Provides tools to issue, verify, and export cryptographically signed receipts for AI agent actions, enabling tamper-proof audit trails for compliance with regulations like the EU AI Act.
Enables AI agents to access authenticated websites by reusing your existing browser profile and cookies, so you never share passwords and sessions persist between runs.
agent-bom v0.104.0 is an open security scanner and self-hosted control plane for AI, MCP, and cloud infrastructure. The default scan profile in MCP server mode exposes 8 MCP tools. Additional profiles provide inventory, findings, compliance, graph, and runtime workflows.
Cryptographic accountability for AI agents. Ed25519-signed receipts for every MCP tool call. Constraints, chains, AI judgment, invoicing, and local dashboard included.
Enables AI agents to securely store and retrieve secrets and make authenticated API calls on their behalf, keeping API keys out of conversation context and supporting local file or GCP Secret Manager backends.
Enables searching and analyzing CVEs and vulnerabilities from multiple sources, optimized for PR review scenarios to help developers identify the latest security issues.
Enables AI coding agents to run Kubernetes inspection and Terraform plan/apply operations inside ephemeral gVisor-sandboxed jobs with short-lived, narrowly-scoped credentials, while routing destructive changes through a human approval gate.
Enables comprehensive threat analysis for Indicators of Compromise (IoCs) including IP addresses, file hashes, domains, and URLs. It provides detailed reputation scores, security vendor evaluations, and network metadata to facilitate security assessments and risk detection.
Enables governed access to corporate Postgres databases via MCP, supporting read-only queries, confirmed data and schema changes, query explanation, audit trail retrieval, and role-based policies with optional Vault secret integration.
Local static inspection of MCP and AI-agent tool manifests before attachment, reporting findings and missing evidence without executing proposed tools. Results do not establish runtime safety.
MCP server for AI search crawler governance, brand safety, and search infrastructure auditing. Provides tools to audit robots.txt, canonical links, sitemaps, redirects, and send IndexNow notifications.
An MCP server that provides Truss threat intelligence capabilities, enabling natural language search, FilterQL filtering, and querying of threat data, along with STIX export and detection rule generation.
MCP server that verifies storefront merchants before AI agents make payments, checking if the merchant is a real legal entity bound to the domain, and returning a PROCEED, ABORT, or REVIEW decision to prevent payment to clones or fraudulent stores.
Provides a zero-install security baseline for AI coding agents, with tools to retrieve curated security rules and check actions against them for self-correction.
Enables defenders to deploy a decoy MCP tool server that records and fingerprints how LLM agents probe, escalate, and persist, without exposing real systems.