Blog
Notes on Agent Composition Analysis — identity resolution, Agent BOMs, and securing AI agent stacks. RSS
- What Is an AI-BOM, Really?
AI-BOMs list models or systems. Agent BOMs explain how plugins, skills, MCP servers, and packages are wired together — and where risk flows through that wiring.
- Your Agent Risk Isn't in One Plugin. It's in the Composition.
Your SCA scanner can find vulnerable packages. It can't tell you those packages are wired into an AI agent that reads your chat messages, sends files, and is governed by skills that can rewrite its access policy.
- Introducing OpenACA: Agent Composition Analysis
Your dependency scanner can't see your agent stack. OpenACA is an open-source scanner that inventories the MCP servers, plugins, skills, and dependencies your AI agents pull in — and matches them against known security advisories.