Command Palette

Search for a command to run...

UnylyUnyly
Browse all

Sbomx

FreeNot checked

Generates a CycloneDX SBOM for mobile apps by unpacking native libs and bundled SDKs, then matches components against known-vuln and tracker/privacy databases.

GitHubEmbed

About

Generates a CycloneDX SBOM for mobile apps by unpacking native libs and bundled SDKs, then matches components against known-vuln and tracker/privacy databases.

README

SBOMX

SBOMX

Generates a CycloneDX SBOM for mobile apps by unpacking native libs and bundled SDKs, then matches components against known-vuln and tracker/privacy databases.

PyPI CI License: COCL 1.0 Suite

Application & Mobile Security — SAST/DAST-lite and binary triage.

pip install cognis-sbomx
sbomx scan .            # → prioritized findings in seconds

🔎 Example output

Real, reproducible output from the tool — runs offline:

$ sbomx-emit --version
sbomx 0.2.4
$ sbomx-emit --help
usage: sbomx [-h] [--version] {scan,db,feeds} ...

Generate a CycloneDX SBOM for mobile apps and match bundled libraries against vulnerability and privacy-tracker databases.

positional arguments:
  {scan,db,feeds}
    scan           scan an .apk/.ipa/zip or directory and produce an SBOM +
                   findings
    db             query the bundled offline 262k-record OSV vulnerability
                   database
    feeds          manage the bundled edge/air-gap vulnerability data feeds

options:
  -h, --help       show this help message and exit
  --version        show program's version number and exit

Command-line interface for SBOMX.

Examples
--------
  # Generate a CycloneDX SBOM (JSON) for an APK and write it to a file
  sbomx scan app.apk --format json -o app.cdx.json

  # Human-readable findings table; exit non-zero if vulns/trackers found
  sbomx scan app.ipa --format table

  # Scan an extracted bundle directory and fail CI on HIGH severity vulns
  sbomx scan ./unpacked_app --fail-on high

  # Use a manifest mapping lib->version to refine version-unknown components
  sbomx scan app.apk --manifest versions.json

Exit codes
----------
  0  clean (no findings, or findings below --fail-on threshold)
  1  findings at/above the fail threshold (default: any tracker or vuln)
  2  usage / runtime error

Blocks above are real sbomx output — reproduce them from a clone.

Sample result format (illustrative values — run on your own data for real findings):

{
"sbomx": {
"platform": "stix",
"findings": [
{
"uuid": "12345678-1234-5678-1234-567812345678",
"vulnerability": {
"name": "CVE-2023-12345"
},
"severity": "high",
"description": "A high-severity vulnerability in the application."
}
]
}
}

Usage — step by step

sbomx generates a CycloneDX SBOM for mobile apps and matches bundled libraries against vulnerability and privacy-tracker databases. Console script: sbomx.

  1. Install:
    pipx install sbomx     # or: pip install sbomx
    
  2. Scan an app bundle (.apk / .ipa / .zip) or an extracted directory and print a findings table:
    sbomx scan app.apk --format table
    
    Exit 1 = findings at/above the --fail-on threshold (default: any finding), 0 = clean, 2 = error.
  3. Emit a CycloneDX 1.5 SBOM as JSON to a file (also --format sarif for GitHub code-scanning, or --format csv for spreadsheets/ticketing):
    sbomx scan app.apk --format json  -o app.cdx.json
    sbomx scan app.apk --format sarif -o app.sarif.json   # upload to code-scanning
    sbomx scan app.apk --format csv   -o findings.csv
    
  4. Refine version-unknown components with a manifest mapping library key to version:
    sbomx scan app.apk --manifest versions.json --format json -o app.cdx.json
    
  5. Gate CI on severity — fail the build only on HIGH+ vulnerabilities/trackers:
    sbomx scan ./unpacked_app --fail-on high || echo "high-severity component findings — blocking release"
    

Contents

Why sbomx?

Syft/Grype ignore the mobile binary world; sbomx surfaces vulnerable bundled SDKs and privacy trackers inside shipped apps — perfect for app-store compliance gating.

sbomx is single-purpose, scriptable, and self-hostable: point it at a target, get prioritized results in the format your workflow already speaks (table · JSON · SARIF), gate CI on it, and let agents drive it over MCP.

