| metadata | {"author":"msaad00","homepage":"https://github.com/msaad00/agent-bom","source":"https://github.com/msaad00/agent-bom","pypi":"https://pypi.org/project/agent-bom/","scorecard":"https://securityscorecards.dev/viewer/?uri=github.com/msaad00/agent-bom","tests":7239,"install":{"pipx":"agent-bom","pip":"agent-bom","docker":"ghcr.io/msaad00/agent-bom:0.86.3"},"openclaw":{"requires":{"bins":[],"env":[],"credentials":"none"},"credential_policy":"Zero credentials required. Policy evaluation is local. Proxy operates on local network only. Policy files are user-provided and never transmitted.","credential_handling":"Policy and audit files may contain credential names but must not expose credential values. Redact token-like values before logging, displaying, or exporting runtime evidence.","optional_env":[],"optional_bins":[],"emoji":"🚫","homepage":"https://github.com/msaad00/agent-bom","source":"https://github.com/msaad00/agent-bom","license":"Apache-2.0","os":["darwin","linux","windows"],"data_flow":"Purely local. Policy evaluation runs on scan results in memory. Proxy intercepts MCP calls on local network only. Audit logs are written locally (JSONL). No data leaves the machine.","file_reads":["user-provided policy files (YAML/JSON policy-as-code)","user-provided audit log files (JSONL from agent-bom proxy)"],"file_writes":["proxy-audit.jsonl (local audit log, only when proxy is running)"],"network_endpoints":[],"telemetry":false,"persistence":false,"privilege_escalation":false,"always":false,"autonomous_invocation":"restricted","disable-model-invocation":true}} |