Agent Bom is an open-source security scanner and self-hosted control plane designed for AI, MCP, and cloud infrastructure. It provides automated vulnerability scanning, compliance packs, audit reporting, risk dashboards, and blast radius mapping through its unified evidence model (ContextGraph). Target users are AppSec, GRC, SRE, platform teams, agent builders, and security engineers looking to secure their code, cloud, and agent environments through read-only scans, CI integration, comprehensive posture tracking, and policy enforcement. It supports multiple deployment methods (Python, Docker) and integrates with MCP, cloud providers (AWS, Azure, GCP, Snowflake), and CI/CD pipelines.
Visit Agent Bom's official website for product details and getting started.
Comprehensive guides and API references for setting up and using Agent Bom.
Discuss features, report issues, and connect with other users of Agent Bom.
Insights and updates related to security practices and the evolution of Agent Bom.