As a sibling breakpilot-platform service I want to consume Certifai
findings / SBOM / CVE via a stable API and/or MCPso that other products
(e.g. werkpilot remediation) can use scanner output.
Documented read API (findings / SBOM / CVE / targets) with RBAC + tenancy.
MCP surface (extend compliance-mcp) exposing the same to platform
agents / tools.
Versioned + authenticated; not tied to the dashboard.
**As a** sibling breakpilot-platform service **I want** to consume Certifai
findings / SBOM / CVE via a stable **API and/or MCP** **so that** other products
(e.g. werkpilot remediation) can use scanner output.
Part of #186. Relates to #137 (werkpilot).
## Acceptance criteria
- [ ] Documented read API (findings / SBOM / CVE / targets) with RBAC + tenancy.
- [ ] MCP surface (extend `compliance-mcp`) exposing the same to platform
agents / tools.
- [ ] Versioned + authenticated; not tied to the dashboard.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
As a sibling breakpilot-platform service I want to consume Certifai
findings / SBOM / CVE via a stable API and/or MCP so that other products
(e.g. werkpilot remediation) can use scanner output.
Part of #186. Relates to #137 (werkpilot).
Acceptance criteria
compliance-mcp) exposing the same to platformagents / tools.