Agent skill

AI Bom

by cdxgen in cdxgen/cdxgen

Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…

Apache-2.0Auto-check passedAgent Workflows

Install AI Bom

skills CLI
$ npx skills add cdxgen/cdxgen --skill ai-bom -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cdxgen/cdxgen ai-bom --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude-plugin/skills/ai-bom .claude/skills/ai-bom && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ai-bom
GitHub stars
1.1k
Token cost
~2.5k tokens
SKILL.md length
809 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
Apache-2.0

At a glance

Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…

  • Asked to inventory AI
  • SKILL.md covers AI-BOM: models and inference…, MCP inventory, AI skill and instruction… and AI authorship provenance, plus 2 more sections
  • Calls jq; reaches huggingface.co
  • Catalog MCP servers

What it does

AI Bom is an agent skill from cdxgen/cdxgen. Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their tools/prompts/resources, agent instruction files, and cdx:ai:codegen provenance signals, then audits them with AI-focused rule packs. Use when asked to inventory AI or ML usage, catalog MCP servers, audit agent instruction or skill files, assess AI supply-chain risk, or detect AI-generated code authorship.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering Agent instruction files, MCP servers and Model hubs and datasets. It works with Model Context Protocol and Hugging Face. The repository describes itself as: Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with…. The licence is Apache-2.0.

When your agent uses it

  • Asked to inventory AI
  • Catalog MCP servers
  • Audit agent instruction
  • Assess AI supply-chain risk

Example prompts

  • “Use the ai-bom skill to generate AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models…”
  • “/ai-bom”

What it can do on your machine

Read from SKILL.md and the folder at commit e256966. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • huggingface.co

    Also links to:

    • cdxgen.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AI Bom loads about 2.5k tokens when it runs. Until then it costs about 125 tokens; SKILL.md has 809 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~125
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cdxgen/cdxgen at commit e256966, republished under its Apache-2.0 licence (© cdxgen). 809 words, ~2,463 tokens.

Download SKILL.mdSave it as .claude/skills/ai-bom/SKILL.md (or your agent's skills folder).
name
ai-bom
description
Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their tools/prompts/resources, agent instruction files, and cdx:ai:codegen provenance signals, then audits them with AI-focused rule packs. Use when asked to inventory AI or ML usage, catalog MCP servers, audit agent instruction or skill files, assess AI supply-chain risk, or detect AI-generated code authorship.

AI-BOM, MCP inventory, and AI provenance

Four related but distinct concerns. Pick the right one before reaching for flags — conflating them produces a document that answers the wrong question.

QuestionProject type
What models and inference services does this use?ai / aibom / ai-bom
What MCP servers, tools, and configs does this ship?mcp
What agent instruction and skill files does it ship?ai-skill / skill / skills
Was this code written with AI assistance?ai-provenance / ai-authorship / aicode / ai-codegen

Read reference/safety.md first. The review-before-sharing rule is especially relevant here: AI and MCP inventory is one of the categories most likely to contain credential-bearing configuration.

AI-BOM: models and inference services

bash
aibom /absolute/path/to/project

Or explicitly, with the audit pack:

bash
cdxgen -r --include-formulation \
  -o /absolute/path/to/aibom.json \
  --bom-audit --bom-audit-categories ai-bom \
  /absolute/path/to/project

--include-formulation matters here: it moves the AI and agentic inventory into the standard CycloneDX formulation[] section so downstream tools consume it as formal formulation data rather than ad-hoc top-level enrichment. Prefer it.

Direct model targets

aibom accepts a model reference rather than a project directory:

bash
aibom pkg:huggingface/deepseek-ai/DeepSeek-R1-Distill-Qwen-7B
aibom https://huggingface.co/deepseek-ai/DeepSeek-R1-Distill-Qwen-7B
aibom /absolute/path/to/Modelfile
aibom /absolute/path/to/model.gguf

Hugging Face model repositories get proper pkg:huggingface/<namespace>/<name>@<revision> purls when a compliant repository reference is available. When remote resolution is enabled, cdxgen follows the revision-aware Hub endpoints, so explicit purl revisions, remote popularity/runtime hints, and Space-linked model/dataset relationships are preserved instead of collapsing to an unversioned HEAD lookup. Datasets referenced by model cards get reusable dataset component references with their own Hugging Face purls.

