Skip to content

feat: add agent-bom skill#101

Closed
msaad00 wants to merge 1 commit intoopenclaw:mainfrom
msaad00:feat/add-agent-bom
Closed

feat: add agent-bom skill#101
msaad00 wants to merge 1 commit intoopenclaw:mainfrom
msaad00:feat/add-agent-bom

Conversation

@msaad00
Copy link

@msaad00 msaad00 commented Feb 23, 2026

Summary

  • Adds agent-bom — an AI supply chain security scanner for MCP servers and AI agents
  • Installable via uvx agent-bom or pip install agent-bom
  • Supports darwin + linux

What agent-bom does

  • Auto-discovers MCP client configs (Claude Desktop, Cursor, VS Code, Windsurf, OpenClaw, etc.)
  • Scans packages against OSV.dev for CVEs
  • Enriches with NVD CVSS, EPSS probability, CISA KEV status
  • Maps blast radius: CVE → package → server → agent → credentials/tools
  • Generates SBOMs (CycloneDX 1.6, SPDX 3.0, SARIF 2.1.0)
  • Enforces security policies and generates remediation plans

Links

AI supply chain security scanner — CVE scanning, blast radius analysis,
policy enforcement, and SBOM generation for MCP servers and AI agents.
@openclaw-barnacle
Copy link

Thanks for the pull request! This repository is read-only and is automatically synced from https://clawhub.ai, so we can’t accept changes here. Please make updates on the website instead.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant