All skills
hardw00t avatar

/sca-security

@f9bb3b2

Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to suppress unexploitable findings. Use when scanning package dependencies (npm, PyPI, Maven, Cargo, Go, RubyGems, Composer), reviewing PR lockfile diffs, generating SBOMs, auditing licenses, hunting malicious packages, or auditing the software supply chain. Triggers on requests to scan dependencies, check vulnerable packages, generate SBOM, license compliance, typosquat/dependency-confusion review, or reachability-based vuln triage.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/sca-security

This session only. Nothing lands on disk.

workflowssbom_generation.md

≈726 tokens on demand. Your agent reads this file only when SKILL.md points to it.

SBOM Generation Workflow

Generate a Software Bill of Materials for a repository or container in CycloneDX and SPDX formats. SBOMs are the foundation for downstream vuln correlation, license audit, and supply chain review — generate once, reuse.

Decision: which tool?

Source Preferred tool Why
Repo (any ecosystem) syft Multi-ecosystem, one binary, both CDX + SPDX
Container image syft <image> Extracts OS packages + app-layer deps
npm project only @cyclonedx/cyclonedx-npm Includes scope=runtime/dev distinction
Python virtualenv cyclonedx-py environment Reads the actual installed set, not spec
Maven multi-module cyclonedx-maven-plugin Honors Maven dependency resolution
Go cyclonedx-gomod mod Honors go.mod version selection

Step 1 — Generate SBOM (Syft, default)

# Directory scan, CycloneDX JSON
syft dir:. -o cyclonedx-json=sbom.cdx.json

# Same source, SPDX JSON (some tools prefer SPDX)
syft dir:. -o spdx-json=sbom.spdx.json

# Container image
syft registry:ghcr.io/org/app:v1.2.3 -o cyclonedx-json=image.cdx.json

# Include file metadata (checksums) — required for high-assurance SBOMs
syft dir:. --source-name myapp --source-version 1.2.3 \
  -o cyclonedx-json=sbom.cdx.json --file-metadata

Parallelism: if repo is polyglot, Syft already walks all ecosystems; one invocation is enough. For per-ecosystem "native" SBOMs (e.g. cyclonedx-npm + cyclonedx-maven), run them in parallel.

Step 2 — Validate

# CycloneDX CLI validation
cyclonedx validate --input-file sbom.cdx.json

# SPDX tools validation
pyspdxtools --input-file sbom.spdx.json

Reject any SBOM missing: serialNumber (CDX) / documentNamespace (SPDX), component purl, version.

Step 3 — Enrich

# Add VEX (Vulnerability Exploitability eXchange) stub
cyclonedx-cli merge --input-files sbom.cdx.json vex.cdx.json \
  --output-file sbom-with-vex.cdx.json

Step 4 — Hand off

  • Vuln correlation: grype sbom:sbom.cdx.json or trivy sbom sbom.cdx.json (see vuln_correlation.md)
  • License audit: jq over sbom.cdx.json (see license_audit.md)
  • Supply chain review: see supply_chain_review.md

Structured output

For each component emit to schemas/finding.json only when a risk is found. The SBOM itself is stored as an artifact; the finding schema captures vulns/license issues derived from it.

Common failure modes

  • syft missing a dep because lockfile was not committed — fail closed; require lockfiles.
  • CDX vs SPDX purl drift — always prefer CDX's purl field for tool interop.
  • Python SBOMs missing system-installed packages when scanning source dir; use cyclonedx-py environment inside the actual runtime venv.

Minimum tool versions (2026-04)

  • syft >= 1.14
  • cyclonedx-cli >= 0.27
  • cyclonedx-maven-plugin >= 2.8

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    A highly comprehensive and professional Software Composition Analysis (SCA) skill designed for auditing dependencies, generating SBOMs, and detecting supply chain attacks. The skill correctly identifies and provides detection workflows for sophisticated attack vectors such as typosquatting, dependency confusion, and malicious install scripts. No malicious patterns or security risks were detected in the skill's own operation.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/sca-security