
Automated SBOM-to-VEX pipeline using a secure multi-agent AI system to analyze CVEs, reason about exploitability, and generate signed CycloneDX VEX documents in compliance with OWASP GenAI guidelines.
Automatically generate signed CycloneDX VEX documents from SBOMs using a secure multi-agent AI pipeline, built in accordance with the OWASP GenAI Security Project guidelines.
Generating an SBOM surfaces hundreds of CVEs. In practice, over 90% are not exploitable in a specific product's runtime context. Without a Vulnerability Exploitability eXchange (VEX) document, every downstream tool — Dependency-Track, release gates, procurement checklists — drowns in false positives.
Read the WIKI for more technical details ans results of testing
Manual VEX generation is time-consuming and does not scale. A skilled analyst can spend hours assessing a single component. A production SBOM may contain 500–2,000 components.
This project automates that reasoning pipeline — securely, without vendor lock-in, with all data remaining on your infrastructure.
Real-world motivation: In 2024, security researcher Johanna Curiel documented exactly this problem while analysing the Kubernetes Java Client (LinkedIn article). The OSV scanner identified a high-risk CVE in
com.diffplug.spotless:spotless-maven-plugin 1.17.0in seconds. Determining it wasnot_affected(build-time plugin, never executed at runtime) took hours of manual analysis. This project automates that reasoning step.
Four security zones. Nothing crosses a boundary without explicit validation.
┌─────────────────────────────────────────────────────────────────┐
│ ZONE 1 — Input ingestion (no LLM) │
│ SBOM upload → Schema validate → Sanitise → SHA-256 audit hash │
└────────────────────────────┬────────────────────────────────────┘
│
┌────────────────────────────▼────────────────────────────────────┐
│ ZONE 2 — OWASP guardrail middleware │
│ Prompt guard (LLM01) · Output filter (LLM02/05) │
│ Agency limiter (LLM06) · Token budget (LLM10) │
└────────────────────────────┬────────────────────────────────────┘
│
┌────────────────────────────▼────────────────────────────────────┐
│ ZONE 3 — Multi-agent pipeline (AutoGen AgentChat) │
│ │
│ Orchestrator │
│ ├── CVE Analyst NVD v2 + OSV + EPSS per component │
│ ├── Exploit Reasoner Call graph · LLM reasoning · RAG │
│ └── VEX Writer CycloneDX 1.6 schema-validated │
│ │
│ Vector store (Qdrant) — signed past VEX decisions │
└────────────────────────────┬────────────────────────────────────┘
│
┌────────────────────────────▼────────────────────────────────────┐
│ ZONE 4 — Output, signing, audit │
│ Human-in-the-loop gate → cosign/GPG sign → audit log │
└─────────────────────────────────────────────────────────────────┘
This project is designed against the OWASP Top 10 for LLM Applications 2025 and the OWASP Top 10 for Agentic Applications 2026.
| OWASP Risk | ID | Mitigation in this project |
|---|---|---|
| Prompt Injection | LLM01 | All SBOM fields sanitised before LLM injection; injection pattern blocklist |
| Sensitive Info Disclosure | LLM02 | PII scrubber on all agent outputs; internal path filter |
| Improper Output Handling | LLM05 | CycloneDX schema validation before signing; retry on failure |
| Excessive Agency | LLM06 | Read-only tools during analysis; HITL gate for all CVSS ≥ 7.0 rulings |
| System Prompt Leakage | LLM07 | Internal policies separated from system prompt |
| Vector / Embedding Weakness | LLM08 | Stored vectors signed; provenance checked before context injection |
| Unbounded Consumption | LLM10 | MaxMessageTermination(20); per-component token budget; NVD timeout |
Human-in-the-loop is mandatory. A VEX
not_affectedstatement for a high-severity CVE is a legal-grade assertion. No VEX is signed without human reviewer approval. This is not configurable.
| Component | Tool | Notes |
|---|---|---|
| Agent orchestration | AutoGen AgentChat v0.4 | Multi-agent, tool-use, message hooks |
| LLM (recommended) | Qwen2.5-Coder-32B | Best structured JSON + security reasoning |
| LLM server | vLLM (prod) / Ollama (dev) | OpenAI-compatible API |
| CVE data | NVD v2 API + OSV.dev + EPSS | All free, no API key required |
| Vector store | Qdrant | Self-hosted, past VEX decisions |
| Embeddings | all-MiniLM-L6-v2 (sentence-transformers) | Fully local |
| SBOM formats | CycloneDX 1.4–1.7 (JSON/XML), SPDX 2.3/3.0 | Schema-validated on ingest |
| VEX output | CycloneDX 1.6 VEX | Schema-validated before signing |
| Signing | cosign (Sigstore keyless) | Timestamped, audit-logged |
| Audit log | PostgreSQL (append-only, pgaudit) | Every agent decision recorded |
Everything runs on-premises. No data leaves your infrastructure.
Hardware (production):
Hardware (development / small SBOMs):
llama3.1:8b via OllamaSoftware:
git clone https://github.com/your-org/sbom-vex-agent
cd sbom-vex-agent
python -m venv .venv && source .venv/bin/activate
pip install -r requirements.txt
# Development — Ollama (CPU/GPU, any laptop)
ollama pull llama3.1
ollama serve
# Production — vLLM (GPU required)
python -m vllm.entrypoints.openai.api_server \
--model Qwen/Qwen2.5-Coder-32B-Instruct \
--gpu-memory-utilization 0.90 \
--host 0.0.0.0 --port 8000
docker compose up -d # starts Qdrant + PostgreSQL
python -m vex_agent analyse \
--sbom path/to/your-sbom.cdx.json \
--output path/to/output.vex.json
The pipeline will:
Copy .env.example to .env and set:
# LLM backend
VLLM_BASE_URL=http://localhost:8000/v1 # or Ollama: http://localhost:11434/v1
LLM_MODEL=Qwen2.5-Coder-32B-Instruct # or llama3.1 for dev
# Services
QDRANT_URL=http://localhost:6333
AUDIT_DB_URL=postgresql://audit:secret@localhost:5432/audit
# Signing (leave blank to use cosign keyless via Sigstore OIDC)
GPG_KEY_ID= # optional: use GPG instead