What problem does it solve?
This Skill removes the uncertainty and manual effort from producing a trustworthy Software Bill of Materials for software releases, container images, and compliance reviews.
Core Features & Use Cases
- Polyglot Coverage: Handles Python, Node.js, Go, Maven, Rust, Ruby, NuGet, Linux packages, and container images.
- Format Selection: Produces CycloneDX or SPDX output depending on the downstream consumer or compliance requirement.
- Validation and Completeness: Checks required metadata such as supplier, version, PURL, dependency relationships, and schema validity.
- Use Case: A security engineer can generate a release-ready SBOM for a mixed Python and JavaScript monorepo, validate it, and flag components missing license data before sharing it with a customer.
Quick Start
Ask the skill to generate a validated CycloneDX or SPDX SBOM for your resolved repository or container image and to report any missing licenses, suppliers, or dependency information.