Open security scanner and self-hosted control plane for AI, MCP, and cloud infrastructure.
Headless agent primitives and human cockpit surfaces over one shared evidence model.
Docs · First Run · Self-host · GitHub Action · Docker · Changelog
What It Is
agent-bom is a read-only scanner and self-hosted control plane for local
projects, agent fleets, MCP runtimes, and cloud estates (AWS, Azure, GCP,
Snowflake).
ContextGraph is agent-bom's unified evidence graph across CLI, API, UI, MCP tools, reports, and gateway decisions. Findings, assets, packages, cloud resources, identities, agents, MCP servers, credentials, and runtime decisions all normalize into that graph so posture, blast radius, and enforcement read from the same evidence.
Blast radius is the core idea: a vulnerable package is linked to the MCP server that loads it, the tools it exposes, reachable credential references, and the agents that can call it — not just a CVE row.
Coverage depth and honest boundaries: AI infrastructure scanning · product boundaries






