Model Download User
open-edge-platform/edge-ai-libraries
Download and convert AI models using the Model Download microservice.
Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…
$ npx skills add cdxgen/cdxgen --skill ai-bom -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install cdxgen/cdxgen ai-bom --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude-plugin/skills/ai-bom .claude/skills/ai-bom && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ai-bom" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/ai-bom into .claude/skills/ai-bom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-bom", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/ai-bomType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add cdxgen/cdxgen --skill ai-bom -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install cdxgen/cdxgen ai-bom --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .agents/skills && cp -r skills-src/claude-plugin/skills/ai-bom .agents/skills/ai-bom && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ai-bom" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/ai-bom into .agents/skills/ai-bom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-bom", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cdxgen/cdxgen --skill ai-bom -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install cdxgen/cdxgen ai-bom --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/claude-plugin/skills/ai-bom .cursor/skills/ai-bom && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ai-bom" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/ai-bom into .cursor/skills/ai-bom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-bom", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/cdxgen/cdxgen.git --path claude-plugin/skills/ai-bom--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add cdxgen/cdxgen --skill ai-bom -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install cdxgen/cdxgen ai-bom --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/claude-plugin/skills/ai-bom .gemini/skills/ai-bom && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ai-bom" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/ai-bom into .gemini/skills/ai-bom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-bom", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install cdxgen/cdxgen ai-bomInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add cdxgen/cdxgen --skill ai-bom -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .github/skills && cp -r skills-src/claude-plugin/skills/ai-bom .github/skills/ai-bom && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ai-bom" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/ai-bom into .github/skills/ai-bom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-bom", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cdxgen/cdxgen --skill ai-bom -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install cdxgen/cdxgen ai-bom --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/claude-plugin/skills/ai-bom .opencode/skills/ai-bom && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ai-bom" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/ai-bom into .opencode/skills/ai-bom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-bom", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ai-bomGenerates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…
AI Bom is an agent skill from cdxgen/cdxgen. Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their tools/prompts/resources, agent instruction files, and cdx:ai:codegen provenance signals, then audits them with AI-focused rule packs. Use when asked to inventory AI or ML usage, catalog MCP servers, audit agent instruction or skill files, assess AI supply-chain risk, or detect AI-generated code authorship.
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Agent Workflows, covering Agent instruction files, MCP servers and Model hubs and datasets. It works with Model Context Protocol and Hugging Face. The repository describes itself as: Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with…. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit e256966. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
jqFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
huggingface.coAlso links to:
cdxgen.github.ioFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
AI Bom loads about 2.5k tokens when it runs. Until then it costs about 125 tokens; SKILL.md has 809 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from cdxgen/cdxgen at commit e256966, republished under its Apache-2.0 licence (© cdxgen). 809 words, ~2,463 tokens.
.claude/skills/ai-bom/SKILL.md (or your agent's skills folder).Four related but distinct concerns. Pick the right one before reaching for flags — conflating them produces a document that answers the wrong question.
| Question | Project type |
|---|---|
| What models and inference services does this use? | ai / aibom / ai-bom |
| What MCP servers, tools, and configs does this ship? | mcp |
| What agent instruction and skill files does it ship? | ai-skill / skill / skills |
| Was this code written with AI assistance? | ai-provenance / ai-authorship / aicode / ai-codegen |
Read reference/safety.md first. The review-before-sharing rule is especially relevant here: AI and MCP inventory is one of the categories most likely to contain credential-bearing configuration.
aibom /absolute/path/to/projectOr explicitly, with the audit pack:
cdxgen -r --include-formulation \
-o /absolute/path/to/aibom.json \
--bom-audit --bom-audit-categories ai-bom \
/absolute/path/to/project--include-formulation matters here: it moves the AI and agentic inventory into
the standard CycloneDX formulation[] section so downstream tools consume it as
formal formulation data rather than ad-hoc top-level enrichment. Prefer it.
aibom accepts a model reference rather than a project directory:
aibom pkg:huggingface/deepseek-ai/DeepSeek-R1-Distill-Qwen-7B
aibom https://huggingface.co/deepseek-ai/DeepSeek-R1-Distill-Qwen-7B
aibom /absolute/path/to/Modelfile
aibom /absolute/path/to/model.ggufHugging Face model repositories get proper
pkg:huggingface/<namespace>/<name>@<revision> purls when a compliant
repository reference is available. When remote resolution is enabled, cdxgen
follows the revision-aware Hub endpoints, so explicit purl revisions, remote
popularity/runtime hints, and Space-linked model/dataset relationships are
preserved instead of collapsing to an unversioned HEAD lookup. Datasets
referenced by model cards get reusable dataset component references with their
own Hugging Face purls.
cdxgen --profile ml-tiny -o /absolute/path/to/bom.json /absolute/path/to/projectml / machine-learning, ml-deep / deep-learning, and ml-tiny trade
depth against runtime. Start with ml and escalate only if the inventory is
thin.
| Category | Checks |
|---|---|
ai-bom | Umbrella pack for AI-BOM review |
ai-security | Security posture of AI services and model usage |
ai-governance | Governance and policy conformance |
ai-performance | Performance-relevant model and runtime findings |
ai-inventory | Alias enabling both ai-agent and mcp-server |
cdxgen -t mcp /absolute/path/to/project \
-o /absolute/path/to/bom.json \
--bom-audit --bom-audit-categories mcp-serverBy default a plain -t js scan also reports shipped MCP configuration files
and AI instruction/skill files, because both can influence build and post-build
lifecycles. Control that overlay:
--exclude-type mcp drops MCP config components, discovered services, and MCP primitives. Genuine MCP SDK dependency packages (@modelcontextprotocol/*, PyPI mcp, io.modelcontextprotocol.sdk) are real supply-chain components and are always retained.--exclude-type ai-skill drops AI skill and instruction inventory.-t mcp produces an exact MCP-focused BOM: SDK packages, discovered services, primitives, and config files such as .vscode/mcp.json.components for MCP SDK packagesservices for discovered MCP serversdependencies links from a server service to the primitives it exposesConfig formats recognised include .vscode/mcp.json, .mcp.json,
claude_desktop_config.json, and opencode.json. Community agent layouts are
covered too: OpenCode, Nanocoder, LangGraph, and common CrewAI project files.
# discovered servers
jq '.services[]' /absolute/path/to/bom.json
# MCP primitives
jq '.components[] | select(.properties[]?.name == "cdx:mcp:role")' /absolute/path/to/bom.json
# shipped MCP config files
jq '.components[] | select(.properties[]?.value == "mcp-config")' /absolute/path/to/bom.json
# service-to-primitive links
jq '.dependencies[] | select(.ref | startswith("urn:service:mcp:"))' /absolute/path/to/bom.json
# audit findings
jq '.annotations[]' /absolute/path/to/bom.jsonKey property namespaces: cdx:mcp:serviceType, cdx:mcp:transport,
cdx:mcp:exposureType, cdx:mcp:authPosture, cdx:mcp:trustProfile,
cdx:mcp:credentialExposure, cdx:mcp:reviewNeeded,
cdx:mcp:security:confusedDeputyRisk, cdx:mcp:security:tokenPassthroughRisk.
Escalate these:
The analysis is deliberately conservative — it prefers literal, explainable signals over speculative reconstruction. So a clean result is not proof of absence. Dynamically generated tool names, endpoints, and capability objects can be missed, and provider/model detection only records explicit literals.
Keep and flag the files:
cdxgen -t js --bom-audit \
--bom-audit-categories mcp-server,ai-agent \
--tlp-classification AMBER \
-o /absolute/path/to/bom.json /absolute/path/to/repoDrop them for a package-only SBOM:
cdxgen -t js --exclude-type ai-skill --exclude-type mcp \
-o /absolute/path/to/bom.json /absolute/path/to/repo--experimental-mcp-pinning (or CDXGEN_EXPERIMENTAL_MCP_PINNING=true), off by
default, records an explicit cdx:mcp:pinning state — pinned, unpinned, or
unhashable — plus cdx:mcp:composition=unknown for remote servers with no
local package. The point is that absence is labelled rather than implied.
These property names are subject to change until the CycloneDX agent-BOM proposal is ratified. Do not build durable tooling on them; tell the user they are experimental if you enable the flag.
cdxgen -t ai-skill /absolute/path/to/project -o /absolute/path/to/bom.json \
--bom-audit --bom-audit-categories ai-agentCovers CLAUDE.md, AGENTS.md, SKILL.md,
.github/copilot-instructions.md, .github/workflows/copilot-setup-steps.yml,
.opencode/**, .nanocoder/**, langgraph.json, and CrewAI files. Properties
land under cdx:agent:*, cdx:tool:*, cdx:skill:*, cdx:langgraph:*, and
cdx:crewai:*.
A different concern entirely: this is a generation-time property injector over git history and CI configuration. It does not inventory MCP servers or models.
cdxgen -t ai-provenance -o /absolute/path/to/bom.json /absolute/path/to/projectSignals land in the BOM document root properties as cdx:ai:codegen:* and
cdx:ai:oversight:*.
Detection is enabled by default in cdx-audit, since all rule categories
run by default:
cdx-audit --bom /absolute/path/to/bom.json --direct-bom-audit
cdx-audit --bom /absolute/path/to/bom.json --direct-bom-audit --categories ai-provenance
cdx-audit --bom /absolute/path/to/bom.json --direct-bom-audit --no-ai-provenanceIf the BOM already carries cdx:ai:codegen:* properties, cdx-audit reuses
them; otherwise it scans the working directory and injects them before
evaluating rules.
The ai-provenance category enables both ai-provenance and ai-oversight.
The oversight rules evaluate whether AI-assisted code was merged with adequate
independent human review, and detect rubber-stamping or quality-gate bypassing.
Treat the output as a signal for a conversation, not a verdict about a person.
In cdxi (see bom-explore): .aibom, .services, .formulation,
.provenance, .auditfindings.
© cdxgen, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in claude-plugin/skills/ai-bom of cdxgen/cdxgen.
Open the folder on GitHubat commit e256966
AI Bom next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| AI Bom this skillcdxgen/cdxgen | 1.1k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | |
| Model Download Useropen-edge-platform/edge-ai-libraries | 169 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | |
| Generate Openenv Envadithya-s-k/FineEnvs | 456 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| Hf MCPhuggingface/skills | 11k | 2 repos | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Chatgpt AppsHaohao-end/openagent | 808 | 1 repos | ~4.9k | Automated safety check: Pass | Apache-2.0 | |
| Clawmemyoloshii/ClawMem | 210 | — | ~7.5k | Automated safety check: Pass | MIT |
open-edge-platform/edge-ai-libraries
Download and convert AI models using the Model Download microservice.
adithya-s-k/FineEnvs
Builds an OpenEnv (Hugging Face) variant of an RL environment.
huggingface/skills
Use Hugging Face Hub via MCP server tools. An agent skill from huggingface/skills.
Haohao-end/openagent
Build, scaffold, refactor, and troubleshoot ChatGPT Apps SDK applications that combine an MCP server and widget UI.
yoloshii/ClawMem
ClawMem operational reference for agents at query time — the 3-rule escalation gate, MCP tool routing, the 4 query-optimization levers, pipeline behavior (query vs intentsearch), composite scoring…
Chorus-AIDLC/Chorus
OpenSpec-mode authoring for Chorus PM workflows in Hermes. An agent skill from Chorus-AIDLC/Chorus.
cdxgen/cdxgen
Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…
cdxgen/cdxgen
Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…
cdxgen/cdxgen
Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…
cdxgen/cdxgen
Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures…
cdxgen/cdxgen
Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…
cdxgen/cdxgen
Reviews a codebase's direct dependencies and designs lightweight, low-risk, zero-dependency custom replacements using cdxgen SBOM evidence, occurrence/callstack usage data, and license and…
Works with
Categories
Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…. AI Bom is an agent skill from cdxgen/cdxgen. Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their tools/prompts/resources, agent instruction files, and cdx:ai:codegen provenance signals, then audits them with AI-focused rule packs.
AI Bom fits situations like: asked to inventory AI; catalog MCP servers; audit agent instruction; assess AI supply-chain risk.
Run `npx skills add cdxgen/cdxgen --skill ai-bom -a claude-code`. Or copy the skill folder (claude-plugin/skills/ai-bom in cdxgen/cdxgen) into .claude/skills/ai-bom in your project. Claude Code loads it when a task matches its description.
Run `npx skills add cdxgen/cdxgen --skill ai-bom -a codex`. Or copy the skill folder (claude-plugin/skills/ai-bom in cdxgen/cdxgen) into .agents/skills/ai-bom in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cdxgen/cdxgen --skill ai-bom -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ai-bom, .gemini/skills/ai-bom, .github/skills/ai-bom and .opencode/skills/ai-bom in your project.
Going by SKILL.md and its folder, AI Bom needs the command-line tools its instructions call (jq).
SKILL.md names 2 domains. In commands or code: huggingface.co; the agent is likely to contact it when it follows the instructions. As links in the text: cdxgen.github.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
AI Bom is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with AI Bom: Model Download User (open-edge-platform/edge-ai-libraries, 169 stars), Generate Openenv Env (adithya-s-k/FineEnvs, 456 stars), Hf MCP (huggingface/skills, 11k stars) and Chatgpt Apps (Haohao-end/openagent, 808 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
cdxgen (a GitHub organization) maintains it in cdxgen/cdxgen, which has 1,085 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 8, 2026.
Source: cdxgen/cdxgen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.