Exporting an AIBOM (Pro)
An AI bill of materials (AIBOM) lists the AI components in an Asset: coding assistants, MCP servers, models, AI packages, AI services and agent skills. DefectDojo produces it as a CycloneDX 1.6 document from the AI Inventory. It is the same export as the SBOM, limited to the AI components, so the two pair by bom-ref.
The AIBOM needs the AI Inventory and Governance feature (beta) turned on from the Feature Flags page.
From the Asset Page
On an Asset, open Locations > Export SBOM & VEX and choose AI bill of materials (AIBOM) as the export type. The format is CycloneDX 1.6. The file downloads as <asset>-aibom.cdx.json.
From the API
GET /api/v2/sbom/{asset_id}/?profile=ai
GET /api/v2/sbom/{asset_id}/?profile=ai&version=5.2.0profile=ai is CycloneDX only. With version, the components are the ones that version’s BOM snapshot recorded, and their AI facts are the Asset’s current ones.
What the Document Contains
- Real component types.
applicationfor assistants and skills,libraryfor packages and packaged MCP servers,machine-learning-modelfor models. Remote AI APIs and remote MCP servers go inservices[]with their endpoints. - A model card for models when the task is known, such as
text-generation. - DefectDojo properties on every entry, using the same names the scanner writes:
defectdojo:ai:category, for examplemcp-serverorsdk;defectdojo:ai:provider;defectdojo:ai:evidence, one property per file path or config key;defectdojo:ai:authorization:authorized,unauthorized, orneeds_reviewwhen no policy has decided yet.
Component types also changed in the ordinary SBOM export: applications, models and services are exported with their real CycloneDX types instead of all being library.