AIBOM v0.1 is a static scanner for AI application inventory.
- Detects common AI providers, models, MCP servers, vector stores, datasets, external APIs, and secret references.
- Flags high-risk inventory patterns such as hard-coded token-like literals, unpinned
npxMCP servers, and curl-pipe-shell installers. - Supports JSON and Markdown export for CI and review workflows.
- Runtime tool calls.
- Provider account permissions.
- Full code data-flow analysis.
- Secret validation or rotation.
- Complete framework coverage.
Treat findings as review prompts. Do not assume absence of findings means an AI app is safe.