agent-bom registry
MCP Server Security Metadata Query and Trust Assessment Tool
Install & Use
Copy this prompt and send it to your AI assistant (Claude / Cursor / TRAE / Codex / WorkBuddy etc.) to auto-install:
Help me install this AI Skill: agent-bom registry. It is used for: MCP Server Security Metadata Query and Trust Assessment Tool Full Skill content: https://321skill.com/skills/agent-bom-registry-x-5/raw/index.md Read that page and install it.
The prompt includes a link to the full Skill content. You can also view the full content.
This Skill addresses the challenges of MCP server security trust assessment and registry queries. In practical development, developers often need to quickly evaluate the security of an MCP server, inspect its metadata, or perform batch risk assessments on multiple servers, but lack a centralized, trusted query interface.
Usage is straightforward: simply install the agent-bom package, then invoke its seven tools—such as registry_lookup, marketplace_check, and fleet_scan—via natural language instructions. For example, telling the AI "Look up the security metadata for the MCP server brave-search" will return that server's trust score, risk level, code scanning results, and more from its entry among 1,013 registry records. You can then use natural language commands to perform operations like pre-installation marketplace checks, batch risk scoring, and skill file trust analysis.
It is particularly suitable for agent developers and operations engineers who need to integrate MCP tools or manage MCP server security, especially for teams or individuals already using or planning to use a large number of MCP servers and requiring rapid filtering of trustworthy servers.
We recommend using this tool consistently when evaluating new MCP servers or conducting batch reviews of existing ones. Note that it primarily relies on a locally bundled dataset of 1,013 registry records; for the latest data, you must manually update the package. Additionally, the optional SAST scanning feature depends on Semgrep, which requires separate installation.
Key Features
Unlike manually accessing MCP official documentation or reviewing server code individually, `agent-bom` comes with 1,013 security metadata records built-in, supporting offline local queries without network requests. It also provides batch risk scoring and SAST code scanning, delivering a one-stop solution for trust assessment.
Limitations
Requires a Python 3.11+ runtime environment. The optional SAST code scanning depends on Semgrep. The registry data is a locally bundled version and may not be the latest (update the package to obtain newer data).
FAQ
Does this tool require an internet connection?
No, the registry data is locally bundled, enabling fully offline queries. The optional SAST scanning requires internet access to fetch Snyk vulnerability data (requires SNYK_TOKEN configuration).
How do I update the registry data?
Update the `agent-bom` package to the latest version via `pip install --upgrade agent-bom`.
Installation guide for AI assistants
If your AI coding assistant (Claude Code, Cursor, TRAE etc.) can see this page, send it this message to auto-install:
Visit https://321skill.com/skills/agent-bom-registry-x-5/raw/index.md to read the original Skill definition (Markdown format) for agent-bom registry, and install it according to the instructions.
Raw Markdown URL for AI: /skills/agent-bom-registry-x-5/raw/index.md