Vex Authoring
relizaio/rearm
Author CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM.
Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…
$ npx skills add cdxgen/cdxgen --skill bom-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install cdxgen/cdxgen bom-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude-plugin/skills/bom-audit .claude/skills/bom-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "bom-audit" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/bom-audit into .claude/skills/bom-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bom-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/bom-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add cdxgen/cdxgen --skill bom-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install cdxgen/cdxgen bom-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .agents/skills && cp -r skills-src/claude-plugin/skills/bom-audit .agents/skills/bom-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "bom-audit" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/bom-audit into .agents/skills/bom-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bom-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cdxgen/cdxgen --skill bom-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install cdxgen/cdxgen bom-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/claude-plugin/skills/bom-audit .cursor/skills/bom-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "bom-audit" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/bom-audit into .cursor/skills/bom-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bom-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/cdxgen/cdxgen.git --path claude-plugin/skills/bom-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add cdxgen/cdxgen --skill bom-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install cdxgen/cdxgen bom-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/claude-plugin/skills/bom-audit .gemini/skills/bom-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "bom-audit" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/bom-audit into .gemini/skills/bom-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bom-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install cdxgen/cdxgen bom-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add cdxgen/cdxgen --skill bom-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .github/skills && cp -r skills-src/claude-plugin/skills/bom-audit .github/skills/bom-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "bom-audit" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/bom-audit into .github/skills/bom-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bom-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cdxgen/cdxgen --skill bom-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install cdxgen/cdxgen bom-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/claude-plugin/skills/bom-audit .opencode/skills/bom-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "bom-audit" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/bom-audit into .opencode/skills/bom-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bom-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
bom-auditRuns supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…
Bom Audit is an agent skill from cdxgen/cdxgen. Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk, dependency source integrity, license policy violations, and SARIF or JSON reporting for code scanning. Use when asked to audit an SBOM, assess supply-chain or dependency risk, check for compromised or malicious packages, triage which dependencies to review first, or produce SARIF from a BOM.
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Supply chain security. It works with npm. The repository describes itself as: Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with…. The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit e256966. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
cdxgen.github.ioFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Bom Audit loads about 2.4k tokens when it runs. Until then it costs about 124 tokens; SKILL.md has 734 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from cdxgen/cdxgen at commit e256966, republished under its Apache-2.0 licence (© cdxgen). 734 words, ~2,410 tokens.
.claude/skills/bom-audit/SKILL.md (or your agent's skills folder).Two distinct mechanisms. Choose deliberately.
| Want | Use |
|---|---|
| Findings embedded while the BOM is generated | cdxgen --bom-audit |
| Analysis of a BOM that already exists | cdx-audit |
| Forward-looking review prioritization for npm/PyPI | cdx-audit (predictive) |
| Rule evaluation against the supplied BOM itself | cdx-audit --direct-bom-audit |
Read reference/safety.md first. Predictive auditing clones upstream repositories and generates child SBOMs, so it does real network work — confirm with the user before a large run.
cdx-audit --bom /absolute/path/to/bom.json
cdx-audit --bom-dir /absolute/path/to/boms --report json --report-file /absolute/path/to/audit.json
cdx-audit --bom /absolute/path/to/bom.json --report sarif --report-file /absolute/path/to/audit.sarifReporters: console (default), json, sarif. Use SARIF for code-scanning
uploads.
Predictive mode extracts npm and PyPI package URLs from the BOM's components, generates a child SBOM for each upstream, and evaluates compromise posture. Cargo/Rust BOMs are also worth auditing this way when the goal is upstream review prioritization.
Exit code 3 means at least one target reached --fail-severity (default
high) or above. That is a policy signal, not a crash — report it as such.
