agent-bom MCP Server
io.github.msaad00/agent-bom
Security scanner and control plane for AI agents, MCP servers, and cloud infrastructure—discover vulnerabilities and trace blast radius.
What is the agent-bom MCP server?
The agent-bom MCP server is an open-source security scanner and self-hosted control plane that discovers AI agents, MCP servers, packages, and credentials in repositories and cloud accounts, then correlates them against vulnerability advisories and security policies. It maps relationships between agents, tools, credentials, and data assets to help teams understand attack surface and prioritize fixes. Run it as a CLI, in CI, as an MCP server for your assistant, or as a self-hosted dashboard.
agent-bom finds and correlates security evidence across AI infrastructure: agents, MCP servers, dependencies, credentials, and cloud resources. It scans repositories and cloud accounts, matches packages against CVE advisories, and builds a graph of agent-to-tool-to-credential relationships to show blast radius and reachable impact. Teams use it to gate CI, inspect findings in a dashboard, and give assistants the same security evidence.
How to install agent-bom
Copy-paste configuration for popular MCP clients.
NVD_API_KEYsecretNVD API key for higher rate limits on vulnerability enrichment
Tools & capabilities
Tools this server exposes to the agent.
scan— Scan a repository or cloud account for agents, MCP servers, packages, credentials and vulnerabilitiescheck— Check a single package against vulnerability advisories before adding it as a dependencymcp server— Run agent-bom as an MCP server to expose security evidence and scanning capabilities to AI assistantsdoctor— Verify agent-bom setup and configurationdb update— Update local vulnerability database from OSV or other sources for offline scanningquickstart— Run a bundled sample estate with pre-populated findings and graph data
Use cases
- Scan a repository in CI to gate deployments on critical vulnerabilities and policy violations
- Trace a CVE through recorded agent, MCP server, and credential relationships to understand blast radius
- Connect cloud accounts to discover agents, workloads, and identities, then correlate findings across infrastructure
- Give Claude or Cursor access to security evidence via MCP to inspect findings and suggest remediation
- Export scan results as SARIF, CycloneDX, SPDX, or JSON for integration with existing security tools
- Run a self-hosted dashboard to track security posture, compliance controls, and remediation campaigns across teams
agent-bom MCP server FAQ
agent-bom discovers AI agents, MCP servers, packages, and credentials in repositories and cloud accounts, matches them against vulnerability advisories, and builds a graph showing relationships and blast radius. It helps teams understand attack surface and prioritize security fixes.
Yes, agent-bom is open-source under the Apache 2.0 license. You can run it as a CLI, in CI, as an MCP server, or self-host the dashboard in your own environment.
Install the Python package (`pip install agent-bom`), then run `agent-bom mcp server` to start the MCP server. Add it to your Cursor or Claude configuration to expose agent-bom's scanning and evidence tools to your assistant. See the MCP client setup guide in the docs.
For local repository scans, no authentication is required. To scan cloud accounts (AWS, GCP, Azure), you provide scoped read-only credentials; the control plane retains state in your own environment. The pilot binds to loopback; authenticated deployments support shared instances with identity and audit boundaries.
agent-bom exports findings as SARIF, CycloneDX, SPDX, JSON, and HTML. Use `-f sarif -o findings.sarif` in CI to upload results as artifacts, or `-f json` to keep structured evidence for further analysis.
Yes. Use `agent-bom db update --osv-ecosystem PyPI` to download vulnerability data for selected ecosystems, then run `agent-bom scan . --offline` without internet access. A full OSV archive can exceed 1 GB; the command shows progress.
README (reference)
Source of truth, from the repository.
agent-bom finds the AI agents, MCP servers, packages and credentials in a repository, workstation or cloud account, matches packages against vulnerability advisories, and connects findings to recorded agent, tool and credential relationships. Run it as a CLI, in CI, as an MCP server for your assistant, or as a self-hosted dashboard. A recorded relationship is evidence to investigate; it does not prove execution or data access. The map above uses labeled sample data. Light view · Dark view.
Start where you work: scan a repository, run the shared dashboard, or connect your assistant. Apache-2.0; the control plane runs in your own environment.
