AgentSPM is a GitHub App that inventories every AI agent living in your repositories, whatever the framework: LangGraph, Google ADK, Claude, CrewAI or custom code. It maps the data flows those agents open, scores their posture and proposes remediation as pull requests.
Agents get written faster than they get catalogued. Security, legal and IT teams end up unable to answer a simple question: how many agents do we run, what do they read, and where does the data go. AgentSPM answers it from the code itself rather than from a declaration.
Each agent is scored against the European AI Act and the NIST AI Risk Management Framework. The transparency obligations of article 50 have applied since 2 August 2026; the high-risk deadline of annex III has been deferred to 2 December 2027. AgentSPM surfaces where a given agent falls before either date matters to you.
AgentSPM is open source and runs inside the European Union. Remediation ships as a pull request in your own repository: you review it and you merge it, nothing is changed without you.