Terravision Cloud Diagrams
patrickchugh/terravision
Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.
Open security platform for agentic infrastructure — broad scanning plus MCP discovery, CVEs, blast radius, SBOMs, CIS benchmarks (AWS, Azure, GCP, Snowflake), OWASP/NIST/MITRE compliance, AISVS…
$ npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills agent-bom --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/agent-bom .claude/skills/agent-bom && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "agent-bom" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/agent-bom into .claude/skills/agent-bom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-bom", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/agent-bomType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills agent-bom --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/agent-bom .agents/skills/agent-bom && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "agent-bom" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/agent-bom into .agents/skills/agent-bom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-bom", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills agent-bom --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/agent-bom .cursor/skills/agent-bom && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "agent-bom" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/agent-bom into .cursor/skills/agent-bom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-bom", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/LeoYeAI/openclaw-master-skills.git --path skills/agent-bom--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills agent-bom --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/agent-bom .gemini/skills/agent-bom && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "agent-bom" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/agent-bom into .gemini/skills/agent-bom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-bom", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install LeoYeAI/openclaw-master-skills agent-bomInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/agent-bom .github/skills/agent-bom && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "agent-bom" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/agent-bom into .github/skills/agent-bom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-bom", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills agent-bom --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/agent-bom .opencode/skills/agent-bom && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "agent-bom" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/agent-bom into .opencode/skills/agent-bom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-bom", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
agent-bomOpen security platform for agentic infrastructure — broad scanning plus MCP discovery, CVEs, blast radius, SBOMs, CIS benchmarks (AWS, Azure, GCP, Snowflake), OWASP/NIST/MITRE compliance, AISVS…
Agent Bom is an agent skill from LeoYeAI/openclaw-master-skills. Open security platform for agentic infrastructure — broad scanning plus MCP discovery, CVEs, blast radius, SBOMs, CIS benchmarks (AWS, Azure, GCP, Snowflake), OWASP/NIST/MITRE compliance, AISVS v1.0, MAESTRO layer tagging, and vector database security checks. Use when the user mentions vulnerability scanning, MCP server trust, compliance, SBOM generation, CIS benchmarks, blast radius, or AI supply chain risk.
Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `_meta.json`). Compatibility notes: Requires Python 3.11+. Install via pipx or pip. No credentials required for basic scanning. Native container image scanning — no external scanner required…
It sits in Security, covering Supply chain security, Vulnerability scanning and Data warehousing. It works with Model Context Protocol, Microsoft Azure, Amazon Web Services and Google Cloud. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pipxpipFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires Python 3.11+. Install via pipx or pip. No credentials required for basic scanning. Native container image scanning — no external scanner required. CIS benchmark checks optionally use cloud SDK credentials (AWS/Azure/GCP/Snowflake).
From compatibility in the SKILL.md frontmatter.
Agent Bom loads about 4.4k tokens when it runs. Until then it costs about 106 tokens; SKILL.md has 845 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its Apache-2.0 licence (© LeoYeAI). 845 words, ~4,374 tokens.
.claude/skills/agent-bom/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Discovers MCP clients and servers across 22 AI tools, scans for CVEs, maps blast radius, runs cloud CIS benchmarks, checks OWASP/NIST/MITRE compliance, generates SBOMs, and assesses AI infrastructure against AISVS v1.0 and MAESTRO framework layers.
