Skip to content
EcoCitizenZ
Agent plugin · Support

ECZ-ID SBOM & CRA Readiness

Support

This page covers the ECZ-ID SBOM & CRA Readiness agent plugin — the package eczid-sbom-cra-readiness, published at version 0.1.1. It tells you how to reach us, what to include so a problem can be reproduced, and how security reports are handled differently from ordinary support.

Applies to:
eczid-sbom-cra-readiness 0.1.1
Effective date:
3 September 2026

In short

  • Support runs by email: support@ecocitizenz.com. There is no account to create and no support portal to sign in to.
  • The plugin is free, and support for it is free. No support contract is required, and none is offered for it.
  • Never send passwords, API keys, tokens, certificates or any other secret. Nothing about this product needs one.
  • Suspected security vulnerabilities go to the same address but under the security reporting route, not the ordinary support route.
  • We publish no response-time commitment for this free plugin, so this page does not imply one.

What the plugin does

ECZ-ID SBOM & CRA Readiness adds one skill to an agent host. When you ask about SBOM or Cyber Resilience Act evidence in a repository, the agent runs a bundled review script over the folder you point it at, then reports what evidence it found, what it did not, why each class matters and what to review next.

The review works from file names and paths only. It looks for a machine-readable SBOM, CycloneDX and SPDX documents, a dependency lockfile, VEX or CSAF vulnerability statements, a vulnerability disclosure policy or security contact, build provenance or attestations, and a release record. It does not open any of those files. So it can tell you that a document exists where a reviewer would expect one, and it cannot tell you whether the contents are any good.

Results are reported as EVIDENCE OBSERVED, EVIDENCE NOT OBSERVED, REVIEW RECOMMENDED and REVIEW REQUIRED, with a Review Priority of LOW, NORMAL, ELEVATED or HIGH and the reasons that produced it. The Review Priority is deterministic: the same file listing always gives the same result. It is not a score, a grade, a pass mark or a verdict.

The Privacy page sets out exactly what the plugin reads and what it does not. The Terms page sets out the basis on which you may use it.

Things worth checking first

Most reports we can act on quickly come down to one of these, and each is faster to check than to describe in an email.

  • Nothing was found in a repository that clearly has evidence. The review skips node_modules, dist, build and similar generated directories, and it ignores hidden dot-directories other than .github, .gitlab and .well-known. Evidence stored only in a skipped location will not be observed.
  • The review stopped short in a large repository. Traversal is bounded by design, so a review cannot run away on a very large tree. Point it at the sub-project you care about rather than at a monorepo root.
  • The host cannot find the skill. Confirm the plugin is installed and enabled in that host, and that a Node.js runtime is available — the bundled review script runs on Node and has no other dependency.
  • You want to see exactly what the review did. The script is short, readable and has no build step. Read review.mjs, or run it yourself with --json for the machine-readable projection.

Getting support

Email support@ecocitizenz.com. This is the support route for every EcoCitizenz product, so please name ECZ-ID SBOM & CRA Readiness in the subject line.

A report we can act on usually contains:

  • the plugin name and version — eczid-sbom-cra-readiness 0.1.1;
  • the agent host and its version, and how the plugin was installed there — which marketplace, or a local copy;
  • your operating system and Node.js version;
  • what you asked the agent to do, and what you expected to happen;
  • what actually happened, quoted rather than summarised;
  • any error text in full and, if the review ran, the --json output — the single most useful attachment for a detection problem;
  • for a detection problem, the file name and path you expected to be observed. The path is enough. We do not need the file.

If the repository is private, please do not send it. A redacted directory listing, or a small public example that reproduces the same behaviour, is more useful and safer for both of us.

What never to send

Nothing about diagnosing this plugin requires a credential, and we will never ask you for one. Please do not include, in a message, an attachment or a screenshot:

  • passwords, passphrases or PINs;
  • API keys, access tokens, session cookies or bearer tokens;
  • private keys, certificates, keystores or signing material;
  • .env files, CI secrets or cloud credentials;
  • customer personal data, or confidential source code you are not free to share.

If you believe you have already sent us a secret, rotate it immediately — that is the only reliable remedy — and then tell us, so we can delete the message on our side.

Reporting a security vulnerability

Security reports are handled separately from ordinary support. If you believe you have found a vulnerability in this plugin, in the review script it ships, or in another EcoCitizenz service, report it to support@ecocitizenz.com with security report in the subject line, rather than raising it in a public issue.

A useful security report describes the affected component and version, the conditions needed to reproduce the issue, the impact you observed, and anything you think we would otherwise miss. Please give us a reasonable opportunity to respond before disclosing publicly, where earlier disclosure would create material risk for users.

EcoCitizenz supports good-faith security research. When testing, please do not access customer data unnecessarily, destroy or alter data, disrupt production systems, perform denial-of-service testing, or exploit an issue beyond what is reasonably required to demonstrate it. Those conditions are set out in the security research section of the Terms.

We do not operate a paid bug-bounty programme for this plugin, and this page offers no reward.

Reporting misuse of ECZ-ID material

Misuse is not the same as a vulnerability. If you have seen a copied manifest on an unrelated origin, an impersonated operator, a stale or misleading proof reference, or a page imitating ECZ-ID verification, use the abuse report route. Reports are reviewed. They do not by themselves decide truth or change any credential state.

Source, and the same review elsewhere

The plugin is open source, so you do not have to take any statement on these pages on trust — you can read every line it runs.

  • The published plugin package — manifest, skill and review script.
  • The ECZ-ID plugins page — how to install this and the other ECZ-ID plugins in your agent host.
  • SBOM and CRA guidance — what each evidence class is for, and what the reporting windows ask of you.
  • The same detectors, guidance and Review Priority also ship in the free VS Code extension ECZ-ID SBOM & CRA Readiness, on the Visual Studio Marketplace and Open VSX. That extension is a separate product with its own release cycle; these pages describe the plugin.

What support does not cover

  • We can explain what the review observed and why. We cannot tell you whether your organisation complies with the Cyber Resilience Act or any other regulation, and nothing we send you is legal or regulatory advice.
  • We do not review your evidence documents for you, and the plugin does not read them. Whether your SBOM, VEX or disclosure policy is adequate is a judgement for you and your advisers.
  • No support answer certifies, approves or guarantees a repository, product, organisation or release, and an ELEVATED or HIGH Review Priority does not mean that anything is unsafe or non-compliant.
  • Setup, subscriptions and checkout for paid ECZ-ID credentials happen in TrustOps, not through this plugin. The plugin sells nothing and takes no payment.

Publisher

ECZ-ID SBOM & CRA Readiness is published by EcoCitizenz Ltd, trading as EcoCitizenz, company number 17348848, registered in England and Wales.

66 Paul StreetLondon EC2A 4NAUnited KingdomContact: support@ecocitizenz.com