agent-bomOpen security scanner for agentic infrastructure — agents, MCP, packages, blast radius, runtime, and trust across MCP discovery, CVEs, SBOMs, CIS benchmarks...
Install via ClawdBot CLI:
clawdbot install msaad00/agent-bomGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://github.com/msaad00/agent-bomUses known external API (expected, informational)
api.github.comAudited Apr 17, 2026 · audit v1.0
Generated Mar 20, 2026
A software development team uses agent-bom to scan their local AI development tools (e.g., Claude Desktop, VS Code Copilot) for MCP server configurations and potential vulnerabilities. This helps identify untrusted MCP servers and generate SBOMs for compliance with internal security policies, ensuring a secure AI supply chain during development.
An organization deploys agent-bom to run CIS benchmark checks on their AWS, Azure, GCP, or Snowflake cloud environments using optional SDK credentials. This assesses compliance with industry standards like NIST and MITRE, maps blast radius for vulnerabilities, and generates reports for audit purposes without exposing sensitive credentials.
A financial or healthcare company uses agent-bom to automatically generate Software Bill of Materials (SBOMs) for their AI applications and infrastructure. This supports compliance with regulations like OWASP AISVS v1.0, helps track dependencies, and scans for CVEs to mitigate supply chain risks in production systems.
A DevOps team integrates agent-bom into their CI/CD pipeline to perform native container image scanning without external tools like Grype/Syft. It checks for vulnerabilities, runs security benchmarks, and tags MAESTRO layers, ensuring secure deployments and reducing risk in automated build processes.
Offer agent-bom as a free open-source tool for basic scanning and SBOM generation, with premium features like advanced CIS benchmark checks, compliance reporting, and enterprise support. Revenue is generated through subscription plans for teams and large organizations needing enhanced security insights.
Provide professional services to help businesses integrate agent-bom into their security workflows, customize scans for specific industries, and conduct audits. Revenue comes from project-based fees, training workshops, and ongoing maintenance contracts for compliance and risk management.
Develop a cloud-based SaaS platform that leverages agent-bom's capabilities to offer centralized vulnerability scanning, compliance dashboards, and automated reporting for multiple clients. Revenue is generated through tiered SaaS subscriptions based on usage, number of scans, and advanced features.
💬 Integration Tip
Start by installing agent-bom via pip or pipx and verify the sanitize_env_vars() function to ensure credential safety before running scans in production environments.
Scored Apr 19, 2026
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Command-line security analyzer for ClawHub skills. Run analyze-skill.sh to scan SKILL.md files for malicious patterns, credential leaks, and C2 infrastructure before installation. Includes threat intelligence database with 20+ detection patterns.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
577+ pattern prompt injection defense. Now with typo-tolerant bypass detection. TieredPatternLoader fully operational. Drop-in defense for any LLM application.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.