Open security scanner and self-hosted control plane for AI, MCP, and cloud infrastructure.
Quick start ·
Self-host ·
Product tour ·
Docs
agent-bom finds the AI agents, MCP servers, packages and credentials in a repository, workstation or cloud account,
matches them against vulnerability advisories, and shows which agent can reach which vulnerable package, tool or secret.
Run it as a CLI, in CI, as an MCP server for your assistant, or as a self-hosted dashboard.
Quick start
Scan a repository in about a minute:
pip install agent-bom
agent-bom scan .
No project handy? Scan the bundled sample estate offline: agent-bom scan --demo --offline.
Agents, MCP servers and what they can reach come first, then the CVEs behind them (excerpt):
Security posture: CRIT 2 HIGH 16 MED 5 · all finding categories
5 agents · 10 servers · 23 packages
DISCOVER | Agents
Agent Type Servers Pkgs Creds Vulns
langchain-service custom 2 4 4 4
claude-desktop claude-desktop 2 6 3 5
ANALYZE | Graph & Policy Findings
HIGH PROMPT_SECURITY Agent calls MCP server without verified identity
HIGH COMBINATION AI agent can reach a credential or privileged tool: langchain-service
MED PROMPT_SECURITY Long-lived static credential on MCP server
ANALYZE | Critical Details
CVE-2023-36258 · langchain@0.0.150 · CRITICAL
Fix: upgrade to ≥ 0.0.247
Blast: langchain-service → llm-orchestrator-server → ANTHROPIC_API_KEY, OPENAI_API_KEY
The sample deliberately triggers a security gate (exit 1). Save CI evidence with
agent-bom scan . -f sarif -o findings.sarif; check setup with agent-bom doctor. First-run guide
Give assistants the same evidence: agent-bom mcp server (MCP support is included by default).
Source version: v0.106.0 · Latest release: v0.105.0. Start with eight focused tools, then select a graph, cloud, runtime or audit
profile. The full catalog has 86 MCP tools, 7 resources, and 8 workflow prompts.
MCP workflows
Developer gates and offline scans
Use uvx agent-bom scan . without a global install, or
uvx agent-bom check requests@2.33.0 --ecosystem pypi before adding a package.
For automatic dependency and secret gates, see
pre-commit and CI setup.
agent-bom db update --osv-ecosystem PyPI covers only the selected ecosystem;
add the ecosystems you need before running agent-bom scan . --offline.
The full agent-bom db update --source osv archive can exceed 1 GB; the command shows live progress.
A non-zero exit can mean a security gate or incomplete assessment: inspect the
report and coverage. Exit codes
Self-host in your environment
Your infrastructure, your identity, your database, your audit boundary. From a published release checkout:
Open http://localhost:3000, then Connections or New Scan.
For cloud accounts, add a scoped read-only connection, verify access, then start a scan.
The pilot binds to loopback and retains state in a Docker volume. Use the authenticated deployment guide for a shared instance.
Going further: Docker pilot · Authenticated deployment ·
Compose with PostgreSQL · Helm · EKS Terraform ·
Snowflake Native App preview · Air-gapped bundle ·
Choose a deployment · Enterprise configuration ·
Connect cloud accounts
Work with your existing tools
Use CLI or GitHub Action, REST API, or MCP; export SARIF, CycloneDX, SPDX, JSON and HTML.
Cloud connectors and fleet sync collect inventory; proxy and gateway deployments add runtime evidence.
Integration capability matrix · MCP client setup ·
Proxy, gateway and fleet · Smithery setup and manifest
Built for the teams that build, secure and govern AI
| Your team | What you can do |
|---|
| Developers & AI engineers | Inspect repositories, dependencies and MCP configuration; bring findings into CI and coding assistants. |
| AppSec & cloud security | Connect cloud accounts, trace findings through workloads and identities, and prioritize fixes by reachable impact. |
| Platform & DevOps | Run a shared control plane, collect fleet evidence, and apply policy to MCP traffic through the proxy or gateway. |
| GRC & audit | Open Compliance to review mappings and export scan evidence with its source, freshness and assessment gaps. |
| Security & engineering leaders | Open Overview to review posture, remediation priorities and tracked AI spend across connected sources. |
| AI assistants & automation | Use MCP workflows to query evidence and inspect findings within the caller’s permissions. |
Product tour
Security, engineering and GRC: prioritize risk and assessment gaps
Start with Posture, inspect evidence in Top risks, and scope inventory in Assets & coverage.
Compliance separates evaluated-control pass rate from assessment coverage.
OWASP and MITRE ATLAS risk mappings describe applicability, not control pass/fail.
The offline synthetic enterprise estate includes evaluated checks; results do not establish certification or an audit opinion.
Explore Top risks, scoped Inventory, recorded scan history, and framework controls and evidence.
AppSec and cloud teams: explain why a finding matters
Follow CVE-2023-4863 in pillow@9.0.0 through recorded relationships between the service, container, tool, workload identity and modeled data asset.
Inspect the source receipts and carry the selected finding into remediation. A recorded path does not by itself prove exploitation or successful data access.

Inspect each hop’s source evidence, permissions and remediation. This reference lab uses modeled infrastructure; select the image for full-size detail.
Explore an agent’s connected assets

Expand connections, focus an entity, then return to the loaded overview. This example uses labeled sample data.
Explore graph navigation, permissions and evidence
Choose a scope in Summary, then Inspect an entity. Filter by type or severity, set direction and hop limits, and expand bounded pages; incomplete views are labeled.
In Context, use Focus here, Back, or an exact identifier. Select a node or arrow to inspect its evidence, freshness and unknowns. Investigate reach & permissions
opens permission receipts, CVE prerequisites and related activity; missing exploitability
stays not assessed. Investigation workflow.
Connect data locations to security evidence. Explore recorded stores and datasets alongside identities and findings.
Distinguish storage, access evidence and collection sources; derived classifications do not prove contents or successful reads. Data and evidence model.
Engineers and GRC: prioritize findings and verify fixes
Review findings by priority, affected asset and evidence. Open remediation for package
upgrades and mapped controls, assign owners, set SLAs and re-scan to verify fixes.
See package remediation and verification
These are application captures, not mockups. Overview, Findings and remediation use
labeled sample data. The graph uses the reproducible reference lab: real parsers,
a pinned advisory scan and authenticated gateway calls, with modeled infrastructure.
A blocked call does not establish that the underlying package was fixed.
Discover and scan · Runtime policy and agent workflows ·
Run the reference evidence lab ·
Evidence workflow · Control-plane architecture
Trust and evidence
Discovery uses read-only access by default. Explicit disk side-scans create temporary cloud resources; runtime enforcement
acts on selected tool calls. Missing evidence stays unavailable or partial. Control mappings are not audit certification.
Product boundaries · Permissions · Threat model ·
Security policy · Release verification ·
Measured matcher proof
Contributing and support
Contributing · Support · Open issues · Apache-2.0 license