pipx install agent-bom
agent-bom agents # auto-discover + scan
agent-bom check langchain==0.1.0 # check a specific package with version
agent-bom fs . # scan filesystem packages
agent-bom image nginx:1.25 # scan container image (native)
agent-bom cloud aws # AWS CIS benchmark
agent-bom iac infra/ # scan Terraform/CloudFormation
agent-bom where # show all discovery paths{
"mcpServers": {
"agent-bom": {
"command": "uvx",
"args": ["agent-bom", "mcp"]
}
}
}| Sub-Skill | Purpose | Triggers |
|---|---|---|
| discover | Find agents, MCP servers, configurations | "find agents", "what's configured", "mcp inventory" |
| scan | CVE scanning, image scanning, SBOM, provenance | "check package", "scan image", "verify", "blast radius" |
| scan-infra | IaC, cloud config, secrets scanning | "check terraform", "scan kubernetes", "find secrets" |
| enforce | Runtime policy enforcement, MCP proxy | "block risky calls", "apply policy", "proxy" |
| compliance | 11-framework compliance, SBOM generation | "compliance report", "NIST", "SOC 2", "OWASP" |
| monitor | Fleet monitoring, trust scores, lifecycle | "fleet", "watch agents", "trust scores" |
| analyze | Blast radius, attack paths, context graph | "blast radius", "threat intel", "attack path" |
| troubleshoot | Diagnostics, doctor, config validation | "doctor", "debug", "why failing", "validate config" |
| Tool | Description |
|---|---|
scan | Full discovery + vulnerability scan pipeline |
check | Check a package for CVEs (OSV, NVD, EPSS, KEV) |
blast_radius | Map CVE impact chain across agents, servers, credentials |
remediate | Prioritized remediation plan for vulnerabilities |
verify | Package integrity + SLSA provenance check |
diff | Compare two scan reports (new/resolved/persistent) |
where | Show MCP client config discovery paths |
inventory | List discovered agents, servers, packages |
| Tool | Description |
|---|---|
compliance | OWASP LLM/Agentic Top 10, EU AI Act, MITRE ATLAS, NIST AI RMF |
policy_check | Evaluate results against custom security policy (17 conditions) |
cis_benchmark | CIS benchmark checks (AWS, Azure v3.0, GCP v3.0, Snowflake) |
generate_sbom | Generate SBOM (CycloneDX or SPDX format) |
aisvs_benchmark | OWASP AISVS v1.0 compliance — 9 AI security checks |
| Tool | Description |
|---|---|
registry_lookup | Look up MCP server in 427+ server security metadata registry |
marketplace_check | Pre-install trust check with registry cross-reference |
fleet_scan | Batch registry lookup + risk scoring for MCP server inventories |
skill_trust | Assess skill file trust level (5-category analysis) |
code_scan | SAST scanning via Semgrep with CWE-based compliance mapping |
| Tool | Description |
|---|---|
context_graph | Agent context graph with lateral movement analysis |
analytics_query | Query vulnerability trends, posture history, and runtime events |
runtime_correlate | Cross-reference proxy audit JSONL with CVE findings, risk amplification |
vector_db_scan | Probe Qdrant/Weaviate/Chroma/Milvus for auth and exposure |
gpu_infra_scan | GPU container and K8s node inventory + unauthenticated DCGM probe (MAESTRO KC6) |
| Tool | Description |
|---|---|
dataset_card_scan | Scan dataset cards for bias, licensing, and provenance issues |
training_pipeline_scan | Scan training pipeline configs for security risks |
browser_extension_scan | Scan browser extensions for risky permissions and AI domain access |
model_provenance_scan | Verify model provenance and supply chain integrity |
prompt_scan | Scan prompt templates for injection and data leakage risks |
model_file_scan | Scan model files for unsafe serialization (pickle, etc.) |
license_compliance_scan | Full SPDX license catalog scan with copyleft and network-copyleft detection |
ingest_external_scan | Import external scan results (CycloneDX/SPDX/JSON) and merge into agent-bom findings |
| Resource | Description |
|---|---|
registry://servers | Browse 427+ MCP server security metadata registry |
# Check a package before installing
check(package="@modelcontextprotocol/server-filesystem", ecosystem="npm")
# Map blast radius of a CVE
blast_radius(cve_id="CVE-2024-21538")
# Full agent discovery + scan
agents()
# Run CIS benchmark
cis_benchmark(provider="aws")
# Run AISVS v1.0 compliance
aisvs_benchmark()
# Scan vector databases for auth misconfigurations
vector_db_scan()
# Discover GPU containers, K8s GPU nodes, and unauthenticated DCGM endpoints
gpu_infra_scan()
# Assess trust of a skill file
skill_trust(skill_content="<paste SKILL.md content>")Always do:
unknown — a CVE ID with no details is still a real finding. Report what is known; mark severity as unknown explicitly.cis_benchmark) — these make live API calls to AWS/Azure/GCP using the user's credentials.UNKNOWN severity as unresolved, not benign — it means data is not yet available, not that the issue is minor.Never do:
agents() autonomously on sensitive environments without user confirmation. The autonomous_invocation policy is restricted.Stop and ask the user when:
CRITICAL CVEs — present findings and ask whether to generate a remediation plan.This skill installs agent-bom from PyPI. Verify the redaction behavior before running with any config files:
# Step 1: Install
pip install agent-bom
# Step 2: Review redaction logic BEFORE scanning
# sanitize_env_vars() replaces ALL env var values with ***REDACTED***
# BEFORE any config data is processed or stored:
# https://github.com/msaad00/agent-bom/blob/main/src/agent_bom/security.py#L159
# Step 3: Review config parsing — only structural data extracted:
# https://github.com/msaad00/agent-bom/blob/main/src/agent_bom/discovery/__init__.py
# Step 4: Verify package provenance (Sigstore)
agent-bom verify agent-bom
# Step 5: Only then run scans
agent-bom agentsWhat is extracted: Server names, commands, args, and URLs from MCP client
config files across 22 AI tools. What is NOT extracted: Env var values are
replaced with ***REDACTED*** by sanitize_env_vars() before any processing.
