Skip to main content

ABOM — the Agent Bill of Materials. Scan, sign, and verify what your AI agents are made of.

Project description

abom-cli

The reference implementation of ABOM — the Agent Bill of Materials. Scan a repo, emit a signed Composition Manifest, and verify it.

pip install abom-cli        # (until published: pip install -e .)
abom scan .                 # → abom.json (signed with ed25519)
abom verify abom.json       # check signature
abom verify abom.json --policy policy.json   # + enforce a policy (exit 1 on violations)

Commands

Command What it does
abom scan [PATH] Detect agent components (models, prompts, tools, MCP servers, frameworks, vector stores, guardrails) and emit a signed Composition Manifest. -o - writes to stdout.
abom verify [FILE] Verify the ed25519 signature; with --policy, enforce model allowlist / residency / egress / approval rules. Non-zero exit on findings (CI-friendly).
abom keygen Show (or create) the local ed25519 signing key (~/.abom/signing_key.pem, override with ABOM_KEY).
abom version Print the tool and spec versions.

All commands accept -v (info) / -vv (debug) / -q (errors only) / --json-logs (NDJSON for CI) — logs go to stderr, so the ABOM on stdout stays clean.

Example

$ abom scan .
  ABOM · my-agent @ 1.2.0
  models                  3  gpt-4o-mini, claude-3-5-sonnet, OpenAI (SDK)
  frameworks              2  LangChain, LangGraph
  MCP servers             2  filesystem, github
  tools                   1  lookup_customer
  prompts                 1  prompts/system.txt
  signed: ed25519 · key 5846eabc738b3542
  → wrote abom.json

How detection works

abom scan is a static scanner (pure stdlib + cryptography):

  • Dependencies (requirements*.txt, pyproject.toml, package.json) → frameworks, model SDKs, vector stores, guardrails.
  • Source → concrete model names (gpt-4o, claude-*, …) and @tool-decorated functions.
  • Prompt files (*.prompt, prompts/*.txt|md) → hashed.
  • MCP configs (mcp.json, claude_desktop_config.json, …) → MCP servers.

Each component records detected_from so the manifest is auditable. The output validates against spec/abom-0.1.schema.json.

Signing

abom scan signs with ed25519 (cryptography). The key lives at ~/.abom/signing_key.pem (override with ABOM_KEY); the public key + a short key_id are embedded so abom verify is self-contained. A Notary / key registry pins trusted key ids in production.

Dev

make install          # pip install -e ".[dev]"
make test             # pytest (audit chain, scanner, signing)
make scan && make verify
make build            # wheel + sdist + twine check
python demo/demo.py   # generate → verify → tamper-evidence walkthrough

What else is in this package

src/abom/ also contains a prototype control-plane (api.py, db.py, orchestration.py, the Notary) behind the optional [server] extra — the beginnings of the commercial layer. It is not required for scan/verify and is not part of the v0.1 spec. See MVP_SPEC.md.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

abom_cli-0.1.8.tar.gz (53.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

abom_cli-0.1.8-py3-none-any.whl (45.9 kB view details)

Uploaded Python 3

File details

Details for the file abom_cli-0.1.8.tar.gz.

File metadata

  • Download URL: abom_cli-0.1.8.tar.gz
  • Upload date:
  • Size: 53.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for abom_cli-0.1.8.tar.gz
Algorithm Hash digest
SHA256 dddbe5604e06b7f62be95a7ab859e50a60c6a94f00f2be9abaa29d2cef1ef3b5
MD5 65f0562bf2869a47d69fa499f159c14b
BLAKE2b-256 d436af6d0e884c835efd87ee4544a1048dcc7cb604874064262443b99f8e4292

See more details on using hashes here.

Provenance

The following attestation bundles were made for abom_cli-0.1.8.tar.gz:

Publisher: release.yml on josephassiga/abom-dev

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file abom_cli-0.1.8-py3-none-any.whl.

File metadata

  • Download URL: abom_cli-0.1.8-py3-none-any.whl
  • Upload date:
  • Size: 45.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for abom_cli-0.1.8-py3-none-any.whl
Algorithm Hash digest
SHA256 6c2425e1381e8c04bb74bfd7fe66274e75f9cb76226506ee01c66d5d84eb17af
MD5 e76d677c1e7c9b468658af00d47e5188
BLAKE2b-256 5d63aa864a44f976ba4ab6414f89dfa0790b7d896d84a00056d8240d0ef06efd

See more details on using hashes here.

Provenance

The following attestation bundles were made for abom_cli-0.1.8-py3-none-any.whl:

Publisher: release.yml on josephassiga/abom-dev

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page