For large BOMs or a triage-first workflow:
cdx-audit --bom /absolute/path/to/bom.json --scope required --max-targets 25| Flag | Effect |
|---|---|
--scope required | Only components with CycloneDX scope=required; a missing scope is treated as required |
--scope all | Default |
--max-targets <n> | Safety limit on unique npm/PyPI purls analyzed |
--min-severity | Filter console/SARIF output (low, medium, high, critical) |
--fail-severity | Severity that triggers exit code 3 (default high) |
# broader baseline, including packages that already carry trusted publishing metadata
cdx-audit --bom /absolute/path/to/bom.json --scope required --include-trusted --max-targets 50
# inspect only that subset
cdx-audit --bom /absolute/path/to/bom.json --only-trustedNever pass --include-trusted together with --only-trusted. Use
--include-trusted only when the user explicitly wants the broader baseline.
cdx-audit --bom /absolute/path/to/bom.json \
--workspace-dir /absolute/path/to/workspace \
--reports-dir /absolute/path/to/reports--workspace-dir reuses cloned repositories and cached child SBOMs.
--reports-dir persists per-target artifacts plus an aggregate JSON report. Use
both when the user expects iterative analysis.
Other useful flags: --allowlist-file (purl prefixes to exclude from target
selection, on top of the built-in allowlist),
--skip-default-branch-recheck, --prioritize-direct-runtime,
--rules-dir for custom rules, and --introspect for a per-BOM build-fidelity
verdict inferred from BOM structure alone.
Queue order is explainable. When trimmed, it prioritizes:
scope=requiredevidence.occurrencesThese affect which packages are audited first, not final severity. Final severity comes from child SBOM findings plus conservative corroboration logic. Do not present queue position as a risk score.
CDXGEN_THINK_MODE=true cdx-audit --bom /absolute/path/to/bom.json --scope required --max-targets 10Prints lightweight score and rationale summaries per package.
Evaluate rules against the supplied BOM itself rather than generating child SBOMs:
cdx-audit --bom /absolute/path/to/bom.json --direct-bom-audit
cdx-audit --bom /absolute/path/to/hbom.json --direct-bom-audit --categories hbom
cdx-audit --bom /absolute/path/to/aibom.json --direct-bom-audit --categories ai-bom
cdx-audit --bom /absolute/path/to/bom.evinse.json --direct-bom-audit --categories golemIn direct mode, --categories applies to the supplied BOM. Default is
obom-runtime for OBOMs and all categories otherwise. In predictive mode it
applies to the generated child SBOMs, defaulting to ai-agent,
ci-permission, dependency-source, package-integrity.
cdxgen -o /absolute/path/to/bom.json --bom-audit /absolute/path/to/project
cdxgen -o /absolute/path/to/bom.json --bom-audit --bom-audit-categories ci-permission /absolute/path/to/projectFindings land in the BOM's annotations[]. Related flags mirror cdx-audit:
--bom-audit-categories, --bom-audit-min-severity,
--bom-audit-fail-severity, --bom-audit-scope, --bom-audit-max-targets,
--bom-audit-include-trusted, --bom-audit-only-trusted,
--bom-audit-rules-dir.
Unknown categories are rejected, not ignored. Aliases such as ai-inventory
and hbom expand to their built-in category sets.
| Category | Covers |
|---|---|
ci-permission | GitHub Actions/GitLab CI privilege and supply-chain risk |
dependency-source | Non-registry, local, or mutable dependency sources |
package-integrity | Deprecated, yanked, tampered, or suspicious packages |
golem-security | Go Evinse/Golem evidence findings |
asar-archive | Electron ASAR archive integrity and contents |
container-risk | Container image risk |
rootfs-hardening | Offline host repository trust, privileged helpers, service drift |
obom-runtime | Live OS runtime artifacts |
hbom-security | Hardware security posture |
host-topology | Merged hardware plus runtime host view |
mcp-server | MCP server exposure and auth posture |
ai-agent | AI instruction and skill files |
ai-inventory | Alias for ai-agent + mcp-server |
ai-bom | Umbrella AI-BOM pack |
ai-security, ai-governance, ai-performance | AI-specific rule packs |
ai-provenance | Alias enabling ai-provenance + ai-oversight |
cbom-security, cbom-compliance | Weak crypto, cipher modes, key sizes, protocol versions |
vscode-extension, chrome-extension | IDE and browser extension risk |
Aliases worth remembering: cbom / crypto-bom for both CBOM packs, hbom for
the full HBOM pack, ai-inventory for AI agent plus MCP.
