"0.76.2\",\n  \"publishedAt\": 1775787205930\n}\n\nArchive v0.76.1: 12 files, 26825 bytes\n\nFiles: analyze/SKILL.md (4208b), compliance/SKILL.md (7524b), discover/SKILL.md (5608b), enforce/SKILL.md (3725b), monitor/SKILL.md (3619b), registry/SKILL.md (4109b), runtime/SKILL.md (2993b), scan-infra/SKILL.md (5922b), scan/SKILL.md (7773b), SKILL.md (17813b), troubleshoot/SKILL.md (3461b), _meta.json (129b)\n\nFile v0.76.1:analyze/SKILL.md\n\n---\nname: agent-bom-analyze\ndescription: >-\n  Analyze blast radius, attack paths, and threat landscape across your AI\n  infrastructure. Use when: \"blast radius\", \"threat intel\", \"risk score\",\n  \"attack path\", \"lateral movement\", \"context graph\", \"who can reach what\".\nversion: 0.76.1\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. No credentials required for\n  blast radius and context graph analysis. Threat intelligence lookups query\n  EPSS and CVE databases.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.1\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Blast radius and context graph analysis operate on local scan data. EPSS and CVE lookups send only public CVE IDs — no internal data.\"\n    optional_env: []\n    optional_bins: []\n    emoji: \"\\U0001F4A5\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Blast radius and context graph analysis operate on local scan results in memory. Only public CVE IDs are sent to EPSS and vulnerability databases for threat intelligence enrichment. No internal config data, credentials, or scan results leave the machine.\"\n    file_reads: []\n    file_writes: []\n    network_endpoints:\n      - url: \"https://api.first.org/data/v1/epss\"\n        purpose: \"EPSS exploit probability scores for CVEs found in scan\"\n        auth: false\n      - url: \"https://api.osv.dev/v1\"\n        purpose: \"OSV vulnerability database — CVE detail lookup\"\n        auth: false\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-analyze — Blast Radius & Attack Path Analysis\n\nAnalyzes blast radius, attack paths, and the threat landscape across your AI\ninfrastructure. Maps lateral movement risks, identifies high-impact CVEs, and\nvisualizes agent context graphs.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom agents --verbose   # blast radius detail for each agent\nagent-bom graph              # generate context graph\n```\n\n## When to Use\n\n- \"blast radius\" / \"what's the blast radius\"\n- \"threat intel\" / \"threat intelligence\"\n- \"risk score\" / \"risk scoring\"\n- \"attack path\" / \"attack paths\"\n- \"lateral movement\"\n- \"context graph\" / \"agent graph\"\n- \"who can reach what\"\n\n## Commands\n\n```bash\n# Blast radius detail (verbose)\nagent-bom agents --verbose\n\n# Generate context graph\nagent-bom graph\n```\n\n## Tools\n\n| Tool | Description |\n|------|-------------|\n| `blast_radius` | Map CVE impact chain across agents, servers, and credentials |\n| `context_graph` | Agent context graph with lateral movement analysis |\n| `analytics_query` | Query vulnerability trends, posture history, and risk scores |\n\n## Examples\n\n```\n# Map blast radius of a specific CVE\nblast_radius(cve_id=\"CVE-2024-21538\")\n\n# Build full context graph\ncontext_graph()\n\n# Query top CVEs by blast radius impact\nanalytics_query(query=\"top_blast_radius\", days=30)\n```\n\n**Example blast radius output:**\n```\nCVE-2024-21538 — CRITICAL (CVSS 9.8, EPSS 0.94)\nBlast Radius: 4 agents affected\n\n  filesystem   [direct]  langchain 0.1.0 → CVE-2024-21538\n    └─ github  [indirect] shares filesystem credential scope\n    └─ slack   [indirect] accessible via filesystem tool call\n  postgres     [direct]  langchain 0.1.0 → CVE-2024-21538\n\nRecommended: Update langchain to ≥ 0.1.17\n```\n\n## Guardrails\n\n- Analysis is read-only — no files are modified.\n- Only public CVE IDs are sent externally (to EPSS and vulnerability databases).\n- No internal config data, credentials, or agent details leave the machine.