OpenChainGraph Suite · ART-386 · Post-quantum readiness
CBOM Structural Lint & CNSA-2.0 Classifier
Validates a pasted CycloneDX 1.6 Cryptography Bill of Materials against a hand-derived field subset (algorithm, key size, certification level, crypto functions) and classifies each declared algorithm asset as quantum-vulnerable or aligned with a CNSA-2.0 target primitive. Every classification is asserted from what the pasted CBOM declares.
🔒 All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.
Structural lint, not a scanner
This tool checks the structure of the CBOM you paste and classifies each declared algorithm against a fixed pattern list. It does not discover cryptographic assets, does not inspect running systems or source code, and does not perform a cryptographic audit. Every finding below is labeled asserted because it reflects a declaration in your CBOM, not an observation.
Data snapshot
The CNSA-2.0 target list and CycloneDX field subset are pinned as data_version in the output. When CISA/NIST publish CBOM minimum elements under the 2026 executive order, this becomes a declared re-pin rather than a code change.
Presets
CBOM Input
Result
Idx
Name
Status
Classification
Notes
Execution Hash & §4 Artifact
SHA-256 execution hash (JCS canonical, RFC 8785):
Ask your agent
Copy this paragraph into Claude, OpenClaw, or any MCP-aware agent to run this exact tool, with this sample, and verify the artifact.
Run the AINumbers MCP tool `lint_cbom_structure`. Task: Validate a pasted CycloneDX 1.6 Cryptography Bill of Materials against a hand-derived field subset and classifies declared algorithm assets as quantum-vulnerable or CNSA-2.0 target-aligned.
Call it with arguments: {"policy_parameters":{}}
Verify before trusting: call `verify_execution_hash` on mcp.ainumbers.co (https://mcp.ainumbers.co/mcp) with the parameter `claimed_hash` set to the returned `execution_hash`, passing the full artifact the run returned (the object containing `policy_parameters` + `output_payload` + `execution_hash`; equivalently `policy_parameters` + `output_payload` with `claimed_hash`), not the bare hash string, or re-run the in-page WebMCP tool `lint_cbom_structure`.
Return the ledger link https://ledger.ainumbers.co/ so a human can re-verify without contacting us.
PII rule: All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.
Open the tool with the sample prefilled: https://ainumbers.co/chaingraph/art-386-lint-cbom-structure.html#p=v1.H4sIAAAAAAAA_wECAP3_e31Dv6ajAgAAAA