Command Palette

Search for a command to run...

UnylyUnyly
Весь каталог

Sbomx

БесплатноНе проверен

Generates a CycloneDX SBOM for mobile apps by unpacking native libs and bundled SDKs, then matches components against known-vuln and tracker/privacy databases.

GitHubEmbed

Описание

Generates a CycloneDX SBOM for mobile apps by unpacking native libs and bundled SDKs, then matches components against known-vuln and tracker/privacy databases.

README

SBOMX

SBOMX

Generates a CycloneDX SBOM for mobile apps by unpacking native libs and bundled SDKs, then matches components against known-vuln and tracker/privacy databases.

PyPI CI License: COCL 1.0 Suite

Application & Mobile Security — SAST/DAST-lite and binary triage.

pip install cognis-sbomx
sbomx scan .            # → prioritized findings in seconds

🔎 Example output

Real, reproducible output from the tool — runs offline:

$ sbomx-emit --version
sbomx 0.2.4
$ sbomx-emit --help
usage: sbomx [-h] [--version] {scan,db,feeds} ...

Generate a CycloneDX SBOM for mobile apps and match bundled libraries against vulnerability and privacy-tracker databases.

positional arguments:
  {scan,db,feeds}
    scan           scan an .apk/.ipa/zip or directory and produce an SBOM +
                   findings
    db             query the bundled offline 262k-record OSV vulnerability
                   database
    feeds          manage the bundled edge/air-gap vulnerability data feeds

options:
  -h, --help       show this help message and exit
  --version        show program's version number and exit

Command-line interface for SBOMX.

Examples
--------
  # Generate a CycloneDX SBOM (JSON) for an APK and write it to a file
  sbomx scan app.apk --format json -o app.cdx.json

  # Human-readable findings table; exit non-zero if vulns/trackers found
  sbomx scan app.ipa --format table

  # Scan an extracted bundle directory and fail CI on HIGH severity vulns
  sbomx scan ./unpacked_app --fail-on high

  # Use a manifest mapping lib->version to refine version-unknown components
  sbomx scan app.apk --manifest versions.json

Exit codes
----------
  0  clean (no findings, or findings below --fail-on threshold)
  1  findings at/above the fail threshold (default: any tracker or vuln)
  2  usage / runtime error

Blocks above are real sbomx output — reproduce them from a clone.

Sample result format (illustrative values — run on your own data for real findings):

{
"sbomx": {
"platform": "stix",
"findings": [
{
"uuid": "12345678-1234-5678-1234-567812345678",
"vulnerability": {
"name": "CVE-2023-12345"
},
"severity": "high",
"description": "A high-severity vulnerability in the application."
}
]
}
}

Usage — step by step

sbomx generates a CycloneDX SBOM for mobile apps and matches bundled libraries against vulnerability and privacy-tracker databases. Console script: sbomx.

  1. Install:
    pipx install sbomx     # or: pip install sbomx
    
  2. Scan an app bundle (.apk / .ipa / .zip) or an extracted directory and print a findings table:
    sbomx scan app.apk --format table
    
    Exit 1 = findings at/above the --fail-on threshold (default: any finding), 0 = clean, 2 = error.
  3. Emit a CycloneDX 1.5 SBOM as JSON to a file (also --format sarif for GitHub code-scanning, or --format csv for spreadsheets/ticketing):
    sbomx scan app.apk --format json  -o app.cdx.json
    sbomx scan app.apk --format sarif -o app.sarif.json   # upload to code-scanning
    sbomx scan app.apk --format csv   -o findings.csv
    
  4. Refine version-unknown components with a manifest mapping library key to version:
    sbomx scan app.apk --manifest versions.json --format json -o app.cdx.json
    
  5. Gate CI on severity — fail the build only on HIGH+ vulnerabilities/trackers:
    sbomx scan ./unpacked_app --fail-on high || echo "high-severity component findings — blocking release"
    

Contents

Why sbomx?

Syft/Grype ignore the mobile binary world; sbomx surfaces vulnerable bundled SDKs and privacy trackers inside shipped apps — perfect for app-store compliance gating.

sbomx is single-purpose, scriptable, and self-hostable: point it at a target, get prioritized results in the format your workflow already speaks (table · JSON · SARIF), gate CI on it, and let agents drive it over MCP.

