Skip to main content

Software Bill of Materials generation + validation in CycloneDX 1.6 and SPDX 2.3 formats. Required by EO 14028 + NIS2 + CRA.

Project description

SBOM CycloneDX + SPDX Generator/Validator MCP

Buy Starter — £29/mo

Signed attestations + unlimited audits + email support. 👉 Subscribe at meok.ai — instant HMAC signing key + Stripe-managed billing.

Free tier remains MIT-licensed and zero-config. Upgrade only when you need signed compliance artefacts for audit.

PyPI License: MIT MEOK AI Labs

Software Bill of Materials generation + validation in CycloneDX 1.6 and SPDX 2.3 formats. Required by EO 14028 + NIS2 + CRA.

Install

pip install sbom-cyclonedx-mcp

Tools

Tool Purpose
generate_sbom_cyclonedx Generate CycloneDX 1.6 SBOM from package manifests
generate_sbom_spdx Generate SPDX 2.3 SBOM
validate_sbom Validate SBOM against CycloneDX/SPDX schema + completeness
vex_attach Attach VEX (Vulnerability Exploitability eXchange) statements
regulation_map Map SBOM to EO 14028 / NIS2 / CRA / FDA requirements

Pairs with

  • meok-attestation-api — POST results to https://meok-attestation-api.vercel.app/sign for cryptographically signed compliance certs
  • meok-attestation-verify — public verification of any MEOK-signed cert
  • Other MEOK governance MCPs via SOV3 mcp_bridge_call

Pricing

  • Free: 10 calls/day. No API key required.
  • Pro £79/mo: unlimited + signed attestations. Subscribe
  • Enterprise £1,499/mo: white-label + on-premise + SLA. hello@meok.ai

Status

Scaffold v1.0.0 ships the MCP framework + 5 tool stubs. v1.1.0 will add real regulation data ingestion.

If your team needs this MCP fully-loaded faster, ping hello@meok.ai for sponsored development.

Wire it up — full stack

Pair this with the MEOK chain that turns one agent action into ONE signed compliance event:

  1. bft-progress-council-mcp — anti-loop guardrail
  2. agent-token-budget-mcp — hard spend cap
  3. agent-prompt-injection-firewall-mcp — OWASP LLM01 scan
  4. agent-audit-logger-mcp — hash-chained evidence
  5. a2a-governance-bridge-mcp — fold N attestations → 1 signed event
  6. agent-incident-relay-mcp — broadcast incidents to 5 regimes simultaneously

See meok.ai/mcp-stack for the architecture and meok.ai/mcp-stack/demo for the live in-browser demo.

License

MIT © MEOK AI Labs

Protocol coverage + Universal PAYG

This MCP is part of MEOK's 47-MCP fleet that bridges every active agent-interop protocol and 30+ regulatory frameworks. See the full coverage matrix at meok.ai/protocols.

Agent interop protocols supported (8 live):

  • MCP (Anthropic) — native
  • A2A (Google + Linux Foundation, absorbed IBM ACP Sept 2025)
  • IBM ACP — covered via A2A merge
  • Stripe ACP (Agentic Commerce Protocol) — Q3 bridge via agent-commerce-protocol-mcp
  • AP2 (Google Agent Payments) — partial via agent-commerce-payments-mcp
  • x402 (Coinbase HTTP 402) — partial via api.meok.ai gateway
  • OASF / AGNTCY (Cisco Outshift + Linux Foundation) — Q3 bridge
  • 👁 ANP (Cisco Agent Network) — watch-list

Pricing options:

Option Price Best for
Self-host (this MCP) £0 — MIT Devs
This MCP Starter £29/mo One-MCP teams
This MCP Pro £79/mo Production + 24h SLA
Universal PAYG £29/mo + £0.0002/call Spiky usage across many MCPs
Substrate bundle (this category) £99-£499/mo A whole pack
MEOK Universe £1,499/mo All 47 MCPs, 500K calls

Each tier above the free self-host adds HMAC-signed attestations verifiable at verify.meok.ai. Linux Foundation governance on the A2A spine means EU regulated buyers can deploy without vendor-lock-in objections.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

sbom_cyclonedx_mcp-1.0.3.tar.gz (204.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

sbom_cyclonedx_mcp-1.0.3-py3-none-any.whl (6.9 kB view details)

Uploaded Python 3

File details

Details for the file sbom_cyclonedx_mcp-1.0.3.tar.gz.

File metadata

  • Download URL: sbom_cyclonedx_mcp-1.0.3.tar.gz
  • Upload date:
  • Size: 204.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.9.6

File hashes

Hashes for sbom_cyclonedx_mcp-1.0.3.tar.gz
Algorithm Hash digest
SHA256 ced42a3478cf6307461e42e6c6e8d3981a0e3e6a9bb0510822bc59dd9193d8ee
MD5 1a01ca159049b06802ade9f9e9ab6cd3
BLAKE2b-256 8d9b8bd73578b66d66cd65c90236c7c37c68d2233fd705980882ba284116d7a0

See more details on using hashes here.

File details

Details for the file sbom_cyclonedx_mcp-1.0.3-py3-none-any.whl.

File metadata

File hashes

Hashes for sbom_cyclonedx_mcp-1.0.3-py3-none-any.whl
Algorithm Hash digest
SHA256 3d273d135137f13143e1fa817590296f3f7ad6c562d19a060fe875be51d62d09
MD5 bd7b08dd063fbb6d26d7c3af529cc1f3
BLAKE2b-256 9d15eec3fffdcc2136c43762182d7cc4aea28e76862bb1c644a8330b3c16deee

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page