sbom-supply-chain
sbom-supply-chain is an code AI skill with a core value of Generate, sign, and verify SBOMs and provenance attestations to secure the software supply chain. It
helps developers solve real-world problems in the code domain, boosting
efficiency, automating repetitive tasks, and optimizing workflows.
Generate, sign, and verify SBOMs and provenance attestations to secure the software supply chain. Use when implementing SLSA controls, artifact trust policies, or compliance evidence for releases.
Quick Facts
mkdir -p ./skills/sbom-supply-chain && curl -sfL https://raw.githubusercontent.com/sickn33/antigravity-awesome-skills/main/skills/sbom-supply-chain/SKILL.md -o ./skills/sbom-supply-chain/SKILL.md Run in terminal / PowerShell. Requires curl (Unix) or PowerShell 5+ (Windows).
Skill Content
# SBOM & Supply Chain Security
Improve release trust with reproducible metadata and verification gates.
When to Use This Skill
Use this skill when:
- Producing SBOMs for container images or application builds
- Verifying dependencies before deploy
- Enforcing signed artifact and provenance policies
- Preparing for SOC2, ISO 27001, or customer security reviews
- Implementing SLSA framework requirements
- Responding to supply chain vulnerabilities (e.g., Log4Shell-style events)
Prerequisites
- `syft` installed for SBOM generation
- `cdxgen` installed for CycloneDX SBOM generation
- `grype` for vulnerability matching against SBOMs
- `cosign` v2+ for signing and attestation
- Container registry with OCI artifact support
- CI/CD pipeline with OIDC identity for keyless signing
SBOM Formats
CycloneDX vs SPDX Comparison
comparison:
cyclonedx:
standard: "OWASP CycloneDX"
focus: "Application security, vulnerability tracking"
formats: ["JSON", "XML", "Protocol Buffers"]
strengths:
- Vulnerability references (VEX support)
- Service and API dependency tracking
- Hardware BOM support
best_for: "Security-focused SBOM, vulnerability management"
spdx:
standard: "Linux Foundation SPDX (ISO/IEC 5962:2021)"
focus: "License compliance, legal review"
formats: ["JSON", "RDF/XML", "Tag-Value", "YAML"]
strengths:
- ISO standard
- License expression language
- Relationship modeling
best_for: "License compliance, regulatory requirements"Syft SBOM Generation
# Generate SBOM for a container image (CycloneDX JSON)
syft ghcr.io/acme/api:v1.2.3 -o cyclonedx-json > sbom-cyclonedx.json
# Generate SBOM in SPDX format
syft ghcr.io/acme/api:v1.2.3 -o spdx-json > sbom-spdx.json
# Generate SBOM from a local directory (source code)
syft dir:. -o cyclonedx-json > sbom-source.json
# Generate SBOM from a Dockerfile/built image
syft docker:my-local-image:latest -o cyclonedx-json > sbom-local.json
# Generate SBOM for a specific package ecosystem
syft dir:. --catalogers python -o cyclonedx-json > sbom-python.json
# Include file hashes for deeper analysis
syft ghcr.io/acme/api:v1.2.3 -o cyclonedx-json --file-metadata > sbom-with-hashes.json
# Multiple output formats simultaneously
syft ghcr.io/acme/api:v1.2.3 \
-o cyclonedx-json=sbom-cdx.json \
-o spdx-json=sbom-spdx.json \
-o table=sbom-summary.txtcdxgen SBOM Generation
# Install cdxgen
npm install -g @cyclonedx/cdxgen
# Generate CycloneDX SBOM for a project directory
cdxgen -o sbom.json .
# Specify project type
cdxgen -t python -o sbom-python.json .
cdxgen -t java -o sbom-java.json .
cdxgen -t node -o sbom-node.json .
cdxgen -t go -o sbom-go.json .
# Generate SBOM with evidence (call stacks, file occurrences)
cdxgen --evidence -o sbom-with-evidence.json .
# Generate for a container image
cdxgen -t docker -o sbom-container.json ghcr.io/acme/api:v1.2.3
# Generate with deep analysis (slower but more accurate)
cdxgen --deep -o sbom-deep.json .
# Output in different formats
cdxgen -o sbom.xml --format xml .Vulnerability Matching
# Scan SBOM for vulnerabilities with Grype
grype sbom:sbom-cyclonedx.json
# Fail on critical/high vulnerabilities
grype sbom:sbom-cyclonedx.json --fail-on high
# Output as JSON for CI processing
grype sbom:sbom-cyclonedx.json -o json > vulnerability-report.json
# Scan container image directly
grype ghcr.io/acme/api:v1.2.3
# Use Trivy with SBOM input
trivy sbom sbom-cyclonedx.json
# Trivy scan with severity filter
trivy sbom sbom-cyclonedx.json --severity CRITICAL,HIGH --exit-code 1Cosign Signing and Attestation
Image Signing
# Keyless signing (recommended - uses OIDC identity from CI)
cosign sign ghcr.io/acme/api@sha256:abc123...
# Sign with a key pair
cosign generate-key-pair
cosign sign --key cosign.key ghcr.io/acme/api@sha256:abc123...
# Verify keyless signature
cosign verify \
--certific🎯 Best For
- QA engineers
- Developers writing unit tests
- Developers scaffolding new projects
- Prototype builders
- Claude users
💡 Use Cases
- Generating test cases for edge conditions
- Writing integration test suites
- Bootstrapping React components
- Creating API route handlers
📖 How to Use This Skill
- 1
Install the Skill
Copy the install command from the Terminal tab and run it. The SKILL.md file downloads to your local skills directory.
- 2
Load into Your AI Assistant
Open Claude and reference the skill. Paste the SKILL.md content or use the system prompt tab.
- 3
Apply sbom-supply-chain to Your Work
Open your project in the AI assistant and ask it to apply the skill. Start with a small module to verify the output quality.
- 4
Review and Refine
Review AI suggestions before committing. Run tests, check for regressions, and iterate on the skill output.
❓ Frequently Asked Questions
Does this generate test mocks?
Many testing skills include mock generation. Check the install command and skill content for details.
Can I customize the generated output?
Yes — modify the skill's prompt instructions to match your project conventions and coding style.
Is sbom-supply-chain compatible with Cursor and VS Code?
Yes — this skill works with any AI coding assistant including Cursor, VS Code with Copilot, and JetBrains IDEs.
Do I need specific dependencies for sbom-supply-chain?
Check the install command and Works With section. Most code skills only require the AI assistant and your codebase.
How do I install sbom-supply-chain?
Copy the install command from the Terminal tab and run it. The skill downloads to ./skills/sbom-supply-chain/SKILL.md, ready to use.
⚠️ Common Mistakes to Avoid
Not testing edge cases
AI tends to generate happy-path tests. Manually review for boundary conditions.
Using generated code without understanding
Understand what generated code does before shipping it to production.
Skipping validation
Always test AI-generated code changes, even for simple refactors.
Missing dependency updates
Check if the skill requires updated dependencies or new packages.