Agent skill

Agent Bom Scan

by LeoYeAI in LeoYeAI/openclaw-master-skills

Open security platform for agentic infrastructure — checks packages for CVEs (OSV, NVD, EPSS, KEV), scans container images, verifies provenance, scans filesystems, and generates SBOMs.

Apache-2.0Auto-check passedSecurity

Install Agent Bom Scan

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills agent-bom-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/agent-bom/scan .claude/skills/agent-bom-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
agent-bom-scan
GitHub stars
2.2k
Token cost
~1.9k tokens
SKILL.md length
210 words
Files
1
Skills in repo
1,235
Repo updated
First seen
Licence
Apache-2.0

At a glance

Open security platform for agentic infrastructure — checks packages for CVEs (OSV, NVD, EPSS, KEV), scans container images, verifies provenance, scans filesystems, and generates SBOMs.

  • : check package
  • SKILL.md covers Install, When to Use, Tools (8) and Examples, plus 3 more sections
  • Calls pipx and pip; reaches github.com
  • Scan dependencies

What it does

Agent Bom Scan is an agent skill from LeoYeAI/openclaw-master-skills. Open security platform for agentic infrastructure — checks packages for CVEs (OSV, NVD, EPSS, KEV), scans container images, verifies provenance, scans filesystems, and generates SBOMs. Use when: "check package", "scan image", "verify", "is this safe", "scan dependencies", "CVE lookup", "blast radius".

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires Python 3.11+. Install via pipx or pip. Native container image scanning — no external scanner required. No API keys required for basic operation.

It sits in Security, covering Vulnerability scanning, Supply chain security and Containers. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is Apache-2.0.

When your agent uses it

  • : check package
  • Scan dependencies

Example prompts

  • “check package”
  • “scan image”
  • “verify”
  • “/agent-bom-scan”

Requirements

  • Python 3
  • Docker
  • Compatibility (from SKILL.md): Requires Python 3.11+. Install via pipx or pip. Native container image scanning — no external scanner required. No API keys required for basic operation.

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pipx
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Python 3.11+. Install via pipx or pip. Native container image scanning — no external scanner required. No API keys required for basic operation.

    From compatibility in the SKILL.md frontmatter.

Context cost

Agent Bom Scan loads about 1.9k tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 210 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its Apache-2.0 licence (© LeoYeAI). 210 words, ~1,933 tokens.

Download SKILL.mdSave it as .claude/skills/agent-bom-scan/SKILL.md (or your agent's skills folder).
name
agent-bom-scan
description
Open security platform for agentic infrastructure — checks packages for CVEs (OSV, NVD, EPSS, KEV), scans container images, verifies provenance, scans filesystems, and generates SBOMs. Use when: "check package", "scan image", "verify", "is this safe", "scan dependencies", "CVE lookup", "blast radius".
compatibility
Requires Python 3.11+. Install via pipx or pip. Native container image scanning — no external scanner required. No API keys required for basic operation.
version
0.75.10
license
Apache-2.0
metadata.author
msaad00
metadata.homepage
https://github.com/msaad00/agent-bom
metadata.source
https://github.com/msaad00/agent-bom
metadata.pypi
https://pypi.org/project/agent-bom/
metadata.scorecard
https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom
metadata.tests
6533

agent-bom-scan — AI Supply Chain Vulnerability Scanner

Checks packages for CVEs, scans container images natively, verifies package provenance via Sigstore, scans filesystems, and generates SBOMs.

Install

bash
pipx install agent-bom
agent-bom agents             # discover agents and scan dependencies
agent-bom check langchain==0.1.0  # check a specific package with version
agent-bom image nginx:1.25   # scan container image (native)
agent-bom fs .               # scan filesystem packages
agent-bom sbom .             # generate SBOM
agent-bom verify agent-bom   # verify Sigstore provenance
agent-bom where              # show all discovery paths
As an MCP Server
json
{
  "mcpServers": {
    "agent-bom": {
      "command": "uvx",
      "args": ["agent-bom", "mcp"]
    }
  }
}

When to Use

  • "check package" / "is this package safe"
  • "scan image" / "scan container"
  • "verify" / "check provenance"
  • "is this safe" / "CVE lookup"
  • "scan dependencies"
  • "blast radius"
  • "generate SBOM"

Tools (8)

ToolDescription
checkCheck a package for CVEs (OSV, NVD, EPSS, KEV)
scanFull discovery + vulnerability scan pipeline
blast_radiusMap CVE impact chain across agents, servers, credentials
remediatePrioritized remediation plan for vulnerabilities
verifyPackage integrity + SLSA provenance check
diffCompare two scan reports (new/resolved/persistent)
whereShow MCP client config discovery paths
inventoryList discovered agents, servers, packages

Examples

# Check a package before installing
check(package="langchain", version="0.1.0", ecosystem="pypi")

# Map blast radius of a CVE
blast_radius(cve_id="CVE-2024-21538")

# Full scan
scan()

# Verify package provenance
verify(package="agent-bom")

Guardrails

  • Show CVEs even when NVD analysis is pending or severity is unknown — a CVE ID is still a real finding.
  • Treat UNKNOWN severity as unresolved, not benign — it means data is not yet available.
  • Do not modify any files, install packages, or change system configuration.
  • Only public package names and CVE IDs leave the machine for vulnerability database lookups.
  • Ask before scanning paths outside the user's home directory.

