Back to updates
New releaseAug 24, 2026

agent-bom v0.102.0

Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.

Share

agent-bom — Discover. Scan. Correlate. Act. Security evidence across repositories, software supply chains, AI and MCP, cloud, identity, and data.

Build PyPI Python 3.11 through 3.14 Docker pulls Apache-2.0 license OpenSSF Scorecard Glama MCP server Smithery MCP server

Open security scanner and self-hosted control plane for AI, MCP, and cloud infrastructure.

Self-host · Deployment models · Quick start · Product tour · Docs

Recorded agent connections linking a role, agents, MCP servers, tool, credential reference, package and finding

agent-bom finds the AI agents, MCP servers, packages and credentials in a repository, workstation or cloud account, matches packages against vulnerability advisories, and connects findings to recorded agent, tool and credential relationships. Run it as a CLI, in CI, as an MCP server for your assistant, or as a self-hosted dashboard. A recorded relationship is evidence to investigate; it does not prove execution or data access. The map above uses labeled sample data. Vertical follows dependencies top to bottom; Horizontal traces the same connections left to right. Compare layouts.

See the same graph horizontally

Horizontal layout of the same nine entities: role to agent to MCP server to package to finding, with tool and credential branches

Start where you work: scan a repository, run the shared dashboard, or connect your assistant. Apache-2.0; the control plane runs in your own environment.

Follow one component: Inventory → component → Findings → Compliance. Keep the exact component and retained snapshot in scope, inspect recorded relationships, and export the loaded evidence. Try the connected-BOM walkthrough.

Self-host in your environment

Your infrastructure, your identity, your database, your audit boundary. From a published release checkout:

git clone --depth 1 --branch v0.107.2 https://github.com/msaad00/agent-bom.git && cd agent-bom
AGENT_BOM_IMAGE_TAG=0.107.2 docker compose up -d

Open http://localhost:3000, then Connections or New Scan. For cloud accounts, add a scoped read-only connection, verify access, then start a scan. The pilot binds to loopback and retains state in a Docker volume. Use the authenticated deployment guide for a shared instance.

Deployment models

Docker pilot · Authenticated deployment · Compose with PostgreSQL · Helm · EKS Terraform · Snowflake Native App preview · Air-gapped bundle · Choose a deployment · Enterprise configuration · Connect cloud accounts

Work with your existing tools

Use CLI or GitHub Action, REST API, or MCP; export SARIF, CycloneDX, SPDX, JSON and HTML. Cloud connectors and fleet sync collect inventory; proxy and gateway deployments add runtime evidence.

Integration capability matrix · MCP client setup · Proxy, gateway and fleet · Smithery setup and manifest

Quick start

Scan a repository and keep the evidence:

pip install agent-bom
agent-bom scan . -f json -o scan.json

Open scan.json for findings and assessment coverage. For pull requests, use agent-bom scan . -f sarif -o findings.sarif and upload the artifact in CI.

For sample inventory and an exact graph link, run agent-bom quickstart --run --offline. It skips package-CVE lookup; use the bundled demo for advisory-backed examples. Follow the first-run handoff.

No project handy? Scan the bundled sample estate offline

Categories