aibom — Agentic AI Bill of Materials scanner
Discover, inventory, and risk-assess the AI agents, models, tools, and MCP
servers in a codebase — without running it. aibom produces an AI-BOM
(the AI equivalent of an SBOM) plus posture findings mapped to the
OWASP LLM Top 10, and gates your CI on new critical/high findings.
Zero dependencies (Python stdlib only). Part of ScopeSafe.
pip install scopesafe-aibom # installs the `aibom` command
aibom . # human-readable report, exit 1 on CRITICAL/HIGH
aibom . --json # raw AI-BOM JSON (SBOM export)
Languages
- Python — AST-based, high precision, with cross-file linkage.
- JavaScript / TypeScript — heuristic detection for the Vercel AI SDK (incl. the v5 gateway/registry idiom), the OpenAI/Anthropic Node SDKs, LangChain.js / LangGraph.js, and Mastra.
What it finds
- Agents — LangChain, LangGraph, CrewAI, AutoGen, LlamaIndex constructors
and graph idioms (
StateGraph().compile(),.bind_tools(), factory functions), with cross-file resolution of imported tools/models; JS/TS agent idioms (createReactAgent, MastraAgent,streamText/generateTexttool loops) - Models — client instantiation across frameworks + direct SDKs, including
config-default model names (
model: str = field(default="provider/model")) - Tools —
@tooldecorators,Tool()constructors,TOOLS = [...]lists, with capability tags (filesystem/exec/network/delete/...) - MCP servers —
.mcp.json/claude_desktop_config.json, scope classification (broad/scoped/unknown) - Posture findings — broadly-scoped MCP servers, exec-capable servers, destructive tools without human-in-the-loop, hardcoded provider keys — each mapped to an OWASP LLM Top 10 category
Continuous monitoring (ScopeSafe platform)
Upload scans to track finding lifecycle (new / recurring / resolved) across your projects and gate PRs:
export AIBOM_TOKEN=aibom_... # workspace API token from settings
export AIBOM_API_URL=https://api.scopesafe.net
aibom . --upload --project my-repo
# aibom: uploaded scan 3f2a... (project 'my-repo')
# findings: 1 new, 4 recurring, 2 resolved
# gate: fail — 1 new high finding(s), e.g. AGENT-001: ...
Exit codes with --upload: 0 gate passed/skipped · 1 gate failed · 2 upload error.
GitHub Action
# .github/workflows/aibom.yml
name: aibom
on: [pull_request]
permissions:
contents: read
pull-requests: write # required for the PR comment
jobs:
scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: sandhipveera/aibom@v0.2.0
with:
api-token: ${{ secrets.AIBOM_TOKEN }} # optional — omit for a local gate scan
api-url: https://api.scopesafe.net # optional
On every pull request the action posts a sticky comment with the AI-BOM
summary, findings, and a link to track/gate them on ScopeSafe (updated in place
on each push, not duplicated). It fails the build on new critical/high risk.
Omit api-token/api-url to run a local gate scan with a signup-oriented
comment. Set comment: "false" to disable the comment. The comment needs
pull-requests: write in the workflow's permissions.
Development
pip install -e ".[dev]"
pytest -q
ruff check src/
License
MIT
Metadata
Release files for scopesafe-aibom 0.3.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| scopesafe_aibom-0.3.0.tar.gz | 26.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| scopesafe_aibom-0.3.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 52.2 kB
Release files / scopesafe_aibom-0.3.0.tar.gz
| Download URL | scopesafe_aibom-0.3.0.tar.gz |
|---|---|
| Size | 26.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
007fba60baa7c9b0dc4712569adaf985b811a4355ddf379feea40c58f58464a8
|
|
BLAKE2b-256 checksum How to use checksums |
a1b333540fc8fc35e2f0a8a6fece02d8da58131bd1ced405f6b294d7c3f77f53
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 4, 2026.
Transparency logRelease files / scopesafe_aibom-0.3.0-py3-none-any.whl
| Download URL | scopesafe_aibom-0.3.0-py3-none-any.whl |
|---|---|
| Size | 25.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
d19598d7640b1e325c60b5e24945f8135d416507d645e3a02c223ceec153f1e2
|
|
BLAKE2b-256 checksum How to use checksums |
2410c7809e95b462cff620adc02d21bd18b52374cbde82a5e313d510d42b678b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 4, 2026.
Transparency log