Generates Software Bill of Materials using Syft and scans for CVEs with Grype. Cross-references findings against the NVD and OSV databases for comprehensive vulnerability detection.
Scanned 6/2/2026
Install to Claude Code
npx -y skills add agentskillexchange/skills --skill sbom-vulnerability-scanner --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Sbom Vulnerability Scanner?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/agentskillexchange-sbom-vulnerability-scanner)More formats (shields.io, HTML) on the badges page.
---
name: "SBOM Vulnerability Scanner"
slug: "sbom-vulnerability-scanner"
description: "Generates Software Bill of Materials using Syft and scans for CVEs with Grype. Cross-references findings against the NVD and OSV databases for comprehensive vulnerability detection."
verification: "security_reviewed"
source: "https://docs.docker.com/"
author: "Docker Inc."
category: "Security & Verification"
framework: "Claude Code"
---
# SBOM Vulnerability Scanner
Generates Software Bill of Materials using Syft and scans for CVEs with Grype. Cross-references findings against the NVD and OSV databases for comprehensive vulnerability detection.
## Installation
Use the upstream install or setup path that matches your environment:
- Docker Docs
- Docker Hardened Images
- Why should I use Docker Compose?
- Docker Desktop overview
Requirements and caveats from upstream:
- Gordon Gordon, your AI assistant for Docker docs
- email: 'docs@docker.com',
- I'm Gordon, your AI assistant for Docker and documentation
Basic usage or getting-started notes:
- Can I run my AI agent in a sandbox?
- Reference
- Browse the CLI and API documentation.
- Source: https://docs.docker.com/
## Documentation
- https://docs.docker.com/
## Source
- [Agent Skill Exchange](https://agentskillexchange.com/skills/sbom-vulnerability-scanner/)
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!