<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>OpenACA Blog</title>
    <link>https://openaca.dev/blog/</link>
    <description>Notes on Agent Composition Analysis — identity resolution, Agent BOMs, and securing AI agent stacks.</description>
    <language>en-us</language>
    <item>
      <title>What Is an AI-BOM, Really?</title>
      <link>https://openaca.dev/blog/what-is-an-ai-bom</link>
      <guid>https://openaca.dev/blog/what-is-an-ai-bom</guid>
      <pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate>
      <description>AI-BOMs list models or systems. Agent BOMs explain how plugins, skills, MCP servers, and packages are wired together — and where risk flows through that wiring.</description>
    </item>
    <item>
      <title>Your Agent Risk Isn't in One Plugin. It's in the Composition.</title>
      <link>https://openaca.dev/blog/your-agent-risk-is-in-the-composition</link>
      <guid>https://openaca.dev/blog/your-agent-risk-is-in-the-composition</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
      <description>Your SCA scanner can find vulnerable packages. It can't tell you those packages are wired into an AI agent that reads your chat messages, sends files, and is governed by skills that can rewrite its access policy.</description>
    </item>
    <item>
      <title>Introducing OpenACA: Agent Composition Analysis</title>
      <link>https://openaca.dev/blog/introducing-openaca</link>
      <guid>https://openaca.dev/blog/introducing-openaca</guid>
      <pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate>
      <description>Your dependency scanner can't see your agent stack. OpenACA is an open-source scanner that inventories the MCP servers, plugins, skills, and dependencies your AI agents pull in — and matches them against known security advisories.</description>
    </item>
  </channel>
</rss>
