Agent skill

Agent Bom Runtime

by LeoYeAI in LeoYeAI/openclaw-master-skills

AI runtime security monitoring — context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries.

Apache-2.0Auto-check passedSecurity

Install Agent Bom Runtime

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom-runtime -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills agent-bom-runtime --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/agent-bom/runtime .claude/skills/agent-bom-runtime && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
agent-bom-runtime
GitHub stars
2.2k
Token cost
~748 tokens
SKILL.md length
99 words
Files
1
Skills in repo
1,215
Repo updated
First seen
Licence
Apache-2.0

At a glance

AI runtime security monitoring — context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries.

  • The user mentions runtime monitoring
  • SKILL.md covers Install, Tools (3), Example Workflows and Privacy & Data Handling, plus 1 more section
  • Calls pipx
  • Lateral movement analysis

What it does

Agent Bom Runtime is an agent skill from LeoYeAI/openclaw-master-skills. AI runtime security monitoring — context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries. Use when the user mentions runtime monitoring, context graphs, lateral movement analysis, audit log correlation, or vulnerability analytics.

Its SKILL.md is about 750 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires Python 3.11+. Install via pipx or pip. Optional: kubectl for Kubernetes context, ClickHouse for analytics storage. No API keys required.

It sits in Security, covering Vulnerability scanning and Red teaming and adversary simulation. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is Apache-2.0.

When your agent uses it

  • The user mentions runtime monitoring
  • Lateral movement analysis
  • Audit log correlation
  • Vulnerability analytics

Example prompts

  • “/agent-bom-runtime”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Requires Python 3.11+. Install via pipx or pip. Optional: kubectl for Kubernetes context, ClickHouse for analytics storage. No API keys required.

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pipx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Python 3.11+. Install via pipx or pip. Optional: kubectl for Kubernetes context, ClickHouse for analytics storage. No API keys required.

    From compatibility in the SKILL.md frontmatter.

Context cost

Agent Bom Runtime loads about 748 tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 99 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~748

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its Apache-2.0 licence (© LeoYeAI). 99 words, ~748 tokens.

Download SKILL.mdSave it as .claude/skills/agent-bom-runtime/SKILL.md (or your agent's skills folder).
name
agent-bom-runtime
description
AI runtime security monitoring — context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries. Use when the user mentions runtime monitoring, context graphs, lateral movement analysis, audit log correlation, or vulnerability analytics.
compatibility
Requires Python 3.11+. Install via pipx or pip. Optional: kubectl for Kubernetes context, ClickHouse for analytics storage. No API keys required.
version
0.75.10
license
Apache-2.0
metadata.author
msaad00
metadata.homepage
https://github.com/msaad00/agent-bom
metadata.source
https://github.com/msaad00/agent-bom
metadata.pypi
https://pypi.org/project/agent-bom/
metadata.scorecard
https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom
metadata.tests
6040

agent-bom-runtime — AI Runtime Security Monitoring

Context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries.

Install

bash
pipx install agent-bom

Tools (3)

ToolDescription
context_graphAgent context graph with lateral movement analysis
analytics_queryQuery vulnerability trends, posture history, and runtime events
runtime_correlateCross-reference runtime audit logs with CVE findings

Example Workflows

# Build context graph from scan results
context_graph()

# Correlate runtime audit with CVE data
runtime_correlate(audit_file="proxy-audit.jsonl")

# Query analytics
analytics_query(query="top_cves", days=30)

Privacy & Data Handling

Operates on scan results already in memory and user-provided audit log files. No automatic file discovery. No network calls unless you configure an optional ClickHouse endpoint for persistent analytics.

Verification

  • Source: github.com/msaad00/agent-bom (Apache-2.0)
  • 6,040+ tests with CodeQL + OpenSSF Scorecard
  • No telemetry: Zero tracking, zero analytics

© LeoYeAI, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/agent-bom/runtime of LeoYeAI/openclaw-master-skills.

