Agent Economy Report

Agent Skill Trust Rating

A ▲ improving

agent-bom scan (agent-bom-scan)

Trend improving: 4,248 downloads in the last 7 days vs 11 in the 7 before (+38518%). The trend is not the direction of the rating.

above the trust line (BBB): proven adoption, mature, nothing alarming in its instructions.

Open security scanner for agentic infrastructure — agents, MCP, packages, blast radius, runtime, and trust for package CVEs (OSV, NVD, EPSS, KEV), container images, provenance, filesystems, and SBOMs. Use when: "check package", "scan image", "verify", "is this safe", "scan dependencies", "CVE lookup

Signals

Downloads4,339 (7d: +4,248)
Installs · stars · versions73 · 0 · 78
Track record34 days in the registry
Authormsaad00
Requiresnone declared
Instructions readyes: payees, wallets and shell patterns extracted from SKILL.md

Flags

Who it pays (x402 counterparties found in its instructions)

serviceservice ratingwallet
No payee found in its instructions.

Install

openclaw skills install @msaad00/agent-bom-scan · registry page

For agents

Free JSON: https://agenteconomy.report/k/agent-bom-scan.json · badge: https://agenteconomy.report/k/agent-bom-scan.svg · paid record via x402: GET https://agenteconomy.report/api/skill/agent-bom-scan (US$ 0.005). Check any skill before installing it with the x402-trust-check skill.

Code audit

No independent code audit of this skill yet. Commission one (US$ 29 per version; the result is published whatever it says).

How this is computed

Adoption (downloads relative to the registry, 7-day velocity, installs), maturity (age, release cadence, stars, author portfolio), inherited payment trust (every host or wallet the skill's instructions pay is looked up in the x402 service trust index; paying a rated service inherits its tier, an unknown hard-coded wallet is flagged) and hygiene (registry moderation verdict, license, declared setup, origin). Flags cap the tier, they never add to it. Trust line at BBB. Rating as of 2026-09-09.