Complete AI Training

MCP server · Security

agent-bom security scanner

by msaad00

Your AI can scan your project for security problems and explain what is risky.

Flow diagram: you ask your AI “Check this project for security problems”, the agent-bom security scanner works in steps: looks through the project, then checks against known flaws, then sorts by how serious, and you get back A clear summary in your chat.

agent-bom is a security scanner made for AI projects. It looks at the files in a project, finds the AI helpers and the pieces of software they use, and checks those pieces against lists of known security problems. It is handy if you build or look after anything that uses AI tools and want a plain report of what needs fixing.

What is an MCP server? The 30-second version

On its own, your AI can only chat with you. An MCP server is a small helper program that gives your AI a new skill or a connection to another app. This one connects your AI to agent-bom, a security scanner. So when you ask your AI to check a project for security issues, it can actually run the scanner and bring the results back to you.

What this MCP server does

You ask your AI something like check this project for security problems. Your AI passes that request to the agent-bom helper. The helper looks through the project, finds the AI agents, the MCP servers, the software packages and the passwords or keys they use, and compares the packages against public lists of known security flaws. Then it hands the findings back, and your AI shows you a summary in the chat, including which problems are serious and which passwords or tools they could reach.

Flow diagram: you ask your AI “Check this project for security problems”, the agent-bom security scanner works in steps: looks through the project, then checks against known flaws, then sorts by how serious, and you get back A clear summary in your chat. Click to zoom

What you can do with it

  • Scan a project folder for known security problems in the software it uses
  • List the AI agents, MCP servers and packages found in a project
  • Show which passwords or keys a problem could reach
  • Check one package before you add it to a project
  • Produce a report file you can share with your team
  • Explain why a particular security finding matters

Try asking your AI

  • “Scan this project and tell me the most serious security problems”
  • “Which packages in this folder have known vulnerabilities?”
  • “Is it safe to add the requests package version 2.33.0 to my project?”
  • “Show me which passwords or keys could be reached if this problem were exploited”

What it gives back to you

You get a written summary in the chat: a list of findings, each with the package name, the problem, how serious it is, and a suggested fix. It can also list the agents, servers and credentials it found. If you ask for a file, it can save a report you can open or share.

Before you start

What you need

  • Python installed on your computer (the scanner is a Python program)
  • The agent-bom package installed, or permission to run it with uvx
  • Access to the project folder you want to scan

Good to know

It reads the files in the project you point it at, so only scan folders you are allowed to look at, and treat its findings as clues to check rather than proof that something was actually attacked.

Install it with your AI

Add agent-bom security scanner to your AI, no technical skills needed

You don't install anything by hand. You copy one prompt, paste it into an AI that can work on your computer, and it checks, installs and connects the server for you, asking you when it needs something.

Sign in to get the install prompt

Members get a ready-made prompt that lets the Claude desktop app check agent-bom security scanner, install it and connect it for them, step by step. You don't need any technical skills: you copy, paste and answer a few questions. Your connected AI can also find and install any of the 4,066 MCP servers here for you.

Sign in Become a member

Who it's for

Developers, security reviewers and anyone who looks after AI projects and wants a plain report of what needs fixing.