SBOM Dependency Risk Scorer

SBOM Dependency Risk Scorer MCP Connector for Claude

A+

Analyze SBOM files to quantify supply chain risk through dependency structure, package staleness, and vulnerability exposure.

4 tools Official Updated Oct 1, 2026 Official Vinkius Partner

The SBOM Dependency Risk Scorer is an analytical engine designed to evaluate the security and maintenance health of software ecosystems. By processing Software Bill of Materials (SPDX/CycloneDX) files, it quantifies risk across three critical vectors: structural complexity, maintenance decay, and known vulnerability exposure. Use analyze_dependency_structure to assess dependency depth, evaluate_package_stalness to identify outdated components, tally_vulnerability_exposure to count CVEs, and calculate_composite_risk_score to generate a single, actionable risk rating.

sbomvulnerabilitydependency-analysiscverisk-assessment

4 tools expose this connector's capabilities to your AI agent.

analyze_dependency_structure

Analyzes the dependency tree structure of an SBOM

evaluate_package_stalness

Evaluates how outdated packages are based on release dates

tally_vulnerability_exposure

Counts known vulnerabilities in the SBOM

calculate_composite_risk_score

Calculates the final security risk score

See how to talk to your AI agent using SBOM Dependency Risk Scorer.

How complex is my dependency tree in this SBOM?

The dependency tree contains 45 total dependencies, with a direct-to-transitive ratio of 0.22, indicating significant nested complexity.

Are there any high-severity vulnerabilities in my project?

The analysis found 3 high-severity vulnerabilities and 12 low-severity vulnerabilities within the provided SBOM content.

What is my overall supply chain risk score?

Your project has a Risk Level of High, driven primarily by high vulnerability density and significant package staleness.

The engine supports both SPDX and CycloneDX formats for analyzing dependency structures.

Related Connectors