agent-bom ingest
Validate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure, GCP, Snowflake, CMDB, or endpoint collectors. Use when a user has canonical inventory JSON and wants l…
Agent Bom
@msaad00
What This Skill Does
Validates and ingests operator-pushed agent-bom inventory JSON from AWS, Azure, GCP, Snowflake, CMDB, or endpoint collectors, then produces local findings, graphs, policy checks, provenance records, and auditor-ready exports without requiring cloud credentials.
Replaces giving agent-bom direct cloud credentials by allowing operators to push canonical inventory JSON for local validation, scanning, and export.
When to Use It
- Validate an operator-generated inventory JSON file against the packaged schema before analysis
- Scan local inventory JSON to produce findings in SARIF format for CI/CD gates
- Export inventory graph as JSON for API consumption or automation workflows
- Generate HTML or Markdown reports from inventory for human review
- Produce CycloneDX or SPDX SBOM exports from validated inventory for compliance
Install
$ openclaw skills install @msaad00/agent-bom-ingestagent-bom-ingest
Use this skill when the operator already produced canonical inventory JSON with an operator-pull adapter, endpoint collector, CMDB export, or AI-agent workflow. The default path is local validation plus local scan/export.
Guardrails
- Validate inventory with the packaged schema before treating it as evidence.
- Require
discovery_provenanceandpermissions_usedwhere the source claims cloud/operator-pushed discovery. - Require a trustworthy
discovery_provenance.source_typesuch asoperator_pushed_inventoryorskill_invoked_pull; do not infer it from prose. - Do not invent provenance, permissions, cloud scopes, or credential posture.
- Do not push to a control plane unless the operator provides the destination URL and auth method explicitly.
- Do not print raw tokens, URL credentials, private keys, or env var values.
Workflow
Validate first:
agent-bom mcp validate inventory.json
Scan locally:
agent-bom scan --inventory inventory.json --format json --output agent-bom-findings.json
Choose output by consumer:
- SARIF for CI/code-scanning gates
- JSON for graph, API, and automation
- HTML or Markdown for human review
- CycloneDX/SPDX for SBOM consumers
Evidence Contract
Valid inventory preserves discovery_provenance, permissions_used,
cloud_origin, redaction state, package identity, server identity, tools, and
security intelligence. If the inventory is malformed or missing required trust
fields, stop and ask the operator to regenerate it rather than scanning a
best-effort summary.
Top skills in this category
API Gateway
@byungkyuCall third-party APIs through the Maton gateway, which injects the credential for an app the user has already connected. Use this skill when the user names a connected app and a concrete action in it - read a mailbox, query a CRM, file an issue, update a spreadsheet, run a query through a connected
Marketing Mode
@thesethroseMarketing Mode combines 23 comprehensive marketing skills covering strategy, psychology, content, SEO, conversion optimization, and paid growth. Use when users need marketing strategy, copywriting, SEO help, conversion optimization, paid advertising, or any marketing tactic.
Blogwatcher
@steipeteMonitor blogs and RSS/Atom feeds for updates using the blogwatcher CLI.
Marketing Skills
@jchopard69Access 23 marketing modules offering checklists, frameworks, and ready-to-use deliverables for CRO, SEO, copywriting, analytics, launches, ads, and social me...
diagram-generator
@matthewyinGenerate and edit diagrams with the mcp-diagram-generator MCP server. Use this skill for new diagrams, existing .drawio/.mmd/.excalidraw edits, network topology, architecture, flowchart, swimlane, sequence, class, ER, and Excalidraw whiteboard work. Always use this skill when the user asks to draw,