sbom skills

46 tagged sbom, measured the same way as everything else here.

Browse within: vulnerability-scanning 22ai-security 21aibom 19blast-radius 19supply-chain-security 14go 13openssf-scorecard 13purl 13devsecops 9cyclonedx 8compliance 5sbom-distribution 5

chainloop-dev/chainloop

Skill Claude CodeCodex

Reviews open Dependabot pull requests, assesses their risk level based on version bump type and CI status, approves low-risk PRs, and merges them. Use when asked to process, review, merge, or triage Dependabot PRs.

583 today A 54 tokens Apache-2.0

upgrading-chart

03

chainloop-dev/chainloop

Skill Claude CodeCodex

Upgrades Helm chart dependencies (PostgreSQL, Vault) in the Chainloop project, including vendorized charts, container images, and CI/CD workflows. Use when the user mentions upgrading Helm charts, Bitnami dependencies, PostgreSQL chart, or Vault chart. CRITICAL - Major version upgrades are FORBIDDEN and must be…

583 today A 73 tokens Apache-2.0

sca-trivy

04

rohunj/claude-build-workflow

Skill Claude CodeCodex

Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license compliance risks. Use when: (1) Scanning container images and filesystems for vulnerabilities and misconfigurations, (2)…

230 7mo ago A 156 tokens

adriannoes/awesome-agentic-ai

Skill Claude CodeCodex

Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API. Builds dependency graphs, calculates risk scores, identifies transitive vulnerability paths, and generates compliance reports.…

53 3d ago A 110 tokens original MIT

diet-remove

08

future-architect/uzomuzo-oss

Skill Claude CodeCodex

Remove a dependency identified by uzomuzo diet — analysis + issue (default) or direct PR.

32 today A 22 tokens Apache-2.0

agent-bom

09

msaad00/agent-bom

Skill Claude CodeCodex

Open security scanner for agentic infrastructure — agents, MCP, packages, blast radius, runtime, and trust across MCP discovery, CVEs, SBOMs, CIS benchmarks (AWS, Azure, GCP, Snowflake), OWASP/NIST/MITRE compliance, AISVS v1.0, MAESTRO layer tagging, and vector database security checks. Use when the user mentions…

31 yesterday A 107 tokens original Apache-2.0

msaad00/agent-bom

Skill Claude CodeCodex

AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks. Generate SBOMs and compliance reports. Use when: "compliance report", "NIST", "SOC 2", "ISO 27001", "OWASP", "EU AI Act", "AISVS", "generate SBOM", "policy check".

31 yesterday A 102 tokens original Apache-2.0

agent-bom-scan

11

msaad00/agent-bom

Skill Claude CodeCodex

Open security scanner for agentic infrastructure — agents, MCP, packages, blast radius, runtime, and trust for package CVEs (OSV, NVD, EPSS, KEV), container images, provenance, filesystems, and SBOMs. Use when: "check package", "scan image", "verify", "is this safe", "scan dependencies", "CVE lookup", "blast radius".

31 yesterday A 89 tokens original Apache-2.0

sbomapp-mcp-server

12

mcpsbom/sbomapp-mcp-server

Skill Claude CodeCodex

SBOMApp is a remote MCP server that provides Software Bill of Materials (SBOM) generation, vulnerability scanning, and dependency analysis capabilities to AI assistants. It enables any MCP-compatible AI client to analyze software projects for security risks, license compliance, and dependency health — directly from…

0 6mo ago A 0 tokens