agent-bom-ingest

Installation
SKILL.md

agent-bom-ingest

Use this skill when the operator already produced canonical inventory JSON with an operator-pull adapter, endpoint collector, CMDB export, or AI-agent workflow. The default path is local validation plus local scan/export.

Guardrails

  • Validate inventory with the packaged schema before treating it as evidence.
  • Require discovery_provenance and permissions_used where the source claims cloud/operator-pushed discovery.
  • Require a trustworthy discovery_provenance.source_type such as operator_pushed_inventory or skill_invoked_pull; do not infer it from prose.
  • Do not invent provenance, permissions, cloud scopes, or credential posture.
  • Do not push to a control plane unless the operator provides the destination URL and auth method explicitly.
  • Do not print raw tokens, URL credentials, private keys, or env var values.
Installs
1
GitHub Stars
22
First Seen
Jun 22, 2026
agent-bom-ingest — msaad00/agent-bom