agent-bom-complianceAI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks. Generate SBOMs and compliance reports. Use when: "compliance report", "NIST", "SOC 2", "ISO 27001", "OWASP", "EU AI Act", "AISVS", "generate SBOM", "policy check".
Install via ClawdBot CLI:
clawdbot install msaad00/agent-bom-complianceGrade Good — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://github.com/msaad00/agent-bomUses known external API (expected, informational)
googleapis.comAudited Apr 17, 2026 · audit v1.0
Generated Mar 21, 2026
A fintech company developing AI-powered fraud detection models uses this skill to audit their AI infrastructure against OWASP LLM Top 10 and MITRE ATLAS frameworks. They run local compliance checks to identify vulnerabilities like prompt injection or data leakage, ensuring their models meet internal security policies before deployment.
A healthcare provider implementing AI diagnostic tools uses this skill to evaluate compliance with the EU AI Act and NIST AI RMF. They generate SBOMs in CycloneDX format to document software components, helping meet transparency requirements and manage risks in high-stakes medical applications.
An e-commerce platform uses this skill to perform CIS benchmark checks on their AWS and GCP cloud accounts. By invoking optional cloud API calls with read-only credentials, they assess configurations against security best practices, identifying misconfigurations in IAM or storage services to prevent breaches.
A startup building AI agents uses this skill to enforce custom policy-as-code rules on their development pipeline. They run policy checks to limit critical vulnerabilities and generate SPDX SBOMs, ensuring third-party dependencies are secure and compliant with industry standards like OWASP Agentic Top 10.
A government agency deploying AI for public services uses this skill to map and measure risks using NIST AI RMF and EU AI Act frameworks. They conduct local evaluations without network calls, maintaining data sovereignty while generating compliance reports and SBOMs for audit trails.
A company integrates this skill into a cloud-based platform offering automated AI compliance checks as a service. They charge subscription fees for continuous monitoring against frameworks like OWASP and EU AI Act, with premium tiers for CIS benchmark integrations across multiple cloud providers.
A cybersecurity firm uses this skill to provide consulting services, helping clients implement and customize compliance workflows. They generate revenue through project-based fees for setting up policy-as-code rules, conducting audits, and training teams on using the tool for regulatory adherence.
The maintainers offer this skill as open-source under Apache-2.0, with revenue from enterprise support contracts and custom feature development. They provide paid support for CIS benchmark integrations and priority updates, targeting large organizations needing scalable compliance solutions.
💬 Integration Tip
Integrate this skill into CI/CD pipelines by running compliance checks after AI model scans; use environment variables for optional cloud credentials only when CIS benchmarks are needed to avoid unnecessary network calls.
Scored Jun 19, 2026
基于睿观的产品图片政策合规检测,通过视觉相似度匹配识别潜在违规商品。当用户提到政策合规检查、产品图片合规、违规检测、禁售商品筛查、基于图片的合规审查、上架前风险排查、policy compliance detection, product compliance review, violation detectio...
AI 合同风险审查服务。当用户需要审查合同、检查法律风险、分析合同条款、 审阅法律文书时使用本技能。覆盖违约责任、知识产权、付款条件、验收标准、 保密义务、管辖法院等15类法律风险。支持快速扫描和深度审查两档服务。 触发词:合同审查、审核合同、检查合同、法律风险、条款分析、法务审查、 合同风险、审合同、法律审查、...
产品图片的图形商标检测与相似度搜索。当用户提到商标检测、图形商标搜索、Logo侵权检查、商标相似度分析、图片商标风险评估、产品图片商标筛查、graphic trademark detection, logo infringement, trademark similarity, trademark risk, i...
面向电商产品Listing的文字商标检测与侵权风险分析。当用户提到商标检测、商标风险检查、品牌侵权筛查、产品标题商标扫描、文字商标查询、Listing合规检查、知识产权风险评估、text trademark detection, trademark infringement, brand infringement...
GDPR and German DSGVO compliance automation. Scans codebases for privacy risks, generates DPIA documentation, tracks data subject rights requests. Use for GD...
CAPA system management for medical device QMS. Covers root cause analysis, corrective action planning, effectiveness verification, and CAPA metrics. Use for...