Skip to main content
Glama

Ai Bom MCP

Buy Starter — £29/mo

Signed attestations + unlimited audits + email support. 👉 Subscribe at meok.ai — instant HMAC signing key + Stripe-managed billing.

Free tier remains MIT-licensed and zero-config. Upgrade only when you need signed compliance artefacts for audit.

MCP server for ai bom mcp operations

PyPI License: MIT MEOK AI Labs

Quick Install

Client

Install

Claude Desktop

Install in Claude

Cursor

Install in Cursor

VS Code

Install in VS Code

Windsurf

Install in Windsurf

Docker

docker run -p 8000:8000 ai-bom-mcp

pip

pip install ai-bom-mcp

Overview

Ai Bom MCP provides AI-powered tools via the Model Context Protocol (MCP).

Tools

Tool

Description

generate_ai_bom

Generate an AI-BOM in CycloneDX ML-BOM format (or SPDX 3.0) with all 10 required

audit_ai_bom_completeness

Audit an existing AI-BOM for completeness against the 10 required field categori

map_to_regulation

Map an AI-BOM against a specific regulatory framework's technical documentation

required_fields

List the 10 required AI-BOM field categories and their fields.

sign_ai_bom_attestation

Generate a cryptographically signed AI-BOM completeness attestation (Pro/Enterpr

Installation

pip install meok-ai-bom-mcp

Usage with Claude Desktop

Add to your Claude Desktop MCP config (claude_desktop_config.json):

{
  "mcpServers": {
    "ai-bom-mcp": {
      "command": "python",
      "args": ["-m", "meok_ai_bom_mcp.server"]
    }
  }
}

Usage with FastMCP

from mcp.server.fastmcp import FastMCP

# This server exposes 5 tool(s) via MCP
# See server.py for full implementation

Wire it up — full stack

Pair this with the MEOK chain that turns one agent action into ONE signed compliance event:

  1. bft-progress-council-mcp — anti-loop guardrail

  2. agent-token-budget-mcp — hard spend cap

  3. agent-prompt-injection-firewall-mcp — OWASP LLM01 scan

  4. agent-audit-logger-mcp — hash-chained evidence

  5. a2a-governance-bridge-mcp — fold N attestations → 1 signed event

  6. agent-incident-relay-mcp — broadcast incidents to 5 regimes simultaneously

See meok.ai/mcp-stack for the full architecture and meok.ai/mcp-stack/demo for the live in-browser demo.

License

MIT © MEOK AI Labs

<<<<<<< Updated upstream

Stashed changes

Sister MCPs

Part of the MEOK Governance pack — designed to work together as a fleet. Install the whole pack with npx meok-setup --pack governance, or pick the ones you need:

  • EU AI Actuvx eu-ai-act-compliance-mcp · PyPI · GitHub

  • DORAuvx dora-compliance-mcp · PyPI · GitHub

  • NIS2uvx nis2-compliance-mcp · PyPI · GitHub

  • Cyber Resilience Actuvx cra-compliance-mcp · PyPI · GitHub

  • AI Incident Reportinguvx ai-incident-reporting-mcp · PyPI · GitHub

  • DORA × NIS2 Crosswalkuvx dora-nis2-crosswalk-mcp · PyPI · GitHub

Full catalogue + Anthropic Registry verify links: meok.ai/anthropic-registry

Protocol coverage + Universal PAYG

This MCP is part of MEOK's 47-MCP fleet that bridges every active agent-interop protocol and 30+ regulatory frameworks. See the full coverage matrix at meok.ai/protocols.

Agent interop protocols supported (8 live):

  • MCP (Anthropic) — native

  • A2A (Google + Linux Foundation, absorbed IBM ACP Sept 2025)

  • IBM ACP — covered via A2A merge

  • Stripe ACP (Agentic Commerce Protocol) — Q3 bridge via agent-commerce-protocol-mcp

  • AP2 (Google Agent Payments) — partial via agent-commerce-payments-mcp

  • x402 (Coinbase HTTP 402) — partial via api.meok.ai gateway

  • OASF / AGNTCY (Cisco Outshift + Linux Foundation) — Q3 bridge

  • 👁 ANP (Cisco Agent Network) — watch-list

Pricing options:

Option

Price

Best for

Self-host (this MCP)

£0 — MIT

Devs

This MCP Starter

£29/mo

One-MCP teams

This MCP Pro

£79/mo

Production + 24h SLA

Universal PAYG

£29/mo + £0.0002/call

Spiky usage across many MCPs

Substrate bundle (this category)

£99-£499/mo

A whole pack

MEOK Universe

£1,499/mo

All 47 MCPs, 500K calls

Each tier above the free self-host adds HMAC-signed attestations verifiable at verify.meok.ai. Linux Foundation governance on the A2A spine means EU regulated buyers can deploy without vendor-lock-in objections.

Install Server
A
license - permissive license
A
quality
B
maintenance

Maintenance

Maintainers
Response time
Release cycle
1Releases (12mo)

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/CSOAI-ORG/ai-bom-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server