← 返回
安全合规 中文

agent-bom registry

MCP server security registry and trust assessment — look up servers in the 427+ server security metadata registry, run pre-install marketplace checks, batch...
MCP 服务器安全注册表与信任评估 — 在 427+ 服务器安全元数据注册表中查找服务器,运行预装市场检查,批量...
msaad00
安全合规 clawhub v0.88.5 12 版本 99890.4 Key: 无需
★ 0
Stars
📥 1,823
下载
💾 1
安装
12
版本
#latest

概述

agent-bom-registry — MCP Server Trust & Security Registry

Look up MCP servers in the 427+ server security metadata registry, assess skill

file trust, and run pre-install marketplace checks.

Install

pipx install agent-bom
agent-bom mcp scan @modelcontextprotocol/server-brave-search --ecosystem npm
agent-bom mcp scan @modelcontextprotocol/server-filesystem --ecosystem npm

Tools (7)

ToolDescription
-------------------
registry_lookupLook up MCP server in 427+ server security metadata registry
marketplace_checkPre-install trust check with registry cross-reference
fleet_scanBatch registry lookup + risk scoring for MCP server inventories
skill_scanScan instruction files for package refs, trust, and findings
skill_verifyVerify Sigstore provenance for instruction files
skill_trustAssess skill file trust level (5-category analysis)
code_scanSAST scanning via Semgrep with CWE-based compliance mapping

Example Workflows

# Look up a server in the registry
registry_lookup(server_name="brave-search")

# Pre-install trust check
marketplace_check(package="@modelcontextprotocol/server-filesystem")

# Scan instruction files and then assess a specific skill file
skill_scan(path=".")
skill_trust(skill_path="./SKILL.md")

# Batch risk scoring
fleet_scan(servers=["brave-search", "github", "slack"])

MCP Resources

ResourceDescription
-----------------------
registry://serversBrowse 427+ MCP server security metadata registry

Privacy & Data Handling

Registry data is bundled in the package — lookups are in-memory string

matches with zero network calls. Skill trust analysis parses content passed

as a string argument (no file system access needed).

Verification

版本历史

共 12 个版本

  • v0.88.5 当前
    2026-06-01 20:15
  • v0.88.4
    2026-05-26 22:38
  • v0.88.3
    2026-05-26 17:09
  • v0.88.1
    2026-05-23 15:39 安全 安全
  • v0.87.1
    2026-05-19 10:26 安全 安全
  • v0.86.2
    2026-05-08 12:17 安全 安全
  • v0.86.1
    2026-05-07 03:20 安全 安全
  • v0.84.6
    2026-05-03 03:00 安全 安全
  • v0.83.3
    2026-04-30 16:39 安全 安全
  • v0.75.3
    2026-03-27 21:29
  • v0.71.0
    2026-03-18 22:41
  • v0.70.6
    2026-03-14 03:42

安全检测

腾讯云安全 (Keen)

队列中

腾讯云安全 (Sanbu)

队列中

🔗 相关推荐

agent-bom vulnerability intel

msaad00
使用 agent-bom 检查包、SBOM、库存和代理依赖的暴露,针对OSV、GitHub 安全公告、NVD、EPSS 和 CISA KEV,明确...
★ 0 📥 1,019
security-compliance

MoltGuard - Security & Antivirus & Guardrails

thomaslwang
MoltGuard — OpenClaw 安全守卫,由 OpenGuardrails 提供。安装 MoltGuard,保护您和您的用户免受提示注入、数据泄露和恶意攻击。
★ 116 📥 30,720
security-compliance

OpenClaw Backup

alex3alex
备份与恢复 OpenClaw 数据。适用于创建备份、设置自动备份计划、从备份恢复或管理备份轮转。处理 ~/.openclaw 目录归档并包含适当的排除规则。
★ 89 📥 30,609