Features

  • ✅ Detects bundled libraries from APK/IPA/zip member paths and native .so/.dylib names
  • ✅ Recovers versions from filenames or a supplied --manifest (key → version)
  • ✅ Matches against a curated vuln DB (CVE-style) and a privacy-tracker DB (Exodus-style)
  • Live threat-feed enrichment: flags findings on CISA's Known-Exploited (KEV) list — see Live data feeds
  • Four output formats: table · CycloneDX 1.5 json · SARIF 2.1.0 sarif · csv
  • ✅ CI gate via --fail-on {info,low,medium,high,critical,never} + exit codes
  • ✅ 11 ready-to-run demos covering iOS/Android/React Native/Flutter/games + live KEV enrichment
  • ✅ Runs on Linux/macOS/Windows · Docker · devcontainer
  • ✅ Ports in Python, JavaScript, Go, and Rust (ports/)

Quick start

pip install cognis-sbomx
sbomx --version
sbomx scan .                       # scan current project
sbomx scan . --format json         # machine-readable
sbomx scan . --fail-on high        # CI gate (non-zero exit)

Example

A real scan of an Android bundle that ships okhttp-4.9.0.jar, native libssl/libwebp, Firebase + Crashlytics and the AppsFlyer SDK:

$ sbomx scan app.apk --format table
Target: app.apk

Components (7):
  appsflyer             ?          maven      pkg:maven/com.appsflyer/appsflyer
  firebase-core         ?          maven      pkg:maven/com.google.firebase/firebase-core
  firebase-crashlytics  ?          maven      pkg:maven/com.google.firebase/firebase-crashlytics
  gson                  ?          maven      pkg:maven/com.google.code.gson/gson
  libwebp               ?          native     pkg:generic/libwebp
  okhttp                4.9.0      maven      pkg:maven/com.squareup.okhttp3/[email protected]
  openssl               1.1.1k     native     pkg:generic/openssl

Vulnerabilities (4):
  [CRITICAL] CVE-2023-4863  libwebp@?
             Heap buffer overflow in WebP lossless (VP8L) decoding; exploited in the wild.
             fix: upgrade to >= 1.3.2
  [HIGH    ] CVE-2022-0778  [email protected]
             BN_mod_sqrt infinite loop (DoS) when parsing certificates.
             fix: upgrade to >= 1.1.1n
  [MEDIUM  ] CVE-2021-0341  [email protected]
             OkHttp improper certificate validation (hostname not verified).
             fix: upgrade to >= 4.9.2

Trackers (3):
  AppsFlyer  (Analytics, Advertisement)
  Google Firebase Analytics  (Analytics)
  Google Firebase Crashlytics  (Crash reporting, Analytics)

Add --enrich-osv to cross-reference every detected component against the bundled 262k-record offline OSV database (no network), or --enrich-kev to flag CVEs that are actively exploited per CISA.

Demos — real-use-case scenarios

Each folder under demos/ ships a generator (make_sample.py) that builds a realistic app bundle plus a SCENARIO.md (where the data came from, the exact command, expected output, and how to act). All library versions are drawn from the tool's own detection rules + vuln DB, so every demo deterministically reproduces its documented findings.

Demo Scenario Highlights
01-basic First Android scan 3 vulns + 2 trackers, table + JSON
02-clean First-party app, no SDKs 0 findings, exit 0
03-mixed Mixed severities --fail-on high vs critical gate
04-ios-banking iOS .ipa framework audit CocoaPods + native crypto, Realm CVE
05-react-native-ecommerce RN privacy + vuln review 3 trackers, CSV export
06-clean-release Release candidate all libs patched, gate passes
07-manifest-resolve Stripped build --manifest resolves version-unknown potentials
08-game-adtech F2P game ad-SDK sweep 5 trackers + native media CVEs
09-flutter-app Flutter native audit 3 HIGH native CVEs
10-ci-sarif-gate CI + GitHub code-scanning SARIF upload + HIGH gate
python demos/04-ios-banking/make_sample.py
python -m sbomx scan demos/04-ios-banking/banking.ipa --format table

Live data feeds — edge / air-gap ingestion

sbomx enriches its findings with real, authoritative public vulnerability feeds. The killer feature: an SBOM finding is no longer "this CVE applies" but "this CVE is being exploited in the wild right now — patch it first."

Feed id Source (real, keyless) Used for
cisa-kev CISA Known Exploited Vulnerabilities Flag + escalate actively-exploited CVEs to critical; surface KEV dateAdded / federal dueDate
osv OSV.dev Package+version vulnerability lookups across ecosystems

Enrich a scan

sbomx scan app.apk --enrich-kev            # online: fetch/refresh KEV, then enrich
sbomx scan app.apk --enrich-kev --offline  # air-gap: use the local KEV cache only

Findings whose CVE is on the KEV list are tagged *** CISA KNOWN-EXPLOITED ***, bumped to critical, and annotated with the authoritative dates:

