Agent skill

Agent Bom Compliance

by LeoYeAI in LeoYeAI/openclaw-master-skills

AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.

Apache-2.0Auto-check passedLegal & Compliance

Install Agent Bom Compliance

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills agent-bom-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/agent-bom/compliance .claude/skills/agent-bom-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
agent-bom-compliance
GitHub stars
2.2k
Token cost
~1.9k tokens
SKILL.md length
332 words
Files
1
Skills in repo
1,235
Repo updated
First seen
Licence
Apache-2.0

At a glance

AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.

  • : compliance report
  • SKILL.md covers Install, When to Use, Tools (5) and Supported Frameworks (14), plus 3 more sections
  • Calls pipx
  • Tasks that involve SOC 2 and security compliance

What it does

Agent Bom Compliance is an agent skill from LeoYeAI/openclaw-master-skills. AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks. Generate SBOMs and compliance reports. Use when: "compliance report", "NIST", "SOC 2", "ISO 27001", "OWASP", "EU AI Act", "AISVS", "generate SBOM", "policy check".

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires Python 3.11+. Install via pipx or pip. OWASP/NIST/EU AI Act/MITRE evaluation and SBOM generation are fully local with zero credentials. CIS benchmark…

It sits in Legal & Compliance, covering SOC 2 and security compliance, AI governance and Supply chain security. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is Apache-2.0.

When your agent uses it

  • : compliance report
  • Tasks that involve SOC 2 and security compliance
  • Tasks that involve AI governance

Example prompts

  • “compliance report”
  • “ISO 27001”
  • “EU AI Act”
  • “/agent-bom-compliance”

Requirements

  • Python 3
  • Docker
  • A credential in AZURE_CLIENT_SECRET
  • Compatibility (from SKILL.md): Requires Python 3.11+. Install via pipx or pip. OWASP/NIST/EU AI Act/MITRE evaluation and SBOM generation are fully local with zero credentials. CIS benchmark checks optionally use cloud SDK credentials (AWS/Azure/GCP/Snowflake) and make read-only API calls to cloud providers when explicitly invoked.

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pipx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Python 3.11+. Install via pipx or pip. OWASP/NIST/EU AI Act/MITRE evaluation and SBOM generation are fully local with zero credentials. CIS benchmark checks optionally use cloud SDK credentials (AWS/Azure/GCP/Snowflake) and make read-only API calls to cloud providers when explicitly invoked.

    From compatibility in the SKILL.md frontmatter.

Context cost

Agent Bom Compliance loads about 1.9k tokens when it runs. Until then it costs about 83 tokens; SKILL.md has 332 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~83
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its Apache-2.0 licence (© LeoYeAI). 332 words, ~1,869 tokens.

Download SKILL.mdSave it as .claude/skills/agent-bom-compliance/SKILL.md (or your agent's skills folder).
name
agent-bom-compliance
description
AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks. Generate SBOMs and compliance reports. Use when: "compliance report", "NIST", "SOC 2", "ISO 27001", "OWASP", "EU AI Act", "AISVS", "generate SBOM", "policy check".
compatibility
Requires Python 3.11+. Install via pipx or pip. OWASP/NIST/EU AI Act/MITRE evaluation and SBOM generation are fully local with zero credentials. CIS benchmark checks optionally use cloud SDK credentials (AWS/Azure/GCP/Snowflake) and make read-only API calls to cloud providers when explicitly invoked.
version
0.75.10
license
Apache-2.0
metadata.author
msaad00
metadata.homepage
https://github.com/msaad00/agent-bom
metadata.source
https://github.com/msaad00/agent-bom
metadata.pypi
https://pypi.org/project/agent-bom/
metadata.scorecard
https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom
metadata.tests
6533

agent-bom-compliance — AI Compliance & Policy Engine

Evaluate AI infrastructure scan results against 14 security and regulatory frameworks. Enforce policy-as-code rules. Generate SBOMs in standard formats. Run AISVS v1.0 and CIS benchmark checks.

Install

bash
pipx install agent-bom
agent-bom agents -f compliance-export  # run agents scan with compliance export
agent-bom generate-sbom                # generate CycloneDX SBOM

When to Use

  • "compliance report" / "run compliance"
  • "NIST" / "NIST AI RMF" / "NIST CSF" / "NIST 800-53"
  • "SOC 2" / "SOC2"
  • "ISO 27001"
  • "OWASP" / "OWASP LLM Top 10" / "OWASP Agentic Top 10"
  • "EU AI Act"
  • "AISVS" / "AI Security Verification Standard"
  • "CMMC" / "FedRAMP"
  • "generate SBOM" / "CycloneDX" / "SPDX"
  • "policy check" / "policy enforcement"

Tools (5)

ToolDescription
complianceOWASP LLM/Agentic Top 10, EU AI Act, MITRE ATLAS, NIST AI RMF
policy_checkEvaluate results against custom security policy (17 conditions)
cis_benchmarkRun CIS benchmark checks against cloud accounts
generate_sbomGenerate SBOM (CycloneDX or SPDX format)
aisvs_benchmarkOWASP AISVS v1.0 compliance — 9 AI security checks

Supported Frameworks (14)