Full rule tables with IDs and severities: https://cdxgen.github.io/cdxgen/#/BOM_AUDIT.
cdx-audit --bom /absolute/path/to/bom.json --license-policy /absolute/path/to/policy.yamlEvaluates every component license and reports prohibited and warning-level
violations as a separate table. Error-level (prohibited) violations cause a
non-zero exit, independent of --fail-severity.
cdxgen --license-policy applies the same policy at generation time.
In dry-run mode the formulation-centric categories are the ones that still
produce meaningful output, since they read declared configuration rather than
resolved dependency trees. ci-permission is the clearest example.
--fail-severity, not with the total count.CI-002, PKG-007) so the user can look it up.In cdxi (see bom-explore): .auditfindings and .auditactions.
© cdxgen, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in claude-plugin/skills/bom-audit of cdxgen/cdxgen.
Open the folder on GitHubat commit e256966
Bom Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Bom Audit this skillcdxgen/cdxgen | 1.1k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| Vex Authoringrelizaio/rearm | 127 | — | ~2.9k | Automated safety check: Pass | AGPL-3.0 | |
| Dependency Update Auditbacknotprop/plannotator | 9.2k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Supply Chain Risk Auditortrailofbits/skills | 7.4k | — | ~1.7k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Corpus Sweepnubjs/nub | 4.4k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Dependency Auditbriiirussell/cybersecurity-skills | 413 | — | ~3.2k | Automated safety check: Warn | MIT |
relizaio/rearm
Author CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM.
backnotprop/plannotator
Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.
trailofbits/skills
Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration…
nubjs/nub
Run a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run).
briiirussell/cybersecurity-skills
Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns.
inkline/inkline
Inkline's platform & trust surface — the styleframe license boundary, supply-chain and secrets hygiene, npm distribution integrity, and the future Studio/commercial direction.
cdxgen/cdxgen
Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…
cdxgen/cdxgen
Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…
cdxgen/cdxgen
Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…
cdxgen/cdxgen
Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures…
cdxgen/cdxgen
Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…
cdxgen/cdxgen
Reviews a codebase's direct dependencies and designs lightweight, low-risk, zero-dependency custom replacements using cdxgen SBOM evidence, occurrence/callstack usage data, and license and…
Works with
Categories
Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…. Bom Audit is an agent skill from cdxgen/cdxgen. Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk, dependency source integrity, license policy violations, and SARIF or JSON reporting for code scanning.
Bom Audit fits situations like: asked to audit an SBOM; assess supply-chain; dependency risk; check for compromised.
Run `npx skills add cdxgen/cdxgen --skill bom-audit -a claude-code`. Or copy the skill folder (claude-plugin/skills/bom-audit in cdxgen/cdxgen) into .claude/skills/bom-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add cdxgen/cdxgen --skill bom-audit -a codex`. Or copy the skill folder (claude-plugin/skills/bom-audit in cdxgen/cdxgen) into .agents/skills/bom-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cdxgen/cdxgen --skill bom-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bom-audit, .gemini/skills/bom-audit, .github/skills/bom-audit and .opencode/skills/bom-audit in your project.
SKILL.md names no scripts, command-line tools or credentials: Bom Audit is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: cdxgen.github.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Bom Audit is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Bom Audit: Vex Authoring (relizaio/rearm, 127 stars), Dependency Update Audit (backnotprop/plannotator, 9.2k stars), Supply Chain Risk Auditor (trailofbits/skills, 7.4k stars) and Corpus Sweep (nubjs/nub, 4.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
cdxgen (a GitHub organization) maintains it in cdxgen/cdxgen, which has 1,085 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 7, 2026.
Source: cdxgen/cdxgen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.