msaad00

22 mods across 1 repository, 31 stars between them.

agent-bom AGENTS.md

01

msaad00/agent-bom

Instructions file CodexOpenCode

Instructions for msaad00/agent-bom, a project described as: Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.

31 yesterday A 6 tokens copy · 100% Apache-2.0

agent-bom CLAUDE.md

02

msaad00/agent-bom

Instructions file

Instructions for msaad00/agent-bom, covering claude-specific addendum, memory, tools and communication.

31 yesterday A 411 tokens original Apache-2.0

agent-bom

03

msaad00/agent-bom

Skill Claude CodeCodex

Open security scanner for agentic infrastructure — agents, MCP, packages, blast radius, runtime, and trust across MCP servers, skills, packages, and agents in Cortex Code.

31 yesterday A 39 tokens original Apache-2.0

agent-bom

04

msaad00/agent-bom

Skill Claude CodeCodex

Open security scanner for agentic infrastructure — agents, MCP, packages, blast radius, runtime, and trust across MCP discovery, CVEs, SBOMs, CIS benchmarks (AWS, Azure, GCP, Snowflake), OWASP/NIST/MITRE compliance, AISVS v1.0, MAESTRO layer tagging, and vector database security checks. Use when the user mentions…

31 yesterday A 107 tokens original Apache-2.0

agent-bom-analyze

05

msaad00/agent-bom

Skill Claude CodeCodex

Analyze blast radius, attack paths, and threat landscape across your AI infrastructure. Use when: "blast radius", "threat intel", "risk score", "attack path", "lateral movement", "context graph", "who can reach what".

31 yesterday A 56 tokens original Apache-2.0

msaad00/agent-bom

Skill Claude CodeCodex

AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks. Generate SBOMs and compliance reports. Use when: "compliance report", "NIST", "SOC 2", "ISO 27001", "OWASP", "EU AI Act", "AISVS", "generate SBOM", "policy check".

31 yesterday A 102 tokens original Apache-2.0

msaad00/agent-bom

Skill Claude CodeCodex

Discover AWS-hosted AI agent and MCP-relevant assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving agent-bom long-lived cloud credentials. Use when a user asks to inventory AWS Bedrock, ECS, SageMaker, Lambda, EKS, Step Functions, EC2, or agentic AWS…

31 yesterday A 96 tokens original Apache-2.0

msaad00/agent-bom

Skill Claude CodeCodex

Discover Azure-hosted AI agent and MCP-relevant assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving agent-bom long-lived Azure credentials. Use when a user asks to inventory Azure OpenAI, Container Apps, AKS, Functions, ML, or agentic Azure infrastructure as…

31 yesterday A 76 tokens original Apache-2.0

msaad00/agent-bom

Skill Claude CodeCodex

Discover GCP-hosted AI agent and MCP-relevant assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving agent-bom long-lived GCP credentials. Use when a user asks to inventory Vertex AI, Cloud Run, Cloud Functions, GKE, or agentic GCP infrastructure as canonical…

31 yesterday C 77 tokens original Apache-2.0

msaad00/agent-bom

Skill Claude CodeCodex

Discover Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and AI-observability assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving agent-bom long-lived Snowflake credentials. Use when a user asks to inventory Snowflake AI or Cortex infrastructure as…

31 yesterday A 75 tokens original Apache-2.0

agent-bom-discover

11

msaad00/agent-bom

Skill Claude CodeCodex

Discover AI agents, MCP servers, and configurations on this machine or environment. Use when: "find agents", "what's configured", "doctor", "what MCP servers", "show me what's installed", "mcp inventory".

31 yesterday B 52 tokens original Apache-2.0

agent-bom-enforce

12

msaad00/agent-bom

Skill Claude CodeCodex

Enforce security policies on MCP tool calls and block dangerous operations at runtime. Use when: "block risky calls", "apply policy", "proxy", "runtime protection", "policy enforcement", "intercept MCP calls".

31 yesterday A 50 tokens original Apache-2.0

agent-bom-ingest

13

msaad00/agent-bom

Skill Claude CodeCodex

Validate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure, GCP, Snowflake, CMDB, or endpoint collectors. Use when a user has canonical inventory JSON and wants local findings, graph, policy, provenance, or auditor-ready exports without giving agent-bom direct cloud credentials.

31 yesterday A 67 tokens original Apache-2.0

agent-bom-monitor

14

msaad00/agent-bom

Skill Claude CodeCodex

Monitor agent fleet, track trust scores, and manage lifecycle states. Use when: "fleet", "watch agents", "runtime status", "trust scores", "fleet sync", "agent lifecycle", "serve dashboard".

31 yesterday A 48 tokens original Apache-2.0

agent-bom-registry

15

msaad00/agent-bom

Skill Claude CodeCodex

MCP server security registry and trust assessment — look up servers in the 1112-entry server security metadata registry, run pre-install marketplace checks, batch fleet risk scoring, assess skill file trust, and run SAST code scans. Use when the user mentions MCP server trust, registry lookup, marketplace check, or…

31 yesterday A 72 tokens original Apache-2.0

agent-bom-runtime

16

msaad00/agent-bom

Skill Claude CodeCodex

AI runtime security monitoring — context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries. Use when the user mentions runtime monitoring, context graphs, lateral movement analysis, audit log correlation, or vulnerability analytics.

31 yesterday A 51 tokens original Apache-2.0

msaad00/agent-bom

Skill Claude CodeCodex

Scan infrastructure-as-code, cloud configurations, and find secrets. Use when: "check terraform", "scan kubernetes", "IaC", "find secrets", "scan dockerfile", "cloud security", "misconfigurations".

31 yesterday A 55 tokens original Apache-2.0

agent-bom-scan

18

msaad00/agent-bom

Skill Claude CodeCodex

Open security scanner for agentic infrastructure — agents, MCP, packages, blast radius, runtime, and trust for package CVEs (OSV, NVD, EPSS, KEV), container images, provenance, filesystems, and SBOMs. Use when: "check package", "scan image", "verify", "is this safe", "scan dependencies", "CVE lookup", "blast radius".

31 yesterday A 89 tokens original Apache-2.0

msaad00/agent-bom

Skill Claude CodeCodex

Diagnose issues, check prerequisites, and validate configurations. Use when: "doctor", "debug", "why failing", "validate config", "check prerequisites", "something is broken", "db status", "fix my setup".

31 yesterday A 53 tokens original Apache-2.0

msaad00/agent-bom

Skill Claude CodeCodex

Use agent-bom to check package, SBOM, inventory, and agent dependency exposure against OSV, GitHub Security Advisories, NVD, EPSS, and CISA KEV with explicit data-boundary choices. Use when a user asks for CVE lookup, advisory intelligence, exploitability context, fix versions, GHSA/OSV/NVD enrichment, or package…

31 yesterday A 88 tokens original Apache-2.0

agent-bom

22

msaad00/agent-bom

MCP server Claude CodeCodexCursor +2

Open security scanner and self-hosted control plane for AI, MCP, and cloud infrastructure. Runs locally from the agent-bom Python package. Needs 1 environment variable to run.

31 yesterday A tokens not measured original Apache-2.0