SBOM Check
Guest access is available after setup. Full account linking verified by PowMCP: Claude only.
Use in your browser
Validate a publicly fetchable CycloneDX or SPDX SBOM, or compare two builds for conformance drift. JSON gets full versioned-schema validation; XML and tag-value get structural, PURL, and SPDX license ID checks.
Guest includes 50 lifetime app requests. Create a free account for 100 app requests each calendar month. One allowance across every app, in your browser and your agent.One allowance across every app, in your browser and your agent. Manage usage
Guest access is available after setup. Full account linking verified by PowMCP: Claude only.
Connect this app on its own. Add other PowMCP apps whenever your agent needs another job done.
Open the apps workspace
Choose your agent. Each button opens a new tab with only this app's endpoint ready to add.
Copy one ready-to-send prompt for any agent that supports remote MCP connections.
For clients that require manual configuration, use this app-only endpoint, its JSON entry, or one terminal command.
ChatGPT: enable Developer mode in Settings → Security and login, then add this MCP endpoint from the Plugins page. Availability depends on your account and workspace policy. PowMCP has not yet verified ChatGPT account linking. OpenAI setup guide
https://powmcp.com/sbom-preflight/mcp {
"mcpServers": {
"powmcp-sbom-preflight": {
"type": "http",
"url": "https://powmcp.com/sbom-preflight/mcp"
}
}
}Terminal agents add this app with one command:
claude mcp add --transport http powmcp-sbom-preflight https://powmcp.com/sbom-preflight/mcpcodex mcp add powmcp-sbom-preflight --url https://powmcp.com/sbom-preflight/mcpgemini mcp add --transport http powmcp-sbom-preflight https://powmcp.com/sbom-preflight/mcpManage, disable, or remove this connection in your agent's own MCP settings. PowMCP does not label an external connection as installed without confirmation from that client.
Proof
Check an SBOM document before you ship it
Validate one CycloneDX or SPDX SBOM (a public URL or a file attached in the conversation) with full versioned-schema validation for JSON documents; CycloneDX XML and SPDX tag-value are parsed and structurally checked, not schema-validated. PURL-syntax and SPDX-license-id checks and document-located defects run on every format, or compare two builds under identical limits, validating document conformance only.
Request cost1 completed result
Guests get 50 lifetime app requests. Free accounts get 100 each calendar month.
sbom_check
Validate one CycloneDX or SPDX software bill of materials before you deliver it or gate a build. Give a publicly fetchable HTTP(S) SBOM URL or attach the SBOM file directly in the conversation (CycloneDX JSON or XML, or SPDX JSON or tag-value) and it downloads the document under an SSRF-guarded, 10 MB-capped fetch, detects the format and spec version from content, validates CycloneDX/SPDX JSON against the correct bundled official versioned JSON schema (CycloneDX XML and SPDX tag-value are parsed and structurally checked instead, never schema-validated, so they always report pass false), and checks every package-url for purl-spec syntax and every declared license against the full SPDX license-id list, returning pass/fail, document-located schema defects, PURL and license-id findings, and a required-field summary. It validates document conformance only: it does not score supply-chain risk, scan for CVEs or vulnerabilities, or confirm the SBOM lists every real component. Fetching and validating a live document can take up to 60 seconds.
sbom_compare
Compare exactly two CycloneDX or SPDX SBOM builds under identical limits to see what drifted release over release. Give two distinct SBOM builds (publicly fetchable HTTP(S) URLs or files attached in the conversation) and it runs the same bounded validation as sbom_check on each: schema conformance for JSON documents (CycloneDX XML and SPDX tag-value are parsed and structurally checked instead), PURL syntax, SPDX license ids, then reports per-build pass and defect counts, which schema/PURL/license findings were introduced or resolved, the added, removed, and version-changed components and licenses, and ranks the builds by pass state then fewer conformance defects (only when the measured findings support a distinction). Use sbom_check for a single document. It ranks automated conformance only and never infers that fewer defects means lower supply-chain risk, better security, or more complete coverage. Fetching and validating two live documents can take up to 60 seconds.
Other apps for the jobs next to SBOM Check.
Scope and boundaries for SBOM Check.
Validate the public CycloneDX JSON SBOM for Proton Bridge 1.6.3 with maxDefects set to 300, or attach one CycloneDX or SPDX file instead of supplying a URL.
Read pass together with schema.applied first: pass means a supported CycloneDX or SPDX JSON document passed the bundled schema plus the scanned PURL and SPDX license checks. XML and tag-value inputs cannot pass because no JSON schema is applied, so read schema.reason before treating failure as a defect. Fix schema, PURL, license, and required-field findings, and treat any truncation marker as incomplete evidence.
Full versioned-schema validation applies only to CycloneDX and SPDX JSON; CycloneDX XML and SPDX tag-value receive structural checks and do not return pass true. Sources are capped at 10 MB, and validation does not find CVEs, assess supply-chain risk, or confirm the SBOM is complete.