STORY · Externalize findings/SBOM/CVE as API + MCP to platform services #191

Open
opened 2026-07-16 22:16:33 +00:00 by sharang · 0 comments
Owner

As a sibling breakpilot-platform service I want to consume Certifai
findings / SBOM / CVE via a stable API and/or MCP so that other products
(e.g. werkpilot remediation) can use scanner output.

Part of #186. Relates to #137 (werkpilot).

Acceptance criteria

  • Documented read API (findings / SBOM / CVE / targets) with RBAC + tenancy.
  • MCP surface (extend compliance-mcp) exposing the same to platform
    agents / tools.
  • Versioned + authenticated; not tied to the dashboard.
**As a** sibling breakpilot-platform service **I want** to consume Certifai findings / SBOM / CVE via a stable **API and/or MCP** **so that** other products (e.g. werkpilot remediation) can use scanner output. Part of #186. Relates to #137 (werkpilot). ## Acceptance criteria - [ ] Documented read API (findings / SBOM / CVE / targets) with RBAC + tenancy. - [ ] MCP surface (extend `compliance-mcp`) exposing the same to platform agents / tools. - [ ] Versioned + authenticated; not tied to the dashboard.
sharang added the enhancementonboarding labels 2026-07-16 22:16:33 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sharang/compliance-scanner-agent#191