Agent skill

Sbom Generate

by 686f6c61 in 686f6c61/alfred-dev

Usar para generar Software Bill of Materials para cumplimiento del CRA.

MITAuto-check passedSecurity

Install Sbom Generate

skills CLI
$ npx skills add 686f6c61/alfred-dev --skill sbom-generate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install 686f6c61/alfred-dev sbom-generate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/686f6c61/alfred-dev.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sbom-generate .claude/skills/sbom-generate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sbom-generate
GitHub stars
117
Token cost
~780 tokens
SKILL.md length
379 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Usar para generar Software Bill of Materials para cumplimiento del CRA.

  • Works in 7 steps: Detectar el ecosistema y las fuentes de… → Listar dependencias directas. Para cada… → Listar dependencias transitivas. Repetir… → …
  • Tasks that involve Supply chain security
  • SKILL.md covers Resumen, Proceso and Criterios de éxito
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Sbom Generate is an agent skill from 686f6c61/alfred-dev. Usar para generar Software Bill of Materials para cumplimiento del CRA. También: Software Bill of Materials, inventario de componentes, CycloneDX, SPDX, cadena de suministro.

Its SKILL.md is about 780 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Supply chain security and Regulatory compliance. The repository describes itself as: Tu equipo de desarrolladores en un plugin. 10 agentes, 11 skills planas, 18 comandos /alfred-dev:. Memoria persistente, quality gates con evidencia y MCP local. The licence is MIT.

When your agent uses it

  • Tasks that involve Supply chain security
  • Tasks that involve Regulatory compliance

Example prompts

  • “/sbom-generate”

Requirements

  • Node.js
  • Docker

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Detectar el ecosistema y las fuentes de dependencias. Identificar todos los ficheros de lock o manifiesto del proyecto
  2. Listar dependencias directas. Para cada dependencia directa, registrar
  3. Listar dependencias transitivas. Repetir el mismo proceso para todas las dependencias de las dependencias. Las transitivas suelen ser la…
  4. Incluir componentes no gestionados por paquetes. Algunos componentes se incluyen de forma manual
  5. Generar en formato estándar. Usar uno de los dos formatos aceptados por la industria
  6. Verificar completitud. Cruzar el SBOM generado con el lock file para asegurar que no falta ninguna dependencia. Verificar que todas las…
  7. Firmar o versionar el SBOM. Asociar el SBOM a una versión concreta del software (tag de Git, versión del paquete). El SBOM debe…

What it can do on your machine

Read from SKILL.md and the folder at commit be0b51e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sbom Generate loads about 780 tokens when it runs. Until then it costs about 47 tokens; SKILL.md has 379 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~47
When it runs · the whole SKILL.md, loaded when a task matches
~780

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from 686f6c61/alfred-dev at commit be0b51e, republished under its MIT licence (© 686f6c61). 379 words, ~780 tokens.

Download SKILL.mdSave it as .claude/skills/sbom-generate/SKILL.md (or your agent's skills folder).
name
sbom-generate
description
Usar para generar Software Bill of Materials para cumplimiento del CRA. También: Software Bill of Materials, inventario de componentes, CycloneDX, SPDX, cadena de suministro.

Generar SBOM (Software Bill of Materials)

Resumen

Este skill genera un inventario completo de todos los componentes de software incluidos en el proyecto, tanto dependencias directas como transitivas. El SBOM es un requisito del Cyber Resilience Act (CRA) europeo y una práctica recomendada de seguridad de la cadena de suministro.

El SBOM permite responder rápidamente a preguntas como "usamos la versión afectada por esta vulnerabilidad?" sin necesidad de investigar manualmente cada proyecto.

Proceso

  1. Detectar el ecosistema y las fuentes de dependencias. Identificar todos los ficheros de lock o manifiesto del proyecto:

    • Node.js: package-lock.json, yarn.lock, pnpm-lock.yaml.
    • Python: requirements.txt, Pipfile.lock, poetry.lock.
    • Rust: Cargo.lock.
    • Go: go.sum.
    • Java: pom.xml, build.gradle.
    • PHP: composer.lock.
  2. Listar dependencias directas. Para cada dependencia directa, registrar:

    • Nombre del paquete.
    • Versión exacta instalada.
    • Licencia.
    • Proveedor o autor.
    • URL del repositorio.
    • Hash de verificación (si está disponible en el lock file).
  3. Listar dependencias transitivas. Repetir el mismo proceso para todas las dependencias de las dependencias. Las transitivas suelen ser la mayoría y las más difíciles de rastrear.

  4. Incluir componentes no gestionados por paquetes. Algunos componentes se incluyen de forma manual:

    • Librerías copiadas directamente (vendoring).
    • Scripts de terceros incluidos vía CDN.
    • Binarios precompilados.
    • Componentes del sistema operativo base (especialmente relevante en contenedores Docker).
  5. Generar en formato estándar. Usar uno de los dos formatos aceptados por la industria:

    • CycloneDX: formato JSON o XML, preferido por OWASP. Más ligero y centrado en seguridad.
    • SPDX: formato estándar ISO (ISO/IEC 5962:2021). Más completo en información de licencias.

    Si existen herramientas automáticas para el ecosistema (como cyclonedx-npm, syft, cdxgen), usarlas. Si no, generar manualmente con la plantilla templates/sbom.md.

  6. Verificar completitud. Cruzar el SBOM generado con el lock file para asegurar que no falta ninguna dependencia. Verificar que todas las licencias están identificadas (ninguna como "desconocida").

  7. Firmar o versionar el SBOM. Asociar el SBOM a una versión concreta del software (tag de Git, versión del paquete). El SBOM debe regenerarse con cada release.

Show full SKILL.md (58 more words)Show less

Criterios de éxito

  • El SBOM incluye todas las dependencias directas y transitivas.
  • Cada componente tiene: nombre, versión, licencia, proveedor y hash.
  • El formato es compatible con CycloneDX o SPDX.
  • No hay licencias marcadas como "desconocida" sin justificación.
  • El SBOM está asociado a una versión concreta del software.
  • Se ha verificado la completitud contra el lock file del proyecto.

© 686f6c61, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/sbom-generate of 686f6c61/alfred-dev.

Open the folder on GitHubat commit be0b51e

Compare with similar skills

Sbom Generate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sbom Generate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sbom Generate this skill686f6c61/alfred-dev117—~780Automated safety check: PassMIT
Bom Convert Validatecdxgen/cdxgen1.1k—~1.5kAutomated safety check: WarnApache-2.0
Codebase Cleanup Deps Auditaiskillstore/marketplace4307 repos~490Automated safety check: PassNone
Open Source PolicyHack23/cia239—~4.6kAutomated safety check: PassApache-2.0
Dependency AuditMathews-Tom/armory328—~2.7kAutomated safety check: PassMIT
Oss Reviewzhou210712/claude-for-legal-ZH225—~2kAutomated safety check: PassApache-2.0

Similar skills

  • Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check: warnings
  • Codebase Cleanup Deps Audit

    aiskillstore/marketplace

    You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security.

    430 GitHub starsUsed in 7 repos~490 tokens
    SecurityAuto-check passed
  • Open source governance, security posture badges, license compliance, SBOM generation, and vulnerability management for transparency-driven development

    239 GitHub stars~4.6k tokensUpdated today
    SecurityAuto-check passed
  • Dependency Audit

    Mathews-Tom/armory

    Audits direct and transitive dependencies for license compliance, maintenance health, CVEs, abandoned packages, and bloat.

    328 GitHub stars~2.7k tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Oss Review

    zhou210712/claude-for-legal-ZH

    开源许可证合规检查——对依赖列表、单个库或对外发布代码. An agent skill from zhou210712/claude-for-legal-ZH.

    225 GitHub stars~2k tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Oss Review

    anthropics/claude-for-legal

    Official

    Open source license compliance check for a dependency list, a single library, or outbound code.

    9.6k GitHub starsUsed in 3 repos~5k tokens
    Legal & ComplianceAuto-check passed

More from 686f6c61/alfred-dev

All 11 skills in this repo
  • Incident Response

    686f6c61/alfred-dev

    Protocolo de respuesta ante incidentes en produccion: triaje, mitigacion, causa raiz y postmortem.

    117 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Memory

    686f6c61/alfred-dev

    This skill should be used when the user asks to record a design decision, search past project decisions, inspect the Alfred memory timeline, or work with the alfred-memory MCP server.

    117 GitHub stars~601 tokensUpdated 1 mo ago
    Auto-check passed
  • PR Workflow

    686f6c61/alfred-dev

    Crear pull requests completas con descripcion, labels y reviewers

    117 GitHub stars~777 tokensUpdated 1 mo ago
    Auto-check passed
  • Sonarqube

    686f6c61/alfred-dev

    Levantar SonarQube con Docker, analizar el código y proponer mejoras.

    117 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check: notes
  • Style Direction

    686f6c61/alfred-dev

    Abrir y operar el companion visual de Selina para elegir una direccion de estilo en proyectos con interfaz.

    117 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Sync Project Docs

    686f6c61/alfred-dev

    Usar para sincronizar la documentación viva del proyecto después de una fase.

    117 GitHub stars~382 tokensUpdated 1 mo ago
    Auto-check passed

Questions about Sbom Generate

What does Sbom Generate do?

Usar para generar Software Bill of Materials para cumplimiento del CRA. Sbom Generate is an agent skill from 686f6c61/alfred-dev. Usar para generar Software Bill of Materials para cumplimiento del CRA.

When should I use Sbom Generate?

Sbom Generate fits situations like: tasks that involve Supply chain security; tasks that involve Regulatory compliance.

How do I install Sbom Generate in Claude Code?

Run `npx skills add 686f6c61/alfred-dev --skill sbom-generate -a claude-code`. Or copy the skill folder (skills/sbom-generate in 686f6c61/alfred-dev) into .claude/skills/sbom-generate in your project. Claude Code loads it when a task matches its description.

How do I install Sbom Generate in Codex?

Run `npx skills add 686f6c61/alfred-dev --skill sbom-generate -a codex`. Or copy the skill folder (skills/sbom-generate in 686f6c61/alfred-dev) into .agents/skills/sbom-generate in your project. Codex loads it when a task matches its description.

Can I use Sbom Generate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add 686f6c61/alfred-dev --skill sbom-generate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sbom-generate, .gemini/skills/sbom-generate, .github/skills/sbom-generate and .opencode/skills/sbom-generate in your project.

What does Sbom Generate need to run?

SKILL.md names no scripts, command-line tools or credentials: Sbom Generate is instructions for the agent only. Our summary lists: Node.js; Docker.

Does Sbom Generate access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Sbom Generate safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sbom Generate use?

Sbom Generate is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sbom Generate use?

About 780 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sbom Generate?

Skills that share tags, products or a category with Sbom Generate: Bom Convert Validate (cdxgen/cdxgen, 1.1k stars), Codebase Cleanup Deps Audit (aiskillstore/marketplace, 430 stars), Open Source Policy (Hack23/cia, 239 stars) and Dependency Audit (Mathews-Tom/armory, 328 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sbom Generate?

686f6c61 (a GitHub user) maintains it in 686f6c61/alfred-dev, which has 117 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on August 15, 2026.

Source: 686f6c61/alfred-dev on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.