
Automated SBOM-to-VEX pipeline using a secure multi-agent AI system to analyze CVEs, reason about exploitability, and generate signed CycloneDX VEX documents in compliance with OWASP GenAI guidelines.
Automatically generate signed CycloneDX VEX documents from SBOMs using a secure multi-agent AI pipeline, built in accordance with the OWASP GenAI Security Project guidelines.
Generating an SBOM surfaces hundreds of CVEs. In practice, over 90% are not exploitable in a specific product's runtime context. Without a Vulnerability Exploitability eXchange (VEX) document, every downstream tool β Dependency-Track, release gates, procurement checklists β drowns in false positives.
Read the WIKI for more technical details ans results of testing
Manual VEX generation is time-consuming and does not scale. A skilled analyst can spend hours assessing a single component. A production SBOM may contain 500β2,000 components.
This project automates that reasoning pipeline β securely, without vendor lock-in, with all data remaining on your infrastructure.
Real-world motivation: In 2024, security researcher Johanna Curiel documented exactly this problem while analysing the Kubernetes Java Client (LinkedIn article). The OSV scanner identified a high-risk CVE in
com.diffplug.spotless:spotless-maven-plugin 1.17.0in seconds. Determining it wasnot_affected(build-time plugin, never executed at runtime) took hours of manual analysis. This project automates that reasoning step.
Four security zones. Nothing crosses a boundary without explicit validation.
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β ZONE 1 β Input ingestion (no LLM) β
β SBOM upload β Schema validate β Sanitise β SHA-256 audit hash β
ββββββββββββββββββββββββββββββ¬βββββββββββββββββββββββββββββββββββββ
β
ββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββ
β ZONE 2 β OWASP guardrail middleware β
β Prompt guard (LLM01) Β· Output filter (LLM02/05) β
β Agency limiter (LLM06) Β· Token budget (LLM10) β
ββββββββββββββββββββββββββββββ¬βββββββββββββββββββββββββββββββββββββ
β
ββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββ
β ZONE 3 β Multi-agent pipeline (AutoGen AgentChat) β
β β
β Orchestrator β
β βββ CVE Analyst NVD v2 + OSV + EPSS per component β
β βββ Exploit Reasoner Call graph Β· LLM reasoning Β· RAG β
β βββ VEX Writer CycloneDX 1.6 schema-validated β
β β
β Vector store (Qdrant) β signed past VEX decisions β
ββββββββββββββββββββββββββββββ¬βββββββββββββββββββββββββββββββββββββ
β
ββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββ
β ZONE 4 β Output, signing, audit β
β Human-in-the-loop gate β cosign/GPG sign β audit log β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
This project is designed against the OWASP Top 10 for LLM Applications 2025 and the OWASP Top 10 for Agentic Applications 2026.
| OWASP Risk | ID | Mitigation in this project |
|---|---|---|
| Prompt Injection | LLM01 | All SBOM fields sanitised before LLM injection; injection pattern blocklist |
| Sensitive Info Disclosure | LLM02 | PII scrubber on all agent outputs; internal path filter |
| Improper Output Handling | LLM05 | CycloneDX schema validation before signing; retry on failure |
| Excessive Agency | LLM06 | Read-only tools during analysis; HITL gate for all CVSS β₯ 7.0 rulings |
| System Prompt Leakage | LLM07 | Internal policies separated from system prompt |
| Vector / Embedding Weakness | LLM08 | Stored vectors signed; provenance checked before context injection |
| Unbounded Consumption | LLM10 | MaxMessageTermination(20); per-component token budget; NVD timeout |
Human-in-the-loop is mandatory. A VEX
not_affectedstatement for a high-severity CVE is a legal-grade assertion. No VEX is signed without human reviewer approval. This is not configurable.
| Component | Tool | Notes |
|---|---|---|
| Agent orchestration | AutoGen AgentChat v0.4 | Multi-agent, tool-use, message hooks |
| LLM (recommended) | Qwen2.5-Coder-32B | Best structured JSON + security reasoning |
| LLM server | vLLM (prod) / Ollama (dev) | OpenAI-compatible API |
| CVE data | NVD v2 API + OSV.dev + EPSS | All free, no API key required |
| Vector store | Qdrant | Self-hosted, past VEX decisions |
| Embeddings | all-MiniLM-L6-v2 (sentence-transformers) | Fully local |
| SBOM formats | CycloneDX 1.4β1.7 (JSON/XML), SPDX 2.3/3.0 | Schema-validated on ingest |
| VEX output | CycloneDX 1.6 VEX | Schema-validated before signing |
| Signing | cosign (Sigstore keyless) | Timestamped, audit-logged |
| Audit log | PostgreSQL (append-only, pgaudit) | Every agent decision recorded |
Everything runs on-premises. No data leaves your infrastructure.
Hardware (production):
Hardware (development / small SBOMs):
llama3.1:8b via OllamaSoftware:
git clone https://github.com/your-org/sbom-vex-agent
cd sbom-vex-agent
python -m venv .venv && source .venv/bin/activate
pip install -r requirements.txt
# Development β Ollama (CPU/GPU, any laptop)
ollama pull llama3.1
ollama serve
# Production β vLLM (GPU required)
python -m vllm.entrypoints.openai.api_server \
--model Qwen/Qwen2.5-Coder-32B-Instruct \
--gpu-memory-utilization 0.90 \
--host 0.0.0.0 --port 8000
docker compose up -d # starts Qdrant + PostgreSQL
python -m vex_agent analyse \
--sbom path/to/your-sbom.cdx.json \
--output path/to/output.vex.json
The pipeline will:
Copy .env.example to .env and set:
# LLM backend
VLLM_BASE_URL=http://localhost:8000/v1 # or Ollama: http://localhost:11434/v1
LLM_MODEL=Qwen2.5-Coder-32B-Instruct # or llama3.1 for dev
# Services
QDRANT_URL=http://localhost:6333
AUDIT_DB_URL=postgresql://audit:secret@localhost:5432/audit
# Signing (leave blank to use cosign keyless via Sigstore OIDC)
GPG_KEY_ID= # optional: use GPG instead