Features

  • ✅ Detects bundled libraries from APK/IPA/zip member paths and native .so/.dylib names
  • ✅ Recovers versions from filenames or a supplied --manifest (key → version)
  • ✅ Matches against a curated vuln DB (CVE-style) and a privacy-tracker DB (Exodus-style)
  • Live threat-feed enrichment: flags findings on CISA's Known-Exploited (KEV) list — see Live data feeds
  • Four output formats: table · CycloneDX 1.5 json · SARIF 2.1.0 sarif · csv
  • ✅ CI gate via --fail-on {info,low,medium,high,critical,never} + exit codes
  • ✅ 11 ready-to-run demos covering iOS/Android/React Native/Flutter/games + live KEV enrichment
  • ✅ Runs on Linux/macOS/Windows · Docker · devcontainer
  • ✅ Ports in Python, JavaScript, Go, and Rust (ports/)

Quick start

pip install cognis-sbomx
sbomx --version
sbomx scan .                       # scan current project
sbomx scan . --format json         # machine-readable
sbomx scan . --fail-on high        # CI gate (non-zero exit)

Example

A real scan of an Android bundle that ships okhttp-4.9.0.jar, native libssl/libwebp, Firebase + Crashlytics and the AppsFlyer SDK:

$ sbomx scan app.apk --format table
Target: app.apk

Components (7):
  appsflyer             ?          maven      pkg:maven/com.appsflyer/appsflyer
  firebase-core         ?          maven      pkg:maven/com.google.firebase/firebase-core
  firebase-crashlytics  ?          maven      pkg:maven/com.google.firebase/firebase-crashlytics
  gson                  ?          maven      pkg:maven/com.google.code.gson/gson
  libwebp               ?          native     pkg:generic/libwebp
  okhttp                4.9.0      maven      pkg:maven/com.squareup.okhttp3/[email protected]
  openssl               1.1.1k     native     pkg:generic/openssl

Vulnerabilities (4):
  [CRITICAL] CVE-2023-4863  libwebp@?
             Heap buffer overflow in WebP lossless (VP8L) decoding; exploited in the wild.
             fix: upgrade to >= 1.3.2
  [HIGH    ] CVE-2022-0778  [email protected]
             BN_mod_sqrt infinite loop (DoS) when parsing certificates.
             fix: upgrade to >= 1.1.1n
  [MEDIUM  ] CVE-2021-0341  [email protected]
             OkHttp improper certificate validation (hostname not verified).
             fix: upgrade to >= 4.9.2

Trackers (3):
  AppsFlyer  (Analytics, Advertisement)
  Google Firebase Analytics  (Analytics)
  Google Firebase Crashlytics  (Crash reporting, Analytics)

Add --enrich-osv to cross-reference every detected component against the bundled 262k-record offline OSV database (no network), or --enrich-kev to flag CVEs that are actively exploited per CISA.

Demos — real-use-case scenarios

Each folder under demos/ ships a generator (make_sample.py) that builds a realistic app bundle plus a SCENARIO.md (where the data came from, the exact command, expected output, and how to act). All library versions are drawn from the tool's own detection rules + vuln DB, so every demo deterministically reproduces its documented findings.

Demo Scenario Highlights
01-basic First Android scan 3 vulns + 2 trackers, table + JSON
02-clean First-party app, no SDKs 0 findings, exit 0
03-mixed Mixed severities --fail-on high vs critical gate
04-ios-banking iOS .ipa framework audit CocoaPods + native crypto, Realm CVE
05-react-native-ecommerce RN privacy + vuln review 3 trackers, CSV export
06-clean-release Release candidate all libs patched, gate passes
07-manifest-resolve Stripped build --manifest resolves version-unknown potentials
08-game-adtech F2P game ad-SDK sweep 5 trackers + native media CVEs
09-flutter-app Flutter native audit 3 HIGH native CVEs
10-ci-sarif-gate CI + GitHub code-scanning SARIF upload + HIGH gate
python demos/04-ios-banking/make_sample.py
python -m sbomx scan demos/04-ios-banking/banking.ipa --format table

Live data feeds — edge / air-gap ingestion

sbomx enriches its findings with real, authoritative public vulnerability feeds. The killer feature: an SBOM finding is no longer "this CVE applies" but "this CVE is being exploited in the wild right now — patch it first."