\n- Present blast radius findings clearly and ask the user whether to generate a remediation plan when CRITICAL CVEs are found.\n\nFile v0.76.1:compliance/SKILL.md\n\n---\nname: agent-bom-compliance\ndescription: >-\n  AI compliance and policy engine — evaluate scan results against OWASP, NIST,\n  SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.\n  Generate SBOMs and compliance reports. Use when:\n  \"compliance report\", \"NIST\", \"SOC 2\", \"ISO 27001\", \"OWASP\", \"EU AI Act\",\n  \"AISVS\", \"generate SBOM\", \"policy check\".\nversion: 0.76.1\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. OWASP/NIST/EU AI Act/MITRE\n  evaluation and SBOM generation are fully local with zero credentials. CIS\n  benchmark checks optionally use cloud SDK credentials (AWS/Azure/GCP/Snowflake)\n  and make read-only API calls to cloud providers when explicitly invoked.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.1\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required for OWASP/NIST/EU AI Act compliance and SBOM generation. CIS benchmark checks (AWS, Azure, GCP, Snowflake) optionally accept cloud credentials — only used locally to call cloud APIs, never transmitted elsewhere.\"\n    optional_env:\n      - name: AWS_PROFILE\n        purpose: \"AWS CIS benchmark checks — uses boto3 with your local AWS profile\"\n        required: false\n      - name: AZURE_TENANT_ID\n        purpose: \"Azure CIS benchmark checks (azure-mgmt-* SDK)\"\n        required: false\n      - name: AZURE_CLIENT_ID\n        purpose: \"Azure CIS benchmark checks — service principal client ID\"\n        required: false\n      - name: AZURE_CLIENT_SECRET\n        purpose: \"Azure CIS benchmark checks — service principal secret\"\n        required: false\n      - name: GOOGLE_APPLICATION_CREDENTIALS\n        purpose: \"GCP CIS benchmark checks (google-cloud-* SDK)\"\n        required: false\n      - name: SNOWFLAKE_ACCOUNT\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_USER\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_PRIVATE_KEY_PATH\n        purpose: \"Snowflake key-pair auth (CI/CD)\"\n        required: false\n      - name: SNOWFLAKE_AUTHENTICATOR\n        purpose: \"Snowflake auth method (default: externalbrowser SSO)\"\n    \n\nArchive v0.76.0: 12 files, 26812 bytes\n\nFiles: analyze/SKILL.md (4208b), compliance/SKILL.md (7524b), discover/SKILL.md (5608b), enforce/SKILL.md (3725b), monitor/SKILL.md (3619b), registry/SKILL.md (4109b), runtime/SKILL.md (2993b), scan-infra/SKILL.md (5922b), scan/SKILL.md (7773b), SKILL.md (17813b), troubleshoot/SKILL.md (3461b), _meta.json (129b)\n\nArchive v0.75.15: 12 files, 26837 bytes\n\nFiles: analyze/SKILL.md (4210b), compliance/SKILL.md (7526b), discover/SKILL.md (5610b), enforce/SKILL.md (3727b), monitor/SKILL.md (3621b), registry/SKILL.md (4110b), runtime/SKILL.md (2994b), scan-infra/SKILL.md (5924b), scan/SKILL.md (7776b), SKILL.md (17816b), troubleshoot/SKILL.md (3463b), _meta.json (130b)\n\nArchive v0.75.14: 12 files, 26833 bytes\n\nFiles: analyze/SKILL.md (4210b), compliance/SKILL.md (7526b), discover/SKILL.md (5610b), enforce/SKILL.md (3727b), monitor/SKILL.md (3621b), registry/SKILL.md (4110b), runtime/SKILL.md (2994b), scan-infra/SKILL.md (5924b), scan/SKILL.md (7776b), SKILL.md (17816b), troubleshoot/SKILL.md (3463b), _meta.json (130b)\n\nArchive v0.75.13: 12 files, 26817 bytes\n\nFiles: analyze/SKILL.md (4210b), compliance/SKILL.md (7526b), discover/SKILL.md (5610b), enforce/SKILL.md (3727b), monitor/SKILL.md (3621b), registry/SKILL.md (4067b), runtime/SKILL.md (2994b), scan-infra/SKILL.md (5924b), scan/SKILL.md (7766b), SKILL.md (17768b), troubleshoot/SKILL.md (3463b), _meta.json (130b)\n\nArchive v0.75.11: 12 files, 26665 bytes\n\nFiles: analyze/SKILL.md (4210b), compliance/SKILL.md (7526b), discover/SKILL.md (5610b), enforce/SKILL.md (3727b), monitor/SKILL.md (3621b), registry/SKILL.md (3881b), runtime/SKILL.md (2994b), scan-infra/SKILL.md (5924b), scan/SKILL.md (7748b), SKILL.md (17567b), troubleshoot/SKILL.md (3463b), _meta.json (130b)\n\nArchive v0.75.10: 12 files, 26675 bytes\n\nFiles: analyze/SKILL.md (4210b), compliance/SKILL.md (7526b), discover/SKILL.md (5610b), enforce/SKILL.md (3727b), monitor/SKILL.md (3621b), registry/SKILL.md (3881b), runtime/SKILL.md (2994b), scan-infra/SKILL.md (5924b), scan/SKILL.md (7748b), SKILL.md (17567b), troubleshoot/SKILL.md (3463b), _meta.json (130b)\n\nArchive v0.75.9: 12 files, 26662 bytes\n\nFiles: analyze/SKILL.md (4208b), compliance/SKILL.md (7555b), discover/SKILL.md (5608b), enforce/SKILL.md (3725b), monitor/SKILL.md (3619b), registry/SKILL.md (3880b), runtime/SKILL.md (2993b), scan-infra/SKILL.md (5922b), scan/SKILL.md (7734b), SKILL.md (17594b), troubleshoot/SKILL.md (3461b), _meta.json (129b)","readmeExcerpt":"Skill: agent-bom Owner: msaad00 Summary: Open security scanner for agentic infrastructure — agents, MCP, packages, blast radius, runtime, and trust across MCP discovery, CVEs, SBOMs, CIS benchmarks... Tags: ai-supply-chain:0.28.1, cve:0.28.1, latest:0.76.4, mcp:0.28.1, sbom:0.28.1, security:0.28.1 Version history: v0.76.4 | 2026-04-13T05:42:38.812Z | user Release v0.76.4 v0.76.2 | 2026-04-10T02:13:25.930Z | user Rele","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"pipx install agent-bom\nagent-bom agents --verbose   # blast radius detail for each agent\nagent-bom graph              # generate context graph"},{"language":"bash","snippet":"# Blast radius detail (verbose)\nagent-bom agents --verbose\n\n# Generate context graph\nagent-bom graph"},{"language":"text","snippet":"# Map blast radius of a specific CVE\nblast_radius(cve_id=\"CVE-2024-21538\")\n\n# Build full context graph\ncontext_graph()\n\n# Query top CVEs by blast radius impact\nanalytics_query(query=\"top_blast_radius\", days=30)"},{"language":"text","snippet":"CVE-2024-21538 — CRITICAL (CVSS 9.8, EPSS 0.94)\nBlast Radius: 4 agents affected\n\n  filesystem   [direct]  langchain 0.1.0 → CVE-2024-21538\n    └─ github  [indirect] shares filesystem credential scope\n    └─ slack   [indirect] accessible via filesystem tool call\n  postgres     [direct]  langchain 0.1.0 → CVE-2024-21538\n\nRecommended: Update langchain to ≥ 0.1.17"},{"language":"bash","snippet":"pipx install agent-bom\nagent-bom agents -f compliance-export  # run agents scan with compliance export\nagent-bom generate-sbom                # generate CycloneDX SBOM"},{"language":"text","snippet":"# Run compliance check against multiple frameworks\ncompliance(frameworks=[\"owasp_llm\", \"eu_ai_act\", \"nist_ai_rmf\"])\n\n# Enforce custom policy\npolicy_check(policy={\"max_critical\": 0, \"max_high\": 5})\n\n# Generate SBOM\ngenerate_sbom(format=\"cyclonedx\")\n\n# Run AISVS v1.0 compliance\naisvs_benchmark()\n\n# Run AWS CIS benchmark\ncis_benchmark(provider=\"aws\")"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"analyze/SKILL.md","content":"---\nname: agent-bom-analyze\ndescription: >-\n  Analyze blast radius, attack paths, and threat landscape across your AI\n  infrastructure. Use when: \"blast radius\", \"threat intel\", \"risk score\",\n  \"attack path\", \"lateral movement\", \"context graph\", \"who can reach what\".\nversion: 0.76.4\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. No credentials required for\n  blast radius and context graph analysis. Threat intelligence lookups query\n  EPSS and CVE databases.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.4\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Blast radius and context graph analysis operate on local scan data. EPSS and CVE lookups send only public CVE IDs — no internal data.\"\n    optional_env: []\n    optional_bins: []\n    emoji: \"\\U0001F4A5\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Blast radius and context graph analysis operate on local scan results in memory. Only public CVE IDs are sent to EPSS and vulnerability databases for threat intelligence enrichment. No internal config data, credentials, or scan results leave the machine.