mySoftwareGuide

Safe & trusted downloads

The best software, verified by experts

Icon of program: agent-bom

agent-bom for

<h2>agent-bom: Open-source BOM scanner for MCP AI infrastructures</h2>

  • Free
  • 4.7
  • V v0.98.3

<h2>agent-bom: Open-source BOM scanner for MCP AI infrastructures</h2>

agent-bom, developed by Msaad00, is an open-source security scanner focused on providing visibility for Model Context Protocol infrastructure and agent fleets. The tool produces a machine-readable AI Bill of Materials while helping teams detect configuration and dependency risks during development and runtime. It targets security engineers and DevOps responsible for agent deployments, and supports self-hosted operation so organizations keep sensitive security data under their own control.

What tasks can you actually use it for?

agent-bom is built to map and track AI components across local and distributed deployments. Its practical tasks include:

  • automatic discovery and inventory of local agents and MCP servers;
  • repository and container image analysis for security findings;
  • Infrastructure-as-Code checks for Terraform and CloudFormation templates;
  • runtime gateway functions to observe and intervene in agent execution.

How accurate and actionable are its security findings?

The tool combines static analysis of code and images with runtime monitoring, producing vulnerability reports and compliance evidence via queryable outputs. Findings are exposed through a REST API and CLI for automation, and a dashboard for human review. The project is actively maintained within its niche community, which helps scanning rules stay current; however, the usefulness of any single finding depends on source quality and correct environment configuration.

Does it fit existing CI/CD and deployment workflows?

agent-bom provides multiple integration points: a command-line interface, a REST API, and a Docker container image that integrates with GitHub Actions and Docker-based pipelines. These interfaces let teams add checks into build and deployment stages. The developer notes compatibility with MCP-based agents specifically, so teams must align deployment patterns with that ecosystem to extract full value.

What privacy and operational controls does it offer?

The project is open-source and designed for self-hosted deployment, enabling teams to retain security data inside their infrastructure. It can be configured to scan private GitHub and GitLab repositories and runs a runtime gateway that acts as an intermediary to monitor agent activity and enforce policies during execution. That design puts operational control with the customer rather than an external service.

Best suited to teams standardizing on MCP deployments

agent-bom is a practical option for security engineers and DevOps teams who need machine-readable inventory and policy control for MCP agent fleets. Its utility is strongest where MCP adoption is established, and organizations using alternative agent platforms should assess compatibility before committing to deployment. Use it as a source of automated evidence alongside manual review in security workflows.

  • Pros

    • Generates an AI Bill of Materials listing agents, tools, and credentials
    • Scans Terraform and CloudFormation templates for IaC misconfigurations
    • Provides a runtime gateway to monitor and control agent behavior
    • Self-hosted deployment via Docker keeps security data on your infrastructure
  • Cons

    • Designed primarily for MCP environments, limiting non‑MCP applicability
    • Self-hosting requires internal operations and ongoing maintenance
    • CI/CD focus on GitHub Actions and Docker requires pipeline adaptation
Icon of program: agent-bom

agent-bom for

  • Free
  • 4.7
  • V v0.98.3