AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
MCP verified Apache-2.0 Self-run

Authorization Bom

mcp-sunilgentyala-authorization-bom · by sunilgentyala

ABOM: a portable Authorization Bill of Materials schema and reference toolkit for human, workload, service, and AI-agent access

No reviews yet
0 installs
15 views
0.0% view→install

Install

$ agentstack add mcp-sunilgentyala-authorization-bom

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/mcp-sunilgentyala-authorization-bom)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Authorization Bom? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

authorization-bom (ABOM)

[](https://github.com/sunilgentyala/authorization-bom/actions/workflows/ci.yml) [](LICENSE) [](pyproject.toml)

ABOM (Authorization Bill of Materials) is a versioned, portable schema and reference toolkit for recording authorization state -- declared, approved, computed-effective, observed-runtime, exception, revoked, and unverified -- across human, workload, service, application, and AI-agent identities. It is designed as a candidate profile/extension for SPDX/CycloneDX-style BOM ecosystems, not a replacement for them.

What this is, precisely

This project's contribution is an interoperability schema + reference tooling, not a novel authorization algorithm. Effective-permission graph analysis, delegation-reachability analysis, and toxic-combination/separation-of-duty detection all have established prior art (commercial and academic), disclosed and compared in [research/comparisonmatrix.md](research/comparisonmatrix.md) and [research/noveltygate.md](research/noveltygate.md). What appears to be missing from existing BOM ecosystems (CycloneDX, SPDX) is a shared, versioned artifact that carries authorization state itself -- across declared/approved/computed/observed/revoked distinctions and across human, workload, service, and AI-agent identity types together -- which is what this schema and tooling provide.

Why ABOM

Three properties, each stated at the narrowest defensible scope and none requiring a new detection algorithm:

  • Cross-identity-type coverage in one document. No standard, product, or preprint found in the

novelty-gate review carries human, workload, service, and AI-agent identities inside the same versioned, portable schema.

  • Full-lifecycle state, not a snapshot. declared, approved, computed, observed,

exception, revoked, and unverified are distinct, coexisting states, so a consumer sees not just what access exists now but how it was arrived at and whether it was independently observed.

  • An evidence-completeness contract. Every code path that cannot fully resolve a grant's

provenance marks it partial or missing rather than silently defaulting to granted or denied -- enforced in src/authbom/engine/ and covered by dedicated negative tests, not just stated intent.

On the synthetic benchmark (10 seeds, benchmarks/results/): the attenuation-corrected effective-permission engine reaches 1.0000 precision/recall vs. a naive baseline's 0.9745 precision (RQ1); agent-inclusive separation-of-duty analysis surfaces violations invisible to a human-only rule scope (RQ4); and the full generate/validate/sign/verify/analyze pipeline completes in under 51ms at the largest tested scale, 228 grants (RQ6). Two results are reported honestly as negative or inconclusive rather than reframed as strengths -- see [research/benchmarkfindings.md](research/benchmarkfindings.md).

Quick start

git clone https://github.com/sunilgentyala/authorization-bom.git
cd authorization-bom
python -m pip install -e ".[dev]"

authbom generate --seed 42 --tenants 2 --output manifest.json
authbom validate manifest.json
authbom analyze manifest.json --now 2026-07-29T12:00:00 --output analysis.json
authbom report analysis.json --format markdown --output report.md

CLI

| Command | Purpose | |---|---| | authbom generate | Produce a deterministic synthetic manifest (for testing/benchmarking) | | authbom import | Parse a read-only source fixture (K8s RBAC, OPA, Cedar, OpenFGA, OAuth, MCP) into a manifest | | authbom validate | Validate a manifest against schema/abom.schema.json | | authbom sign | HMAC-sign every grant and attach a manifest-level attestation | | authbom verify | Verify grant signatures and attestations | | authbom diff | Diff two manifests' grants (added/removed/changed) | | authbom analyze | Run effective-permission, delegation, drift, toxic-combination, and revocation analysis | | authbom reconcile | Merge observed runtime-evidence events into a manifest | | authbom report | Render an analysis result as JSON, Markdown, or SARIF |

Documentation

  • [Schema](schema/abom.schema.json) and [example manifests](schema/examples/)
  • [Formal model](docs/formal_model.md) -- effective-permission closure, drift, toxic combinations, revocation convergence
  • [Threat model](docs/threat_model.md) -- 14 abuse cases and their mitigations/residual risk
  • [Architecture](docs/architecture.md)
  • [Limitations](docs/limitations.md) -- read this before relying on any specific claim
  • [Reproducibility guide](docs/reproducibility.md)
  • Research trail: [novelty gate](research/noveltygate.md), [comparison matrix](research/comparisonmatrix.md), [gap analysis / research questions](research/gapanalysis.md), [benchmark findings](research/benchmarkfindings.md)

Security

Every adapter in src/authbom/adapters/ is read-only and credential-free by design -- it parses an already-exported fixture, never connects to a live system. See [SECURITY.md](SECURITY.md) for the vulnerability reporting policy and [docs/threatmodel.md](docs/threatmodel.md) for the full threat model.

Status

Alpha (0.1.0). Synthetic-benchmark-validated only; not yet evaluated against production authorization estates. See [docs/limitations.md](docs/limitations.md) for the complete, current list of known gaps.

License

Apache License 2.0 -- see [LICENSE](LICENSE).

Citation

See [CITATION.cff](CITATION.cff).

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.