ML depth profiles
bash
cdxgen --profile ml-tiny -o /absolute/path/to/bom.json /absolute/path/to/project

ml / machine-learning, ml-deep / deep-learning, and ml-tiny trade depth against runtime. Start with ml and escalate only if the inventory is thin.

AI audit categories
CategoryChecks
ai-bomUmbrella pack for AI-BOM review
ai-securitySecurity posture of AI services and model usage
ai-governanceGovernance and policy conformance
ai-performancePerformance-relevant model and runtime findings
ai-inventoryAlias enabling both ai-agent and mcp-server

MCP inventory

bash
cdxgen -t mcp /absolute/path/to/project \
  -o /absolute/path/to/bom.json \
  --bom-audit --bom-audit-categories mcp-server

By default a plain -t js scan also reports shipped MCP configuration files and AI instruction/skill files, because both can influence build and post-build lifecycles. Control that overlay:

  • --exclude-type mcp drops MCP config components, discovered services, and MCP primitives. Genuine MCP SDK dependency packages (@modelcontextprotocol/*, PyPI mcp, io.modelcontextprotocol.sdk) are real supply-chain components and are always retained.
  • --exclude-type ai-skill drops AI skill and instruction inventory.
  • -t mcp produces an exact MCP-focused BOM: SDK packages, discovered services, primitives, and config files such as .vscode/mcp.json.
What the MCP inventory contains
  • components for MCP SDK packages
  • services for discovered MCP servers
  • synthetic components for MCP primitives: tools, prompts, resources, resource templates
  • dependencies links from a server service to the primitives it exposes

Config formats recognised include .vscode/mcp.json, .mcp.json, claude_desktop_config.json, and opencode.json. Community agent layouts are covered too: OpenCode, Nanocoder, LangGraph, and common CrewAI project files.

Inspecting an MCP BOM
bash
# discovered servers
jq '.services[]' /absolute/path/to/bom.json

# MCP primitives
jq '.components[] | select(.properties[]?.name == "cdx:mcp:role")' /absolute/path/to/bom.json

# shipped MCP config files
jq '.components[] | select(.properties[]?.value == "mcp-config")' /absolute/path/to/bom.json

# service-to-primitive links
jq '.dependencies[] | select(.ref | startswith("urn:service:mcp:"))' /absolute/path/to/bom.json

# audit findings
jq '.annotations[]' /absolute/path/to/bom.json

Key property namespaces: cdx:mcp:serviceType, cdx:mcp:transport, cdx:mcp:exposureType, cdx:mcp:authPosture, cdx:mcp:trustProfile, cdx:mcp:credentialExposure, cdx:mcp:reviewNeeded, cdx:mcp:security:confusedDeputyRisk, cdx:mcp:security:tokenPassthroughRisk.

Show full SKILL.md (368 more words)Show less
The MCP findings that matter most

Escalate these:

  • unauthenticated Streamable HTTP MCP servers, and unauthenticated tool exposure
  • network-exposed servers built on non-official SDKs or wrappers
  • networked endpoints discovered only from configuration files
  • inline credentials or token-forwarding settings in MCP configs
  • dynamic client registration paired with static client identities
  • public or tunneled endpoints referenced only from AI agent files
  • hidden Unicode in agent instruction and skill files
  • agent-file MCP references not otherwise declared in package or source inventory

The analysis is deliberately conservative — it prefers literal, explainable signals over speculative reconstruction. So a clean result is not proof of absence. Dynamically generated tool names, endpoints, and capability objects can be missed, and provider/model detection only records explicit literals.

