AI agent security needs a composition graph, not just an SBOM (opens in new tab)
Your SCA scanner can find vulnerable packages. It can't tell you those packages are wired into an AI agent that reads your chat messages, sends files, and is governed by skills that can rewrite its access policy.
Read the original article