Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ”’ Security
  3. Agent Bom
Agent Bom logo
Health: ActiveRecent health check succeeded.Last checked 9/9/2026, 9:31:09 PM

Agent Bom

User RatingsBe the first to rate and review this MCP server!
View Repository31 GitHub StarsTotal stargazers on GitHub for the source repository (31 stars).Visit Website
securitysupply-chaincompliancesbomvulnerability-scanning

Open-source AI supply chain security scanner and control plane with 77 MCP tools and multi-ecosystem compliance enforcement.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Not yet automatically verified

We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β€” we're steadily working through the catalog.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ

Client Config & Setup

Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "msaad00-agent-bom": {
      "command": "uvx",
      "args": [
        "agent-bom"
      ]
    }
  }
}

πŸ’‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Directory Badge Claim listing AlternativesπŸ”’ More in Security

Overview

agent-bom scans repositories, container images, and cloud accounts to detect vulnerabilities, map exposure paths, and generate SBOMs. It correlates findings into a unified graph model for CLI, CI, and browser investigations. The tool supports compliance enforcement across multiple standards and can be run without an account or self-hosted within your infrastructure.

Use cases

β€’Scan AI agents, MCP servers, and dependencies for known vulnerabilities
β€’Generate CycloneDX and SPDX Software Bill of Materials (SBOMs)
β€’Investigate exposure paths and credential risks in AI supply chains
β€’Enforce compliance with OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act
β€’Integrate security scanning into CI/CD pipelines and runtime policy enforcement

Key features

β€’Auto-discovers 20 MCP clients and supports 15 package ecosystems
β€’Detects CVEs using OSV, NVD, EPSS, and CISA KEV databases
β€’Maps blast radius from vulnerabilities to exposed credentials and tools
β€’Runs CIS benchmarks and compliance checks across 16 compliance surfaces
β€’Generates CycloneDX and SPDX SBOM formats
β€’Provides a unified graph model correlating static and runtime evidence

Capabilities & Tool Schemas

Inspect callable tools, capabilities, and parameters exposed to AI agents by Agent Bom.

Extracted Tool Capabilities
Auto-discovers 20 MCP clients and supports 15 package ecosystems
Detects CVEs using OSV, NVD, EPSS, and CISA KEV databases
Maps blast radius from vulnerabilities to exposed credentials and tools
Runs CIS benchmarks and compliance checks across 16 compliance surfaces
Generates CycloneDX and SPDX SBOM formats
Provides a unified graph model correlating static and runtime evidence

Documentation Overview

agent-bom β€” Discover. Scan. Correlate. Act. Security evidence across repositories, software supply chains, AI and MCP, cloud, identity, and data.

Build PyPI Python 3.11 through 3.14 Docker pulls Apache-2.0 license OpenSSF Scorecard Glama MCP server Smithery MCP server

Open security scanner and self-hosted control plane for AI, MCP, and cloud infrastructure.

Product tour Β· Self-host Β· Quick start Β· Docs

Built for the teams that build, secure and govern AI

Your teamWhat you can do
Developers & AI engineersInspect repositories, dependencies and MCP configuration; bring findings into CI and coding assistants.
AppSec & cloud securityConnect cloud accounts, trace findings through workloads and identities, and prioritize fixes by reachable impact.
Platform & DevOpsRun a shared control plane, collect fleet evidence, and apply policy to MCP traffic through the proxy or gateway.
GRC & auditOpen Compliance to review mappings and export scan evidence with its source, freshness and assessment gaps.
Security & engineering leadersOpen Overview to review posture, remediation priorities and tracked AI spend across connected sources.
AI assistants & automationUse MCP workflows to query evidence and inspect findings within the caller’s permissions.

Product tour

Security and engineering leaders: decide what needs attention

See the current risk posture, critical findings, assessment coverage and tracked AI spend together. Open the underlying evidence before assigning a priority.

Actual Overview screen with sample posture, finding counts, coverage and qualified AI spend

AppSec and cloud teams: explain why a finding matters

Follow CVE-2023-4863 in pillow@9.0.0 from its service and container through the tool, workload identity and reachable data asset. Inspect the source receipts and carry the selected finding into remediation.

Reference lab application graph connecting a real Pillow advisory to modeled infrastructure and its remediation action

Engineers and GRC: prioritize findings and verify fixes

Review findings by priority, affected asset, detection evidence and available fix. Open remediation to compare package upgrades and mapped controls, assign owners, set SLAs and re-scan to verify fixes.

Actual Findings screen with labeled sample findings, priority, affected assets, detection evidence and remediation actions

See package remediation and verification

Actual remediation screen with sample package upgrades, affected controls and campaign verification workflow

These are application captures, not mockups. Overview, Findings and remediation use labeled sample data. The graph uses the reproducible reference lab: real parsers, a pinned advisory scan and authenticated gateway calls, with modeled infrastructure. A blocked call does not establish that the underlying package was fixed.

Discover and scan Β· Runtime policy and agent workflows Β· Run the reference evidence lab Β· Evidence workflow Β· Control-plane architecture

Self-host in your environment

Your infrastructure, your identity, your database, your audit boundary. Run the control plane on a workstation, a VM or your Kubernetes cluster. Connect the sources you need and add fleet collection or runtime enforcement as teams adopt them. The deployment guides cover credentials, persistence and access controls for each supported path.

For a workstation pilot, run from a published release checkout:

Terminal
docker compose up -d

Open http://localhost:3000, then Connections or New Scan. For cloud accounts, add a scoped read-only connection, verify access, then start a scan. The pilot binds to loopback and retains state in a Docker volume. Use the authenticated deployment guide below for a shared instance.

Where you run itStart here
Workstation evaluationDocker pilot β€” packaged API, dashboard and persistent state
Shared VM / private cloudAuthenticated deployment Β· Compose profile β€” PostgreSQL and configured identity
KubernetesHelm deployment Β· EKS Terraform
SnowflakeNative App installation
Restricted networksAir-gapped image bundle

Choose a deployment Β· Enterprise configuration Β· Connect cloud accounts

Work with your existing tools

Use the CLI or GitHub Action in CI, the REST API for automation, and MCP from coding assistants. Export SARIF, CycloneDX, SPDX, JSON and HTML for downstream workflows. Cloud connectors and fleet sync feed the control plane; proxy and gateway deployments contribute runtime evidence.

Integration capability matrix Β· MCP client setup Β· Proxy, gateway and fleet Β· Smithery setup and manifest

Quick start

Scan a repository:

Terminal
pip install agent-bom
agent-bom scan .

Save CI evidence with agent-bom scan . -f sarif -o findings.sarif. Use agent-bom doctor to check setup. First-run guide

Try the CLI demo: agent-bom scan --demo --offline. The synthetic sample deliberately triggers a security gate (exit 1).

Recorded agent-bom CLI showing sample findings and remediation guidance

The recording runs the offline command and pages its output for readability.

Give assistants access to the same evidence:

Terminal
pip install 'agent-bom[mcp-server]'
agent-bom mcp server

Start with eight focused tools, then select a graph, cloud, runtime or audit profile. The full catalog has 86 MCP tools, 7 resources, and 8 workflow prompts. MCP workflows

Developer gates and offline scans

Use uvx agent-bom scan . without a global install, or uvx agent-bom check requests@2.33.0 --ecosystem pypi before adding a package. For automatic dependency and secret gates, see pre-commit and CI setup.

agent-bom db update --osv-ecosystem PyPI covers only the selected ecosystem; add the ecosystems you need before running agent-bom scan . --offline. The full agent-bom db update --source osv archive can exceed 1 GB; the command shows live progress. A non-zero exit can mean a security gate or incomplete assessment: inspect the report and coverage. Exit codes

Trust and evidence

Discovery uses read-only access by default. Explicit disk side-scans create temporary cloud resources; runtime enforcement acts on selected tool calls. Missing evidence stays unavailable or partial. Control mappings are not audit certification.

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Security View all alternatives
  • Agentward logoAgentward

    Permission control plane for AI agents. MCP proxy that enforces least-privilege YAML policies on every tool call, classifies sensitive data (PII/PHI), detects dangerous skill chains, and generates compliance audit trails. Supports stdio and HTTP proxy modes.

    πŸ”’ Security2 views
    Compare vs Agentward β†’
  • Codeinspectus logoCodeinspectus

    Local-first, zero-egress security scanner for AI-generated / "vibe-coded" JS/TS. Bundles Opengrep, Gitleaks & Trivy behind one CWE-keyed schema and adds AI-code-specific checks (client-side secret exposure, Supabase RLS, prompt-injection & LLM-output XSS sinks). No account, no telemetry.

    πŸ”’ Security6 views
    Compare vs Codeinspectus β†’
  • Security Scanner AI MCP logoSecurity Scanner AI MCP

    Security Scanner Ai automation via MCP. Includes scan dependencies, check headers, scan secr...

    πŸ”’ Security5 views
    Compare vs Security Scanner AI MCP β†’
  • Shellward logoShellward

    AI Agent Security Middleware & MCP Server with 8-layer defense including prompt injection detection, DLP data flow tracking, command blocking, and PII detection. 7 MCP tools, zero dependencies.

    πŸ”’ Security2 views
    Compare vs Shellward β†’

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks β€” not a rating.

GitHub stars
31
Stargazers on the source repository.
Last commit
2d ago
Most recent push to the default branch.
Directory activity
2 views
Config copies, upvotes, and views on AllMCPs.

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about Agent Bom

No, agent-bom can be run without an account for scanning and analysis.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewAgent Bom AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/msaad00-agent-bom?style=directory)](https://allmcps.com/mcp/msaad00-agent-bom)
HTML Embed
<a href="https://allmcps.com/mcp/msaad00-agent-bom"><img src="https://allmcps.com/api/badge/msaad00-agent-bom?style=directory" alt="Agent Bom on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ”’Security
PricingFree
More technical detailsExpand β–Ύ
TransportSTDIO
RuntimePython
AuthNo auth required
LicenseApache-2.0
Last updatedSep 9, 2026
11/11 checks healthy over the last 32d
Views2
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars31
GitHub Star CountTotal stargazers on GitHub representing community popularity (31 stars).
Last commit2d ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Sep 9, 2026
56Quality signal: Good Β· 56/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools25/30
Adoption & activity7/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

Supply-chain signal

No high-severity advisories surfaced by our automated scan.

Critical 0High 0Medium 0Low 0

Scanned 22d ago via OSV.dev Β· agent-bom (PyPI)

β˜… FeaturedAllMCPs Server logo

AllMCPs Server

The official MCP server for AllMCPs.com - submit and manage tools directly from your AI. The open directory for MCP servers. Connect Claude, Cursor, Windsurf, and AI agents to databases, tools, files, and APIs. Explore 10,000+ servers. AllMCPs is the premier, open directory for discovering, evaluating, and installing Model Context Protocol (MCP) servers to equip AI agents and LLMs with real-world superpowers.

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ”’ Security β†’Best MCP servers for Security β†’Alternatives to Agent Bom β†’Install in Claude DesktopInstall in CursorInstall in VS Code