agent-bom-compliance — AI Compliance & Policy Engine
Evaluate AI infrastructure scan results against 14 security and regulatory
frameworks. Enforce policy-as-code rules. Generate SBOMs in standard formats.
Run AISVS v1.0 and CIS benchmark checks.
Install
CODEBLOCK0
When to Use
- - "compliance report" / "run compliance"
- "NIST" / "NIST AI RMF" / "NIST CSF" / "NIST 800-53"
- "SOC 2" / "SOC2"
- "ISO 27001"
- "OWASP" / "OWASP LLM Top 10" / "OWASP Agentic Top 10"
- "EU AI Act"
- "AISVS" / "AI Security Verification Standard"
- "CMMC" / "FedRAMP"
- "generate SBOM" / "CycloneDX" / "SPDX"
- "policy check" / "policy enforcement"
Tools (5)
| Tool | Description |
|---|
| INLINECODE0 | OWASP LLM/Agentic Top 10, EU AI Act, MITRE ATLAS, NIST AI RMF |
| INLINECODE1 |
Evaluate results against custom security policy (17 conditions) |
|
cis_benchmark | Run CIS benchmark checks against cloud accounts |
|
generate_sbom | Generate SBOM (CycloneDX or SPDX format) |
|
aisvs_benchmark | OWASP AISVS v1.0 compliance — 9 AI security checks |
Supported Frameworks (14)
- - OWASP LLM Top 10 (2025) — prompt injection, supply chain, data leakage
- OWASP MCP Top 10 — MCP-specific security risks
- OWASP Agentic Top 10 — tool poisoning, rug pulls, credential theft
- OWASP AISVS v1.0 — AI Security Verification Standard (9 checks)
- MITRE ATLAS — adversarial ML threat framework
- NIST AI RMF — govern, map, measure, manage lifecycle
- NIST CSF 2.0 — identify, protect, detect, respond, recover
- NIST 800-53 Rev 5 — federal security controls (CM-8, RA-5, SI-2, SR-3)
- FedRAMP Moderate — derived from NIST 800-53 controls
- EU AI Act — risk classification, transparency, SBOM requirements
- ISO 27001:2022 — information security controls (Annex A)
- SOC 2 — Trust Services Criteria
- CIS Controls v8 — implementation groups IG1/IG2/IG3
- CMMC 2.0 — cybersecurity maturity model (Level 1-3)
Examples
CODEBLOCK1
Privacy & Data Handling
OWASP, NIST, EU AI Act, MITRE ATLAS, AISVS, SBOM generation, and policy
checks run entirely locally on scan data already in memory. No network calls,
no credentials needed for these features.
CIS benchmark checks (optional, user-initiated) call cloud provider APIs
using your locally configured credentials. These are read-only API calls to
AWS, Azure, GCP, or Snowflake. You must explicitly run cis_benchmark(provider=...)
and confirm before any cloud API calls are made.
Verification
agent-bom-compliance — AI合规与策略引擎
根据14个安全与监管框架评估AI基础设施扫描结果。执行策略即代码规则。生成标准格式的SBOM。运行AISVS v1.0和CIS基准检查。
安装
bash
pipx install agent-bom
agent-bom agents -f compliance-export # 运行带合规导出的代理扫描
agent-bom generate-sbom # 生成CycloneDX格式的SBOM
使用场景
- - 合规报告 / 运行合规检查
- NIST / NIST AI RMF / NIST CSF / NIST 800-53
- SOC 2 / SOC2
- ISO 27001
- OWASP / OWASP LLM Top 10 / OWASP Agentic Top 10
- 欧盟AI法案
- AISVS / AI安全验证标准
- CMMC / FedRAMP
- 生成SBOM / CycloneDX / SPDX
- 策略检查 / 策略执行
工具(5个)
| 工具 | 描述 |
|---|
| compliance | OWASP LLM/Agentic Top 10、欧盟AI法案、MITRE ATLAS、NIST AI RMF |
| policy_check |
根据自定义安全策略评估结果(17个条件) |
| cis_benchmark | 对云账户运行CIS基准检查 |
| generate_sbom | 生成SBOM(CycloneDX或SPDX格式) |
| aisvs_benchmark | OWASP AISVS v1.0合规检查——9项AI安全检查 |
支持的框架(14个)
- - OWASP LLM Top 10(2025)——提示注入、供应链、数据泄露
- OWASP MCP Top 10——MCP特定安全风险
- OWASP Agentic Top 10——工具投毒、拉地毯骗局、凭证窃取
- OWASP AISVS v1.0——AI安全验证标准(9项检查)
- MITRE ATLAS——对抗性机器学习威胁框架
- NIST AI RMF——治理、映射、衡量、管理生命周期
- NIST CSF 2.0——识别、保护、检测、响应、恢复
- NIST 800-53 Rev 5——联邦安全控制(CM-8、RA-5、SI-2、SR-3)
- FedRAMP Moderate——源自NIST 800-53控制
- 欧盟AI法案——风险分类、透明度、SBOM要求
- ISO 27001:2022——信息安全控制(附录A)
- SOC 2——信任服务标准
- CIS Controls v8——实施组IG1/IG2/IG3
- CMMC 2.0——网络安全成熟度模型(1-3级)
示例
针对多个框架运行合规检查
compliance(frameworks=[owasp
llm, euai
act, nistai_rmf])
执行自定义策略
policy
check(policy={maxcritical: 0, max_high: 5})
生成SBOM
generate_sbom(format=cyclonedx)
运行AISVS v1.0合规检查
aisvs_benchmark()
运行AWS CIS基准检查
cis_benchmark(provider=aws)
隐私与数据处理
OWASP、NIST、欧盟AI法案、MITRE ATLAS、AISVS、SBOM生成和策略检查完全在本地运行,使用已在内存中的扫描数据。这些功能无需网络调用,无需凭据。
CIS基准检查(可选,由用户发起)使用您本地配置的凭据调用云提供商API。这些是对AWS、Azure、GCP或Snowflake的只读API调用。您必须显式运行cis_benchmark(provider=...)并在进行任何云API调用前确认。
验证