Agent discovery & inventory

Cisco AI Defense AI BOM

Open-source scanner from Cisco's AI Defense team that inspects codebases, container images and cloud environments to produce an AI bill of materials listing models, agents, tools, MCP servers and clients, datasets, prompts, guardrails and secrets. Detection is static analysis plus catalog matching, with optional LLM-based enrichment.

open_source · generally available · Research snapshot 2026-09-06

Visit the official product source ↗

Where it fits

Agent discovery & inventory · Model lifecycle & governance

Useful conversation with: AppSec engineer, Platform engineer, AI security researcher.

Ask for a demonstration

Demonstrate running the scanner against one of our Python repositories and a container image, and show the resulting AI-BOM entries for agents, tools and MCP servers.

Capabilities and evidence

Support labels reflect the supplied research. Documentation and vendor claims are not independent product tests. “Not established” means the researcher did not find support; it does not prove a capability is absent.

Documented by provider

Scans codebases, container images and cloud environments to produce an inventory of models, agents, tools, MCP servers and clients, datasets, prompts, guardrails and secrets, with support listed for Python, JavaScript/TypeScript, Java, Go, Rust, Ruby and C#.

Limit: Repository README describes capability; depth of non-Python language support and cloud scanning is not detailed there.

Source s1

Documented by provider

Uses libcst-based static Python analysis to capture assignments, decorators, type annotations, context managers and class definitions, matching fully qualified symbols against a DuckDB catalog, with optional LLM enrichment for model names and call-path annotation.

Limit: Documentation describes the Python analysis path specifically; detection is limited to components represented in the catalog or custom rules.

Source s2

Documented by provider

Supports custom component catalogs, base-class detection rules, exclude patterns and inline source annotations via a .aibom.yaml file and comment tags.

Limit: Requires engineering effort to tune; no managed UI or continuous monitoring is claimed.

Source s2

Limitations to discuss

Sources

  1. cisco-ai-defense/aibom · Cisco AI Defense (GitHub) · official repository
    Access date reported by researcher: 2026-09-06
  2. AI BOM | Cisco AI Defense · Cisco · official docs
    Access date reported by researcher: 2026-09-06

Listing does not imply partnership, supplier status, a working DutyGraph integration, or a compliance certification.

Suggest a correction