Validate an OpenVEX document: @context from openvex.dev, each statement has vulnerability, products[], valid status, and — when status=not_affected — a justification. Zero network. Terminal node of the sbom-provenance-attestation chain.
OpenVEX v0.2Vulnerability DisclosureEU CRA Art.14W3C VC §13.11Zero PIIClient-side only
🔒 All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.
Scope
Terminal node of the sbom-provenance-attestation chain (art-135→136→137). Validates an OpenVEX document per the VEX spec: correct @context, all statements carry a vulnerability reference, products array, a recognised status (not_affected/affected/fixed/under_investigation), and — critically — a justification when status=not_affected (required by the VEX specification). Supports EU CRA Article 14 coordinated disclosure readiness.
Copy this paragraph into Claude, OpenClaw, or any MCP-aware agent to run this exact tool, with this sample, and verify the artifact.
Run the AINumbers MCP tool `validate_openvex_statement`. Task: Validate an OpenVEX document: @context from openvex.dev, each statement has vulnerability, products[], valid status (not_affected/affected/fixed/under_investigation), and justification when status=not_affected.
Call it with arguments: {"policy_parameters":{"vex":{"@context":"https://openvex.dev/ns/v0.2.0","statements":[{"vulnerability":{"name":"CVE-2026-0001"},"products":["pkg:generic/app@1.0"],"status":"not_affected","justification":"vulnerable_code_not_in_execute_path"}]}}}
Verify before trusting: call `verify_execution_hash` on mcp.ainumbers.co (https://mcp.ainumbers.co/mcp) with the parameter `claimed_hash` set to the returned `execution_hash`, passing the full artifact the run returned (the object containing `policy_parameters` + `output_payload` + `execution_hash`; equivalently `policy_parameters` + `output_payload` with `claimed_hash`), not the bare hash string, or re-run the in-page WebMCP tool `validate_openvex_statement`.
Return the ledger link https://ledger.ainumbers.co/ so a human can re-verify without contacting us.
PII rule: All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.
Open the tool with the sample prefilled: https://ainumbers.co/chaingraph/art-137-openvex-statement-validator.html#p=v1.H4sIAAAAAAAA_wHfACD_eyJ2ZXgiOnsiQGNvbnRleHQiOiJodHRwczovL29wZW52ZXguZGV2L25zL3YwLjIuMCIsInN0YXRlbWVudHMiOlt7InZ1bG5lcmFiaWxpdHkiOnsibmFtZSI6IkNWRS0yMDI2LTAwMDEifSwicHJvZHVjdHMiOlsicGtnOmdlbmVyaWMvYXBwQDEuMCJdLCJzdGF0dXMiOiJub3RfYWZmZWN0ZWQiLCJqdXN0aWZpY2F0aW9uIjoidnVsbmVyYWJsZV9jb2RlX25vdF9pbl9leGVjdXRlX3BhdGgifV19fa4pisrfAAAA