# SBOM Vulnerability Scanner

> Generates Software Bill of Materials using Syft and scans for CVEs with Grype. Cross-references findings against the NVD and OSV databases for comprehensive vulnerability detection.

- Skill: `agentskillexchange/sbom-vulnerability-scanner` (Agent Skill)
- Install (CLI): `npx skillmds@latest add agentskillexchange/sbom-vulnerability-scanner`
- Raw SKILL.md: https://api.skillmd.com/api/skills/agentskillexchange/sbom-vulnerability-scanner/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: agentskillexchange (https://skillmd.com/u/agentskillexchange)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/agentskillexchange/sbom-vulnerability-scanner

---


# SBOM Vulnerability Scanner

Generates Software Bill of Materials using Syft and scans for CVEs with Grype. Cross-references findings against the NVD and OSV databases for comprehensive vulnerability detection.

## Installation

Use the upstream install or setup path that matches your environment:
- Docker Docs
- Docker Hardened Images
- Why should I use Docker Compose?
- Docker Desktop overview

Requirements and caveats from upstream:
- Gordon Gordon, your AI assistant for Docker docs
- email: 'docs@docker.com',
- I'm Gordon, your AI assistant for Docker and documentation

Basic usage or getting-started notes:
- Can I run my AI agent in a sandbox?
- Reference
- Browse the CLI and API documentation.

- Source: https://docs.docker.com/

## Documentation

- https://docs.docker.com/

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/sbom-vulnerability-scanner/)