Release-review pattern

Keep and flag the files:

bash
cdxgen -t js --bom-audit \
  --bom-audit-categories mcp-server,ai-agent \
  --tlp-classification AMBER \
  -o /absolute/path/to/bom.json /absolute/path/to/repo

Drop them for a package-only SBOM:

bash
cdxgen -t js --exclude-type ai-skill --exclude-type mcp \
  -o /absolute/path/to/bom.json /absolute/path/to/repo
Experimental MCP pinning

--experimental-mcp-pinning (or CDXGEN_EXPERIMENTAL_MCP_PINNING=true), off by default, records an explicit cdx:mcp:pinning state — pinned, unpinned, or unhashable — plus cdx:mcp:composition=unknown for remote servers with no local package. The point is that absence is labelled rather than implied.

These property names are subject to change until the CycloneDX agent-BOM proposal is ratified. Do not build durable tooling on them; tell the user they are experimental if you enable the flag.

AI skill and instruction inventory

bash
cdxgen -t ai-skill /absolute/path/to/project -o /absolute/path/to/bom.json \
  --bom-audit --bom-audit-categories ai-agent

Covers CLAUDE.md, AGENTS.md, SKILL.md, .github/copilot-instructions.md, .github/workflows/copilot-setup-steps.yml, .opencode/**, .nanocoder/**, langgraph.json, and CrewAI files. Properties land under cdx:agent:*, cdx:tool:*, cdx:skill:*, cdx:langgraph:*, and cdx:crewai:*.

AI authorship provenance

A different concern entirely: this is a generation-time property injector over git history and CI configuration. It does not inventory MCP servers or models.

bash
cdxgen -t ai-provenance -o /absolute/path/to/bom.json /absolute/path/to/project

Signals land in the BOM document root properties as cdx:ai:codegen:* and cdx:ai:oversight:*.

Detection is enabled by default in cdx-audit, since all rule categories run by default:

bash
cdx-audit --bom /absolute/path/to/bom.json --direct-bom-audit
cdx-audit --bom /absolute/path/to/bom.json --direct-bom-audit --categories ai-provenance
cdx-audit --bom /absolute/path/to/bom.json --direct-bom-audit --no-ai-provenance

If the BOM already carries cdx:ai:codegen:* properties, cdx-audit reuses them; otherwise it scans the working directory and injects them before evaluating rules.

The ai-provenance category enables both ai-provenance and ai-oversight. The oversight rules evaluate whether AI-assisted code was merged with adequate independent human review, and detect rubber-stamping or quality-gate bypassing.

Treat the output as a signal for a conversation, not a verdict about a person.

Exploring the result

In cdxi (see bom-explore): .aibom, .services, .formulation, .provenance, .auditfindings.

Reference

© cdxgen, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in claude-plugin/skills/ai-bom of cdxgen/cdxgen.

Open the folder on GitHubat commit e256966

Compare with similar skills

AI Bom next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AI Bom compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AI Bom this skillcdxgen/cdxgen1.1k—~2.5kAutomated safety check: PassApache-2.0
Model Download Useropen-edge-platform/edge-ai-libraries169—~3.8kAutomated safety check: PassApache-2.0
Generate Openenv Envadithya-s-k/FineEnvs456—~2.4kAutomated safety check: PassApache-2.0
Hf MCPhuggingface/skills11k2 repos~1.2kAutomated safety check: PassApache-2.0
Chatgpt AppsHaohao-end/openagent8081 repos~4.9kAutomated safety check: PassApache-2.0
Clawmemyoloshii/ClawMem210—~7.5kAutomated safety check: PassMIT

Similar skills

  • Model Download User

    open-edge-platform/edge-ai-libraries

    Download and convert AI models using the Model Download microservice.

    169 GitHub stars~3.8k tokensUpdated today
    Backend & APIsAuto-check passed
  • Generate Openenv Env

    adithya-s-k/FineEnvs

    Builds an OpenEnv (Hugging Face) variant of an RL environment.

    456 GitHub stars~2.4k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Hf MCP

    huggingface/skills

    Official

    Use Hugging Face Hub via MCP server tools. An agent skill from huggingface/skills.

