Agent tools / Dependency and security inspection
Generate an inventory SBOM
Create an auditable package inventory.
Status: implemented. Runtime: browser-or-local. Version: 1.0.0.
Inventory and advisories need observation dates; findings require reachability triage. No arbitrary scanning of third-party systems.
Supported profile
This tool accepts the schema below. Its result includes data and versioned runtime metadata. Read warnings in returned data for algorithm coverage and assumptions.
Input schema
{
"type": "object",
"properties": {
"packages": {
"type": "array",
"maxItems": 2000,
"items": {
"type": "object",
"maxProperties": 2000
}
},
"name": {
"type": "string",
"maxLength": 200000
}
},
"required": [
"packages"
],
"additionalProperties": false
}Output schema
{
"$schema": "http://json-schema.org/draft-07/schema#",
"type": "object",
"properties": {
"data": {
"type": "object",
"properties": {
"sbom": {
"type": "object",
"properties": {
"bomFormat": {
"const": "CycloneDX"
},
"specVersion": {
"const": "1.6"
},
"version": {
"const": 1
},
"metadata": {
"type": "object",
"properties": {
"component": {
"type": "object",
"properties": {
"type": {
"const": "application"
},
"name": {
"type": "string",
"maxLength": 200000
}
},
"required": [
"type",
"name"
],
"additionalProperties": false,
"maxProperties": 2000
}
},
"required": [
"component"
],
"additionalProperties": false,
"maxProperties": 2000
},
"components": {
"type": "array",
"items": {
"type": "object",
"properties": {
"type": {
"const": "library"
},
"name": {
"type": "string",
"maxLength": 200000
},
"version": {
"type": "string",
"maxLength": 200000
},
"purl": {
"type": "string",
"maxLength": 200000
},
"licenses": {
"type": "array",
"items": {
"type": "object",
"properties": {
"license": {
"type": "object",
"properties": {
"id": {
"type": "string",
"maxLength": 200000
}
},
"required": [
"id"
],
"additionalProperties": false,
"maxProperties": 2000
}
},
"required": [
"license"
],
"additionalProperties": false,
"maxProperties": 2000
},
"maxItems": 2000
}
},
"required": [
"type",
"name",
"version"
],
"additionalProperties": false,
"maxProperties": 2000
},
"maxItems": 2000
}
},
"required": [
"bomFormat",
"specVersion",
"version",
"metadata",
"components"
],
"additionalProperties": false,
"maxProperties": 2000
},
"warning": {
"type": "string",
"maxLength": 200000
}
},
"required": [
"sbom",
"warning"
],
"additionalProperties": false,
"maxProperties": 2000
},
"metadata": {
"type": "object",
"properties": {
"tool": {
"const": "dependency.sbom"
},
"version": {
"const": "1.0.0"
},
"runtime": {
"type": "string",
"enum": [
"local",
"browser",
"server"
]
},
"elapsedMs": {
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
"retained": {
"const": false
}
},
"required": [
"tool",
"version",
"runtime",
"retained"
],
"additionalProperties": false,
"maxProperties": 2000
}
},
"required": [
"data",
"metadata"
],
"additionalProperties": false,
"$defs": {
"json": {
"anyOf": [
{
"type": "null"
},
{
"type": "boolean"
},
{
"type": "number"
},
{
"type": "string",
"maxLength": 200000
},
{
"type": "array",
"items": {
"$ref": "#/$defs/json"
},
"maxItems": 2000
},
{
"type": "object",
"maxProperties": 2000,
"additionalProperties": {
"$ref": "#/$defs/json"
}
}
]
}
}
}Example arguments
{
"packages": [
{
"name": "example",
"version": "1.0.0",
"license": "MIT"
}
],
"name": "App"
}Local MCP tool name: dependency__sbom. Browser and local execution work without a key.
Hosted REST and MCP execution are disabled in this release. Run the example in the browser console below, or use the local MCP server from this repository.
Privacy and limits
256 KiB arguments, 512 KiB output, 20 nesting levels and 2,000 array entries. No input/output logging in this layer. Browser/local utilities do not submit inputs remotely. Optional network operations disclose destination requests. Caller-supplied policies and guardrail findings never grant execution privileges.
136 matching tools
Generate an inventory SBOM
Create an auditable package inventory.
Inventory and advisories need observation dates; findings require reachability triage. No arbitrary scanning of third-party systems.
Result
Run a tool to see its structured result.
Let a browser agent use this console
Enable WebMCP when your browser supports it. Inputs run locally and results remain visible here.