[CRITICAL] CVE-2023-4863  [email protected]  *** CISA KNOWN-EXPLOITED ***
           Heap buffer overflow in WebP lossless (VP8L) decoding; exploited in the wild.
           KEV: added 2023-09-13  patch-by 2023-10-04  ransomware=Unknown
           fix: upgrade to >= 1.3.2

Manage the feeds

sbomx feeds list                       # the feeds this tool consumes (+ URLs)
sbomx feeds update cisa-kev            # keyless HTTPS fetch -> disk cache
sbomx feeds get cisa-kev --offline     # re-serve from cache, never touch network

Edge / air-gap workflow

The ingestion engine (sbomx/datafeeds.py, stdlib-only) caches every feed to disk and re-serves it offline, so sbomx keeps working on disconnected / classified / forward-deployed gear. Set the cache location with COGNIS_FEEDS_CACHE (default ~/.cache/cognis-feeds).

Sneakernet into an air gap:

# on a connected host
sbomx feeds update cisa-kev
python -m sbomx.datafeeds snapshot-export feeds.tar.gz
#  ... carry feeds.tar.gz across the gap ...
# on the disconnected enclave
python -m sbomx.datafeeds snapshot-import feeds.tar.gz
sbomx scan app.apk --enrich-kev --offline

See demos/11-kev-enrichment for a complete, offline-runnable example. The test suite ships a trimmed real-data feed cache under tests/fixtures/feeds-cache/, so CI enriches findings with zero network access.

Architecture

flowchart LR
  IN[target / manifest] --> P[sbomx<br/>checks + rules]
  P --> OUT[findings (JSON / SARIF)]

Use it from any AI stack

sbomx is interoperable with every popular way of using AI:

  • MCP serversbomx mcp (Claude Desktop, Cursor, Cognis.Studio, uncensored-fleet)
  • OpenAI-compatible / JSON — pipe sbomx scan . --format json into any agent or LLM
  • LangChain · CrewAI · AutoGen · LlamaIndex — wrap the CLI/JSON as a tool in one line
  • CI / scripts — exit codes + SARIF for non-AI pipelines

How it compares

Cognis sbomx Syft + Grype, extended to the mobile binary (APK
Self-hostable, no account varies
Single command, zero config ⚠️
JSON + SARIF for CI varies
MCP-native (AI agents)
Polyglot ports (JS/Go/Rust)
Open license ✅ COCL varies

Built in the spirit of Syft + Grype, extended to the mobile binary (APK/IPA native .so/dylib) world, re-framed the Cognis way. Missing a credit? Open a PR.

Integrations

Pipes into your stack: SARIF for code-scanning, JSON for anything, an MCP server (sbomx mcp) for AI agents, and a webhook forwarder for SIEM/Slack/Jira. See docs/INTEGRATIONS.md.

Install — every way, every platform

pip install "git+https://github.com/cognis-digital/sbomx.git"    # pip (works today)
pipx install "git+https://github.com/cognis-digital/sbomx.git"   # isolated CLI
uv tool install "git+https://github.com/cognis-digital/sbomx.git" # uv
pip install cognis-sbomx                                          # PyPI (when published)
docker run --rm ghcr.io/cognis-digital/sbomx:latest --help        # Docker
brew install cognis-digital/tap/sbomx                             # Homebrew tap
curl -fsSL https://raw.githubusercontent.com/cognis-digital/sbomx/main/install.sh | sh
Linux macOS Windows Docker Cloud
scripts/setup-linux.sh scripts/setup-macos.sh scripts/setup-windows.ps1 docker run ghcr.io/cognis-digital/sbomx DEPLOY.md (AWS/Azure/GCP/k8s)

Related Cognis tools

  • apkpeek — One-command static triage of Android APK/AAB binaries: surfaces hardcoded secrets, exported components, dangerous permissions, and insecure manifest flags as a single SARIF report.
  • ipasnitch — Static scanner for iOS .ipa bundles that flags ATS exceptions, missing entitlements hardening, embedded URLs/secrets, and weak Info.plist transport settings.
  • hookcraft — Generates ready-to-run Frida instrumentation scripts from a YAML intent (e.g. 'bypass SSL pinning', 'dump crypto keys') and verifies they attach to a target process.
  • dastlite — A headless, config-as-code DAST runner that crawls an authenticated web/mobile-API surface and fires a curated active-scan ruleset, emitting deduplicated SARIF.
  • semsift — Lightweight semantic-aware SAST that runs curated taint rules over diffs only, so PRs get fast incremental SAST instead of whole-repo scan fatigue.
  • cheatsense — Anti-cheat telemetry analyzer that ingests game session logs and flags statistically anomalous input/aim/movement signatures with explainable per-flag scoring.

