Data & analysis

agent-bom registry

Check MCP servers and skill files for registry risk, provenance, trust, and code findings.

What it does

Look up MCP servers in a bundled 1,059-entry security metadata registry and run pre-install package checks without network calls. Batch-score server inventories, inspect instruction files for package references and trust findings, verify Sigstore provenance, or scan code with Semgrep and CWE-based compliance mapping.

When to use it

  • Pre-install MCP marketplace checks
  • Batch risk scoring for server inventories
  • Skill file trust and provenance review
  • Semgrep SAST with CWE mapping

The skill document

agent-bom-registry — MCP Server Trust & Security Registry

Look up MCP servers in the 1059-entry server security metadata registry, assess skill file trust, and run pre-install marketplace checks.

Install

pipx install agent-bom
agent-bom mcp scan @modelcontextprotocol/server-brave-search --ecosystem npm
agent-bom mcp scan @modelcontextprotocol/server-filesystem --ecosystem npm

Tools (7)

ToolDescription
registry_lookupLook up MCP server in the 1059-entry security metadata registry
marketplace_checkPre-install trust check with registry cross-reference
fleet_scanBatch registry lookup + risk scoring for MCP server inventories
skill_scanScan instruction files for package refs, trust, and findings
skill_verifyVerify Sigstore provenance for instruction files
skill_trustAssess skill file trust level (5-category analysis)
code_scanSAST scanning via Semgrep with CWE-based compliance mapping

Example Workflows

# Look up a server in the registry
registry_lookup(server_name="brave-search")

# Pre-install trust check
marketplace_check(package="@modelcontextprotocol/server-filesystem")

# Scan instruction files and then assess a specific skill file
skill_scan(path=".")
skill_trust(skill_path="./SKILL.md")

# Batch risk scoring
fleet_scan(servers=["brave-search", "github", "slack"])

MCP Resources

ResourceDescription
registry://serversBrowse the 1059-entry MCP server security metadata registry

Privacy & Data Handling

Registry data is bundled in the package — lookups are in-memory string matches with zero network calls. Skill trust analysis parses content passed as a string argument (no file system access needed).

Verification

  • Source: github.com/msaad00/agent-bom (Apache-2.0)
  • 7,100+ tests with CodeQL + OpenSSF Scorecard
  • No telemetry: Zero tracking, zero analytics

Questions people ask

Do registry lookups send server names over the network?
No. Registry data is bundled with the package, and lookups use in-memory string matching with zero network calls.
What can it assess in an instruction file?
It can scan instruction files for package references, trust, and findings; assess trust using five categories; and verify Sigstore provenance.
Can it evaluate multiple MCP servers at once?
Yes. `fleet_scan` performs batch registry lookup and risk scoring for an MCP server inventory.

Related skills

Scan agent dependencies, packages, images, and filesystems for CVEs, provenance issues, and blast radius.

by Agent Bom73 installs

Correlate runtime activity with CVEs and analyze context graphs, vulnerability trends, and security posture.

72 installs

Evaluate AI scan results against security frameworks, enforce policies, and export CycloneDX or SPDX SBOMs.

by Agent Bom73 installs

Send physical mail and turn forwarded documents into context for linked postal replies.

79 installs3 stars

Publish services, find marketplace work, manage delivery, and route non-custodial crypto payments through hosted MCP.

87 installs3 stars