\"\n    file_reads: []\n    file_writes: []\n    network_endpoints:\n      - url: \"https://api.first.org/data/v1/epss\"\n        purpose: \"EPSS exploit probability scores for CVEs found in scan\"\n        auth: false\n      - url: \"https://api.osv.dev/v1\"\n        purpose: \"OSV vulnerability database — CVE detail lookup\"\n        auth: false\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-analyze — Blast Radius & Attack Path Analysis\n\nAnalyzes blast radius, attack paths, and the threat landscape across your AI\ninfrastructure. Maps lateral movement risks, identifies high-impact CVEs, and\nvisualizes agent context graphs.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom agents --verbose   # blast radius detail for each agent\nagent-bom graph              # generate context graph\n```\n\n## When to Use\n\n- \"blast radius\" / \"what's the blast radius\"\n- \"threat intel\" / \"threat intelligence\"\n- \"risk score\" / \"risk scoring\"\n- \"attack path\" / \"attack paths\"\n- \"lateral movement\"\n- \"context graph\" / \"agent graph\"\n- \"who can reach what\"\n\n## Commands\n\n```bash\n# Blast radius detail (verbose)\nagent-bom agents --verbose\n\n# Generate context graph\nagent-bom graph\n```\n\n## Tools\n\n| Tool | Description |\n|------|-------------|\n| `blast_radius` | Map CVE impact chain ac"},{"path":"compliance/SKILL.md","content":"---\nname: agent-bom-compliance\ndescription: >-\n  AI compliance and policy engine — evaluate scan results against OWASP, NIST,\n  SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.\n  Generate SBOMs and compliance reports. Use when:\n  \"compliance report\", \"NIST\", \"SOC 2\", \"ISO 27001\", \"OWASP\", \"EU AI Act\",\n  \"AISVS\", \"generate SBOM\", \"policy check\".\nversion: 0.76.4\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. OWASP/NIST/EU AI Act/MITRE\n  evaluation and SBOM generation are fully local with zero credentials. CIS\n  benchmark checks optionally use cloud SDK credentials (AWS/Azure/GCP/Snowflake)\n  and make read-only API calls to cloud providers when explicitly invoked.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.4\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required for OWASP/NIST/EU AI Act compliance and SBOM generation. CIS benchmark checks (AWS, Azure, GCP, Snowflake) optionally accept cloud credentials — only used locally to call cloud APIs, never transmitted elsewhere.\"\n    optional_env:\n      - name: AWS_PROFILE\n        purpose: \"AWS CIS benchmark checks — uses boto3 with your local AWS profile\"\n        required: false\n      - name: AZURE_TENANT_ID\n        purpose: \"Azure CIS benchmark checks (azure-mgmt-* SDK)\"\n        required: false\n      - name: AZURE_CLIENT_ID\n        purpose: \"Azure CIS benchmark checks — service principal client ID\"\n        required: false\n      - name: AZURE_CLIENT_SECRET\n        purpose: \"Azure CIS benchmark checks — service principal secret\"\n        required: false\n      - name: GOOGLE_APPLICATION_CREDENTIALS\n        purpose: \"GCP CIS benchmark checks (google-cloud-* SDK)\"\n        required: false\n      - name: SNOWFLAKE_ACCOUNT\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_USER\n        purpose: \"Snowflake CIS benchmark checks\"\n        required: false\n      - name: SNOWFLAKE_PRIVATE_KEY_PATH\n        purpose: \"Snowflake key-pair auth (CI/CD)\"\n        required: false\n      - name: SNOWFLAKE_AUTHENTICATOR\n        purpose: \"Snowflake auth method (default: externalbrowser SSO)\"\n        required: false\n    optional_bins: []\n    emoji: \"\\U00002705\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: >-\n      OWASP/NIST/EU AI Act/MITRE/SBOM evaluation is purely local — zero network\n      calls. CIS benchmark checks (optional, user-initiated) call cloud provider\n      APIs (AWS/Azure/GCP/Snowflake"},{"path":"discover/SKILL.md","content":"---\nname: agent-bom-discover\ndescription: >-\n  Discover AI agents, MCP servers, and configurations on this machine or\n  environment. Use when: \"find agents\", \"what's configured\", \"doctor\",\n  \"what MCP servers\", \"show me what's installed\", \"mcp inventory\".