openSUSEopenSUSEOfficial·4 Agent Skills Included

cavil

Open source license review, risk scoring, and SBOM generation

Scans source packages for license text, detects vendored components, and generates SPDX-compliant Software Bill of Materials reports. Replaces slow manual legal review with curated pattern matching, risk scoring, and approval workflows for every package update. Helps lawyers and reviewers triage unresolved license matches, research unknown licenses, and file reusable pattern proposals faster.
npx skills add openSUSE/cavil --all -g -y

All Skills in This Repository (4)

Pure Emerald Level Indicators

Frequently Asked Questions

FAQPage Schema
How to install Cavil skills?

Run `npx skills add openSUSE/cavil --all -g -y` in your terminal to install all skills in this suite globally.

What does Cavil do for legal reviews?

Cavil scans RPMs, DEBs, and tarballs for license text using 28,000 curated patterns, then produces risk-scored legal reports and SPDX 3.0 SBOMs for human reviewers to approve or reject.

Can Cavil generate an SBOM for EU CRA compliance?

Yes. Cavil generates Software Bill of Materials reports in SPDX 3.0.1 format that follow BSI TR-03183-2 for the EU Cyber Resilience Act and cover the CISA minimum elements.

How do the Cavil skills help reviewers?

The skills let your agent draft review notes, research unknown licenses, propose reusable license patterns, and clear unresolved scanner matches, all as advisory input for a human lawyer.

Do I need legal expertise to use Cavil?

No. The skills guide the review step by step and explain risk levels in plain language, but final accept or reject decisions always stay with a human reviewer.

Related Repositories in Legal & Compliance

View All in Legal & Compliance