Open the folder on GitHubat commit e5199b5

Compare with similar skills

Agent Bom Runtime next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Agent Bom Runtime compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Agent Bom Runtime this skillLeoYeAI/openclaw-master-skills2.2k—~748Automated safety check: PassApache-2.0
Web Exfiltration DetectionTencent/AI-Infra-Guard6.8k—~1.8kAutomated safety check: PassApache-2.0
Data Leakage DetectionTencent/AI-Infra-Guard6.8k—~954Automated safety check: PassApache-2.0
Cybersecurityohmyjahh/xquads-squads276—~895Automated safety check: PassMIT
Exploiting Vulnerabilities With Metasploit Frameworkmukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: NotesApache-2.0
Detecting Attacks On Historian Serversmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0

Similar skills

  • Web Exfiltration Detection

    Tencent/AI-Infra-Guard

    Probes whether an agent with web fetch and stored user memory can be tricked by a malicious page into leaking data through chained URL paths.

    6.8k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • Data Leakage Detection

    Tencent/AI-Infra-Guard

    Tests a target AI agent for sensitive information disclosure, such as its system prompt, credentials, personal data and internal configuration, using escalating dialogue probes.

    6.8k GitHub stars~954 tokensUpdated today
    SecurityAuto-check passed
  • Cybersecurity

    ohmyjahh/xquads-squads

    Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…

    276 GitHub stars~895 tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Exploiting Vulnerabilities With Metasploit Framework

    mukul975/Anthropic-Cybersecurity-Skills

    Uses the Metasploit Framework (msfconsole and its exploit, auxiliary, and post-exploitation modules) to validate that identified CVEs and vulnerabilities are actually exploitable, gather…

    34k GitHub stars~1.9k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Detecting Attacks On Historian Servers

    mukul975/Anthropic-Cybersecurity-Skills

    Detect cyber attacks on OT historian servers (OSIsoft PI, Ignition, GE Proficy, Wonderware InSQL) using a Python detector that flags unauthorized queries, data manipulation, and lateral-movement…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Testing For Business Logic Vulnerabilities

    mukul975/Anthropic-Cybersecurity-Skills

    Manually identifies flaws in application business logic - price manipulation, multi-step workflow bypass, and privilege escalation - by intercepting and modifying requests with Burp Suite, going…

    34k GitHub stars~3.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from LeoYeAI/openclaw-master-skills

All 1,215 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Agent Bom Runtime

What does Agent Bom Runtime do?

AI runtime security monitoring — context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries. Agent Bom Runtime is an agent skill from LeoYeAI/openclaw-master-skills. AI runtime security monitoring — context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries.

When should I use Agent Bom Runtime?

Agent Bom Runtime fits situations like: the user mentions runtime monitoring; lateral movement analysis; audit log correlation; vulnerability analytics.

How do I install Agent Bom Runtime in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom-runtime -a claude-code`. Or copy the skill folder (skills/agent-bom/runtime in LeoYeAI/openclaw-master-skills) into .claude/skills/agent-bom-runtime in your project. Claude Code loads it when a task matches its description.

How do I install Agent Bom Runtime in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom-runtime -a codex`. Or copy the skill folder (skills/agent-bom/runtime in LeoYeAI/openclaw-master-skills) into .agents/skills/agent-bom-runtime in your project. Codex loads it when a task matches its description.

Can I use Agent Bom Runtime in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom-runtime -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/agent-bom-runtime, .gemini/skills/agent-bom-runtime, .github/skills/agent-bom-runtime and .opencode/skills/agent-bom-runtime in your project.

What does Agent Bom Runtime need to run?

Going by SKILL.md and its folder, Agent Bom Runtime needs the command-line tools its instructions call (pipx). Our summary lists: Python 3. Compatibility (from SKILL.md): Requires Python 3.11+. Install via pipx or pip. Optional: kubectl for Kubernetes context, ClickHouse for analytics storage. No API keys required..

Does Agent Bom Runtime access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Agent Bom Runtime safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Agent Bom Runtime use?

Agent Bom Runtime is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Agent Bom Runtime use?

About 748 tokens (SKILL.md is roughly 3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Agent Bom Runtime?

Skills that share tags, products or a category with Agent Bom Runtime: Web Exfiltration Detection (Tencent/AI-Infra-Guard, 6.8k stars), Data Leakage Detection (Tencent/AI-Infra-Guard, 6.8k stars), Cybersecurity (ohmyjahh/xquads-squads, 276 stars) and Exploiting Vulnerabilities With Metasploit Framework (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Agent Bom Runtime?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,158 GitHub stars. The repository holds 1,215 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.