agent-bom registry
MCP Server Security Registry and Trust Assessment Tool
Install & Use
Copy this prompt and send it to your AI assistant (Claude / Cursor / TRAE / Codex / WorkBuddy etc.) to auto-install:
Help me install this AI Skill: agent-bom registry. It is used for: MCP Server Security Registry and Trust Assessment Tool Full Skill content: https://321skill.com/skills/agent-bom-registry-x-9/raw/index.md Read that page and install it.
The prompt includes a link to the full Skill content. You can also view the full content.
This Skill addresses the pain point of security trust assessment for MCP (Model Context Protocol) servers. In practical development, developers often need to install and use various MCP servers but lack a centralized security metadata registry to quickly evaluate a server's trustworthiness. This tool comes pre-bundled with 1013 MCP server security metadata records and supports registry lookup, pre-installation marketplace checks, batch fleet risk scoring, skill file trust assessment, and SAST code scanning.
Usage is straightforward: simply install the agent-bom package and invoke the provided seven tools (registry_lookup, marketplace_check, fleet_scan, skill_scan, skill_verify, skill_trust, code_scan) via natural language instructions. For example, you can say, "Look up the security record for the brave-search MCP server," and it will immediately search the local registry and return the security metadata. You can also perform batch scans of an entire MCP server inventory to obtain risk scores.
It is particularly well-suited for agent development teams, operations engineers, and security testers who need to manage multiple MCP servers—especially teams already building AI applications with the MCP protocol and requiring security vetting for every integrated server.
It is recommended to run a marketplace_check for a pre-installation trust assessment before installing any new MCP server. Note that the SAST code scanning feature requires optional installation of Semgrep. The registry data is locally bundled, requires no internet connection, and works offline.
Key Features
Unlike using online vulnerability scanners such as Snyk, `agent-bom-registry` comes with 1013 locally bundled MCP server security metadata records, enabling offline registry queries without network connectivity or API keys. It also supports batch fleet risk scoring and skill file trust assessment, covering the entire lifecycle of MCP server security.
Limitations
Requires Python 3.11+. SAST code scanning depends on optional Semgrep installation. Registry data is locally bundled; updates require upgrading the package version.
FAQ
Does this tool require an internet connection?
No. The registry data is locally bundled, and all lookup operations are performed in local memory, requiring no network connection. Optionally, using Snyk for code scanning requires a SNYK_TOKEN and internet access.
How many records are in the registry?
It currently contains 1013 MCP server security metadata records, covering mainstream MCP servers.
Installation guide for AI assistants
If your AI coding assistant (Claude Code, Cursor, TRAE etc.) can see this page, send it this message to auto-install:
Visit https://321skill.com/skills/agent-bom-registry-x-9/raw/index.md to read the original Skill definition (Markdown format) for agent-bom registry, and install it according to the instructions.
Raw Markdown URL for AI: /skills/agent-bom-registry-x-9/raw/index.md