cs.SEJun 16, 2026

Execution-bound advisory automation for agentic AI: a reproducible AIBOM-driven CSAF-VEX framework

Authors: Petar RadanlievOmar SantosCarsten MapleKay Atefi

Organizations: Department of Computer Sciences, University of Oxford, Wolfson Building, Parks Rd, Oxford OX1 3QG · The Alan Turing Institute, British Library, 96 Euston Rd., London NW1 2DB · Cisco Systems, RTP, North Carolina, United States · University of Warwick – WMG, 6 Lord Bhattacharyya Way, Coventry CV4 7AL · Department of Computer Science, School of Digital & Physical Sciences, Faculty of science and Engineering, University of Hull

Abstract

A protocol driven framework is presented that binds SBOM and AIBOM artefacts to deterministic environment capture and structured runtime telemetry. Exploitability is computed from declared artefacts, observed activation conditions, and enforced execution policies. CSAF VEX advisories are generated from combined static and runtime evidence, cryptographically signed, and validated through deterministic replay. Evaluation uses approximately 10000 component entries across synthetic Agentic AI workloads 50 to 5000 components, incorporating OSV, GitHub Advisory, KEV, and EPSS datasets.

Explore similar work

CardsList