Self-host in your environment
Your infrastructure, your identity, your database, your audit boundary. From a published release checkout:
git clone --depth 1 --branch v0.106.1 https://github.com/msaad00/agent-bom.git && cd agent-bom
AGENT_BOM_IMAGE_TAG=0.106.1 docker compose up -d
Open http://localhost:3000, then Connections or New Scan. For cloud accounts, add a scoped read-only connection, verify access, then start a scan. The pilot binds to loopback and retains state in a Docker volume. Use the authenticated deployment guide for a shared instance.
Deployment models
Docker pilot · Authenticated deployment · Compose with PostgreSQL · Helm · EKS Terraform · Snowflake Native App preview · Air-gapped bundle · Choose a deployment · Enterprise configuration · Connect cloud accounts
<details> <summary>Work with your existing tools</summary>Use CLI or GitHub Action, REST API, or MCP; export SARIF, CycloneDX, SPDX, JSON and HTML. Cloud connectors and fleet sync collect inventory; proxy and gateway deployments add runtime evidence.
Integration capability matrix · MCP client setup · Proxy, gateway and fleet · Smithery setup and manifest
</details>Quick start
Scan a repository and keep the evidence:
pip install agent-bom
agent-bom scan . -f json -o scan.json
Open scan.json for findings and assessment coverage. For pull requests, use agent-bom scan . -f sarif -o findings.sarif and upload the artifact in CI.
For sample inventory and an exact graph link, run agent-bom quickstart --run --offline. It skips package-CVE lookup; use the bundled demo for advisory-backed examples. Follow the first-run handoff.
agent-bom scan --demo --offline lists sample agents, CVEs with recorded agent, MCP server and credential associations, and policy findings (excerpt from current source; installed-release output may differ):
Security posture: CRIT 7 HIGH 10 MED 6 · all finding categories
5 agents · 10 servers · 23 packages
DISCOVER | Agents
Agent Type Servers Pkgs Creds Vulns
langchain-service custom 2 4 4 4
claude-desktop claude-desktop 2 6 3 5
ANALYZE | Critical Details
CVE-2023-36258 · langchain@0.0.150 · CRITICAL
Fix: upgrade to ≥ 0.0.247
Blast: langchain-service → llm-orchestrator-server → ANTHROPIC_API_KEY, OPENAI_API_KEY
ANALYZE | Graph & Policy Findings (8 occurrences)
CRIT COMBINATION AI agent can reach a credential or privileged tool: langchain-service
HIGH PROMPT_SECURITY Agent calls MCP server without verified identity
MED PROMPT_SECURITY Long-lived static credential on MCP server
The sample deliberately triggers a security gate (exit 1). Save CI evidence with agent-bom scan . -f sarif -o findings.sarif; check setup with agent-bom doctor. First-run guide · GitHub Action
Give assistants the same evidence: agent-bom mcp server (MCP support is included by default).
Source version: v0.107.0 · Latest release: v0.106.1. Start with eight focused tools, then select a graph, cloud, runtime or audit
profile. The full catalog has 88 MCP tools, 7 resources, and 8 workflow prompts.
MCP workflows
Use uvx agent-bom scan . without a global install, or
uvx agent-bom check requests@2.33.0 --ecosystem pypi before adding a package.
For automatic dependency and secret gates, see pre-commit and CI setup.
agent-bom db update --osv-ecosystem PyPI covers only the selected ecosystem;
add the ecosystems you need before running agent-bom scan . --offline.
The full agent-bom db update --source osv archive can exceed 1 GB; the command shows live progress.
A non-zero exit can mean a security gate or incomplete assessment: inspect the
report and coverage. Exit codes
Built for the teams that build, secure and govern AI
| Your team | What you can do |
|---|---|
| Developers & AI engineers | Inspect repositories, dependencies and MCP configuration; bring findings into CI and coding assistants. |
| AppSec & cloud security | Connect cloud accounts, trace findings through workloads and identities, and prioritize fixes by reachable impact. |
| Platform & DevOps | Run a shared control plane, collect fleet evidence, and apply policy to MCP traffic through the proxy or gateway. |
| GRC & audit | Open Compliance to review mappings and export scan evidence with its source, freshness and assessment gaps. |
| Security & engineering leaders | Open Overview to review posture, remediation priorities and tracked AI spend across connected sources. |
| AI assistants & automation | Use MCP workflows to query evidence and inspect findings within the caller’s permissions. |
Product tour
Security, engineering and GRC: prioritize risk and assessment gaps
Start with Posture, inspect evidence in Top risks, and scope inventory in Assets & coverage. Compliance separates evaluated-control pass rate from assessment coverage. OWASP and MITRE ATLAS risk mappings describe applicability, not control pass/fail. The offline synthetic enterprise estate includes evaluated checks; results do not establish certification or an audit opinion.
