SKILL.md
agent-bom-analyze — Blast Radius & Attack Path Analysis
Analyzes blast radius, attack paths, and the threat landscape across your AI infrastructure. Maps lateral movement risks, identifies high-impact CVEs, and visualizes agent context graphs.
Install
pipx install agent-bom
agent-bom agents --verbose # blast radius detail for each agent
agent-bom graph # generate context graph
When to Use
- "blast radius" / "what's the blast radius"
- "threat intel" / "threat intelligence"
- "risk score" / "risk scoring"
- "attack path" / "attack paths"
- "lateral movement"
- "context graph" / "agent graph"
- "who can reach what"
Commands
# Blast radius detail (verbose)
agent-bom agents --verbose
# Generate context graph
agent-bom graph
Tools
| Tool | Description |
|---|---|
blast_radius | Map CVE impact chain across agents, servers, and credentials |
context_graph | Agent context graph with lateral movement analysis |
analytics_query | Query vulnerability trends, posture history, and risk scores |
Examples
# Map blast radius of a specific CVE
blast_radius(cve_id="CVE-2024-21538")
# Build full context graph
context_graph()
# Query top CVEs by blast radius impact
analytics_query(query="top_blast_radius", days=30)
Example blast radius output:
CVE-2024-21538 — CRITICAL (CVSS 9.8, EPSS 0.94)
Blast Radius: 4 agents affected
filesystem [direct] langchain 0.1.0 → CVE-2024-21538
└─ github [indirect] shares filesystem credential scope
└─ slack [indirect] accessible via filesystem tool call
postgres [direct] langchain 0.1.0 → CVE-2024-21538
Recommended: Update langchain to ≥ 0.1.17
