Generate and validate CycloneDX and SPDX SBOMs for compliance and supply chain security.
Copy the install command and let the AI configure it · recommended for beginners
Please install the "io.github.CSOAI-ORG/sbom-cyclonedx-mcp" MCP server from askskill: Run: claude mcp add 'io-github-csoai-org-sbom-cyclonedx-mcp' -- npx -y sbom-cyclonedx-mcp
Generate a CycloneDX 1.6 SBOM for this software project, and list the main components, versions, licenses, and dependencies.
A CycloneDX 1.6 compliant SBOM file with a summary of components.
Validate this SPDX 2.3 SBOM for specification compliance, and identify missing fields, format errors, or potential consistency issues.
A validation report showing pass/fail status, specific issues, and suggested fixes.
Export this project as both CycloneDX 1.6 and SPDX 2.3, then compare differences in component data and license representation.
Two SBOM outputs plus a comparison summary to help choose the right delivery format.
Generate machine-readable NIST OSCAL and FedRAMP compliance packages.
Plan features and create structured software design documents stored locally.
Query projects, findings, analyses, and upload BOMs to Dependency-Track.
Run app security scans, track remediation, and integrate SBOM/SARIF into CI.
Embed and manage diagrams in MDX documentation for clearer technical communication.
Integrate Sicoob APIs for Pix, boleto, and SPB workflows securely.