
agent-bom v0.102.0
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Open security scanner and self-hosted control plane for AI, MCP, and cloud infrastructure.
Self-host · Deployment models · Quick start · Product tour · Docs
agent-bom finds the AI agents, MCP servers, packages and credentials in a repository, workstation or cloud account, matches packages against vulnerability advisories, and connects findings to recorded agent, tool and credential relationships. Run it as a CLI, in CI, as an MCP server for your assistant, or as a self-hosted dashboard. A recorded relationship is evidence to investigate; it does not prove execution or data access. The map above uses labeled sample data. Vertical follows dependencies top to bottom; Horizontal traces the same connections left to right. Compare layouts.
Start where you work: scan a repository, run the shared dashboard, or connect your assistant. Apache-2.0; the control plane runs in your own environment.
Follow one component: Inventory → component → Findings → Compliance. Keep the exact component and retained snapshot in scope, inspect recorded relationships, and export the loaded evidence. Try the connected-BOM walkthrough.
Self-host in your environment
Your infrastructure, your identity, your database, your audit boundary. From a published release checkout:
git clone --depth 1 --branch v0.107.2 https://github.com/msaad00/agent-bom.git && cd agent-bom
AGENT_BOM_IMAGE_TAG=0.107.2 docker compose up -d
Open http://localhost:3000, then Connections or New Scan. For cloud accounts, add a scoped read-only connection, verify access, then start a scan. The pilot binds to loopback and retains state in a Docker volume. Use the authenticated deployment guide for a shared instance.
Deployment models
Docker pilot · Authenticated deployment · Compose with PostgreSQL · Helm · EKS Terraform · Snowflake Native App preview · Air-gapped bundle · Choose a deployment · Enterprise configuration · Connect cloud accounts
Work with your existing tools
Use CLI or GitHub Action, REST API, or MCP; export SARIF, CycloneDX, SPDX, JSON and HTML. Cloud connectors and fleet sync collect inventory; proxy and gateway deployments add runtime evidence.
Integration capability matrix · MCP client setup · Proxy, gateway and fleet · Smithery setup and manifest
Quick start
Scan a repository and keep the evidence:
pip install agent-bom
agent-bom scan . -f json -o scan.json
Open scan.json for findings and assessment coverage. For pull requests, use agent-bom scan . -f sarif -o findings.sarif and upload the artifact in CI.
For sample inventory and an exact graph link, run agent-bom quickstart --run --offline. It skips package-CVE lookup; use the bundled demo for advisory-backed examples. Follow the first-run handoff.