<p align="center"> <a href="docs/images/dashboard-live.png"><img src="docs/images/dashboard-live.png" alt="Overview of posture, findings and assessment gaps with evaluated-control counts and framework logos in a labeled sample environment" width="1440"></a> </p>Explore Top risks, scoped Inventory, recorded scan history, framework controls and evidence, and the per-agent BOM preview.
AppSec and cloud teams: explain why a finding matters
Follow CVE-2023-4863 in pillow@9.0.0 through recorded relationships between the service, container, tool, workload identity and modeled data asset. Inspect the source receipts and carry the selected finding into remediation. A recorded path does not by itself prove exploitation or successful data access.
<a href="docs/images/correlation-graph-live.png"><img src="docs/images/correlation-graph-live.png" alt="Reference lab path linking a Pillow advisory, workload identity and modeled data asset" width="1440"></a>
<details> <summary>Explore graph navigation, permissions and evidence</summary>Choose a scope in Summary, then Inspect an entity. Filter by type or severity, set direction and hop limits, and expand bounded pages; incomplete views are labeled. In Context, use Focus here, Back, or an exact identifier. Select a node or arrow to inspect its evidence, freshness and unknowns. Investigate reach & permissions opens permission receipts, CVE prerequisites and related activity; missing exploitability stays not assessed. Investigation workflow.
Connect data locations to security evidence. Explore recorded stores and datasets alongside identities and findings. Distinguish storage, access evidence and collection sources; derived classifications do not prove contents or successful reads. Data and evidence model.
</details>Engineers and GRC: prioritize findings and verify fixes
Review findings by priority, affected asset and evidence. Open remediation for package upgrades and mapped controls, assign owners, set SLAs and re-scan to verify fixes.
<p align="center"> <a href="docs/images/dependency-map-live.png"><img src="docs/images/dependency-map-live.png" alt="Actual Findings screen with labeled sample findings, priority, affected assets, detection evidence and remediation actions" width="920"></a> </p> <details> <summary>See package remediation and verification</summary> <p align="center"> <a href="docs/images/remediation-live.png"><img src="docs/images/remediation-live.png" alt="Actual remediation screen with sample package upgrades, affected controls and campaign verification workflow" width="920"></a> </p> </details>These are application captures, not mockups. Overview, Findings and remediation use labeled sample data. The graph uses the reproducible reference lab: real parsers, a pinned advisory scan and authenticated gateway calls, with modeled infrastructure. A blocked call does not establish that the underlying package was fixed.
Discover and scan · Runtime policy and agent workflows · Run the reference evidence lab · Evidence workflow · Control-plane architecture
Trust and evidence
Discovery uses read-only access by default. Explicit disk side-scans create temporary cloud resources; runtime enforcement acts on selected tool calls. Missing evidence stays unavailable or partial. Control mappings are not audit certification.
Product boundaries · Permissions · Threat model · Security policy · Release verification · Measured matcher proof
Contributing and support
Related MCP servers
Scan any public site for AI-agent visibility; get scored findings, a machine-readable fix pack, and
View repository →
Local Talkform schemas, bundled interview templates, and config validation for AI agents.
RFC 9110 x402 Solana compliance screening and micropayments gateway for AI agents.
Qualified eIDAS RFC 3161 timestamping for AI workflow provenance. SIGNIUS/IDnow backbone.

Local-first MCP server and CLI for validating and generating synthetic ACH files.

io.github.msdanyg/smart-connections-mcp
Local semantic search over your Obsidian vault using Smart Connections embeddings—no cloud, fully private.