\nversion: 0.76.4\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. No credentials required.\n  Registry data (427+ MCP servers) is bundled in-package with zero network calls.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.4\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Discovery reads only structural config data (server names, commands, args, URLs). Env var values are replaced with ***REDACTED*** by sanitize_env_vars() before any processing.\"\n    optional_env: []\n    optional_bins: []\n    emoji: \"\\U0001F50E\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Env var values are NEVER extracted from config files. sanitize_env_vars() replaces all env values with ***REDACTED*** BEFORE any config data is processed or stored. Source: https://github.com/msaad00/agent-bom/blob/main/src/agent_bom/security.py#L159\"\n    data_flow: \"Purely local. Reads MCP client config files across 22+ AI tools. Only structural data (server names, commands, URLs) is extracted. Env var values are redacted before processing. No data leaves the machine.\"\n    file_reads:\n      # Claude Desktop\n      - \"~/Library/Application Support/Claude/claude_desktop_config.json\"\n      - \"~/.config/Claude/claude_desktop_config.json\"\n      # Claude Code\n      - \"~/.claude/settings.json\"\n      - \"~/.claude.json\"\n      # Cursor\n      - \"~/.cursor/mcp.json\"\n      - \"~/Library/Application Support/Cursor/User/globalStorage/cursor.mcp/mcp.json\"\n      # Windsurf\n      - \"~/.windsurf/mcp.json\"\n      # Cline\n      - \"~/Library/Application Support/Code/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.json\"\n      # VS Code Copilot\n      - \"~/Library/Application Support/Code/User/mcp.json\"\n      # Codex CLI\n      - \"~/.codex/config.toml\"\n      # Gemini CLI\n      - \"~/.gemini/settings.json\"\n      # Goose\n      - \"~/.config/goose/config.yaml\"\n      # Continue\n      - \"~/.continue/config.json\"\n      # Zed\n      - \"~/.config/zed/settings.json\"\n      # Roo Code\n      - \"~/Library/Application Support/Code/User/globalStorage/rooveterinaryinc.roo-cline/settings/cline_mcp_settings.json\"\n      # Amazon Q\n      - \"~/Library/Application Support/Code/User/globalStorage/am"},{"path":"enforce/SKILL.md","content":"---\nname: agent-bom-enforce\ndescription: >-\n  Enforce security policies on MCP tool calls and block dangerous operations at\n  runtime. Use when: \"block risky calls\", \"apply policy\", \"proxy\",\n  \"runtime protection\", \"policy enforcement\", \"intercept MCP calls\".\nversion: 0.76.4\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. No credentials required.\n  Policy files are user-provided YAML/JSON. Proxy runs locally.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.4\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required. Policy evaluation is local. Proxy operates on local network only. Policy files are user-provided and never transmitted.\"\n    optional_env: []\n    optional_bins: []\n    emoji: \"\\U0001F6AB\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Purely local. Policy evaluation runs on scan results in memory. Proxy intercepts MCP calls on local network only. Audit logs are written locally (JSONL). No data leaves the machine.\"\n    file_reads:\n      - \"user-provided policy files (YAML/JSON policy-as-code)\"\n      - \"user-provided audit log files (JSONL from agent-bom proxy)\"\n    file_writes:\n      - \"proxy-audit.jsonl (local audit log, only when proxy is running)\"\n    network_endpoints: []\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n    disable-model-invocation: true\n---\n\n# agent-bom-enforce — Runtime Policy Enforcement\n\nEnforces security policies on MCP tool calls and blocks dangerous operations\nat runtime. Runs a local proxy that intercepts MCP calls and evaluates them\nagainst policy-as-code rules.