Agent skill

Agent Bom Registry

by LeoYeAI in LeoYeAI/openclaw-master-skills

MCP server security registry and trust assessment — look up servers in the 427+ server security metadata registry, run pre-install marketplace checks, batch fleet risk scoring, assess skill file…

Apache-2.0Auto-check passedSecurity

Install Agent Bom Registry

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom-registry -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills agent-bom-registry --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/agent-bom/registry .claude/skills/agent-bom-registry && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
agent-bom-registry
GitHub stars
2.2k
Token cost
~969 tokens
SKILL.md length
140 words
Files
1
Skills in repo
1,235
Repo updated
First seen
Licence
Apache-2.0

At a glance

MCP server security registry and trust assessment — look up servers in the 427+ server security metadata registry, run pre-install marketplace checks, batch fleet risk scoring, assess skill file…

  • The user mentions MCP server trust
  • SKILL.md covers Install, Tools (5), Example Workflows and MCP Resources, plus 2 more sections
  • Calls pipx
  • Registry lookup

What it does

Agent Bom Registry is an agent skill from LeoYeAI/openclaw-master-skills. MCP server security registry and trust assessment — look up servers in the 427+ server security metadata registry, run pre-install marketplace checks, batch fleet risk scoring, assess skill file trust, and run SAST code scans. Use when the user mentions MCP server trust, registry lookup, marketplace check, or skill trust assessment.

Its SKILL.md is about 970 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires Python 3.11+. Install via pipx or pip. Optional: Semgrep for SAST code scanning. No API keys or network access required (registry is bundled).

It sits in Security, covering Static analysis and SAST and MCP servers. It works with Model Context Protocol. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is Apache-2.0.

When your agent uses it

  • The user mentions MCP server trust
  • Registry lookup
  • Marketplace check
  • Skill trust assessment

Example prompts

  • “/agent-bom-registry”

Requirements

  • Python 3
  • A credential in SNYK_TOKEN
  • Compatibility (from SKILL.md): Requires Python 3.11+. Install via pipx or pip. Optional: Semgrep for SAST code scanning. No API keys or network access required (registry is bundled).

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pipx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Python 3.11+. Install via pipx or pip. Optional: Semgrep for SAST code scanning. No API keys or network access required (registry is bundled).

    From compatibility in the SKILL.md frontmatter.

Context cost

Agent Bom Registry loads about 969 tokens when it runs. Until then it costs about 88 tokens; SKILL.md has 140 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~88
When it runs · the whole SKILL.md, loaded when a task matches
~969

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its Apache-2.0 licence (© LeoYeAI). 140 words, ~969 tokens.

Download SKILL.mdSave it as .claude/skills/agent-bom-registry/SKILL.md (or your agent's skills folder).
name
agent-bom-registry
description
MCP server security registry and trust assessment — look up servers in the 427+ server security metadata registry, run pre-install marketplace checks, batch fleet risk scoring, assess skill file trust, and run SAST code scans. Use when the user mentions MCP server trust, registry lookup, marketplace check, or skill trust assessment.
compatibility
Requires Python 3.11+. Install via pipx or pip. Optional: Semgrep for SAST code scanning. No API keys or network access required (registry is bundled).
version
0.75.10
license
Apache-2.0
metadata.author
msaad00
metadata.homepage
https://github.com/msaad00/agent-bom
metadata.source
https://github.com/msaad00/agent-bom
metadata.pypi
https://pypi.org/project/agent-bom/
metadata.scorecard
https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom
metadata.tests
6040

agent-bom-registry — MCP Server Trust & Security Registry

Look up MCP servers in the 427+ server security metadata registry, assess skill file trust, and run pre-install marketplace checks.

Install

bash
pipx install agent-bom
agent-bom registry-lookup brave-search
agent-bom marketplace-check @anthropic/server-filesystem

Tools (5)

ToolDescription
registry_lookupLook up MCP server in 427+ server security metadata registry
marketplace_checkPre-install trust check with registry cross-reference
fleet_scanBatch registry lookup + risk scoring for MCP server inventories
skill_trustAssess skill file trust level (5-category analysis)
code_scanSAST scanning via Semgrep with CWE-based compliance mapping

Example Workflows

# Look up a server in the registry
registry_lookup(server_name="brave-search")

# Pre-install trust check
marketplace_check(package="@modelcontextprotocol/server-filesystem")

# Assess trust of a skill file
skill_trust(skill_content="<paste SKILL.md content>")

# Batch risk scoring
fleet_scan(servers=["brave-search", "github", "slack"])

MCP Resources

ResourceDescription
registry://serversBrowse 427+ MCP server security metadata registry

Privacy & Data Handling

Registry data is bundled in the package — lookups are in-memory string matches with zero network calls. Skill trust analysis parses content passed as a string argument (no file system access needed).