  • OWASP LLM Top 10 (2025) — prompt injection, supply chain, data leakage
  • OWASP MCP Top 10 — MCP-specific security risks
  • OWASP Agentic Top 10 — tool poisoning, rug pulls, credential theft
  • OWASP AISVS v1.0 — AI Security Verification Standard (9 checks)
  • MITRE ATLAS — adversarial ML threat framework
  • NIST AI RMF — govern, map, measure, manage lifecycle
  • NIST CSF 2.0 — identify, protect, detect, respond, recover
  • NIST 800-53 Rev 5 — federal security controls (CM-8, RA-5, SI-2, SR-3)
  • FedRAMP Moderate — derived from NIST 800-53 controls
  • EU AI Act — risk classification, transparency, SBOM requirements
  • ISO 27001:2022 — information security controls (Annex A)
  • SOC 2 — Trust Services Criteria
  • CIS Controls v8 — implementation groups IG1/IG2/IG3
  • CMMC 2.0 — cybersecurity maturity model (Level 1-3)

Examples

# Run compliance check against multiple frameworks
compliance(frameworks=["owasp_llm", "eu_ai_act", "nist_ai_rmf"])

# Enforce custom policy
policy_check(policy={"max_critical": 0, "max_high": 5})

# Generate SBOM
generate_sbom(format="cyclonedx")

# Run AISVS v1.0 compliance
aisvs_benchmark()

# Run AWS CIS benchmark
cis_benchmark(provider="aws")

Privacy & Data Handling

OWASP, NIST, EU AI Act, MITRE ATLAS, AISVS, SBOM generation, and policy checks run entirely locally on scan data already in memory. No network calls, no credentials needed for these features.

CIS benchmark checks (optional, user-initiated) call cloud provider APIs using your locally configured credentials. These are read-only API calls to AWS, Azure, GCP, or Snowflake. You must explicitly run cis_benchmark(provider=...) and confirm before any cloud API calls are made.

Verification

  • Source: github.com/msaad00/agent-bom (Apache-2.0)
  • 6,533+ tests with CodeQL + OpenSSF Scorecard
  • No telemetry: Zero tracking, zero analytics

© LeoYeAI, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/agent-bom/compliance of LeoYeAI/openclaw-master-skills.

Open the folder on GitHubat commit e5199b5

Compare with similar skills

Agent Bom Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Agent Bom Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Agent Bom Compliance this skillLeoYeAI/openclaw-master-skills2.2k—~1.9kAutomated safety check: PassApache-2.0
AI GovernanceHack23/cia239—~1.4kAutomated safety check: PassApache-2.0
Moai Ref Secopsmodu-ai/moai-adk1.2k—~2.6kAutomated safety check: PassApache-2.0
Securitytelagod/code-abyss244—~907Automated safety check: PassMIT
Sailpillar-labs/sail-skill113—~5.1kAutomated safety check: PassCustom licence
Nist 800 53Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.3kAutomated safety check: PassMIT

Similar skills

  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Moai Ref Secops

    modu-ai/moai-adk

    DevSecOps, container, and API operational defensive security reference: CI/CD pipeline hardening, secret scanning, IaC misconfiguration detection, SAST/DAST integration, container image scanning…

    1.2k GitHub stars~2.6k tokensUpdated yesterday
    SecurityAuto-check passed
  • Security

    telagod/code-abyss

    Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries…

    244 GitHub stars~907 tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Sail

    pillar-labs/sail-skill

    Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents.

    113 GitHub stars~5.1k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    946 GitHub starsUsed in 1 repo~3.3k tokens
    Legal & ComplianceAuto-check passed
  • Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…

    1.1k GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check: warnings

More from LeoYeAI/openclaw-master-skills

All 1,200 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Questions about Agent Bom Compliance

What does Agent Bom Compliance do?

AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks. Agent Bom Compliance is an agent skill from LeoYeAI/openclaw-master-skills.0, and related frameworks.

When should I use Agent Bom Compliance?

Agent Bom Compliance fits situations like: : compliance report; tasks that involve SOC 2 and security compliance; tasks that involve AI governance.

How do I install Agent Bom Compliance in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom-compliance -a claude-code`. Or copy the skill folder (skills/agent-bom/compliance in LeoYeAI/openclaw-master-skills) into .claude/skills/agent-bom-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Agent Bom Compliance in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom-compliance -a codex`. Or copy the skill folder (skills/agent-bom/compliance in LeoYeAI/openclaw-master-skills) into .agents/skills/agent-bom-compliance in your project. Codex loads it when a task matches its description.

Can I use Agent Bom Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/agent-bom-compliance, .gemini/skills/agent-bom-compliance, .github/skills/agent-bom-compliance and .opencode/skills/agent-bom-compliance in your project.

What does Agent Bom Compliance need to run?

Going by SKILL.md and its folder, Agent Bom Compliance needs the command-line tools its instructions call (pipx). Our summary lists: Python 3; Docker; A credential in AZURE_CLIENT_SECRET. Compatibility (from SKILL.md): Requires Python 3.11+. Install via pipx or pip. OWASP/NIST/EU AI Act/MITRE evaluation and SBOM generation are fully local with zero credentials. CIS benchmark checks optionally use cloud SDK credentials (AWS/Azure/GCP/Snowflake) and make read-only API calls to cloud providers when explicitly invoked..

Does Agent Bom Compliance access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Agent Bom Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Agent Bom Compliance use?

Agent Bom Compliance is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Agent Bom Compliance use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Agent Bom Compliance?

Skills that share tags, products or a category with Agent Bom Compliance: AI Governance (Hack23/cia, 239 stars), Moai Ref Secops (modu-ai/moai-adk, 1.2k stars), Security (telagod/code-abyss, 244 stars) and Sail (pillar-labs/sail-skill, 113 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Agent Bom Compliance?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,161 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.