Skip to content

msaad00/agent-bom

v0.32.0 Feature

This release adds 3 notable features for engineering teams evaluating rollout.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

ai-agents ai-security ai-supply-chain aibom blast-radius cloud-security
+14 more
compliance container-security cyclonedx security kubernetes llm-security mcp mcp-server owasp sarif sbom security-scanner supply-chain-security vulnerability-scanning

Summary

AI summary

Added four new MCP tools (verify, where, inventory, diff), two resources, and three discovery clients.

Full changelog

What's New in v0.32.0

MCP Server Expansion

  • Smithery 100/100: All 13 tool parameters now have JSON Schema descriptions
  • 4 new MCP tools: verify (package integrity), where (discovery paths), inventory (agent/server listing), diff (report comparison)
  • 2 MCP resources: registry://servers (427+ server threat intel), policy://template
  • 4 new scan params: transitive, verify_integrity, fail_severity, policy

New Discovery Clients

  • Roo Code and Amazon Q Developer — auto-discovered alongside 11 existing MCP clients (15 total)

Trust & Security UX

  • HTML trust assessment section: Verdict badge, 5-category table, recommendations — matches CLI panel
  • Trust panel shows source file: "Trust Assessment — SKILL.md" instead of generic title
  • --open flag: Auto-open HTML/graph-html reports in default browser
  • SKILL.md hardened: 31 file_reads declared (was 27), updated justification

HTML Reports

  • Compliance tables: OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF with pass/warn/fail badges
  • Trust assessment section: Verdict, categories, recommendations in dark theme

CLI Improvements

  • Scan presets: --preset ci (quiet, json, fail-on-critical), --preset enterprise (full enrichment), --preset quick
  • Elapsed time: Shown in scan completion divider

Stats

  • 1043 tests passing
  • 13 MCP tools, 2 resources, 3 prompts
  • 15 discovery clients

What's Changed

  • feat: Smithery param descriptions + scan params + doc fixes (#33)
  • feat: 4 new MCP tools + 2 resources + 2 discovery clients (#34)
  • feat: scan presets, elapsed time, HTML compliance tables (#35)
  • feat: trust UX + HTML trust section + --open flag + SKILL.md hardening (#36)
  • chore: bump version to v0.32.0 (#38)

Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.31.9...v0.32.0

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track msaad00/agent-bom

Get notified when new releases ship.

Sign up free

About msaad00/agent-bom

AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.

All releases →

Related context

Beta — feedback welcome: [email protected]