返回顶部
a

agent-bom-compliance

>-

作者: admin | 来源: ClawHub
源自
ClawHub
版本
V 0.76.4
安全检测
已通过
603
下载量
0
收藏
概述
安装方式
版本历史

agent-bom-compliance

# agent-bom-compliance — AI Compliance & Policy Engine Evaluate AI infrastructure scan results against 14 security and regulatory frameworks. Enforce policy-as-code rules. Generate SBOMs in standard formats. Run AISVS v1.0 and CIS benchmark checks. ## Install ```bash pipx install agent-bom agent-bom agents -f compliance-export # run agents scan with compliance export agent-bom generate-sbom # generate CycloneDX SBOM ``` ## When to Use - "compliance report" / "run compliance" - "NIST" / "NIST AI RMF" / "NIST CSF" / "NIST 800-53" - "SOC 2" / "SOC2" - "ISO 27001" - "OWASP" / "OWASP LLM Top 10" / "OWASP Agentic Top 10" - "EU AI Act" - "AISVS" / "AI Security Verification Standard" - "CMMC" / "FedRAMP" - "generate SBOM" / "CycloneDX" / "SPDX" - "policy check" / "policy enforcement" ## Tools (5) | Tool | Description | |------|-------------| | `compliance` | OWASP LLM/Agentic Top 10, EU AI Act, MITRE ATLAS, NIST AI RMF | | `policy_check` | Evaluate results against custom security policy (17 conditions) | | `cis_benchmark` | Run CIS benchmark checks against cloud accounts | | `generate_sbom` | Generate SBOM (CycloneDX or SPDX format) | | `aisvs_benchmark` | OWASP AISVS v1.0 compliance — 9 AI security checks | ## Supported Frameworks (14) - **OWASP LLM Top 10** (2025) — prompt injection, supply chain, data leakage - **OWASP MCP Top 10** — MCP-specific security risks - **OWASP Agentic Top 10** — tool poisoning, rug pulls, credential theft - **OWASP AISVS v1.0** — AI Security Verification Standard (9 checks) - **MITRE ATLAS** — adversarial ML threat framework - **NIST AI RMF** — govern, map, measure, manage lifecycle - **NIST CSF 2.0** — identify, protect, detect, respond, recover - **NIST 800-53 Rev 5** — federal security controls (CM-8, RA-5, SI-2, SR-3) - **FedRAMP Moderate** — derived from NIST 800-53 controls - **EU AI Act** — risk classification, transparency, SBOM requirements - **ISO 27001:2022** — information security controls (Annex A) - **SOC 2** — Trust Services Criteria - **CIS Controls v8** — implementation groups IG1/IG2/IG3 - **CMMC 2.0** — cybersecurity maturity model (Level 1-3) ## Examples ``` # Run compliance check against multiple frameworks compliance(frameworks=["owasp_llm", "eu_ai_act", "nist_ai_rmf"]) # Enforce custom policy policy_check(policy={"max_critical": 0, "max_high": 5}) # Generate SBOM generate_sbom(format="cyclonedx") # Run AISVS v1.0 compliance aisvs_benchmark() # Run AWS CIS benchmark cis_benchmark(provider="aws") ``` ## Privacy & Data Handling **OWASP, NIST, EU AI Act, MITRE ATLAS, AISVS, SBOM generation, and policy checks** run entirely locally on scan data already in memory. No network calls, no credentials needed for these features. **CIS benchmark checks** (optional, user-initiated) call cloud provider APIs using your locally configured credentials. These are read-only API calls to AWS, Azure, GCP, or Snowflake. You must explicitly run `cis_benchmark(provider=...)` and confirm before any cloud API calls are made. ## Verification - **Source**: [github.com/msaad00/agent-bom](https://github.com/msaad00/agent-bom) (Apache-2.0) - **7,100+ tests** with CodeQL + OpenSSF Scorecard - **No telemetry**: Zero tracking, zero analytics

标签

skill ai

通过对话安装

该技能支持在以下平台通过对话安装:

OpenClaw WorkBuddy QClaw Kimi Claude

方式一:安装 SkillHub 和技能

帮我安装 SkillHub 和 agent-bom-compliance-1776115656 技能

方式二:设置 SkillHub 为优先技能安装源

设置 SkillHub 为我的优先技能安装源,然后帮我安装 agent-bom-compliance-1776115656 技能

通过命令行安装

skillhub install agent-bom-compliance-1776115656

下载 Zip 包

⬇ 下载 agent-bom-compliance v0.76.4

文件大小: 3.44 KB | 发布时间: 2026-4-14 15:54

v0.76.4 最新 2026-4-14 15:54
Release v0.76.4

Archiver·手机版·闲社网·闲社论坛·羊毛社区· 多链控股集团有限公司 · 苏ICP备2025199260号-1

Powered by Discuz! X5.0   © 2024-2025 闲社网·线报更新论坛·羊毛分享社区·http://xianshe.com

p2p_official_large
返回顶部