agent-bom
Related Servers
Alternatives to agent-bom
No user-submitted related servers found.
Related Servers
- FlicenseAqualityCmaintenanceScan for AI tools and agents - MCP servers & CLIs for scanning, auditing, and managing your AI environment1-
- AlicenseNot gradedqualityBmaintenanceSecurity scanner for MCP servers. Detects prompt injection, command injection, auth bypass, and excessive permissions across tools, resources, and prompts.11 npm2MIT
- AlicenseCqualityDmaintenanceSecurity scanner and MCP server that catches dangerous patterns in MCP servers and AI agent projects, such as leaked secrets, shell execution, and prompt-injection text. Runs as both a CLI and MCP server with CI-friendly severity gates.21MIT
- AlicenseAqualityDmaintenanceA security scanner that evaluates installed MCP servers for vulnerabilities by aggregating findings from 16 scanning engines into detailed trust scores. It enables users to scan their local AI agent configurations or specific repository URLs for potential security risks.419 PyPI2Apache 2.0
- AlicenseAqualityDmaintenanceSecurity scanner for AI agent packages that enables AI agents to audit MCP servers and packages for vulnerabilities, prompt injection, and supply chain attacks.5167 npm3AGPL 3.0
- FlicenseNot gradedqualityCmaintenanceMCP server for auditing AI agent permissions and access by scanning for the trifecta of credentials, injection, and reach without heavy infrastructure.-
TDQS
Scored across 8 tools
scan and generate_sbom both extract dependencies but differ in output (AI-BOM vs SBOM); compliance and policy_check both evaluate security posture but one maps to frameworks and the other enforces custom rules. Most tools have clearly distinct purposes, though some overlap in the underlying scanning could confuse an agent.
Names mix single verbs (scan, check, remediate), nouns (compliance, exposure_paths), and verb_noun compounds (generate_sbom, policy_check, intel_lookup). The inconsistency in verb style and structure reduces predictability, though all are readable.
8 tools is well-scoped for an AI supply chain security server, covering scanning, checking, compliance, SBOM generation, policy, remediation, intel, and exposure paths. No tool feels redundant or unnecessary.
Core lifecycle is covered: scan, check, generate_sbom, compliance, policy_check, remediate, plus intel_lookup and exposure_paths. Missing a dedicated 'list past scans' or policy management tool, but scan's result_id paging mitigates; minor gaps only.