Blog
Notes on Agent Composition Analysis — identity resolution, Agent BOMs, and securing AI agent stacks. RSS
- How the EU Cyber Resilience Act (CRA) impacts AI Agents
The CRA asks manufacturers to say what their product is made of, ship it without known holes, and document their diligence on third-party components. Agent stacks have no universal component model — and the first obligations land on 11 September 2026.
- What Is an AI-BOM, Really?
AI-BOMs list models or systems. Agent BOMs explain how plugins, skills, MCP servers, and packages are wired together — and where risk flows through that wiring.
- Your Agent Risk Isn't in One Plugin. It's in the Composition.
Your SCA scanner can find vulnerable packages. It can't tell you those packages are wired into an AI agent that reads your chat messages, sends files, and is governed by skills that can rewrite its access policy.
- Introducing OpenACA: Agent Composition Analysis
Your dependency scanner can't see your agent stack. OpenACA is an open-source scanner that inventories the MCP servers, plugins, skills, and dependencies your AI agents pull in — and matches them against known security advisories.