Open security scanner and self-hosted control plane for AI, MCP, and cloud infrastructure.
Quick start · Self-host · Deployment models · Product tour · Docs
For security, AppSec and GRC teams, agent-bom finds the AI agents, MCP servers, packages and credentials in a repository, container image or cloud account, checks the packages against vulnerability advisories, and traces each finding to the agents, tools and credentials it can reach.
pip install agent-bom
agent-bom scan .
agent-bom scan --demo --offlineagent-bom scan . inventories the current project and checks its packages against advisories. agent-bom scan --demo --offline runs a bundled sample estate with no network access and exits 1 on purpose, because the sample trips the security gate.
For CI, write SARIF with agent-bom scan . -f sarif -o findings.sarif and upload it; check setup with agent-bom doctor. First-run guide
To give an assistant the same evidence, run agent-bom mcp server. Start with eight focused tools, then select a graph, cloud, runtime or audit profile. The full catalog has 88 MCP tools, 7 resources, and 8 workflow prompts. MCP workflows
No project handy? Scan the bundled sample estate offline
agent-bom scan --demo --offline lists sample agents, CVEs with recorded agent, MCP server and credential associations, and policy findings (excerpt from current source; installed-release output may differ):
Security posture: CRIT 7 HIGH 10 MED 6 · all finding categories
5 agents · 10 servers · 23 packages
DISCOVER | Agents
Agent Type Servers Pkgs Creds Vulns
langchain-service custom 2 4 4 4
claude-desktop claude-desktop 2 6 3 5
ANALYZE | Critical Details
CVE-2023-36258 · [email protected] · CRITICAL
Fix: upgrade to ≥ 0.0.247
Blast: langchain-service → llm-orchestrator-server → ANTHROPIC_API_KEY, OPENAI_API_KEY
ANALYZE | Graph & Policy Findings (8 occurrences)
CRIT COMBINATION AI agent can reach a credential or privileged tool: langchain-service
HIGH PROMPT_SECURITY Agent calls MCP server without verified identity
MED PROMPT_SECURITY Long-lived static credential on MCP server
For sample inventory with an exact graph link, run agent-bom quickstart --run --offline (it skips package-CVE lookup). First-run guide
Developer gates and offline scans
Use uvx agent-bom scan . without a global install, or
uvx agent-bom check [email protected] --ecosystem pypi before adding a package.
For automatic dependency and secret gates, see pre-commit and CI setup.
agent-bom db update --osv-ecosystem PyPI covers only the selected ecosystem;
add the ecosystems you need before running agent-bom scan . --offline.
The full agent-bom db update --source osv archive can exceed 1 GB; the command shows live progress.
A non-zero exit can mean a security gate or incomplete assessment: inspect the
report and coverage. Exit codes
Run it as a CLI, in CI, as an MCP server for your assistant, or as a self-hosted dashboard; Apache-2.0, and the control plane runs in your own environment. A recorded relationship is evidence to investigate; it does not prove execution or data access. The map above uses labeled sample data. To trace one vulnerable dependency to the affected agents and into remediation, try the connected-BOM walkthrough.
Your infrastructure, your identity, your database, your audit boundary. From a published release checkout:
git clone --depth 1 --branch v0.108.3 https://github.com/msaad00/agent-bom.git && cd agent-bom
AGENT_BOM_IMAGE_TAG=0.108.3 docker compose up -dOpen http://localhost:3000, then Connections or New Scan. For cloud accounts, add a scoped read-only connection, verify access, then start a scan. The pilot binds to loopback and retains state in a Docker volume. Use the authenticated deployment guide for a shared instance.
Docker pilot · Authenticated deployment · Compose with PostgreSQL · Helm · EKS Terraform · Snowflake Native App preview · Air-gapped bundle · Choose a deployment · Enterprise configuration · Connect cloud accounts
Work with your existing tools
Use CLI or GitHub Action, REST API, or MCP; export SARIF, CycloneDX, SPDX, JSON and HTML. Cloud connectors and fleet sync collect inventory; proxy and gateway deployments add runtime evidence.
Integration capability matrix · MCP client setup · Proxy, gateway and fleet · Smithery setup and manifest
| Your team | What you can do |
|---|---|
| Developers & AI engineers | Inspect repositories, dependencies and MCP configuration; bring findings into CI and coding assistants. |
| AppSec & cloud security | Connect cloud accounts, trace findings through workloads and identities, and prioritize fixes by reachable impact. |
| Platform & DevOps | Run a shared control plane, collect fleet evidence, and apply policy to MCP traffic through the proxy or gateway. |
| GRC & audit | Open Compliance to review mappings and export scan evidence with its source, freshness and assessment gaps. |
| Security & engineering leaders | Open Overview to review posture, remediation priorities and tracked AI spend across connected sources. |
| AI assistants & automation | Use MCP workflows to query evidence and inspect findings within the caller’s permissions. |
Start with Posture, inspect evidence in Top risks, and scope inventory in Assets & coverage. Compliance separates evaluated-control pass rate from assessment coverage. OWASP and MITRE ATLAS risk mappings describe applicability, not control pass/fail. The offline synthetic enterprise estate includes evaluated checks; results do not establish certification or an audit opinion.
Explore expanded framework evidence, Top risks, scoped Inventory, recorded scan history, framework controls and evidence, and the per-agent BOM preview.
Follow CVE-2023-4863 in [email protected] through recorded relationships between the service, container, tool, workload identity and modeled data asset. Inspect the source receipts and carry the selected finding into remediation. A recorded path does not by itself prove exploitation or successful data access.
Explore graph navigation, permissions and evidence
Choose a scope in Summary, then Inspect an entity. Filter by type or severity, set direction and hop limits, and expand bounded pages; incomplete views are labeled. In Context, use Focus here, Back, or an exact identifier. Select a node or arrow to inspect its evidence, freshness and unknowns. Investigate reach & permissions opens permission receipts, CVE prerequisites and related activity; missing exploitability stays not assessed. Investigation workflow.
Connect data locations to security evidence. Explore recorded stores and datasets alongside identities and findings. Distinguish storage, access evidence and collection sources; derived classifications do not prove contents or successful reads. Data and evidence model.
Connect the upgrade decision, the responsible owner and the evidence needed to close the risk.
| Decision | Engineering and governance evidence |
|---|---|
| What do we fix first? | Prioritize package upgrades using severity, recorded agent and credential associations, and available fixes. |
| Who owns the work? | Assign owners and SLAs, link tickets, and track remediation campaigns. |
| Did the fix hold? | Re-scan the same scope, compare retained findings, and verify the campaign before closing it. |
| What supports the control review? | Review evaluated checks, source receipts and assessment gaps; export scoped evidence. A control mapping alone is not a passing check. |
Run the before-and-after dependency example · Review component control evidence · Compliance evidence workflow
These are application captures, not mockups. Overview, Findings and remediation use labeled sample data. The graph uses the reproducible reference lab: real parsers, a pinned advisory scan and authenticated gateway calls, with modeled infrastructure. A blocked call does not establish that the underlying package was fixed.
Discover and scan · Runtime policy and agent workflows · Run the reference evidence lab · Evidence workflow · Control-plane architecture
Discovery uses read-only access by default. Explicit disk side-scans create temporary cloud resources; runtime enforcement acts on selected tool calls. Missing evidence stays unavailable or partial. Control mappings are not audit certification.
Product boundaries · Permissions · Threat model · Security policy · Release verification · Measured matcher proof · Graph workload: command, receipt and limits
Contributing · Support · Open issues · Apache-2.0 license
Source version: v0.108.3 · Latest release: v0.108.3 · Changelog




