# ChainRisk Lens: AI-Powered Software Supply-Chain Investigation from SBOMs

> Source: <https://dev.to/jijo-007/chainrisk-lens-ai-powered-software-supply-chain-investigation-from-sboms-57b9>
> Published: 2026-10-02 17:26:45+00:00

*This is a submission for the [Hacktoberfest Weekend Challenge: Build for a Friend](https://dev.to/challenges/hacktoberfest-weekend-2026-10-01)*

I built **ChainRisk Lens**, an open-source AI-assisted software supply-chain investigation tool.

I built it for a friend who works with software dependencies and needs a simpler way to answer:

**“If this dependency is compromised, what could be affected?”**

ChainRisk Lens takes a CycloneDX SBOM, builds a deterministic dependency graph, calculates potential downstream impact, traces dependency paths, and uses an open-weight AI model to explain and investigate the evidence.

The key idea is simple: **deterministic analysis produces the security evidence; AI explains and investigates it.**

**Repository:** [https://github.com/jijo-OO7/ChainRisk-Lens](https://github.com/jijo-OO7/ChainRisk-Lens)

Example:

```
chainrisk-lens investigate \
  testdata/minimal-cyclonedx.json \
  --target library@2.3.4 \
  --model gemma4:e2b \
  --question "What could be affected if this component is compromised?"

Code
ChainRisk Lens on GitHub
The core pipeline is:
CycloneDX SBOM
      ↓
Parser / Normalization
      ↓
Dependency Graph
      ↓
Deterministic Impact Analysis
      ↓
Investigation Evidence
      ↓
Open-Weight AI
      ↓
Human / JSON Report
```

ChainRisk Lens is written in Go and uses a standard-library-only core.

For AI investigation, I integrated Ollama and designed the model layer to remain provider/model agnostic. The project's default model is Gemma, while other Ollama-compatible models can be selected through --model.

The deterministic layer handles:

Open-weight AI makes it possible to run the investigation locally rather than requiring users to send their software supply-chain data to a proprietary AI API.

It also keeps the architecture flexible: the deterministic analysis does not depend on a particular model, and users can choose an Ollama-compatible model appropriate for their environment.

For supply-chain security, keeping control over where dependency information is processed is an important part of the design.

Prize Categories
