Skip to content
msaad00Public

About

Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

31 stars

Watchers

0 watching

Forks

Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Latest commit

 

History

4,300 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

agent-bom — Discover. Scan. Correlate. Act. Security evidence across repositories, software supply chains, AI and MCP, cloud, identity, and data.

Build PyPI Python 3.11 through 3.14 Docker pulls Apache-2.0 license OpenSSF Scorecard Glama MCP server Smithery MCP server

Open security scanner and self-hosted control plane for AI, MCP, and cloud infrastructure.

Quick start · Self-host · Deployment models · Product tour · Docs

For security, AppSec and GRC teams, agent-bom finds the AI agents, MCP servers, packages and credentials in a repository, container image or cloud account, checks the packages against vulnerability advisories, and traces each finding to the agents, tools and credentials it can reach.

Quick start

pip install agent-bom
agent-bom scan .
agent-bom scan --demo --offline

agent-bom scan . inventories the current project and checks its packages against advisories. agent-bom scan --demo --offline runs a bundled sample estate with no network access and exits 1 on purpose, because the sample trips the security gate. For CI, write SARIF with agent-bom scan . -f sarif -o findings.sarif and upload it; check setup with agent-bom doctor. First-run guide To give an assistant the same evidence, run agent-bom mcp server. Start with eight focused tools, then select a graph, cloud, runtime or audit profile. The full catalog has 88 MCP tools, 7 resources, and 8 workflow prompts. MCP workflows

No project handy? Scan the bundled sample estate offline

agent-bom scan --demo --offline lists sample agents, CVEs with recorded agent, MCP server and credential associations, and policy findings (excerpt from current source; installed-release output may differ):

  Security posture:   CRIT  7   HIGH  10   MED   6 · all finding categories
  5 agents · 10 servers · 23 packages
DISCOVER | Agents
  Agent                Type              Servers    Pkgs    Creds    Vulns
  langchain-service    custom                  2       4        4        4
  claude-desktop       claude-desktop          2       6        3        5
ANALYZE | Critical Details
  CVE-2023-36258 · [email protected] · CRITICAL
  Fix: upgrade to ≥ 0.0.247
  Blast: langchain-service → llm-orchestrator-server → ANTHROPIC_API_KEY, OPENAI_API_KEY
ANALYZE | Graph & Policy Findings (8 occurrences)
   CRIT  COMBINATION AI agent can reach a credential or privileged tool: langchain-service
   HIGH  PROMPT_SECURITY Agent calls MCP server without verified identity
   MED   PROMPT_SECURITY Long-lived static credential on MCP server

For sample inventory with an exact graph link, run agent-bom quickstart --run --offline (it skips package-CVE lookup). First-run guide

Recorded agent-bom CLI showing sample findings and remediation guidance

Developer gates and offline scans

Use uvx agent-bom scan . without a global install, or uvx agent-bom check [email protected] --ecosystem pypi before adding a package. For automatic dependency and secret gates, see pre-commit and CI setup.

agent-bom db update --osv-ecosystem PyPI covers only the selected ecosystem; add the ecosystems you need before running agent-bom scan . --offline. The full agent-bom db update --source osv archive can exceed 1 GB; the command shows live progress. A non-zero exit can mean a security gate or incomplete assessment: inspect the report and coverage. Exit codes

Recorded agent connections linking a role, agents, MCP servers, tool, credential reference, package and finding

Run it as a CLI, in CI, as an MCP server for your assistant, or as a self-hosted dashboard; Apache-2.0, and the control plane runs in your own environment. A recorded relationship is evidence to investigate; it does not prove execution or data access. The map above uses labeled sample data. To trace one vulnerable dependency to the affected agents and into remediation, try the connected-BOM walkthrough.

Self-host in your environment

Your infrastructure, your identity, your database, your audit boundary. From a published release checkout:

git clone --depth 1 --branch v0.108.3 https://github.com/msaad00/agent-bom.git && cd agent-bom
AGENT_BOM_IMAGE_TAG=0.108.3 docker compose up -d

Open http://localhost:3000, then Connections or New Scan. For cloud accounts, add a scoped read-only connection, verify access, then start a scan. The pilot binds to loopback and retains state in a Docker volume. Use the authenticated deployment guide for a shared instance.

