msaad00/agent-bom
🐍 🏠 ☁️ 🍎 🪟 🐧 - AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.
Quick Install
{
"mcpServers": {
"msaad00-agent-bom": {
"command": "npx",
"args": [
"-y",
"msaad00-agent-bom"
]
}
}
}Using an AI coding agent (Claude Code, Cursor, etc.)? Copy a ready-made prompt that tells it to fetch the setup instructions and install this server for you.
Documentation Overview
Open security scanner and self-hosted control plane for AI, MCP, and cloud infrastructure.
Scan repositories, images, and cloud accounts; centralize evidence across environments; and enforce AI and MCP runtime policy in infrastructure you control.
15 package ecosystems · 16 compliance surfaces · 77 MCP tools · no account required
Quick start ·
Docs ·
Live demo
What it is
agent-bom is an open scanner and self-hosted control plane for software,
cloud, identity, AI-agent, and MCP evidence. One Finding + UnifiedGraph model
powers CLI and CI artifacts, fleet and browser investigations, compliance
evidence, and runtime policy.
Use the scanner without an account, or deploy the shared control plane inside your own cloud, VPC, Kubernetes cluster, database, identity, and audit boundary.
Graph provenance remains explicit: collected, inferred, static, and runtime relationships stay distinct, and unavailable evidence is never upgraded to observed.
Control-plane architecture
Who it is for
| Role | Start here | Primary outcome |
|---|---|---|
| Developers | agent-bom scan . | Find and explain issues before code leaves the workstation |
| AppSec | agent-bom scan . -f sarif -o findings.sarif | Triage reachable findings and enforce CI gates |
| Security engineers | pip install 'agent-bom[ui]' && agent-bom serve | Investigate exposure paths, identities, and evidence provenance |
| Platform / SRE | agent-bom connect aws | Centralize estate inventory, jobs, and runtime controls |
| GRC / audit | agent-bom report compliance-narrative scan.json | Review control mappings and export evidence with explicit gaps |
| Leadership / CISO | pip install 'agent-bom[ui]' && agent-bom serve | Review posture, coverage, material risk, and change over time |
| AI / MCP owners | pip install 'agent-bom[mcp-server]' && agent-bom mcp server | Inventory tools and apply allow, warn, or block decisions |
AppSec and GRC remain separate workflows: findings and reachability are not presented as audit certification. See product boundaries.
Product gallery
The gallery uses deterministic sample data, visibly labeled in the UI. It is product-state proof, not customer or advisory evidence.
| Overview | Findings |
|---|---|
![]() | ![]() |
| Investigation | Remediation |
|---|---|
![]() | ![]() |
| Cloud and environment lineage | Agent mesh |
|---|---|
![]() | ![]() |
Quick start
Run against the repository in your current directory:
pip install agent-bom
agent-bom scan .
The console shows inventory, findings, and reachable impact. Save an artifact
with agent-bom scan . -f sarif -o findings.sarif, or follow the
first-run guide for exit codes, formats, and CI use.
Try without a repository
Use the curated, explicitly synthetic sample when you only want to inspect the output shape:
agent-bom scan --demo --offline
The sample intentionally contains blocking findings, so exit status 1 is
expected.
Self-host
Start the loopback control plane:
pip install 'agent-bom[ui]'
agent-bom serve
For a shared deployment, use the documented Docker or Helm path and configure real identity, TLS, PostgreSQL, encryption, and audit keys before exposing it.
| Target | Start here |
|---|---|
| Docker Compose | Pilot compose |
| Helm / Kubernetes | helm install agent-bom oci://ghcr.io/msaad00/charts/agent-bom --version 0.98.2 |
| EKS | Terraform module |
| Snowflake SPCS / Native App | scripts/deploy/install.sh snowflake-native · install guide |
| Air-gapped | Image bundle guide |
Examples target this release candidate; confirm release availability before copying an exact pin. Otherwise, use the latest version shown on PyPI.
Deployment overview · Enterprise configuration · Cloud connections
Advanced integrations and runtime entry points
| Need | First action | Artifact or next step |
|---|---|---|
| GitHub CI | uses: msaad00/agent-bom@v0.98.2 | SARIF, PR summary, and a policy exit code |
| Cloud evidence | agent-bom connect aws | Stored connection reference; run scans from the control plane |
| Runtime gateway | agent-bom gateway serve --from-control-plane http://127.0.0.1:8422 --bind 127.0.0.1:8090 | Allow, warn, and block audit events |
| Agent interface | agent-bom mcp server | 77 MCP tools, 6 resources, and 8 workflow prompts |
| Agent distribution | Smithery manifest · Glama · MCP registry · Docker MCP | Registry-specific installation metadata |
MCP server mode exposes 77 MCP tools, 6 resources, and 8 workflow prompts, all read-first: discovery and analysis never mutate a scanned target.
The CLI, Docker, API, Helm chart, MCP server, gateway, and SDK are distribution surfaces of the same product. The Snowflake SPCS / Native App lane runs inside the customer's Snowflake account; it is a customer-owned deployment target, not an agent-bom-hosted service. Snowflake and Snowpark also remain connector and runtime integrations for the other deployment profiles.
Every way to install it
| Surface | Get it |
|---|---|
| Python package | pip install agent-bom — PyPI |
| Container | docker pull agentbom/agent-bom — Docker Hub |
| Kubernetes | helm install agent-bom oci://ghcr.io/msaad00/charts/agent-bom |
| GitHub Action | msaad00/agent-bom |
| MCP server | pip install 'agent-bom[mcp-server]' && agent-bom mcp server |
| MCP registries | Smithery manifest · Glama · MCP registry · Docker MCP |
| SDKs | Python · TypeScript · Go |
Trust
- Read-only discovery by default; runtime write decisions are separate and explicit.
- Credentials are write-only where stored, encrypted at rest, and never returned by API responses.
- API and control-plane routes are tenant scoped and auth protected outside explicit local mode.
- Missing evidence is shown as unavailable or partial, never converted into a factual zero.
- Public examples and screenshots use deterministic synthetic identifiers only.
Threat model · Release verification · Security policy · MCP security model
Contributing
Start with CONTRIBUTING.md, AGENTS.md, and the open issues.
Apache-2.0 licensed.





