Agent Bom

data-ai MCP Server

Open-source AI supply chain security scanner. Discover agents, MCP servers, GPU workloads. Scan for CVEs. Map blast radius to credentials and tools. CIS benchmarks (AWS, Snowflake). 10-framework compliance. Policy-as-code. REST API, MCP server, CLI, Helm.

VerifiedInstall Ready
data-aidata-aiaws
8 views0 stars0 forksApache-2.0

Why This Matters

Discovered via smithery and last synced 3mo ago.

VerifiedInstall Ready
Source
smithery
Stars
0
Last synced
3mo ago
Install
Instructions detected

Install

1. Install the package

uvx agent-bom mcp server

2. Add to claude_desktop_config.json

{
  "mcpServers": {
    "agent-bom": {
      "command": "uvx",
      "args": [
        "agent-bom",
        "mcp",
        "server"
      ]
    }
  }
}

Config file location: ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) / %APPDATA%\Claude\claude_desktop_config.json (Windows)

56
Tools
0
Resources
0
Prompts
Standard I/O
Transport

Available Tools (56)

AWS

`pip install 'agent-bom[aws]'`

Policy-as-code

—

Source

How

Vulnerabilities

CVE browser with severity/EPSS/KEV filters

Jobs

Background scan job management

OpenTelemetry

`pip install 'agent-bom[otel]'`

CLI

`agent-bom scan`

Provider

Depth

Prometheus

`--push-gateway` / `--otel-endpoint`

Registry

427+ MCP server browser

Smithery

[smithery.yaml](smithery.yaml)

Standard

Local model inventory via API + manifests

Governance

Snowflake access, privileges, data classification

Partial

Full (OWASP + ATLAS + NIST + EU AI Act + ...)

Railway

[Dockerfile.sse](Dockerfile.sse)

Scan

Enterprise scan form with cloud options

Traces

OpenTelemetry trace ingestion + vulnerable tool call flagging

Dashboard

`pip install 'agent-bom[ui]'`

Deploy

Command

PyPI

`pip install agent-bom`

Dimension

Weight

Gateway

Runtime MCP policy rules + audit log

Databricks

`pip install 'agent-bom[databricks]'`

Platform

Link

Category

Frameworks

Compliance

10-framework compliance posture (OWASP Agentic, OWASP LLM, OWASP MCP, ATLAS, NIST AI RMF, EU AI Act, NIST CSF 2.0, ISO 27001, SOC 2, CIS Controls v8)

Snowflake

`SNOWFLAKE_ACCOUNT=... agent-bom api`

Kubernetes

kubectl across namespaces

Signal

Detection

Yes

Yes — OSV + NVD CVSS v4 + EPSS + CISA KEV + GHSA + NVIDIA CSAF + NVD status tracking

API

`agent-bom api --snowflake`

OpenClaw

[SKILL.md](integrations/openclaw/SKILL.md)

Goal

Run

Layer

Usually deploy first

Agents

Fleet registry + lifecycle state management

Component

Description

Page

Description

Activity

Agent activity timeline + AI observability

Docker

`docker run agentbom/agent-bom scan`

Helm

[`deploy/helm/agent-bom/`](deploy/helm/agent-bom/)

ToolHive

[registry entry](integrations/toolhive/server.json)

Preview

Managed K8s, container services

Endpoint

Description

Fleet

Agent trust scoring + fleet management

verify

Package + version

Backend

Best for

Postgres

Snowflake only when the published backend parity is the reason to choose it

File

Use when

Mode

Best for

Extra

Command

When

What's sent

optional

analytics and backup/export scale

yes

primary transactional store

Path

Starts from

Need

Start here

Surface

Owns