# Sbom Analysis

> Activate when the user opens, mentions, or asks questions about a .sbom.json file, an AI Bill of Materials, an aibom.json, or asks about what AI components an application uses. Also activate when the user asks about component dependencies, LLM model usage, tool permissions, datastore access, or the attack surface of an AI system.

## Facts
- Page: https://tashan.sh/capability/skill-nuguardai-sbom-analysis
- tashan id: skill:NuGuardAI/sbom-analysis
- Source: https://github.com/NuGuardAI/nuguard
- Type: skill
- Category: security
- tashan score: not scored (catalogued only — too little public evidence)
- Adoption: 9.0
- Upkeep: 98.0
- Freshness: 95.0
- Evidence coverage: 84% of the inputs this score can use
- Health: active
- Instruction depth: not yet graded
- License: NOASSERTION
- Official: no

## Install

```sh
cp -r sbom-analysis ~/.claude/skills/
```

## Security audit
Not scanned. We audit npm-published capabilities; this one has no npm package we can resolve, or has not reached the queue. This is not a clean bill of health.

---
Measured 2026-09-12 by tashan (https://tashan.sh) from public evidence. Scorer s5.
