Security Controls for What AI and Agents Add
SBOMator expands the inventory boundary beyond normal package manifests, providing an AI/ML profile aligned to the G7 SBOM-for-AI minimum elements โ covering models, datasets, MCP servers, and agent skills, all analyzed locally.
The AI / Agent Supply Chain
HalluSquatting Protection
Local intelligence for hallucinated and malicious package names, optional registry validation, updateable feeds, and real-time endpoint alerts.
Full Agent-Skill Security
SkillSpector locates lexical and hidden threats; Droid judges context, separates real risk from false positives, and feeds verdicts into a learning loop (Locate-and-Judge).
G7-Aligned AI/ML-BOM
Classifies AI components and marks output against G7 SBOM-for-AI guidance while preserving missing manual fields โ seven clusters: metadata, system, models, datasets, infrastructure, security, KPIs.
Model Artifacts
CycloneDX machine-learning-model components with format, path, size, and SHA-256 integrity evidence (.gguf, .safetensors, .onnx, .tflite, .pt, .h5).
MCP Inventory & Integrity
Server command, arguments, transport, and package reference, with pin-status and integrity monitoring.
ML Frameworks & Agent Frameworks
Identifies AI/LLM SDKs, agent frameworks, and vector databases with AI-role metadata.
DataBOM โ Dataset Provenance
Fully local scanning of AI training datasets โ dataset content is never uploaded.
Source & Collection Coverage
Source-domain inventory and collection-timestamp coverage.
Privacy Indicators
PII detection (email, phone, IP, payment-card) and GDPR Article 9 special-category indicators.
Guideline Checks
EDPB web-scraping guideline checks and a completeness score.
Local Dataset Readers
JSONL, CSV, and text readers with configurable record limits.
Standards-Based Output
CycloneDX 1.6 ML-BOM with data components, plus an HTML provenance report.
Evidence-Rich Findings
Secrets and provenance-risk findings surfaced as evidence.
Controlled Code Provenance
Similarity evidence without blind disclosure โ reduces copied-code and licensing risk without presenting a no-match result as legal clearance.
Git Scope
New, modified, staged, unstaged, and untracked lines by default.
Privacy Gate
Comments, secrets, credentials, sensitive paths, and high-entropy values removed.
Consent
External search requires an explicit operator decision.
Verify
Candidates fetched, compared locally, and recorded as evidence.
Bring Your AI Supply Chain Into the Inventory
See how SBOMator maps AI components, agent capabilities, datasets, and provenance evidence without sending sensitive content away.