agent-bom — AI Supply Chain Security Scanner
Scans AI infrastructure for vulnerabilities, generates SBOMs, and enforces
compliance. Discovers MCP clients, servers, and packages across 18+ AI platforms.
Install (Recommended: Local-First)
Local scanning eliminates all third-party trust concerns. All vulnerability
databases (OSV, NVD, EPSS, KEV) are queried directly from your machine.
pipx install agent-bom
agent-bom scan # auto-discover 18 MCP clients + scan
agent-bom check langchain # check a specific package
agent-bom where # show all discovery paths
As an MCP Server (Local)
{
"mcpServers": {
"agent-bom": {
"command": "uvx",
"args": ["agent-bom", "mcp"]
}
}
}
As a Docker Container
docker run --rm ghcr.io/msaad00/agent-bom:0.38.1 scan
Self-Hosted SSE Server
docker build -f Dockerfile.sse -t agent-bom-sse .
docker run -p 8080:8080 agent-bom-sse
# Connect: { "type": "sse", "url": "http://localhost:8080/sse" }
Available MCP Tools (14 tools)
| Tool |
Description |
scan |
Full discovery + vulnerability scan pipeline |
check |
Check a package for CVEs (OSV, NVD, EPSS, KEV) |
blast_radius |
Map CVE impact chain across agents, servers, credentials |
registry_lookup |
Look up MCP server in 427+ server threat registry |
compliance |
OWASP LLM/Agentic Top 10, EU AI Act, MITRE ATLAS, NIST AI RMF |
remediate |
Prioritized remediation plan for vulnerabilities |
verify |
Package integrity + SLSA provenance check |
skill_trust |
Assess skill file trust level (5-category analysis) |
generate_sbom |
Generate SBOM (CycloneDX or SPDX format) |
policy_check |
Evaluate results against security policy |
diff |
Compare two scan reports (new/resolved/persistent) |
marketplace_check |
Pre-install trust check with registry cross-reference |
where |
Show MCP client config discovery paths |
inventory |
List discovered agents, servers, packages |
MCP Resources
| Resource |
Description |
registry://servers |
Browse 427+ MCP server threat intelligence registry |
policy://template |
Default security policy template |
Example Workflows
# Check a package before installing
check(package="@modelcontextprotocol/server-filesystem", ecosystem="npm")
# Map blast radius of a CVE
blast_radius(cve_id="CVE-2024-21538")
# Look up a server in the threat registry
registry_lookup(server_name="brave-search")
# Generate an SBOM
generate_sbom(format="cyclonedx")
# Assess trust of a skill file
skill_trust(skill_content="<paste SKILL.md content>")
Remote SSE Endpoint (Optional)
For MCP clients that only support remote servers (e.g., some Claude Desktop
configurations), a convenience endpoint is available:
{
"mcpServers": {
"agent-bom": {
"type": "sse",
"url": "https://trustworthy-solace-production-14a6.up.railway.app/sse"
}
}
}
Important: This endpoint queries the same public vulnerability databases
as local scanning. It receives only the arguments you provide in tool calls
(package names, CVE IDs, server names). For sensitive environments, use local
installation or self-host your own instance.
Security Boundaries
Safe to send (public data only)
- Public package names + versions (
langchain, express@4.18.2)
- Public CVE IDs (
CVE-2024-21538)
- Public MCP server names (
brave-search)
- Ecosystem identifiers (
pypi, npm, go)
Never send
- API keys, tokens, passwords, or
.env contents
- Full config files (may contain credentials)
- Internal URLs, hostnames, or proprietary package names
- Use
${env:VAR} references, never literal credential values
Verification
1---2name: agent-bom3description: AI supply chain security scanner — check packages for CVEs, look up MCP servers in the 427+ server threat registry, assess blast radius, generate SBOMs, enforce compliance (OWASP, MITRE ATLAS, EU AI Act, NIST AI RMF). Use when the user mentions vulnerability scanning, dependency security, SBOM generation, MCP server trust, or AI supply chain risk.4license: Apache-2.05---6
7# agent-bom — AI Supply Chain Security Scanner
8
9Scans AI infrastructure for vulnerabilities, generates SBOMs, and enforces
10compliance. Discovers MCP clients, servers, and packages across 18+ AI platforms.
11
12## Install (Recommended: Local-First)
13
14Local scanning eliminates all third-party trust concerns. All vulnerability
15databases (OSV, NVD, EPSS, KEV) are queried directly from your machine.
16
17```bash
18pipx install agent-bom
19agent-bom scan # auto-discover 18 MCP clients + scan
20agent-bom check langchain # check a specific package
21agent-bom where # show all discovery paths
22```
23
24### As an MCP Server (Local)
25
26```json
27{
28 "mcpServers": {
29 "agent-bom": {
30 "command": "uvx",
31 "args": ["agent-bom", "mcp"]
32 }
33 }
34}
35```
36
37### As a Docker Container
38
39```bash
40docker run --rm ghcr.io/msaad00/agent-bom:0.38.1 scan
41```
42
43### Self-Hosted SSE Server
44
45```bash
46docker build -f Dockerfile.sse -t agent-bom-sse .
47docker run -p 8080:8080 agent-bom-sse
48# Connect: { "type": "sse", "url": "http://localhost:8080/sse" }
49```
50
51## Available MCP Tools (14 tools)
52
53| Tool | Description |
54|------|-------------|
55| `scan` | Full discovery + vulnerability scan pipeline |
56| `check` | Check a package for CVEs (OSV, NVD, EPSS, KEV) |
57| `blast_radius` | Map CVE impact chain across agents, servers, credentials |
58| `registry_lookup` | Look up MCP server in 427+ server threat registry |
59| `compliance` | OWASP LLM/Agentic Top 10, EU AI Act, MITRE ATLAS, NIST AI RMF |
60| `remediate` | Prioritized remediation plan for vulnerabilities |
61| `verify` | Package integrity + SLSA provenance check |
62| `skill_trust` | Assess skill file trust level (5-category analysis) |
63| `generate_sbom` | Generate SBOM (CycloneDX or SPDX format) |
64| `policy_check` | Evaluate results against security policy |
65| `diff` | Compare two scan reports (new/resolved/persistent) |
66| `marketplace_check` | Pre-install trust check with registry cross-reference |
67| `where` | Show MCP client config discovery paths |
68| `inventory` | List discovered agents, servers, packages |
69
70## MCP Resources
71
72| Resource | Description |
73|----------|-------------|
74| `registry://servers` | Browse 427+ MCP server threat intelligence registry |
75| `policy://template` | Default security policy template |
76
77## Example Workflows
78
79```
80# Check a package before installing
81check(package="@modelcontextprotocol/server-filesystem", ecosystem="npm")
82
83# Map blast radius of a CVE
84blast_radius(cve_id="CVE-2024-21538")
85
86# Look up a server in the threat registry
87registry_lookup(server_name="brave-search")
88
89# Generate an SBOM
90generate_sbom(format="cyclonedx")
91
92# Assess trust of a skill file
93skill_trust(skill_content="<paste SKILL.md content>")
94```
95
96## Remote SSE Endpoint (Optional)
97
98For MCP clients that only support remote servers (e.g., some Claude Desktop
99configurations), a convenience endpoint is available:
100
101```json
102{
103 "mcpServers": {
104 "agent-bom": {
105 "type": "sse",
106 "url": "https://trustworthy-solace-production-14a6.up.railway.app/sse"
107 }
108 }
109}
110```
111
112**Important:** This endpoint queries the same public vulnerability databases
113as local scanning. It receives only the arguments you provide in tool calls
114(package names, CVE IDs, server names). For sensitive environments, use local
115installation or self-host your own instance.
116
117## Security Boundaries
118
119### Safe to send (public data only)
120
121- Public package names + versions (`langchain`, `express@4.18.2`)
122- Public CVE IDs (`CVE-2024-21538`)
123- Public MCP server names (`brave-search`)
124- Ecosystem identifiers (`pypi`, `npm`, `go`)
125
126### Never send
127
128- API keys, tokens, passwords, or `.env` contents
129- Full config files (may contain credentials)
130- Internal URLs, hostnames, or proprietary package names
131- Use `${env:VAR}` references, never literal credential values
132
133## Verification
134
135- **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0)
136- **PyPI**: [pypi.org/project/agent-bom](https://pypi.org/project/agent-bom/)
137- **Smithery**: 99/100 quality score
138- **Sigstore signed**: `agent-bom verify agent-bom@0.38.1`
139- **2,099 tests** with automated security scanning (CodeQL + OpenSSF Scorecard)
140- **OpenSSF Scorecard**: [securityscorecards.dev](https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom)
141- **No telemetry**: Zero tracking, zero analytics