Verification

  • Source: github.com/msaad00/agent-bom (Apache-2.0)
  • 6,040+ tests with CodeQL + OpenSSF Scorecard
  • No telemetry: Zero tracking, zero analytics

© LeoYeAI, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/agent-bom/registry of LeoYeAI/openclaw-master-skills.

Open the folder on GitHubat commit e5199b5

Compare with similar skills

Agent Bom Registry next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Agent Bom Registry compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Agent Bom Registry this skillLeoYeAI/openclaw-master-skills2.2k—~969Automated safety check: PassApache-2.0
Ida Reversesickn33/agentic-awesome-skills47k1 repos~3.1kAutomated safety check: PassMIT
Forensifyalexgreensh/repo-forensics190—~2.5kAutomated safety check: NotesCustom licence
Plugin Scanneriflytek/skillhub5.2k2 repos~1.1kAutomated safety check: NotesApache-2.0
Webcrypt MCPputervision/state-memory-mcp50—~847Automated safety check: PassMIT
Security Passcyanheads/pubmed-mcp-server158—~6.4kAutomated safety check: PassApache-2.0

Similar skills

  • Ida Reverse

    sickn33/agentic-awesome-skills

    Reverse engineer binaries with IDA Pro: decompilation, disassembly, data-flow tracking, cross-references, and IDA MCP automation for deep static analysis of PE/ELF/Mach-O targets.

    47k GitHub starsUsed in 1 repo~3.1k tokens
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    190 GitHub stars~2.5k tokensUpdated 13 days ago
    SecurityAuto-check: notes
  • Plugin Scanner

    iflytek/skillhub

    Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.

    5.2k GitHub starsUsed in 2 repos~1.1k tokens
    SecurityAuto-check: notes
  • Webcrypt MCP

    putervision/state-memory-mcp

    Teaches the agent to use the WebCrypt MCP server for AES-256-GCM symmetric encryption, RSA-4096 hybrid encryption, key generation, digital signatures, hashing, and post-quantum cryptography.

    50 GitHub stars~847 tokensUpdated 7 days ago
    SecurityAuto-check passed
  • Security Pass

    cyanheads/pubmed-mcp-server

    Review an MCP server for common security gaps: LLM-facing surfaces as injection vector (tools, resources, prompts, descriptions), scope blast radius, destructive ops without consent, upstream auth…

    158 GitHub stars~6.4k tokensUpdated today
    SecurityAuto-check passed
  • MCP gateway security patterns, token management, request validation, and audit logging for MCP communications

    239 GitHub stars~2.4k tokensUpdated today
    SecurityAuto-check passed

More from LeoYeAI/openclaw-master-skills

All 1,235 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Questions about Agent Bom Registry

What does Agent Bom Registry do?

MCP server security registry and trust assessment — look up servers in the 427+ server security metadata registry, run pre-install marketplace checks, batch fleet risk scoring, assess skill file…. Agent Bom Registry is an agent skill from LeoYeAI/openclaw-master-skills. MCP server security registry and trust assessment — look up servers in the 427+ server security metadata registry, run pre-install marketplace checks, batch fleet risk scoring, assess skill file trust, and run SAST code scans.

When should I use Agent Bom Registry?

Agent Bom Registry fits situations like: the user mentions MCP server trust; registry lookup; marketplace check; skill trust assessment.

How do I install Agent Bom Registry in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom-registry -a claude-code`. Or copy the skill folder (skills/agent-bom/registry in LeoYeAI/openclaw-master-skills) into .claude/skills/agent-bom-registry in your project. Claude Code loads it when a task matches its description.

How do I install Agent Bom Registry in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom-registry -a codex`. Or copy the skill folder (skills/agent-bom/registry in LeoYeAI/openclaw-master-skills) into .agents/skills/agent-bom-registry in your project. Codex loads it when a task matches its description.

Can I use Agent Bom Registry in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom-registry -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/agent-bom-registry, .gemini/skills/agent-bom-registry, .github/skills/agent-bom-registry and .opencode/skills/agent-bom-registry in your project.

What does Agent Bom Registry need to run?

Going by SKILL.md and its folder, Agent Bom Registry needs the command-line tools its instructions call (pipx). Our summary lists: Python 3; A credential in SNYK_TOKEN. Compatibility (from SKILL.md): Requires Python 3.11+. Install via pipx or pip. Optional: Semgrep for SAST code scanning. No API keys or network access required (registry is bundled)..

Does Agent Bom Registry access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Agent Bom Registry safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Agent Bom Registry use?

Agent Bom Registry is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Agent Bom Registry use?

About 969 tokens (SKILL.md is roughly 3.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Agent Bom Registry?

Skills that share tags, products or a category with Agent Bom Registry: Ida Reverse (sickn33/agentic-awesome-skills, 47k stars), Forensify (alexgreensh/repo-forensics, 190 stars), Plugin Scanner (iflytek/skillhub, 5.2k stars) and Webcrypt MCP (putervision/state-memory-mcp, 50 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Agent Bom Registry?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,161 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.