Developer · Local MCP server
agent-bom
Security scanner and graph for agentic infrastructure — agents, MCP, runtime, and blast radius.
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
io.github.msaad00/agent-bom- Version
- 0.107.2
- Status
- Active
- Category
- developer
- Transport
- stdio (local process)
- Package
- PyPI
- Published
- 2026-10-01
- Updated
- 2026-10-01
- Publisher
- msaad00 (GitHub)
- Repository
- github.com/msaad00/agent-bom
- Source
- Registry API entry
Packages
| Registry | Package | Version | Transport |
|---|---|---|---|
| PyPIruntime: uvx | agent-bom | 0.107.2 | stdio |
How to connect agent-bom
agent-bom runs locally from a Python package published to PyPI: agent-bom version 0.107.2. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Python; clients usually start it with uvx (from uv) or after pip install — the usual command is uvx agent-bom. It reads the environment variable NVD_API_KEY (secret); set it in the client's configuration for this server.
In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):
{
"mcpServers": {
"agent-bom": {
"command": "uvx",
"args": [
"agent-bom"
],
"env": {
"NVD_API_KEY": "<secret>"
}
}
}
}Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More developer servers
| Server | Runs |
|---|---|
| Agent Venue RadarScreen AI-work venues for inventory, funding, payouts, withdrawal, economics, and security risk. | Local · stdio |
| Agent Verified RelayViridis Verified: wrap any MCP server with tamper-evident delivery receipts + metered fees. | Remote · HTTP |
| Agent WatchMonitoring for the agent economy — liveness, latency, trust scoring for MCP endpoints. | Remote · HTTP |
| Agent Workspace MCPA sandboxed, agentic workspace providing secure filesystem, bash, and uv-powered Python execution. | Local · stdio |
| agent-deviceMCP server for mobile app automation: verify, control, and debug iOS, Android, TV, and desktop apps. | Local · stdio |
| agent-godmodeSandboxed workspace MCP: file ops, argv-only run_command, list_files; BYO LLM prompts. | Local · stdio |
| agent-toolEncoding-aware, indentation-file tools for AI coding agents with SSH, SFTP, and 20+ tools. | Local · stdio |
| agent.socialFree social platform for AI agents — boards with tool-call receipts; MCP server + REST API. | Remote & Local · HTTP, stdio |