Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
agent-bom — Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC. | Kitploit
उपकरण/GitHubGitHub/msaad00/agent-bom
Vulnerability ScannersContainer SecurityCloud SecurityDevSecOpsSecret DetectionThreat IntelligenceSupply Chain SecurityMisconfigurationAI Security
GitHubmsaad00/agent-bom

agent-bom

Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.

297311घं 39मि पहलेKitploit द्वारा समीक्षित
रिपॉजिटरी देखेंवेबसाइट

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

agent-bom — Discover. Scan. Correlate. Act. Security evidence across repositories, software supply chains, AI and MCP, cloud, identity, and data.

Build PyPI Python 3.11 through 3.14 Docker pulls Apache-2.0 license OpenSSF Scorecard Glama MCP server Smithery MCP server

Open security scanner and self-hosted control plane for AI, MCP, and cloud infrastructure.

Self-host · Deployment models · Quick start · Product tour · Docs

Recorded agent connections linking a role, agents, MCP servers, tool, credential reference, package and finding

agent-bom finds the AI agents, MCP servers, packages and credentials in a repository, workstation or cloud account, matches packages against vulnerability advisories, and connects findings to recorded agent, tool and credential relationships. Run it as a CLI, in CI, as an MCP server for your assistant, or as a self-hosted dashboard. A recorded relationship is evidence to investigate; it does not prove execution or data access. The map above uses labeled sample data. Light view · Dark view.

Start where you work: scan a repository, run the shared dashboard, or connect your assistant. Apache-2.0; the control plane runs in your own environment.

Self-host in your environment

Your infrastructure, your identity, your database, your audit boundary. From a published release checkout:

git clone --depth 1 --branch v0.106.1 https://github.com/msaad00/agent-bom.git && cd agent-bom
AGENT_BOM_IMAGE_TAG=0.106.1 docker compose up -d

Open http://localhost:3000, then Connections or New Scan. For cloud accounts, add a scoped read-only connection, verify access, then start a scan. The pilot binds to loopback and retains state in a Docker volume. Use the authenticated deployment guide for a shared instance.

Deployment models

Docker pilot · Authenticated deployment · Compose with PostgreSQL · Helm · EKS Terraform · Snowflake Native App preview · Air-gapped bundle · Choose a deployment · Enterprise configuration · Connect cloud accounts

Work with your existing tools

Use CLI or GitHub Action, REST API, or MCP; export SARIF, CycloneDX, SPDX, JSON and HTML. Cloud connectors and fleet sync collect inventory; proxy and gateway deployments add runtime evidence.

Integration capability matrix · MCP client setup · Proxy, gateway and fleet · Smithery setup and manifest

Quick start

Scan a repository and keep the evidence:

pip install agent-bom
agent-bom scan . -f json -o scan.json

Open scan.json for findings and assessment coverage. For pull requests, use agent-bom scan . -f sarif -o findings.sarif and upload the artifact in CI.

No project handy? Scan the bundled sample estate offline

agent-bom scan --demo --offline lists sample agents, CVEs with recorded agent, MCP server and credential associations, and policy findings (excerpt from current source; installed-release output may differ):

  Security posture:   CRIT  7   HIGH  10   MED   6 · all finding categories
  5 agents · 10 servers · 23 packages
DISCOVER | Agents
  Agent                Type              Servers    Pkgs    Creds    Vulns
  langchain-service    custom                  2       4        4        4
  claude-desktop       claude-desktop          2       6        3        5
ANALYZE | Critical Details
  CVE-2023-36258 · [email protected] · CRITICAL
  Fix: upgrade to ≥ 0.0.247
  Blast: langchain-service → llm-orchestrator-server → ANTHROPIC_API_KEY, OPENAI_API_KEY
ANALYZE | Graph & Policy Findings (8 occurrences)
   CRIT  COMBINATION AI agent can reach a credential or privileged tool: langchain-service
   HIGH  PROMPT_SECURITY Agent calls MCP server without verified identity
   MED   PROMPT_SECURITY Long-lived static credential on MCP server

The sample deliberately triggers a security gate (exit 1). Save CI evidence with agent-bom scan . -f sarif -o findings.sarif; check setup with agent-bom doctor. First-run guide · GitHub Action

टूल डाउनलोड करें