agent-bom registry
MCP server security registry and trust assessment — look up servers in the 1081-entry server security metadata registry, run pre-install marketplace checks, batch fleet risk scorin…
Agent Bom
@msaad00
What This Skill Does
Security registry and trust assessment tool for MCP servers. Looks up servers in a bundled 1013-entry metadata registry, runs pre-install marketplace checks, batch fleet risk scoring, skill file trust analysis, and SAST code scans via Semgrep. No network calls or API keys required for core functionality.
Replaces manual security vetting of MCP servers by providing a bundled registry with trust scores, marketplace cross-references, and automated code scanning in a single offline tool.
When to Use It
- Look up an MCP server's security metadata before installing it
- Run a pre-install trust check on a package from the MCP marketplace
- Batch scan and risk-score an inventory of MCP servers in your fleet
- Assess the trust level of a skill file (SKILL.md) for security posture
- Scan instruction files for package references and security findings
- Run SAST code scanning with CWE-based compliance mapping on MCP server code
Install
$ openclaw skills install @msaad00/agent-bom-registryagent-bom-registry — MCP Server Trust & Security Registry
Look up MCP servers in the 1081-entry server security metadata registry, assess skill file trust, and run pre-install marketplace checks.
Install
pipx install agent-bom
agent-bom mcp scan @modelcontextprotocol/server-brave-search --ecosystem npm
agent-bom mcp scan @modelcontextprotocol/server-filesystem --ecosystem npm
Tools (7)
| Tool | Description |
|---|---|
registry_lookup | Look up MCP server in the 1081-entry security metadata registry |
marketplace_check | Pre-install trust check with registry cross-reference |
fleet_scan | Batch registry lookup + risk scoring for MCP server inventories |
skill_scan | Scan instruction files for package refs, trust, and findings |
skill_verify | Verify Sigstore provenance for instruction files |
skill_trust | Assess skill file trust level (5-category analysis) |
code_scan | SAST scanning via Semgrep with CWE-based compliance mapping |
Example Workflows
# Look up a server in the registry
registry_lookup(server_name="brave-search")
# Pre-install trust check
marketplace_check(package="@modelcontextprotocol/server-filesystem")
# Scan instruction files and then assess a specific skill file
skill_scan(path=".")
skill_trust(skill_path="./SKILL.md")
# Batch risk scoring
fleet_scan(servers=["brave-search", "github", "slack"])
MCP Resources
| Resource | Description |
|---|---|
registry://servers | Browse the 1081-entry MCP server security metadata registry |
Privacy & Data Handling
Registry data is bundled in the package — lookups are in-memory string matches with zero network calls. Skill trust analysis parses content passed as a string argument (no file system access needed).
Verification
- Source: github.com/msaad00/agent-bom (Apache-2.0)
- 7,100+ tests with CodeQL + OpenSSF Scorecard
- No telemetry: Zero tracking, zero analytics
Top skills in this category
Superpowers Dev Workflow
@wlshlad85Spec-first, TDD, subagent-driven software development workflow. Use when: (1) building any new feature or app — triggers brainstorm → plan → subagent executi...
Skill Vetter
@spclaudehomeSecurity-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
Agent Browser
@matrixyHeadless browser automation CLI optimized for AI agents with accessibility tree snapshots and ref-based element selection
Free Ride - Unlimited free AI
@shaivpidadiManages free AI models from OpenRouter for OpenClaw. Automatically ranks models by quality, configures fallbacks for rate-limit handling, and updates opencla...
Clawdhub
@steipeteUse the ClawdHub CLI to search, install, update, and publish agent skills from clawdhub.com. Use when you need to fetch new skills on the fly, sync installed skills to latest or a specific version, or publish new/updated skill folders with the npm-installed clawdhub CLI.