arckit-us-sbom-eo-14028

Generate CISA-compliant self-attestations and SBOMs in CycloneDX or SPDX formats.

Updated Jul 24, 2026
One-click install
npx skills add https://github.com/tractorjuice/arckit-kimi --skill arckit-us-sbom-eo-14028
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: arckit-us-sbom-eo-14028
Source: https://github.com/tractorjuice/arckit-kimi/tree/main/skills/arckit-us-sbom-eo-14028
Command: npx skills add https://github.com/tractorjuice/arckit-kimi --skill arckit-us-sbom-eo-14028

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

This Skill automates the complex, high-stakes process of generating secure-software self-attestations and SBOMs required for compliance with US federal mandates like EO 14028 and OMB M-22-18.

Core Features & Use Cases

  • Compliance Automation: Generates CISA-compliant self-attestation forms mapped to NIST 800-218 SSDF practices.
  • SBOM Generation: Produces machine-readable Software Bill of Materials in CycloneDX or SPDX formats.
  • Use Case: An enterprise architect needs to provide a formal attestation for a new software release to a federal agency; this skill gathers the necessary project artifacts and generates the required documentation and inventory reports.

Quick Start

Invoke the arckit-us-sbom-eo-14028 skill to generate a compliance package for your current project.

Frequently Asked Questions about arckit-us-sbom-eo-14028

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a secure-software self-attestation for EO 14028 compliance?

To generate secure-software self-attestations for EO 14028, you map your software development practices to NIST 800-218 SSDF controls. This process gathers project architecture artifacts and build pipeline metadata to produce CISA-compliant documentation.

Can I generate a Software Bill of Materials in SPDX or CycloneDX format for federal mandates?

You can generate machine-readable Software Bill of Materials in either CycloneDX or SPDX formats. This SBOM generation satisfies federal cybersecurity mandates by ensuring accurate provenance and vulnerability reporting for enterprise software releases.

What NIST controls are required for OMB M-22-18 secure software attestations?

OMB M-22-18 secure software attestations require mapping development practices to NIST 800-218 SSDF practices and NIST 800-53 controls. This mapping demonstrates that adequate security controls are integrated into your software development lifecycle.

Does generating an SBOM require integration with my build pipeline metadata?

Generating an accurate SBOM requires integration with build pipeline metadata and project-specific architecture artifacts. This integration ensures accurate provenance and vulnerability reporting for your software components.

What is the best way to automate CISA-compliant self-attestation forms for federal agencies?

The best way to automate CISA-compliant self-attestation forms is by mapping software development practices directly to NIST 800-218 SSDF practices. This ensures your formal attestation package meets federal cybersecurity mandates.

When do I need an SBOM and self-attestation package for enterprise architecture workflows?

You need an SBOM and self-attestation package when providing a new software release to a federal agency. This compliance package maps your enterprise architecture artifacts to required NIST controls for vulnerability reporting.