Skip to main content
Glama
EricSeokgon

egovframe-scaffold-mcp

by EricSeokgon

SBOM 생성 (CycloneDX)

generate_egovframe_sbom

Generate a CycloneDX 1.6 JSON SBOM for Maven/Gradle projects without modifying build files; optionally enrich components with eGovFrame status and OSV vulnerabilities.

Instructions

Maven/Gradle 프로젝트의 SBOM 을 CycloneDX 1.6 JSON 으로 만듭니다(빌드 파일 변경 없음). Maven 은 cyclonedx-maven-plugin(makeAggregateBom, 해시·라이선스 포함), Gradle 은 해석된 의존성 트리로 문서를 구성합니다. enrich=true(기본)면 component 마다 기준 판정(egovframe:status·basis·baseline)을 properties 로 붙이고, offline=false 면 OSV 로 알려진 취약점을 vulnerabilities[] 로 넣습니다. 출력은 프로젝트 안 경로(기본 sbom/bom.cdx.json)만 허용하고 기존 파일은 overwrite=true 가 아니면 거부하며, dryRun(기본)은 실행 없이 계획만 돌려줍니다. 2027년부터 단계화되는 공공기관 SBOM 등록·제출에 쓸 수 있는 표준 형식입니다.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
scopeNoruntime(compile+runtime, 기본) | all(test·provided 포함)runtime
authorNoSBOM 작성자(metadata.authors) — 없으면 supplier
dryRunNotrue(기본)면 실행 없이 명령·출력 경로만 보고
enrichNocomponent 마다 기준 판정 속성 부착
formatNo응답 형식markdown
offlineNofalse 면 OSV 조회 결과를 vulnerabilities[] 로 포함
supplierNo공급자(주 component·문서 metadata.supplier) — 없으면 pom <organization><name>
bomFormatNoSBOM 형식(현재 CycloneDX JSON)cyclonedx-json
overwriteNo기존 출력 파일 덮어쓰기 허용
timeoutMsNo생성 명령 타임아웃(ms)
outputPathNo프로젝트 상대 출력 경로sbom/bom.cdx.json
projectDirYes프로젝트 디렉터리(절대경로 권장)
componentNameNo주 component 이름 덮어쓰기(기본 artifactId)
fillSuppliersNo공급자가 없는 component 를 공급자 표(catalog/sbom-rules.json)로 보완(egovframe:supplierBasis=catalog) — 기본은 enrich 와 같음
componentVersionNo주 component 버전 덮어쓰기(기본 pom version)

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
bytesYes
notesYes
directYes
dryRunYes
formatYes
commandYes
logTailNo
minimumNo
writtenYes
osvErrorNo
statusesYes
buildToolYes
generatorYes
componentsYes
durationMsNo
outputPathYes
projectDirYes
transitiveYes
overwrittenYes
specVersionYes
absolutePathYes
vulnerabilitiesYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed6 schema fields changedv0.40.0
    • addedInput schema / properties / author
      Added value: +{
      +  "description": "SBOM 작성자(metadata.authors) — 없으면 supplier",
      +  "maxLength": 200,
      +  "minLength": 1,
      +  "type": "string"
      +}
    • addedInput schema / properties / componentName
      Added value: +{
      +  "description": "주 component 이름 덮어쓰기(기본 artifactId)",
      +  "maxLength": 200,
      +  "minLength": 1,
      +  "type": "string"
      +}
    • addedInput schema / properties / componentVersion
      Added value: +{
      +  "description": "주 component 버전 덮어쓰기(기본 pom version)",
      +  "maxLength": 100,
      +  "minLength": 1,
      +  "type": "string"
      +}
    • addedInput schema / properties / fillSuppliers
      Added value: +{
      +  "description": "공급자가 없는 component 를 공급자 표(catalog/sbom-rules.json)로 보완(egovframe:supplierBasis=catalog) — 기본은 enrich 와 같음",
      +  "type": "boolean"
      +}
    • addedInput schema / properties / supplier
      Added value: +{
      +  "description": "공급자(주 component·문서 metadata.supplier) — 없으면 pom <organization><name>",
      +  "maxLength": 200,
      +  "minLength": 1,
      +  "type": "string"
      +}
    • addedOutput schema / properties / minimum
      Added value: +{
      +  "additionalProperties": true,
      +  "properties": {
      +    "componentsWithGaps": {
      +      "type": "integer"
      +    },
      +    "missing": {
      +      "items": {
      +        "type": "string"
      +      },
      +      "type": "array"
      +    },
      +    "supplierFromCatalog": {
      +      "type": "integer"
      +    },
      +    "verdict": {
      +      "enum": [
      +        "ready",
      +        "needs-work"
      +      ],
      +      "type": "string"
      +    }
      +  },
      +  "required": [
      +    "verdict",
      +    "missing",
      +    "componentsWithGaps",
      +    "supplierFromCatalog"
      +  ],
      +  "type": "object"
      +}
  2. Addedv0.36.1

TDQS

A4/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Despite annotations already covering the safety profile (readOnlyHint=false, destructiveHint=false, openWorldHint=true), the description adds substantial behavioral detail: no build-file mutation, output restricted to project-relative paths, existing files rejected unless overwrite=true, dryRun returns a plan only, and offline=false triggers OSV vulnerability lookup. These are exactly the operational facts an agent needs before calling.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Purpose and output format are front-loaded, and the paragraph is dense with load-bearing facts rather than filler. It is on the long side for a single block, but nearly every clause carries behavioral information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 15-parameter mutation tool with a rich schema, output schema, and annotations, the description covers generation mechanics, write-guard behavior, and enrichment/OSV semantics well. The only mild gap is selection guidance against sibling tools, which is not strictly required given the output schema and annotations carry the rest.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so baseline is 3, but the description goes further by tying key flags to downstream effects (enrich attaches egovframe:status/basis/baseline properties, offline=false populates vulnerabilities[], dryRun default returns only a plan, output path constrained). It adds meaning beyond the schema rather than restating it.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource — generating a CycloneDX 1.6 JSON SBOM for Maven/Gradle projects — plus the concrete mechanism (cyclonedx-maven-plugin, resolved Gradle dependency tree). The purpose is unambiguous and implicitly separable from check_egovframe_sbom, but no sibling is named explicitly, so it falls just short of 5.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It supplies real context (usable for public-institution SBOM registration/submission phased in from 2027) and spells out default behaviors, but gives no explicit when-to-use/when-not guidance and never contrasts itself with alternatives like check_egovframe_sbom or generate_egovframe_report. Usage is implied rather than directed.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.