Feed id Source (real, keyless) Used for
cisa-kev CISA Known Exploited Vulnerabilities Flag + escalate actively-exploited CVEs to critical; surface KEV dateAdded / federal dueDate
osv OSV.dev Package+version vulnerability lookups across ecosystems

Enrich a scan

sbomx scan app.apk --enrich-kev            # online: fetch/refresh KEV, then enrich
sbomx scan app.apk --enrich-kev --offline  # air-gap: use the local KEV cache only

Findings whose CVE is on the KEV list are tagged *** CISA KNOWN-EXPLOITED ***, bumped to critical, and annotated with the authoritative dates:

[CRITICAL] CVE-2023-4863  [email protected]  *** CISA KNOWN-EXPLOITED ***
           Heap buffer overflow in WebP lossless (VP8L) decoding; exploited in the wild.
           KEV: added 2023-09-13  patch-by 2023-10-04  ransomware=Unknown
           fix: upgrade to >= 1.3.2

Manage the feeds

sbomx feeds list                       # the feeds this tool consumes (+ URLs)
sbomx feeds update cisa-kev            # keyless HTTPS fetch -> disk cache
sbomx feeds get cisa-kev --offline     # re-serve from cache, never touch network

Edge / air-gap workflow

The ingestion engine (sbomx/datafeeds.py, stdlib-only) caches every feed to disk and re-serves it offline, so sbomx keeps working on disconnected / classified / forward-deployed gear. Set the cache location with COGNIS_FEEDS_CACHE (default ~/.cache/cognis-feeds).

Sneakernet into an air gap:

# on a connected host
sbomx feeds update cisa-kev
python -m sbomx.datafeeds snapshot-export feeds.tar.gz
#  ... carry feeds.tar.gz across the gap ...
# on the disconnected enclave
python -m sbomx.datafeeds snapshot-import feeds.tar.gz
sbomx scan app.apk --enrich-kev --offline

See demos/11-kev-enrichment for a complete, offline-runnable example. The test suite ships a trimmed real-data feed cache under tests/fixtures/feeds-cache/, so CI enriches findings with zero network access.

Architecture

flowchart LR
  IN[target / manifest] --> P[sbomx<br/>checks + rules]
  P --> OUT[findings (JSON / SARIF)]

Use it from any AI stack

sbomx is interoperable with every popular way of using AI:

  • MCP serversbomx mcp (Claude Desktop, Cursor, Cognis.Studio, uncensored-fleet)
  • OpenAI-compatible / JSON — pipe sbomx scan . --format json into any agent or LLM
  • LangChain · CrewAI · AutoGen · LlamaIndex — wrap the CLI/JSON as a tool in one line
  • CI / scripts — exit codes + SARIF for non-AI pipelines

How it compares

Cognis sbomx Syft + Grype, extended to the mobile binary (APK
Self-hostable, no account varies
Single command, zero config ⚠️
JSON + SARIF for CI varies
MCP-native (AI agents)
Polyglot ports (JS/Go/Rust)
Open license ✅ COCL varies

Built in the spirit of Syft + Grype, extended to the mobile binary (APK/IPA native .so/dylib) world, re-framed the Cognis way. Missing a credit? Open a PR.

Integrations

Pipes into your stack: SARIF for code-scanning, JSON for anything, an MCP server (sbomx mcp) for AI agents, and a webhook forwarder for SIEM/Slack/Jira. See docs/INTEGRATIONS.md.

Install — every way, every platform

pip install "git+https://github.com/cognis-digital/sbomx.git"    # pip (works today)
pipx install "git+https://github.com/cognis-digital/sbomx.git"   # isolated CLI
uv tool install "git+https://github.com/cognis-digital/sbomx.git" # uv
pip install cognis-sbomx                                          # PyPI (when published)
docker run --rm ghcr.io/cognis-digital/sbomx:latest --help        # Docker
brew install cognis-digital/tap/sbomx                             # Homebrew tap
curl -fsSL https://raw.githubusercontent.com/cognis-digital/sbomx/main/install.sh | sh
Linux macOS Windows Docker Cloud
scripts/setup-linux.sh scripts/setup-macos.sh scripts/setup-windows.ps1 docker run ghcr.io/cognis-digital/sbomx DEPLOY.md (AWS/Azure/GCP/k8s)

Related Cognis tools

  • apkpeek — One-command static triage of Android APK/AAB binaries: surfaces hardcoded secrets, exported components, dangerous permissions, and insecure manifest flags as a single SARIF report.
  • ipasnitch — Static scanner for iOS .ipa bundles that flags ATS exceptions, missing entitlements hardening, embedded URLs/secrets, and weak Info.plist transport settings.
  • hookcraft — Generates ready-to-run Frida instrumentation scripts from a YAML intent (e.g. 'bypass SSL pinning', 'dump crypto keys') and verifies they attach to a target process.
  • dastlite — A headless, config-as-code DAST runner that crawls an authenticated web/mobile-API surface and fires a curated active-scan ruleset, emitting deduplicated SARIF.
  • semsift — Lightweight semantic-aware SAST that runs curated taint rules over diffs only, so PRs get fast incremental SAST instead of whole-repo scan fatigue.
  • cheatsense — Anti-cheat telemetry analyzer that ingests game session logs and flags statistically anomalous input/aim/movement signatures with explainable per-flag scoring.

