What problem does it solve? Engineers and security teams often need NIST SP 800-218 (SSDF) guidance mid-task but cannot recall specific practices, tasks, or implementation examples, forcing them to re-read the full 36-page standard. ## Core Features & Use Cases - Practice lookup by ID: Ask for PO.1, PW.4.4, or RV.3 and get the practice definition, tasks, and implementation guidance from reconstructed reference notes. - Topic-based retrieval: Query threat modelling, SBOM, code signing, compiler hardening, vulnerability disclosure, or supply chain security and receive the relevant chapter content. - Supporting references: Includes a glossary of ~40 terms, 13 When/How/Trade-offs patterns, and a decision-table cheatsheet mapping situations to practices. - Use Case: When onboarding a new supplier, ask about security requirements flow-down and receive PO.1.3 guidance on contract clauses, attestation, and provenance obligations aligned with EO 14028. ## Quick Start Ask the agent to explain SSDF practice PW.4.4 and how to continuously verify third-party components against newly disclosed CVEs.