endor-sbom

Generate and manage SBOMs in CycloneDX and SPDX formats with NTIA checks.

2|Updated Feb 4, 2026
One-click install
npx skills add https://github.com/endorlabs/skills-ideas --skill endor-sbom-endorlabs
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: endor-sbom
Source: https://github.com/endorlabs/skills-ideas/tree/main/skills/endor-sbom
Command: npx skills add https://github.com/endorlabs/skills-ideas --skill endor-sbom-endorlabs

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

SBOM management automates the creation, analysis, and alignment of software component inventories, reducing manual effort and increasing visibility into dependencies and licenses.

Core Features & Use Cases

  • Export SBOMs in CycloneDX and SPDX formats from a project
  • Import and analyze external SBOMs to identify components, dependencies, and risks
  • Compare SBOMs to detect drift and NTIA compliance gaps
  • Validate SBOM formats to ensure standard-conformance and audit readiness

Quick Start

Export an SBOM for your current project using CycloneDX or SPDX formats to begin inventorying components.

Frequently Asked Questions about endor-sbom

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I export an SBOM in CycloneDX or SPDX format for software supply chain compliance?

To export an SBOM in CycloneDX or SPDX formats, you provide your project UUID to trigger the Endorctl export workflow. This generates a standardized software component inventory to support compliance and audit readiness.

What is the best way to compare SBOMs to detect dependency drift and NTIA compliance gaps?

Comparing SBOMs allows you to detect dependency drift and NTIA compliance gaps by analyzing differences between software component inventories. The process validates formats and highlights variations to ensure ongoing standard conformance.

Can I import and analyze external SBOMs to identify components and risks?

Yes, you can import and analyze external SBOMs to identify software components, dependencies, and risks. This process automates inventory alignment and increases visibility into software supply chain vulnerabilities.

Do I need a project UUID to validate SBOM formats for audit readiness?

Yes, a project UUID is required to enforce Endorctl SBOM workflows, including validating SBOM formats. This ensures standard-conformance and audit readiness for your software supply chain inventory.

Why does SBOM management matter for software supply chain risk assessment?

SBOM management matters for risk assessment because it automates the creation and analysis of software component inventories. This reduces manual effort and increases visibility into dependencies and licenses across your software supply chain.