SBOM Desk - is the SBOM your build produced fit to send a customer?

sbom-desk.skillsafe.ai

Clean

Drop the CycloneDX or SPDX software bill of materials your build just produced and work it through one sitting. A real SBOM reader runs free in your browser: it parses CycloneDX JSON, SPDX JSON and SPDX tag-value (including multi-line text blocks), scores the seven NTIA minimum elements as a share of components rather than a boolean, grades twelve conformance checks, parses package URLs properly so a scoped npm namespace, a missing @version and a mixed-case type are all read correctly, parses SPDX licence expressions with the operator honoured so an OR is the choice it is and an AND stacks, names retired identifiers with their replacement (GPL-2.0 is ambiguous where GPL-2.0-only is not), separates source-available licences such as BUSL, SSPL and Elastic from real open source, reads licenseConcluded and licenseDeclared as the two different statements they are, and walks the dependency graph for depth, reachability, isolated components and references pointing at components that are not in the document. Free exports with no account: a component inventory CSV, a licence summary, the NTIA scorecard, the dependency edge list, a package-URL list and an attribution NOTICE draft that lists what it cannot fill in rather than looking complete. Then four AI lanes over the same document: the publish gate (the twelve checks and seven elements re-decided for your audience, ending in publish / publish-with-caveats / hold), the licence rulings (one per distinct expression against your allow-list and shipping model, with obligations, notice gaps and the exceptions somebody must grant), the exposure triage (where to point a real scanner first - there is no vulnerability database here and the prompt forbids inventing a CVE, so the honest answer is usually that some components are not clean, they are unscanned), and the fix plan with a sendable statement for the customer's security team. Every prescan flag must be reconciled exactly once and the page names the ones the model skipped. Derived from four agent skills: @patricio0312rev/artifact-sbom-publisher, @jorgealves/license-compliance-auditor, @patricio0312rev/dependency-vulnerability-triage and @patricio0312rev/dependency-doctor. Not affiliated with those skills' authors, with the OWASP Foundation and the CycloneDX project, with the Linux Foundation and the SPDX project, or with any tool named here. Nothing it produces is legal advice.

Share

Details

PricingUsage-based + 10% creator margin
Billed model rate$2.75 in / $16.50 out per 1M tokens
Creator margin+10%
Effective rate$3.00 in / $18.00 out per 1M tokens
Security scanClean — skill and frontend scanned
Model gpt-terra
Created2026-08-27
Updated2026-08-28

Every public app is built from a security-scanned skill and must pass a clean scan — skill and frontend — before it can be listed. Have a skill of your own? Turn it into an app — or read the step-by-step walkthrough.