Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
SBOM-VEX-Taint-Analysis β€” Automated SBOM-to-VEX pipeline using a secure multi-agent AI system to analyze CVEs, reason about exploitability, and generate signed CycloneDX VEX documents in compliance with OWASP GenAI guidelines. | Kitploit
Tools/GitHubGitHub/owasp/sbom-vex-taint-analysis
Vulnerability AnalysisSupply Chain SecurityPapers & ResearchLearning & EducationCurated ResourcesAI Security
GitHubowasp/sbom-vex-taint-analysis

SBOM-VEX-Taint-Analysis

Automated SBOM-to-VEX pipeline using a secure multi-agent AI system to analyze CVEs, reason about exploitability, and generate signed CycloneDX VEX documents in compliance with OWASP GenAI guidelines.

View Repository
21772 months agoNot yet reviewed

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share

SBOM β†’ VEX Agent

Automatically generate signed CycloneDX VEX documents from SBOMs using a secure multi-agent AI pipeline, built in accordance with the OWASP GenAI Security Project guidelines.

License: MIT OWASP CycloneDX AutoGen


The Problem

Generating an SBOM surfaces hundreds of CVEs. In practice, over 90% are not exploitable in a specific product's runtime context. Without a Vulnerability Exploitability eXchange (VEX) document, every downstream tool β€” Dependency-Track, release gates, procurement checklists β€” drowns in false positives.

Read the WIKI for more technical details ans results of testing

Manual VEX generation is time-consuming and does not scale. A skilled analyst can spend hours assessing a single component. A production SBOM may contain 500–2,000 components.

This project automates that reasoning pipeline β€” securely, without vendor lock-in, with all data remaining on your infrastructure.

Real-world motivation: In 2024, security researcher Johanna Curiel documented exactly this problem while analysing the Kubernetes Java Client (LinkedIn article). The OSV scanner identified a high-risk CVE in com.diffplug.spotless:spotless-maven-plugin 1.17.0 in seconds. Determining it was not_affected (build-time plugin, never executed at runtime) took hours of manual analysis. This project automates that reasoning step.


Architecture

Four security zones. Nothing crosses a boundary without explicit validation.

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  ZONE 1 β€” Input ingestion (no LLM)                              β”‚
β”‚  SBOM upload β†’ Schema validate β†’ Sanitise β†’ SHA-256 audit hash  β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                             β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  ZONE 2 β€” OWASP guardrail middleware                            β”‚
β”‚  Prompt guard (LLM01) Β· Output filter (LLM02/05)                β”‚
β”‚  Agency limiter (LLM06) Β· Token budget (LLM10)                  β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                             β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  ZONE 3 β€” Multi-agent pipeline (AutoGen AgentChat)              β”‚
β”‚                                                                  β”‚
β”‚  Orchestrator                                                    β”‚
β”‚       β”œβ”€β”€ CVE Analyst       NVD v2 + OSV + EPSS per component   β”‚
β”‚       β”œβ”€β”€ Exploit Reasoner  Call graph Β· LLM reasoning Β· RAG    β”‚
β”‚       └── VEX Writer        CycloneDX 1.6 schema-validated      β”‚
β”‚                                                                  β”‚
β”‚  Vector store (Qdrant) β€” signed past VEX decisions              β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                             β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  ZONE 4 β€” Output, signing, audit                                β”‚
β”‚  Human-in-the-loop gate β†’ cosign/GPG sign β†’ audit log           β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

OWASP GenAI Compliance

This project is designed against the OWASP Top 10 for LLM Applications 2025 and the OWASP Top 10 for Agentic Applications 2026.

OWASP RiskIDMitigation in this project
Prompt InjectionLLM01All SBOM fields sanitised before LLM injection; injection pattern blocklist
Sensitive Info DisclosureLLM02PII scrubber on all agent outputs; internal path filter
Improper Output HandlingLLM05CycloneDX schema validation before signing; retry on failure
Excessive AgencyLLM06Read-only tools during analysis; HITL gate for all CVSS β‰₯ 7.0 rulings
System Prompt LeakageLLM07Internal policies separated from system prompt
Vector / Embedding WeaknessLLM08Stored vectors signed; provenance checked before context injection
Unbounded ConsumptionLLM10MaxMessageTermination(20); per-component token budget; NVD timeout

Human-in-the-loop is mandatory. A VEX not_affected statement for a high-severity CVE is a legal-grade assertion. No VEX is signed without human reviewer approval. This is not configurable.


Tech Stack

ComponentToolNotes
Agent orchestrationAutoGen AgentChat v0.4Multi-agent, tool-use, message hooks
LLM (recommended)Qwen2.5-Coder-32BBest structured JSON + security reasoning
LLM servervLLM (prod) / Ollama (dev)OpenAI-compatible API
CVE dataNVD v2 API + OSV.dev + EPSSAll free, no API key required
Vector storeQdrantSelf-hosted, past VEX decisions
Embeddingsall-MiniLM-L6-v2 (sentence-transformers)Fully local
SBOM formatsCycloneDX 1.4–1.7 (JSON/XML), SPDX 2.3/3.0Schema-validated on ingest
VEX outputCycloneDX 1.6 VEXSchema-validated before signing
Signingcosign (Sigstore keyless)Timestamped, audit-logged
Audit logPostgreSQL (append-only, pgaudit)Every agent decision recorded

Everything runs on-premises. No data leaves your infrastructure.


Requirements

Hardware (production):

  • 1Γ— A100 80GB, or 2Γ— RTX 3090 (48GB VRAM combined) for Qwen2.5-Coder-32B
  • 16GB+ system RAM
  • 100GB+ SSD for model weights and vector store

Hardware (development / small SBOMs):

  • Any machine with 16GB RAM β€” use llama3.1:8b via Ollama

Software:

  • Python 3.11+
  • Docker + Docker Compose
  • Node.js 18+ (for cosign tooling)

Quick Start

1. Clone and install

git clone https://github.com/your-org/sbom-vex-agent
cd sbom-vex-agent
python -m venv .venv && source .venv/bin/activate
pip install -r requirements.txt

2. Start the LLM backend

# Development β€” Ollama (CPU/GPU, any laptop)
ollama pull llama3.1
ollama serve

# Production β€” vLLM (GPU required)
python -m vllm.entrypoints.openai.api_server \
  --model Qwen/Qwen2.5-Coder-32B-Instruct \
  --gpu-memory-utilization 0.90 \
  --host 0.0.0.0 --port 8000

3. Start supporting services

docker compose up -d   # starts Qdrant + PostgreSQL

4. Run the agent on an SBOM

python -m vex_agent analyse \
  --sbom path/to/your-sbom.cdx.json \
  --output path/to/output.vex.json

The pipeline will:

  1. Validate and sanitise the SBOM
  2. Look up CVEs for each component
  3. Reason about exploitability
  4. Present draft VEX to a human reviewer
  5. Sign and emit the final document on approval

Configuration

Copy .env.example to .env and set:

# LLM backend
VLLM_BASE_URL=http://localhost:8000/v1    # or Ollama: http://localhost:11434/v1
LLM_MODEL=Qwen2.5-Coder-32B-Instruct     # or llama3.1 for dev

# Services
QDRANT_URL=http://localhost:6333
AUDIT_DB_URL=postgresql://audit:secret@localhost:5432/audit

# Signing (leave blank to use cosign keyless via Sigstore OIDC)
GPG_KEY_ID=                               # optional: use GPG instead

Project Structure

Download Tool