    11k GitHub starsUsed in 2 repos~1.2k tokens
    AI & LLM EngineeringAuto-check passed
  • Chatgpt Apps

    Haohao-end/openagent

    Build, scaffold, refactor, and troubleshoot ChatGPT Apps SDK applications that combine an MCP server and widget UI.

    808 GitHub starsUsed in 1 repo~4.9k tokens
    Agent WorkflowsAuto-check passed
  • Clawmem

    yoloshii/ClawMem

    ClawMem operational reference for agents at query time — the 3-rule escalation gate, MCP tool routing, the 4 query-optimization levers, pipeline behavior (query vs intentsearch), composite scoring…

    210 GitHub stars~7.5k tokensUpdated 3 days ago
    Agent WorkflowsAuto-check passed
  • Openspec Aware

    Chorus-AIDLC/Chorus

    OpenSpec-mode authoring for Chorus PM workflows in Hermes. An agent skill from Chorus-AIDLC/Chorus.

    1.2k GitHub stars~7.2k tokensUpdated today
    Agent WorkflowsAuto-check: notes

More from cdxgen/cdxgen

All 17 skills in this repo
  • Bom Audit

    cdxgen/cdxgen

    Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…

    1.1k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Bom Evidence

    cdxgen/cdxgen

    Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…

    1.1k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Bom Explore

    cdxgen/cdxgen

    Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…

    1.1k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Bom Signing

    cdxgen/cdxgen

    Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures…

    1.1k GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…

    1.1k GitHub stars~1.5k tokensUpdated today
    Auto-check: warnings
  • Bom Slimmer

    cdxgen/cdxgen

    Reviews a codebase's direct dependencies and designs lightweight, low-risk, zero-dependency custom replacements using cdxgen SBOM evidence, occurrence/callstack usage data, and license and…

    1.1k GitHub stars~1.6k tokensUpdated today
    Auto-check passed

Questions about AI Bom

What does AI Bom do?

Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…. AI Bom is an agent skill from cdxgen/cdxgen. Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their tools/prompts/resources, agent instruction files, and cdx:ai:codegen provenance signals, then audits them with AI-focused rule packs.

When should I use AI Bom?

AI Bom fits situations like: asked to inventory AI; catalog MCP servers; audit agent instruction; assess AI supply-chain risk.

How do I install AI Bom in Claude Code?

Run `npx skills add cdxgen/cdxgen --skill ai-bom -a claude-code`. Or copy the skill folder (claude-plugin/skills/ai-bom in cdxgen/cdxgen) into .claude/skills/ai-bom in your project. Claude Code loads it when a task matches its description.

How do I install AI Bom in Codex?

Run `npx skills add cdxgen/cdxgen --skill ai-bom -a codex`. Or copy the skill folder (claude-plugin/skills/ai-bom in cdxgen/cdxgen) into .agents/skills/ai-bom in your project. Codex loads it when a task matches its description.

Can I use AI Bom in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cdxgen/cdxgen --skill ai-bom -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ai-bom, .gemini/skills/ai-bom, .github/skills/ai-bom and .opencode/skills/ai-bom in your project.

What does AI Bom need to run?

Going by SKILL.md and its folder, AI Bom needs the command-line tools its instructions call (jq).

Does AI Bom access the network?

SKILL.md names 2 domains. In commands or code: huggingface.co; the agent is likely to contact it when it follows the instructions. As links in the text: cdxgen.github.io. This is read from the text; nothing was executed.

Is AI Bom safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does AI Bom use?

AI Bom is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AI Bom use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to AI Bom?

Skills that share tags, products or a category with AI Bom: Model Download User (open-edge-platform/edge-ai-libraries, 169 stars), Generate Openenv Env (adithya-s-k/FineEnvs, 456 stars), Hf MCP (huggingface/skills, 11k stars) and Chatgpt Apps (Haohao-end/openagent, 808 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AI Bom?

cdxgen (a GitHub organization) maintains it in cdxgen/cdxgen, which has 1,085 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 8, 2026.

Source: cdxgen/cdxgen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.