Explore the suite → 🗂️ all 170+ tools · ⭐ awesome-cognis · 🔗 cognis-sources · 🤖 uncensored-fleet · 🧠 engram

Contributing

PRs, new rules, and demo scenarios are welcome under the collaboration-pull model — see CONTRIBUTING.md and SECURITY.md.

⭐ If sbomx saved you time, star it — it genuinely helps others find it.

Interoperability

{} composes with the 300+ tool Cognis suite — JSON in/out and a shared OpenAI-compatible /v1 backbone. See INTEROP.md for the suite map, composition patterns, and reference stacks.

License

Source-available under the Cognis Open Collaboration License (COCL) v1.0 — free for personal, internal-evaluation, research, and educational use; commercial / production use requires a license ([email protected]). See LICENSE.


Cognis Digital · one of 170+ tools in the Cognis Neural Suite · Making Tomorrow Better Today

Bundled vulnerability database

Ships sbomx/cognis_vulndb.jsonl.gz262,351 real vulnerabilities (OSV: PyPI/npm/Go/Maven/RubyGems/crates.io/NuGet) with detailed metadata (CVE/GHSA aliases, ecosystem, severity/CVSS, affected packages, dates). Pure-stdlib offline loader vulndb_local.VulnDB (count/by_cve/by_package/search), air-gap ready. Refresh/extend via datafeeds.py bulk.

Offline CycloneDX-component → CVE matching

sbomx scan ... --enrich-osv maps every detected CycloneDX component to the package coordinate OSV uses for its ecosystem and matches it against the bundled 262k-record corpus — fully offline, no network, no key:

Ecosystem Component coordinate probed
Maven pkg:maven/<group>/<artifact><group>:<artifact> (e.g. com.squareup.okhttp3:okhttp)
npm the package name (e.g. react-native)
CocoaPods the framework name (e.g. Alamofire)
native the library key (e.g. openssl, sqlite, libwebp)

OSV-sourced findings are appended to the scan result, de-duplicated against the curated VULN_DB, severity-bucketed from the record's CVSS v3 vector, and marked version-unconfirmed when the compact corpus carries no version range — so the tool never silently claims a precise match it cannot prove.

sbomx scan app.apk --enrich-osv --format json -o app.cdx.json

Query the database directly (handy for triage / CI):

sbomx db count                                            # 262351
sbomx db cve CVE-2021-44228                               # log4j → GHSA-jfh8-c2jp-5v3q
sbomx db package org.apache.logging.log4j:log4j-core      # advisories for the maven coordinate
sbomx db search "buffer overflow" --limit 5
from sbomx.vulndb_local import VulnDB
db = VulnDB()
db.count()                              # 262351
db.by_cve("CVE-2021-44228")             # [{'id': 'GHSA-jfh8-c2jp-5v3q', 'aliases': ['CVE-2021-44228'], ...}]
db.by_package("org.apache.logging.log4j:log4j-core")

Edge / air-gap refresh

The corpus is the offline baseline — the tool has 262k real vulns the moment it is cloned, with zero setup. To refresh or extend it from upstream while connected, then sneakernet into a disconnected enclave, use the stdlib-only datafeeds.py ingestion engine against the real, keyless NVD / OSV / GHSA / CISA-KEV feeds catalogued in data_feeds_2026.json:

# on a connected host: refresh feeds into the disk cache
python -m sbomx.datafeeds update osv cisa-kev
python -m sbomx.datafeeds snapshot-export feeds.tar.gz
#  ... carry feeds.tar.gz across the air gap ...
# on the disconnected enclave: import + scan offline
python -m sbomx.datafeeds snapshot-import feeds.tar.gz
sbomx scan app.apk --enrich-osv --enrich-kev --offline

from github.com/cognis-digital/sbomx

Установка Sbomx

У этого сервера нет опубликованного пакета — он собирается из исходников. Открой репозиторий и следуй инструкции в README.

▸ github.com/cognis-digital/sbomx

FAQ

Sbomx MCP бесплатный?

Да, Sbomx MCP бесплатный — установка в пару кликов через Unyly без оплаты.

Нужен ли API-ключ для Sbomx?

Нет, Sbomx работает без API-ключей и переменных окружения.

Sbomx — hosted или self-hosted?

Self-hosted: сервер запускается локально на твоей машине командой из раздела установки.

Как установить Sbomx в Claude Desktop, Claude Code или Cursor?

Открой Sbomx на unyly.org, выбери вкладку своего клиента (Claude Desktop, Claude Code, Cursor) и нажми Install — конфиг сгенерируется автоматически, без правки JSON.

Похожие MCP

Compare Sbomx with

Не уверен что выбрать?

Найди свой стек за 60 секунд

Автор?

Embed-бейдж для README

Похожее

Все в категории development