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom proxy              # start enforcement proxy\nagent-bom policy apply policy.yaml  # apply a policy file\nagent-bom policy check       # check current policy status\n```\n\n## When to Use\n\n- \"block risky calls\" / \"block dangerous MCP calls\"\n- \"apply policy\" / \"enforce policy\"\n- \"proxy\" / \"MCP proxy\"\n- \"runtime protection\"\n- \"policy enforcement\"\n- \"intercept MCP calls\"\n\n## Commands\n\n```bash\n# Start the enforcement proxy\nagent-bom proxy\n\n# Apply a policy file\nagent-bom policy apply policy.yaml\n\n# Check current policy status\nagent-bom policy check\n```\n\n## Example Policy File\n\n```yaml\n# policy.yaml\nrules:\n  - id: block-shell-exec\n    description: Block shell execution tool calls\n    match:\n      tool: \"bash|shell|exec|run_command\"\n    action: block\n    severity: cri"},{"path":"monitor/SKILL.md","content":"---\nname: agent-bom-monitor\ndescription: >-\n  Monitor agent fleet, track trust scores, and manage lifecycle states. Use\n  when: \"fleet\", \"watch agents\", \"runtime status\", \"trust scores\",\n  \"fleet sync\", \"agent lifecycle\", \"serve dashboard\".\nversion: 0.76.4\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+. Install via pipx or pip. No credentials required for\n  fleet listing and trust score tracking. Optional server dashboard available\n  via agent-bom serve.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  scorecard: https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom\n  tests: 7239\n  install:\n    pipx: agent-bom\n    pip: agent-bom\n    docker: ghcr.io/msaad00/agent-bom:0.76.4\n  openclaw:\n    requires:\n      bins: []\n      env: []\n      credentials: none\n    credential_policy: \"Zero credentials required for fleet listing and trust score tracking. Fleet sync reads local scan state. Dashboard server (agent-bom serve) runs on localhost only.\"\n    optional_env: []\n    optional_bins: []\n    emoji: \"\\U0001F4CA\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    data_flow: \"Purely local. Fleet data is read from local scan state. Dashboard server (agent-bom serve) runs on localhost and exposes no data externally. No data leaves the machine.\"\n    file_reads:\n      - \"local scan state and fleet registry (managed by agent-bom)\"\n    file_writes: []\n    network_endpoints: []\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-monitor — Agent Fleet Monitor\n\nMonitor agent fleet health, track trust scores, and manage agent lifecycle\nstates across your AI infrastructure. Start a local dashboard server for\ncontinuous monitoring.\n\n## Install\n\n```bash\npipx install agent-bom\nagent-bom fleet sync         # sync fleet state with latest scan\nagent-bom fleet list         # list all agents and trust scores\nagent-bom serve              # start local monitoring dashboard\n```\n\n## When to Use\n\n- \"fleet\" / \"agent fleet\"\n- \"watch agents\" / \"monitor agents\"\n- \"runtime status\"\n- \"trust scores\"\n- \"fleet sync\"\n- \"agent lifecycle\"\n- \"serve dashboard\" / \"start dashboard\"\n\n## Commands\n\n```bash\n# Sync fleet state with latest scan\nagent-bom fleet sync\n\n# List all agents with trust scores\nagent-bom fleet list\n\n# Start local monitoring dashboard\nagent-bom serve\n```\n\n## Examples\n\n```\n# Sync fleet\nfleet_sync()\n\n# List agents and trust scores\nfleet_list()\n\n# Start dashboard server\nserve()\n```\n\n**Example fleet list output:**\n```\nAgent Fleet — 7 agents tracked\n  filesystem   trust: 92  status: healthy   last-scan: 2m ago\n  brave-search trust: 88  status: healthy   last-scan: 2m ago\n  github       trust: 95  status: healthy "}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1941,"uniquenessScore":33,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T14:12:25.466Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T14:12:25.466Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T15:30:47.377Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}