Privacy & Data Handling

bash
# Step 1: Install
pip install agent-bom

# Step 2: Review redaction logic BEFORE scanning
# sanitize_env_vars() replaces ALL env var values with ***REDACTED***
# BEFORE any config data is processed or stored:
# https://github.com/msaad00/agent-bom/blob/main/src/agent_bom/security.py#L159

# Step 3: Verify package provenance (Sigstore)
agent-bom verify agent-bom

# Step 4: Only then run scans
agent-bom agents

Verification

  • Source: github.com/msaad00/agent-bom (Apache-2.0)
  • Sigstore signed: agent-bom verify agent-bom@0.75.10
  • 6,533+ tests with CodeQL + OpenSSF Scorecard
  • No telemetry: Zero tracking, zero analytics

© LeoYeAI, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/agent-bom/scan of LeoYeAI/openclaw-master-skills.

Open the folder on GitHubat commit e5199b5

Compare with similar skills

Agent Bom Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Agent Bom Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Agent Bom Scan this skillLeoYeAI/openclaw-master-skills2.2k—~1.9kAutomated safety check: PassApache-2.0
Warp Vulnerability Triagewarpdotdev/warp65k1 repos~2.1kAutomated safety check: PassAGPL-3.0
Container Scanning with GrypeAgentSecOps/SecOpsAgentKit2201 repos~2.5kAutomated safety check: PassCustom licence
Container Securityhardw00t/ai-security-arsenal104—~2.8kAutomated safety check: PassNone
Sca TrivyAgentSecOps/SecOpsAgentKit2202 repos~3.7kAutomated safety check: PassCustom licence
Sbom SyftAgentSecOps/SecOpsAgentKit2201 repos~3.5kAutomated safety check: PassCustom licence

Similar skills

  • Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    SecurityAuto-check passed
  • Container Scanning with Grype

    AgentSecOps/SecOpsAgentKit

    Scans container images, filesystems and SBOMs with Grype for known vulnerabilities, ranks them by CVSS, EPSS and CISA KEV, and wires scans into CI/CD thresholds.

    220 GitHub starsUsed in 1 repo~2.5k tokens
    SecurityAuto-check passed
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    104 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    220 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • Sbom Syft

    AgentSecOps/SecOpsAgentKit

    Software Bill of Materials (SBOM) generation using Syft for container images, filesystems, and archives.

    220 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check passed
  • Container Security Hardening

    sickn33/agentic-awesome-skills

    Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.

    47k GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check: notes

More from LeoYeAI/openclaw-master-skills

All 1,235 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Agent Bom Scan

What does Agent Bom Scan do?

Open security platform for agentic infrastructure — checks packages for CVEs (OSV, NVD, EPSS, KEV), scans container images, verifies provenance, scans filesystems, and generates SBOMs. Agent Bom Scan is an agent skill from LeoYeAI/openclaw-master-skills. Open security platform for agentic infrastructure — checks packages for CVEs (OSV, NVD, EPSS, KEV), scans container images, verifies provenance, scans filesystems, and generates SBOMs.

When should I use Agent Bom Scan?

Agent Bom Scan fits situations like: : check package; scan dependencies.

How do I install Agent Bom Scan in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom-scan -a claude-code`. Or copy the skill folder (skills/agent-bom/scan in LeoYeAI/openclaw-master-skills) into .claude/skills/agent-bom-scan in your project. Claude Code loads it when a task matches its description.

How do I install Agent Bom Scan in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom-scan -a codex`. Or copy the skill folder (skills/agent-bom/scan in LeoYeAI/openclaw-master-skills) into .agents/skills/agent-bom-scan in your project. Codex loads it when a task matches its description.

Can I use Agent Bom Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill agent-bom-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/agent-bom-scan, .gemini/skills/agent-bom-scan, .github/skills/agent-bom-scan and .opencode/skills/agent-bom-scan in your project.

What does Agent Bom Scan need to run?

Going by SKILL.md and its folder, Agent Bom Scan needs the command-line tools its instructions call (pipx and pip). Our summary lists: Python 3; Docker. Compatibility (from SKILL.md): Requires Python 3.11+. Install via pipx or pip. Native container image scanning — no external scanner required. No API keys required for basic operation..

Does Agent Bom Scan access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Agent Bom Scan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Agent Bom Scan use?

Agent Bom Scan is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Agent Bom Scan use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Agent Bom Scan?

Skills that share tags, products or a category with Agent Bom Scan: Warp Vulnerability Triage (warpdotdev/warp, 65k stars), Container Scanning with Grype (AgentSecOps/SecOpsAgentKit, 220 stars), Container Security (hardw00t/ai-security-arsenal, 104 stars) and Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Agent Bom Scan?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,160 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.