sbom-syft
Generate SBOMs with Syft
Manual software inventories are incomplete and difficult to maintain. This skill guides repeatable Syft SBOM generation for containers, filesystems, archives, and CI pipelines.
Do not auto-install this skill.
The canonical policy requires operator review before any installation action.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "sbom-syft" from https://skillstore.io/skills/agentsecops-sbom-syft.md and its manifest at https://skillstore.io/api/skills/agentsecops-sbom-syft/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "sbom-syft". Create a CycloneDX inventory for the release image and retain it for audit.
Expected outcome:
- Target confirmed as the immutable release image digest.
- CycloneDX output stored with the release artifacts.
- Validation checks confirm the file is readable and contains package components.
Using "sbom-syft". Compare dependencies between two application releases and highlight license changes.
Expected outcome:
- Added and removed packages are grouped by ecosystem.
- Version changes are listed separately from package additions.
- New or changed licenses are flagged for compliance review.
Using "sbom-syft". Prepare a secure CI plan for generating and signing an SBOM.
Expected outcome:
The plan pins tool sources, verifies downloads, generates the SBOM, enforces scan policy, signs the attestation, and retains verification evidence.
Security Audit
CriticalMost detections are false positives caused by Markdown formatting, defensive examples, or fixed local operations. The template still includes a critical pipe-to-shell installer and instructions that download mutable artifacts without integrity verification. It also exposes a GitHub token to an unpinned action and contains CI controls that can fail open.
Confirmed security concerns (4)
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
โ๏ธ External commands (50)
๐ Network access (24)
๐ Filesystem access (4)
๐ Env variables (23)
โก Contains scripts (2)
Detected Patterns
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/agentsecops-sbom-syft/audits/9?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/agentsecops-sbom-syft?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/agentsecops-sbom-syft?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/agentsecops-sbom-syft/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/agentsecops-sbom-syft.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
AgentSecOps. (2026). sbom-syft security audit report (audit version 9) [Author version 0.1.0]. Skillstore. https://skillstore.io/skills/agentsecops-sbom-syft/audits/9BibTeX citation
@techreport{agentsecops-agentsecops-sbom-syft-2026,
author = {AgentSecOps},
title = {sbom-syft security audit report (audit version 9)},
institution = {Skillstore},
year = {2026},
number = {9},
url = {https://skillstore.io/skills/agentsecops-sbom-syft/audits/9},
note = {Author version 0.1.0}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "sbom-syft security audit report (audit version 9)"
version: "0.1.0"
type: report
authors:
- name: "AgentSecOps"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/agentsecops-sbom-syft/audits/9"
identifiers:
- type: other
value: "skillstore:agentsecops-sbom-syft:audit:9"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Inventory Release Images
Generate CycloneDX and SPDX inventories for each container release and retain them with build artifacts.
Automate Build Evidence
Add repeatable SBOM generation, validation, and artifact retention to an existing delivery pipeline.
Review Dependency Licenses
Extract package and license data for compliance review across applications and container images.
Try These Prompts
Create a CycloneDX SBOM for <container-image>. Confirm the target, choose a safe output path, and explain how to validate the result.
Generate an SPDX SBOM for <project-path>. Exclude <patterns>, report detected ecosystems, and identify likely coverage gaps.
Design a CI job for <platform> that generates an SBOM for <artifact>. Pin dependencies, verify tools, retain outputs, and fail on missing reports.
Plan an advanced workflow for <image> that generates multiple SBOM formats, scans vulnerabilities, enforces policy, signs attestations, and verifies published evidence.
Best Practices
- Scan immutable image digests and record the matching source revision.
- Pin every action, image, and binary, then verify downloaded artifacts before execution.
- Store SBOMs as protected release evidence and regenerate them after dependency changes.
Avoid
- Do not pipe remote installation scripts directly into a shell.
- Do not treat an SBOM as proof that software is vulnerability-free or compliant.
- Do not store registry credentials in committed Syft configuration files.
Frequently Asked Questions
What targets can this skill inventory?
Which SBOM formats are supported?
Does this skill include Syft?
Can it find vulnerabilities?
Can it support license compliance?
How should SBOMs be protected?
Developer Details
Author
AgentSecOpsLicense
MIT
Author version
v0.1.0
Skillstore revision
r2
Ref
9e952417e76879bc9d853e1b8b2cd6d6d8d4a1c2
Maintenance freshness
7/24/2026
Usage
7 downloads ยท 386 views
File structure