Skip to content
mcp/skillhub

agent-bom MCP Server

by msaad00io.github.msaad00/agent-bomv0.108.2

AI supply chain security scanner: discovers MCP clients, scans dependencies for CVEs, maps blast radius to credentials and tools, and generates SBOMs.

31Pythonstdioofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Active1d ago

Install agent-bom MCP server

Install in Claude Code

claude mcp add agent-bom -e NVD_API_KEY='<nvd-api-key>' -- uvx agent-bom mcp server

Configuration

VariableRequiredSecretDescription
NVD_API_KEY—yesNVD API key for higher rate limits on vulnerability enrichment

Freshness

Active — last maintenance signal 1d ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    2026-10-09 · 1d ago · GitHub

  2. Latest release

    2026-10-08 · 1d ago · GitHub · v0.108.3

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-10-08 · 1d ago · official registry · v0.108.2

FAQ

›How do I install the agent-bom MCP server in Claude Code?

Run: claude mcp add agent-bom -e NVD_API_KEY='<nvd-api-key>' -- uvx agent-bom mcp server. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.

›Does agent-bom require an API key?

Yes. It expects NVD_API_KEY, of which 1 is a secret.

›Can I use agent-bom as a remote (hosted) MCP server?

No hosted endpoint is published; it runs locally over stdio.

›Is agent-bom in the official MCP registry?

Yes, as io.github.msaad00/agent-bom.

Alternatives to agent-bom

Other security MCP servers.

View all