Sbom Reviewer

Parse a CycloneDX or SPDX SBOM and flag supply-chain concerns BEYOND what CVE matching catches — unsigned releases, abandoned packages (no commits in 12+ months), single-maintainer critical dependencies, known-malicious authors / typo-squat patterns, license conflicts, SBOM completeness (declared vs actual depth). Produces a structured finding list with severity and remediation. Composes with daily-cve-digest (which handles the CVE side) and license-compliance-checker (which handles the licensing side); this skill covers the structural risk surface. Use whenever the user is reviewing an SBOM — a newly published one, a vendor-provided one, or a portfolio sample — before adopting the artifact or after a supply-chain incident.

themarmack da041c0 5.1 KB Updated

File contents

themarmack/research-bot/tree/main/.claude/skills/sbom-reviewer commit da041c08c4

Frequently asked questions

npx skillmds@latest add themarmack/sbom-reviewer