Only public package names and CVE IDs are sent to vulnerability databases.
Cloud CIS checks use locally configured credentials and call only the cloud
provider's own APIs.
agent-bom verify agent-bom@0.75.10© LeoYeAI, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/agent-bom of LeoYeAI/openclaw-master-skills.
Open the folder on GitHubat commit e5199b5
Agent Bom next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Agent Bom this skillLeoYeAI/openclaw-master-skills | 2.2k | — | ~4.4k | Automated safety check: Pass | Apache-2.0 | |
| Terravision Cloud Diagramspatrickchugh/terravision | 1.6k | — | ~5.6k | Automated safety check: Notes | AGPL-3.0-only | |
| Spotinfoalexei-led/spotinfo | 164 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Drawio MCP Diagrammingthomast1906/github-copilot-agent-skills | 202 | — | ~6.6k | Automated safety check: Pass | None | |
| Migrating To Amazon Redshiftaws/agent-toolkit-for-aws | 2.8k | — | ~2.7k | Automated safety check: Notes | Apache-2.0 | |
| Skill InspectorNVIDIA/SkillSpector | 20k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 |
patrickchugh/terravision
Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.
alexei-led/spotinfo
Query Spot/preemptible VM prices, savings and interruption risk across AWS, GCP and Azure with the spotinfo CLI.
thomast1906/github-copilot-agent-skills
Create and edit diagrams using the Draw.io MCP server — any shape, any vendor.
aws/agent-toolkit-for-aws
Guides an end-to-end data-warehouse migration to Amazon Redshift — discovery, schema/SQL/stored-procedure/macro/script conversion, data migration, validation, performance comparison, and reporting.
NVIDIA/SkillSpector
Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.
vulnersCom/api
A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK.
LeoYeAI/openclaw-master-skills
Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.
LeoYeAI/openclaw-master-skills
Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.
LeoYeAI/openclaw-master-skills
Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.
LeoYeAI/openclaw-master-skills
Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.
LeoYeAI/openclaw-master-skills
Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.
LeoYeAI/openclaw-master-skills
Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.
Categories
Open security platform for agentic infrastructure — broad scanning plus MCP discovery, CVEs, blast radius, SBOMs, CIS benchmarks (AWS, Azure, GCP, Snowflake), OWASP/NIST/MITRE compliance, AISVS…. Agent Bom is an agent skill from LeoYeAI/openclaw-master-skills.0, MAESTRO layer tagging, and vector database security checks.
Agent Bom fits situations like: the user mentions vulnerability scanning; MCP server trust; SBOM generation; AI supply chain risk.
Run `npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom -a claude-code`. Or copy the skill folder (skills/agent-bom in LeoYeAI/openclaw-master-skills) into .claude/skills/agent-bom in your project. Claude Code loads it when a task matches its description.
Run `npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom -a codex`. Or copy the skill folder (skills/agent-bom in LeoYeAI/openclaw-master-skills) into .agents/skills/agent-bom in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/agent-bom, .gemini/skills/agent-bom, .github/skills/agent-bom and .opencode/skills/agent-bom in your project.
Going by SKILL.md and its folder, Agent Bom needs the command-line tools its instructions call (pipx and pip). Our summary lists: Python 3; Docker; A credential in SNYK_TOKEN; A credential in AZURE_CLIENT_SECRET. Compatibility (from SKILL.md): Requires Python 3.11+. Install via pipx or pip. No credentials required for basic scanning. Native container image scanning — no external scanner required. CIS benchmark checks optionally use cloud SDK credentials (AWS/Azure/GCP/Snowflake)..
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Agent Bom is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.4k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Agent Bom: Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars), Spotinfo (alexei-led/spotinfo, 164 stars), Drawio MCP Diagramming (thomast1906/github-copilot-agent-skills, 202 stars) and Migrating To Amazon Redshift (aws/agent-toolkit-for-aws, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,160 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.
Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.