Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Install
uvx agent-bomNVD_API_KEYoptional · secret — NVD API key for higher rate limits on vulnerability enrichment
Open security scanner and self-hosted control plane for AI, MCP, and cloud infrastructure.
Self-host · Deployment models · Quick start · Product tour · Docs
agent-bom finds the AI agents, MCP servers, packages and credentials in a repository, workstation or cloud account, matches packages against vulnerability advisories, and connects findings to recorded agent, tool and credential relationships. Run it as a CLI, in CI, as an MCP server for your assistant, or as a self-hosted dashboard. A recorded relationship is evidence to investigate; it does not prove execution or data access. The map above uses labeled sample data. Light view · Dark view.
Start where you work: scan a repository, run the shared dashboard, or connect your assistant. Apache-2.0; the control plane runs in your own environment.
Self-host in your environment
Your infrastructure, your identity, your database, your audit boundary. From a published release checkout:
git clone --depth 1 --branch v0.107.0 https://github.com/msaad00/agent-bom.git && cd agent-bom
AGENT_BOM_IMAGE_TAG=0.107.0 docker compose up -d
Open http://localhost:3000, then Connections or New Scan. For cloud accounts, add a scoped read-only connection, verify access, then start a scan. The pilot binds to loopback and retains state in a Docker volume. Use the authenticated deployment guide for a shared instance.
Deployment models
Docker pilot · Authenticated deployment · Compose with PostgreSQL · Helm · EKS Terraform · Snowflake Native App preview · Air-gapped bundle · Choose a deployment · Enterprise configuration · Connect cloud accounts
Work with your existing toolsUse CLI or GitHub Action, REST API, or MCP; export SARIF, CycloneDX, SPDX, JSON and HTML. Cloud connectors and fleet sync collect inventory; proxy and gateway deployments add runtime evidence.
Integration capability matrix · MCP client setup · Proxy, gateway and fleet · Smithery setup and manifest
Quick start
Scan a repository and keep the evidence:
pip install agent-bom
agent-bom scan . -f json -o scan.json
Open scan.json for findings and assessment coverage. For pull requests, use agent-bom scan . -f sarif -o findings.sarif and upload the artifact in CI.
For sample inventory and an exact graph link, run agent-bom quickstart --run --offline. It skips package-CVE lookup; use the bundled demo for advisory-backed examples. Follow the first-run handoff.
agent-bom scan --demo --offline lists sample agents, CVEs with recorded agent, MCP server and credential associations, and policy findings (excerpt from current source; installed-release output may differ):
Security posture: CRIT 7 HIGH 10 MED 6 · all finding categories
5 agents · 10 servers · 23 packages
DISCOVER | Agents
Agent Type Servers Pkgs Creds Vulns
langchain-service custom 2 4 4 4
claude-desktop claude-desktop 2 6 3 5
ANALYZE | Critical Details
CVE-2023-36258 · langchain@0.0.150 · CRITICAL
Fix: upgrade to ≥ 0.0.247
Blast: langchain-service → llm-orchestrator-server → ANTHROPIC_API_KEY, OPENAI_API_KEY
ANALYZE | Graph & Policy Findings (8 occurrences)
CRIT COMBINATION AI agent can reach a credential or privileged tool: langchain-service
HIGH PROMPT_SECURITY Agent calls MCP server without verified identity
MED PROMPT_SECURITY Long-lived static credential on MCP server
The sample deliberately triggers a security gate (exit 1). Save CI evidence with agent-bom scan . -f sarif -o findings.sarif; check setup with agent-bom doctor. First-run guide · GitHub Action
Give assistants the same evidence: agent-bom mcp server (MCP support is included by default).
Source version: v0.107.1 · Latest release: v0.107.0. Start with eight focused tools, then select a graph, cloud, runtime or audit
profile. The full catalog has 88 MCP tools, 7 resources, and 8 workflow prompts.
MCP workflows
Use uvx agent-bom scan . without a global install, or
uvx agent-bom check requests@2.33.0 --ecosystem pypi before adding a package.
For automatic dependency and secret gates, see pre-commit and CI setup.
agent-bom db update --osv-ecosystem PyPI covers only the selected ecosystem;
add the ecosystems you need before running agent-bom scan . --offline.
The full agent-bom db update --source osv archive can exceed 1 GB; the command shows live progress.
A non-zero exit can mean a security gate or incomplete assessment: inspect the
report and coverage. Exit codes
Built for the teams that build, secure and govern AI
| Your team | What you can do |
|---|---|
| Developers & AI engineers | Inspect repositories, dependencies and MCP configuration; bring findings into CI and coding assistants. |
| AppSec & cloud security | Connect cloud accounts, trace findings through workloads and identities, and prioritize fixes by reachable impact. |
| Platform & DevOps | Run a shared control plane, collect fleet evidence, and apply policy to MCP traffic through the proxy or gateway. |
| GRC & audit | Open Compliance to review mappings and export scan evidence with its source, freshness and assessment gaps. |
| Security & engineering leaders | Open Overview to review posture, remediation priorities and tracked AI spend across connected sources. |
| AI assistants & automation | Use MCP workflows to query evidence and inspect findings within the caller’s permissions. |
Product tour
Security, engineering and GRC: prioritize risk and assessment gaps
Start with Posture, inspect evidence in Top risks, and scope inventory in Assets & coverage. Compliance separates evaluated-control pass rate from assessment coverage. OWASP and MITRE ATLAS risk mappings describe applicability, not control pass/fail. The offline synthetic enterprise estate includes evaluated checks; results do not establish certification or an audit opinion.
Explore Top risks, scoped Inventory, recorded scan history, framework controls and evidence, and the per-agent BOM preview.
AppSec and cloud teams: explain why a finding matters
Follow CVE-2023-4863 in pillow@9.0.0 through recorded relationships between the service, container, tool, workload identity and modeled data asset. Inspect the source receipts and carry the selected finding into remediation. A recorded path does not by itself prove exploitation or successful data access.
Explore graph navigation, permissions and evidenceChoose a scope in Summary, then Inspect an entity. Filter by type or severity, set direction and hop limits, and expand bounded pages; incomplete views are labeled. In Context, use Focus here, Back, or an exact identifier. Select a node or arrow to inspect its evidence, freshness and unknowns. Investigate reach & permissions opens permission receipts, CVE prerequisites and related activity; missing exploitability stays not assessed. Investigation workflow.
Connect data locations to security evidence. Explore recorded stores and datasets alongside identities and findings. Distinguish storage, access evidence and collection sources; derived classifications do not prove contents or successful reads. Data and evidence model.
Engineers and GRC: prioritize findings and verify fixes
Review findings by priority, affected asset and evidence. Open remediation for package upgrades and mapped controls, assign owners, set SLAs and re-scan to verify fixes.
See package remediation and verificationThese are application captures, not mockups. Overview, Findings and remediation use labeled sample data. The graph uses the reproducible reference lab: real parsers, a pinned advisory scan and authenticated gateway calls, with modeled infrastructure. A blocked call does not establish that the underlying package was fixed.
Discover and scan · Runtime policy and agent workflows · Run the reference evidence lab · Evidence workflow · Control-plane architecture
Trust and evidence
Discovery uses read-only access by default. Explicit disk side-scans create temporary cloud resources; runtime enforcement acts on selected tool calls. Missing evidence stays unavailable or partial. Control mappings are not audit certification.
Product boundaries · Permissions · Threat model · Security policy · Release verification · Measured matcher proof