Deployment models

Docker pilot · Authenticated deployment · Compose with PostgreSQL · Helm · EKS Terraform · Snowflake Native App preview · Air-gapped bundle · Choose a deployment · Enterprise configuration · Connect cloud accounts

Work with your existing tools

Use CLI or GitHub Action, REST API, or MCP; export SARIF, CycloneDX, SPDX, JSON and HTML. Cloud connectors and fleet sync collect inventory; proxy and gateway deployments add runtime evidence.

Integration capability matrix · MCP client setup · Proxy, gateway and fleet · Smithery setup and manifest

Built for the teams that build, secure and govern AI

Your team What you can do
Developers & AI engineers Inspect repositories, dependencies and MCP configuration; bring findings into CI and coding assistants.
AppSec & cloud security Connect cloud accounts, trace findings through workloads and identities, and prioritize fixes by reachable impact.
Platform & DevOps Run a shared control plane, collect fleet evidence, and apply policy to MCP traffic through the proxy or gateway.
GRC & audit Open Compliance to review mappings and export scan evidence with its source, freshness and assessment gaps.
Security & engineering leaders Open Overview to review posture, remediation priorities and tracked AI spend across connected sources.
AI assistants & automation Use MCP workflows to query evidence and inspect findings within the caller’s permissions.

Product tour

Security, engineering and GRC: prioritize risk and assessment gaps

Start with Posture, inspect evidence in Top risks, and scope inventory in Assets & coverage. Compliance separates evaluated-control pass rate from assessment coverage. OWASP and MITRE ATLAS risk mappings describe applicability, not control pass/fail. The offline synthetic enterprise estate includes evaluated checks; results do not establish certification or an audit opinion.

Posture and open findings with compliance and security-area disclosures collapsed in a labeled sample environment

Explore expanded framework evidence, Top risks, scoped Inventory, recorded scan history, framework controls and evidence, and the per-agent BOM preview.

AppSec and cloud teams: explain why a finding matters

Follow CVE-2023-4863 in [email protected] through recorded relationships between the service, container, tool, workload identity and modeled data asset. Inspect the source receipts and carry the selected finding into remediation. A recorded path does not by itself prove exploitation or successful data access.

Reference lab path linking a Pillow advisory, workload identity and modeled data asset

Explore graph navigation, permissions and evidence

Choose a scope in Summary, then Inspect an entity. Filter by type or severity, set direction and hop limits, and expand bounded pages; incomplete views are labeled. In Context, use Focus here, Back, or an exact identifier. Select a node or arrow to inspect its evidence, freshness and unknowns. Investigate reach & permissions opens permission receipts, CVE prerequisites and related activity; missing exploitability stays not assessed. Investigation workflow.

Connect data locations to security evidence. Explore recorded stores and datasets alongside identities and findings. Distinguish storage, access evidence and collection sources; derived classifications do not prove contents or successful reads. Data and evidence model.

Engineers and GRC: turn exposure into an accountable fix

Connect the upgrade decision, the responsible owner and the evidence needed to close the risk.

Decision Engineering and governance evidence
What do we fix first? Prioritize package upgrades using severity, recorded agent and credential associations, and available fixes.
Who owns the work? Assign owners and SLAs, link tickets, and track remediation campaigns.
Did the fix hold? Re-scan the same scope, compare retained findings, and verify the campaign before closing it.
What supports the control review? Review evaluated checks, source receipts and assessment gaps; export scoped evidence. A control mapping alone is not a passing check.

Sample remediation plan with package fixes, affected agents, credential associations and an owner/SLA verification workflow

Run the before-and-after dependency example · Review component control evidence · Compliance evidence workflow

These are application captures, not mockups. Overview, Findings and remediation use labeled sample data. The graph uses the reproducible reference lab: real parsers, a pinned advisory scan and authenticated gateway calls, with modeled infrastructure. A blocked call does not establish that the underlying package was fixed.

Discover and scan · Runtime policy and agent workflows · Run the reference evidence lab · Evidence workflow · Control-plane architecture

Trust and evidence

Discovery uses read-only access by default. Explicit disk side-scans create temporary cloud resources; runtime enforcement acts on selected tool calls. Missing evidence stays unavailable or partial. Control mappings are not audit certification.

Product boundaries · Permissions · Threat model · Security policy · Release verification · Measured matcher proof · Graph workload: command, receipt and limits

Contributing and support

Contributing · Support · Open issues · Apache-2.0 license

Source version: v0.108.3 · Latest release: v0.108.3 · Changelog

About

Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

31 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages