generating-and-analyzing-sboms

mukul975/generating-and-analyzing-sboms · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Generate CycloneDX and SPDX SBOMs from container images and filesystems, scan them for vulnerabilities with Grype, and sign attestations with Cosign for supply-chain trust.

SKILL.md

Files

This skill is a package of 5 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.3 KB
  • 📄standards.md 1.4 KB
  • 📁scripts
  • ⚙️agent.py 5.3 KB
  • 📄LICENSE 11.0 KB

Related

  1. analyzing-sbom-for-supply-chain-vulnerabilities · mukul975 bundle
    Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API, building dependency graphs, calculating risk scores, and generating compliance reports.
    24.6k
    repo stars
  2. securing-container-registry-images · mukul975 bundle
    Scan container images for vulnerabilities with Trivy and Grype, generate SBOMs, sign images with Cosign and Sigstore, configure registry access controls, and enforce security gates in CI/CD pipelines.
    24.6k
    repo stars
  3. supply-chain-security · zhaoxuya520 bundle
    Assess software supply chain security by generating SBOMs, scanning dependencies, auditing CI/CD pipelines, analyzing container images, and verifying vulnerability reachability.
    12.8k
    repo stars
  4. scanning-container-images-with-grype · mukul975 bundle
    Scan container images for known vulnerabilities using Anchore Grype with SBOM-based matching and configurable severity thresholds.
    24.6k
    repo stars
  5. verifying-build-provenance-with-slsa-sigstore · mukul975 bundle
    Verify signed artifacts and SLSA build provenance with Sigstore cosign and slsa-verifier, enforce keyless OIDC identity, and apply SLSA Build levels to harden the software supply chain.
    24.6k
    repo stars
  6. performing-container-security-scanning-with-trivy · mukul975 bundle
    Scan container images, filesystems, and Kubernetes manifests for vulnerabilities, misconfigurations, exposed secrets, and license compliance issues using Aqua Security Trivy with SBOM generation and CI/CD integration.
    24.6k
    repo stars

Frequently asked questions

How do I install the generating-and-analyzing-sboms skill?

Run npx skillmds add mukul975/generating-and-analyzing-sboms in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the generating-and-analyzing-sboms skill do?

Generate CycloneDX and SPDX SBOMs from container images and filesystems, scan them for vulnerabilities with Grype, and sign attestations with Cosign for supply-chain trust. It is listed under Security, Coding & Dev Tools, DevOps & Infra, CI/CD, Vulnerability Scanning on SkillMD.

Is generating-and-analyzing-sboms safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with generating-and-analyzing-sboms?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is generating-and-analyzing-sboms free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published generating-and-analyzing-sboms?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.