This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+14 more
Summary
AI summaryAdded four new MCP tools (verify, where, inventory, diff), two resources, and three discovery clients.
Full changelog
What's New in v0.32.0
MCP Server Expansion
- Smithery 100/100: All 13 tool parameters now have JSON Schema descriptions
- 4 new MCP tools:
verify(package integrity),where(discovery paths),inventory(agent/server listing),diff(report comparison) - 2 MCP resources:
registry://servers(427+ server threat intel),policy://template - 4 new scan params:
transitive,verify_integrity,fail_severity,policy
New Discovery Clients
- Roo Code and Amazon Q Developer — auto-discovered alongside 11 existing MCP clients (15 total)
Trust & Security UX
- HTML trust assessment section: Verdict badge, 5-category table, recommendations — matches CLI panel
- Trust panel shows source file: "Trust Assessment — SKILL.md" instead of generic title
--openflag: Auto-open HTML/graph-html reports in default browser- SKILL.md hardened: 31 file_reads declared (was 27), updated justification
HTML Reports
- Compliance tables: OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF with pass/warn/fail badges
- Trust assessment section: Verdict, categories, recommendations in dark theme
CLI Improvements
- Scan presets:
--preset ci(quiet, json, fail-on-critical),--preset enterprise(full enrichment),--preset quick - Elapsed time: Shown in scan completion divider
Stats
- 1043 tests passing
- 13 MCP tools, 2 resources, 3 prompts
- 15 discovery clients
What's Changed
- feat: Smithery param descriptions + scan params + doc fixes (#33)
- feat: 4 new MCP tools + 2 resources + 2 discovery clients (#34)
- feat: scan presets, elapsed time, HTML compliance tables (#35)
- feat: trust UX + HTML trust section + --open flag + SKILL.md hardening (#36)
- chore: bump version to v0.32.0 (#38)
Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.31.9...v0.32.0
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About msaad00/agent-bom
AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.
Related context
Related tools
Beta — feedback welcome: [email protected]