Open security scanner for agentic infrastructure — agents, MCP, packages, blast radius, runtime, and trust for package CVEs (OSV, NVD, EPSS, KEV), container images, provenance, filesystems, and SBOMs. Use when: "check package", "scan image", "verify", "is this safe", "scan dependencies", "CVE lookup", "blast radius".
$npx -y skills add msaad00/agent-bom --skill scanInstalls into the current project.
Run `npx skills use "https://github.com/msaad00/agent-bom" --skill "msaad00/agent-bom/scan"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/msaad00/agent-bom" that are relevant to the current task. Run `npx skills add "https://github.com/msaad00/agent-bom"` and select the relevant skills, then follow their instructions.