Petar Radanliev, Kayvan Atefi, Omar Santos, Carsten Maple
• Proposes agentic VEX generation using Agent2Agent and Model Context Protocol • Embeds runtime traceability and exploitability logic in reproducible TRE pipelines • Automates vulnerability filtering and digital signing in SACRO-compliant systems • Supports federated reproducibility and schema validation for VEX artefacts • Enhances AI supply chain assurance with context-aware risk signalling This study presents a framework for automating the generation and validation of machine-readable vulnerability statements, known as Vulnerability-Exploitability Exchange (VEX) artefacts, within secure research environments. The work addresses a critical limitation in existing vulnerability reporting, where static scoring systems often fail to capture whether a flaw is truly exploitable in a specific analytic context. By integrating structured metadata capture, runtime instrumentation, and cryptographically verifiable provenance, the framework classifies vulnerabilities as affected, fixed, or not relevant, supported by machine-readable evidence bundles. The methodology was evaluated using containerised applications seeded with deliberately vulnerable components. Software bill of materials and vulnerability scanners were applied to generate baseline inventories, while reproducibility frameworks validated that results could be independently replicated. Findings demonstrate that automated VEX generation can reduce false positives by distinguishing theoretical from actionable risks, thereby improving security assurance and reproducibility in federated infrastructures. At the same time, the research acknowledges significant challenges. Computational overhead from multi-layered monitoring, dependence on external tools, and the risk of false negatives introduce barriers to adoption. Broader pilot studies across heterogeneous domains and benchmarking on standardised testbeds are required to enhance generalisability. Privacy concerns from extensive runtime monitoring and the need for sustainable maintenance models also demand attention. By combining automation with human oversight and aligning with emerging standards, the study contributes a reproducible, auditable, and context-sensitive approach to vulnerability management. The work provides both a proof-of-concept and a roadmap for refining security practices in sensitive computational environments.