Yocto security sbom
Skill Higangssh/yocto-agent-skills/skills/yocto-security-sbom
Review and debug Yocto license metadata, LIC_FILES_CHKSUM, LICENSE_FLAGS, incompatible licenses, license manifests, SPDX/SBOM generation, CVE checking, archiver/copyleft source compliance, and security policy. Use for compliance, CVE, SBOM, license, commercial license, source archiving, or security review questions.From its SKILL.md
npx -y skills add Higangssh/yocto-agent-skills --skill yocto-security-sbomAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- 6 stars6 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
- runs commandsInstructs the agent to run 4 commands, including `bitbake -e <recipe> | rg '^(LICENSE|LIC_FILES_CHKSUM|LICENSE_FLAGS|LICENSE_FLAGS_ACCEPTED|INCOMPATIBLE_LICENSE|CVE|SPDX|ARCHIVER)[:=]'` and 3 more.
SKILL.md
2.2 KB, 444 tokens by cl100k_base, as published. Nobody here has run it
Yocto Security SBOM
Use this skill for security, license, CVE, SBOM, and compliance workflows. Treat class names and output paths as release-sensitive.
Evidence
Ask for or inspect:
target Yocto release
recipe LICENSE and LIC_FILES_CHKSUM
license QA error
image/license manifest output
SPDX/SBOM configuration and output
CVE check configuration and reports
archiver/copyleft configuration
commercial license policy
Useful commands:
bitbake -e <recipe> | rg '^(LICENSE|LIC_FILES_CHKSUM|LICENSE_FLAGS|LICENSE_FLAGS_ACCEPTED|INCOMPATIBLE_LICENSE|CVE|SPDX|ARCHIVER)[:=]'
bitbake -c populate_lic <recipe>
bitbake <image>
find tmp/deploy -maxdepth 4 -iname '*spdx*' -o -path '*licenses*'
Review Rules
LIC_FILES_CHKSUMis mandatory unlessLICENSE = "CLOSED".- License checksum mismatch means upstream license text changed; inspect before updating the checksum.
- Keep commercial license acceptance explicit and narrow.
- Verify current release SBOM/CVE class names before recommending
create-spdx, CVE classes, or output paths. - Use archiver/copyleft flows when source offer obligations matter.
- Do not confuse build-time
DEPENDSwith packages included in final image license manifests.
References
- Read ../../references/yocto/security-sbom.md.
- Read ../../references/bitbake/classes-core.md for
license,archiver,create-spdx, and release-sensitive security classes. - Read ../../references/yocto/migration.md for SBOM/CVE release changes.
Output
Answer with:
- license/security artifact being debugged
- release-sensitive class or variable to verify
- exact metadata or policy fix
- validation command and expected artifact
- compliance caveat if legal interpretation is required
What ships with it: 3 files
11.2 KB alongside SKILL.md
references/
- classes-core.md4.6 KB
- migration.md4.2 KB
- security-sbom.md2.4 KB