Software Bill of Materials generation + validation in CycloneDX 1.6 and SPDX 2.3 formats. Required by EO 14028 + NIS2 + CRA.
Project description
SBOM CycloneDX + SPDX Generator/Validator MCP
Buy Starter — £29/mo
Signed attestations + unlimited audits + email support. 👉 Subscribe at meok.ai — instant HMAC signing key + Stripe-managed billing.
Free tier remains MIT-licensed and zero-config. Upgrade only when you need signed compliance artefacts for audit.
Software Bill of Materials generation + validation in CycloneDX 1.6 and SPDX 2.3 formats. Required by EO 14028 + NIS2 + CRA.
Install
pip install sbom-cyclonedx-mcp
Tools
| Tool | Purpose |
|---|---|
generate_sbom_cyclonedx |
Generate CycloneDX 1.6 SBOM from package manifests |
generate_sbom_spdx |
Generate SPDX 2.3 SBOM |
validate_sbom |
Validate SBOM against CycloneDX/SPDX schema + completeness |
vex_attach |
Attach VEX (Vulnerability Exploitability eXchange) statements |
regulation_map |
Map SBOM to EO 14028 / NIS2 / CRA / FDA requirements |
Pairs with
meok-attestation-api— POST results to https://meok-attestation-api.vercel.app/sign for cryptographically signed compliance certsmeok-attestation-verify— public verification of any MEOK-signed cert- Other MEOK governance MCPs via SOV3
mcp_bridge_call
Pricing
- Free: 10 calls/day. No API key required.
- Pro £79/mo: unlimited + signed attestations. Subscribe
- Enterprise £1,499/mo: white-label + on-premise + SLA. hello@meok.ai
Status
Scaffold v1.0.0 ships the MCP framework + 5 tool stubs. v1.1.0 will add real regulation data ingestion.
If your team needs this MCP fully-loaded faster, ping hello@meok.ai for sponsored development.
License
MIT © MEOK AI Labs
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file sbom_cyclonedx_mcp-1.0.2.tar.gz.
File metadata
- Download URL: sbom_cyclonedx_mcp-1.0.2.tar.gz
- Upload date:
- Size: 6.3 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.9.6
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
7cda338f193f8b617f506a926febb6c4e289116f5a5b771273c4f7f3ee834907
|
|
| MD5 |
9ffc69301de86e70cbddc197a93efd8f
|
|
| BLAKE2b-256 |
e283a831533cde03b0bf5698e9230f2a3fad610309cf95aa617f05579b2aa9da
|
File details
Details for the file sbom_cyclonedx_mcp-1.0.2-py3-none-any.whl.
File metadata
- Download URL: sbom_cyclonedx_mcp-1.0.2-py3-none-any.whl
- Upload date:
- Size: 5.9 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.11.15
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
7a0a095eb9bc58e05b85a8233f3811ff9fc0ba46220f42f32cc3210001fde4f8
|
|
| MD5 |
52f978ae571a99a40d7b43eed3179f39
|
|
| BLAKE2b-256 |
ee6b97d35f55586bba91b4f5e89cea1fecbea814a9b2017ace8e93f8910490fe
|