AgentIndex icon
AgentIndex
ToolsCategoriesTrendingNewCompare
Submit Tool
Home/
Security & Safety/
agent-bom
agent-bom logo

agent-bom

Active·★ 20·Apache-2.0·Updated 2026-05-29
★ Trending★ Security & Safety★ LLM Infra

Open security scanner for AI supply chain: agents, MCP, containers, cloud, GPU, and runtime with blast-radius analysis.

agent-bom is an end-to-end open security scanner for the AI supply chain. It performs CVE discovery, blast-radius analysis, and provides remediation guidance. It supports multiple entry points including agent scanning, container image scanning, IaC scanning, and a self-hosted enterprise deployment.

#ai-agents#ai-security#ai-supply-chain#aibom#blast-radius#cloud-security#compliance#container-security
$ Install
$ pip install agent-bom
↗ Visit site★ GitHub
01

Features

01End-to-end blast radius analysis from CVE to credential exposure
02Multi-entrypoint scanning: agents, images, IaC, packages, cloud
03Compliance export (FedRAMP, SOC2, NIST AI RMF, etc.) with tamper-evident evidence bundles
04Self-hosted enterprise deployment with Helm, Postgres, ClickHouse, and Snowflake backends
05Runtime MCP proxy and gateway for traffic enforcement and audit
02

Compatibility

CLI
Command Line Interface
Verified via docs
Docker
Docker Container
Verified via docs
Kubernetes
Kubernetes Helm
Verified via docs
GitHub Actions
GitHub Action
Verified via docs
MCP Server
MCP Server
Verified via docs
03

Quick start

1
$ pip install agent-bom
04

Use cases

↳CI/CD gating for AI supply chain security
↳Security team audit of AI agents and MCP servers
↳Self-hosted enterprise security scanning with fleet management
05

Alternatives

awesome-n8n-templates logo
awesome-n8n-templates★ 22.6k
Supercharge your workflow automation with this curated collection of n8n templates! Instantly connect your favorite apps-like Gmail, Telegram, Google Drive, Slack, and more-with ready-to-use, AI-powered automations. Save time, boost productivity, and unlock the true potential of n8n in just a few clicks.
vs →
FastMCP logo
FastMCP★ 25.4k
The fast, Pythonic way to build MCP servers and clients. Designed by the Pydantic team for type safety and speed.
vs →
agents-best-practices logo
agents-best-practices★ 1.1k
Provider-neutral Agent Skill for Codex, Claude Code, and agentic harness design.
vs →
holaOS logo
holaOS★ 5.4k
The agent environment for long-horizon work, continuity, and self-evolution.
vs →
stackql logo
stackql★ 843
Query, provision and operate Cloud and SaaS resources and APIs using an extensible SQL based framework
vs →
awesome-claude logo
awesome-claude★ 250
HeyClaude is a curated registry and distribution surface for Claude and AI-workflow assets: agents, MCP servers, skills, commands, hooks, rules, guides, tools, jobs, Raycast feeds, static data exports, and an npm MCP package.
vs →
initrunner logo
initrunner★ 38
Define AI agent roles in YAML and run them anywhere: CLI, API server, or autonomous daemon
vs →
thunderbit-mcp-server logo
thunderbit-mcp-server★ 13
AI-powered web scraping and structured data extraction. CLI + MCP server + Claude Code plugin for the Thunderbit Open API.
vs →
See all alternatives →

Related searches

agent-bom AlternativesBest Security & Safety Tools 2026Open Source Security & Safetyagent-bom Tutorialagent-bom Vs Competitorsai-agentsai-securityai-supply-chain

Comments

Log in to leave a comment
  • C
    Corey JohnsonMay 7, 2026

    Security scanner for AI supply chain — agents, MCP, containers, cloud, GPU all covered.

  • M
    Morgan AndersonApr 2, 2026

    Bill of materials approach to AI security is the right model for auditability.

  • K
    Kai JohnsonMar 28, 2026

    Good for security teams who need to understand the AI tooling attack surface.

  • C
    Corey KimMar 6, 2026

    Open-source means the scanning logic is transparent and auditable.

On this page
01Features02Compatibility03Quick start04Use cases05Alternatives
Stats
GitHub Stars★ 20
Last commit2d ago
StatusActive
LicenseApache-2.0
CategorySecurity & Safety
Trend (30d)
+0.8↑ 0.7%
Links
Documentation↗Discussion↗Issues↗Releases↗

Deploy on DigitalOcean — Get $200 Free Credit

Ad
© 2026 AgentIndex.app|Built by a 10-year iOS Developer.
QYSGitHubBuy me a coffee ☕

Browse by Category

Code AssistantWorkflow AutomationRAG / Knowledge BaseMulti-AgentBrowser AutomationLLM InfraDev ToolingObservability

Not affiliated with Anthropic, OpenAI or Microsoft.