analyzing-sbom-for-supply-chain-vulnerabilities

mukul975/analyzing-sbom-for-supply-chain-vulnerabilities · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API, building dependency graphs, calculating risk scores, and generating compliance reports.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 5.9 KB
  • 📁scripts
  • ⚙️agent.py 27.7 KB
  • 📄LICENSE 11.0 KB

Related

  1. generating-and-analyzing-sboms · mukul975 bundle
    Generate CycloneDX and SPDX SBOMs from container images and filesystems, scan them for vulnerabilities with Grype, and sign attestations with Cosign for supply-chain trust.
    24.6k
    repo stars
  2. scanning-container-images-with-grype · mukul975 bundle
    Scan container images for known vulnerabilities using Anchore Grype with SBOM-based matching and configurable severity thresholds.
    24.6k
    repo stars
  3. securing-container-registry-images · mukul975 bundle
    Scan container images for vulnerabilities with Trivy and Grype, generate SBOMs, sign images with Cosign and Sigstore, configure registry access controls, and enforce security gates in CI/CD pipelines.
    24.6k
    repo stars
  4. gov-cybersecurity · martc03
    Queries real-time vulnerability intelligence from NIST NVD, CISA KEV, EPSS, and MITRE ATT&CK via a remote MCP server, offering seven tools for CVE lookup, search, and trending analysis.
    5
    repo stars
  5. gha-security-review · getsentry bundle
    Audits GitHub Actions workflows for exploitable vulnerabilities with concrete attack scenarios.
    845
    repo stars
  6. supply-chain-security · zhaoxuya520 bundle
    Assess software supply chain security by generating SBOMs, scanning dependencies, auditing CI/CD pipelines, analyzing container images, and verifying vulnerability reachability.
    12.8k
    repo stars

Frequently asked questions

How do I install the analyzing-sbom-for-supply-chain-vulnerabilities skill?

Run npx skillmds add mukul975/analyzing-sbom-for-supply-chain-vulnerabilities in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the analyzing-sbom-for-supply-chain-vulnerabilities skill do?

Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API, building dependency graphs, calculating risk scores, and generating compliance reports. It is listed under Security, Vulnerability Scanning on SkillMD.

Is analyzing-sbom-for-supply-chain-vulnerabilities safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with analyzing-sbom-for-supply-chain-vulnerabilities?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is analyzing-sbom-for-supply-chain-vulnerabilities free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published analyzing-sbom-for-supply-chain-vulnerabilities?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.