Explore the suite → 🗂️ all 170+ tools · ⭐ awesome-cognis · 🔗 cognis-sources · 🤖 uncensored-fleet · 🧠 engram

Contributing

PRs, new rules, and demo scenarios are welcome under the collaboration-pull model — see CONTRIBUTING.md and SECURITY.md.

⭐ If sbomx saved you time, star it — it genuinely helps others find it.

Interoperability

{} composes with the 300+ tool Cognis suite — JSON in/out and a shared OpenAI-compatible /v1 backbone. See INTEROP.md for the suite map, composition patterns, and reference stacks.

License

Source-available under the Cognis Open Collaboration License (COCL) v1.0 — free for personal, internal-evaluation, research, and educational use; commercial / production use requires a license ([email protected]). See LICENSE.


Cognis Digital · one of 170+ tools in the Cognis Neural Suite · Making Tomorrow Better Today

Bundled vulnerability database

Ships sbomx/cognis_vulndb.jsonl.gz262,351 real vulnerabilities (OSV: PyPI/npm/Go/Maven/RubyGems/crates.io/NuGet) with detailed metadata (CVE/GHSA aliases, ecosystem, severity/CVSS, affected packages, dates). Pure-stdlib offline loader vulndb_local.VulnDB (count/by_cve/by_package/search), air-gap ready. Refresh/extend via datafeeds.py bulk.

Offline CycloneDX-component → CVE matching

sbomx scan ... --enrich-osv maps every detected CycloneDX component to the package coordinate OSV uses for its ecosystem and matches it against the bundled 262k-record corpus — fully offline, no network, no key:

Ecosystem Component coordinate probed
Maven pkg:maven/<group>/<artifact><group>:<artifact> (e.g. com.squareup.okhttp3:okhttp)
npm the package name (e.g. react-native)
CocoaPods the framework name (e.g. Alamofire)
native the library key (e.g. openssl, sqlite, libwebp)

OSV-sourced findings are appended to the scan result, de-duplicated against the curated VULN_DB, severity-bucketed from the record's CVSS v3 vector, and marked version-unconfirmed when the compact corpus carries no version range — so the tool never silently claims a precise match it cannot prove.

sbomx scan app.apk --enrich-osv --format json -o app.cdx.json

Query the database directly (handy for triage / CI):

sbomx db count                                            # 262351
sbomx db cve CVE-2021-44228                               # log4j → GHSA-jfh8-c2jp-5v3q
sbomx db package org.apache.logging.log4j:log4j-core      # advisories for the maven coordinate
sbomx db search "buffer overflow" --limit 5
from sbomx.vulndb_local import VulnDB
db = VulnDB()
db.count()                              # 262351
db.by_cve("CVE-2021-44228")             # [{'id': 'GHSA-jfh8-c2jp-5v3q', 'aliases': ['CVE-2021-44228'], ...}]
db.by_package("org.apache.logging.log4j:log4j-core")

Edge / air-gap refresh

The corpus is the offline baseline — the tool has 262k real vulns the moment it is cloned, with zero setup. To refresh or extend it from upstream while connected, then sneakernet into a disconnected enclave, use the stdlib-only datafeeds.py ingestion engine against the real, keyless NVD / OSV / GHSA / CISA-KEV feeds catalogued in data_feeds_2026.json:

# on a connected host: refresh feeds into the disk cache
python -m sbomx.datafeeds update osv cisa-kev
python -m sbomx.datafeeds snapshot-export feeds.tar.gz
#  ... carry feeds.tar.gz across the air gap ...
# on the disconnected enclave: import + scan offline
python -m sbomx.datafeeds snapshot-import feeds.tar.gz
sbomx scan app.apk --enrich-osv --enrich-kev --offline

from github.com/cognis-digital/sbomx

Installing Sbomx

This server has no published package — it is built from source. Open the repository and follow its README.

▸ github.com/cognis-digital/sbomx

FAQ

Is Sbomx MCP free?

Yes, Sbomx MCP is free — one-click install via Unyly at no cost.

Does Sbomx need an API key?

No, Sbomx runs without API keys or environment variables.

Is Sbomx hosted or self-hosted?

Self-hosted: the server runs locally on your machine via the install command above.

How do I install Sbomx in Claude Desktop, Claude Code or Cursor?

Open Sbomx on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.

Related MCPs

Compare Sbomx with

Not sure what to pick?

Find your stack in 60 seconds

Author?

Embed badge for your README

Browse similar

All development MCPs