Basenull AI Ops · Inventory
The AI Bill of Materials for your GitHub org.
Agents, MCP servers, model dependencies, AI-driven CI — they live in your repos today, and no SBOM scanner sees them. Paste a repository and get the inventory your auditor keeps asking for.
What it finds
MCP servers
Every server wired into .mcp.json, Cursor, VS Code, or Gemini configs — with the commands and third-party URLs they point at.
Agents and instructions
CLAUDE.md, AGENTS.md, Cursor rules, Copilot instructions, Claude Code skills, subagents, and lifecycle hooks.
AI in CI
GitHub Actions that run coding agents or call model APIs — automation with repo permissions someone should know about.
Models and SDKs
Anthropic, OpenAI, LangChain, LlamaIndex, MCP SDKs, agent frameworks — from package.json to pyproject.toml to go.mod.
Paste a repository
Any public GitHub repo. No signup, no OAuth — the scan reads the repository tree and parses configs and manifests. Zero AI calls; the detection is deterministic.
Get the AI-BOM report
A permanent URL you can hand to your CISO, plus a JSON download for the audit folder. Every finding links to the exact file on GitHub.
Monitor the whole org
Team scans every repository in your GitHub organization, rescans weekly, and emails you when the AI surface drifts — a new MCP server, a new model dependency.
Why now
"What AI is deployed in our stack?" now has a deadline.
EU AI Act deployer obligations, NIST AI RMF, ISO 42001 — every framework starts with the same control: maintain an inventory of AI systems. Meanwhile the actual AI surface moved into your repos: a developer adds an MCP server to .cursor/mcp.json and nothing in your tooling notices. ai-bom makes the register a scan, not a survey.
- Findings link to the exact file and branch on GitHub — evidence, not claims.
- JSON export drops into the audit folder next to your CycloneDX SBOMs.
- Discovered MCP servers link straight to mcp-inspect (audit the surface) and mcp-watch (monitor it for changes).
Free for public repos. Team for the whole org.
Unlimited single-repo scans with shareable reports, free. Team at $49/mo scans every repo in your organization — private included — rescans weekly, and alerts you on drift.
See pricing