Security Sbom

Use this skill when asked about SBOM, software bill of materials, dependency graph, SPDX, CycloneDX, supply chain security, component inventory, or dependency analysis. This skill enforces: SBOM generation in CycloneDX/SPDX formats, dependency vulnerability correlation with severity gating, license compliance checks, and attestation signing. Do NOT use for: static code analysis (SAST), container image scanning, or secret detection.

j4flmao Updated

File contents

j4flmao/agent-skills/tree/main/skills/security/sbom commit 5682a110ca

Frequently asked questions

npx skillmds@latest add j4flmao/security-sbom