Install
openclaw skills install agent-bom-discover-awsDiscover AWS-hosted AI agent and MCP-relevant assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving age...
openclaw skills install agent-bom-discover-awsUse this skill to collect AWS AI and workload inventory from the operator's
environment as canonical inventory. The skill is discover-only by default:
write schema-valid JSON to an operator-selected path and stop. Run
agent-bom only when the operator explicitly wants findings, graph, policy,
or exports from that inventory.
agent-bom trust or
/v1/discovery/providers.AWS_ACCESS_KEY_ID,
AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, or bearer tokens.| Mode | What happens | Data boundary |
|---|---|---|
discover-only | Emit canonical inventory JSON and stop | No agent-bom scan or API handoff |
scan-local | Run agent-bom agents --inventory ... on the generated file | Local handoff into the scanner |
export | Write JSON/SARIF or another operator-selected output | Local output only unless the operator routes it elsewhere |
Use discover-only unless the operator asks for scan results or an export.
python examples/operator_pull/aws_inventory_adapter.py \
--region us-east-1 \
--profile readonly-audit \
--source aws-skill-invoked \
--discovery-method skill_invoked_pull \
--output aws-inventory.json
agent-bom agents --inventory aws-inventory.json
agent-bom agents --inventory aws-inventory.json --format json --output agent-bom-aws-findings.json
Start narrow, then expand deliberately:
python examples/operator_pull/aws_inventory_adapter.py \
--region us-east-1 \
--profile readonly-audit \
--source aws-skill-invoked \
--discovery-method skill_invoked_pull \
--include-ecs \
--include-lambda \
--include-eks \
--output aws-inventory.json
Use --no-include-ecs or similar flags to disable default services when an
operator wants a smaller scope.
The inventory emitted by this skill uses:
source: aws-skill-invokeddiscovery_provenance.source_type: skill_invoked_pulldiscovery_provenance.observed_via: skill_invoked_pull, aws_sdkmetadata.permissions_usedcloud_origin, cloud_principal, lifecycle fields, packages, and
MCP server launch metadataIf schema validation fails, stop and fix the inventory instead of scanning a best-effort or prose summary.
The skill does not push inventory to an API by default. Any push, scan, or managed control-plane handoff must be a separate operator-approved handoff command with the destination URL, auth method, and retained evidence classes made explicit.