Agent skill

Bom Audit

by cdxgen in cdxgen/cdxgen

Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…

Apache-2.0Auto-check passedSecurity

Install Bom Audit

skills CLI
$ npx skills add cdxgen/cdxgen --skill bom-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cdxgen/cdxgen bom-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude-plugin/skills/bom-audit .claude/skills/bom-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bom-audit
GitHub stars
1.1k
Token cost
~2.4k tokens
SKILL.md length
734 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
Apache-2.0

At a glance

Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…

  • Works in 5 steps: direct runtime dependencies → explicit CycloneDX scope=required → stronger source evidence via… → …
  • Asked to audit an SBOM
  • SKILL.md covers Predictive audit of an…, Direct BOM audit, Embedded audit during generation and Rule categories, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Bom Audit is an agent skill from cdxgen/cdxgen. Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk, dependency source integrity, license policy violations, and SARIF or JSON reporting for code scanning. Use when asked to audit an SBOM, assess supply-chain or dependency risk, check for compromised or malicious packages, triage which dependencies to review first, or produce SARIF from a BOM.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Supply chain security. It works with npm. The repository describes itself as: Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with…. The licence is Apache-2.0.

When your agent uses it

  • Asked to audit an SBOM
  • Assess supply-chain
  • Dependency risk
  • Check for compromised

Example prompts

  • “/bom-audit”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. direct runtime dependencies
  2. explicit CycloneDX scope=required
  3. stronger source evidence via evidence.occurrences
  4. non-development ahead of development-only packages
  5. non-platform-specific ahead of platform-constrained packages

What it can do on your machine

Read from SKILL.md and the folder at commit e256966. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cdxgen.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bom Audit loads about 2.4k tokens when it runs. Until then it costs about 124 tokens; SKILL.md has 734 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~124
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cdxgen/cdxgen at commit e256966, republished under its Apache-2.0 licence (© cdxgen). 734 words, ~2,410 tokens.

Download SKILL.mdSave it as .claude/skills/bom-audit/SKILL.md (or your agent's skills folder).
name
bom-audit
description
Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk, dependency source integrity, license policy violations, and SARIF or JSON reporting for code scanning. Use when asked to audit an SBOM, assess supply-chain or dependency risk, check for compromised or malicious packages, triage which dependencies to review first, or produce SARIF from a BOM.

Audit a BOM for supply-chain risk

Two distinct mechanisms. Choose deliberately.

WantUse
Findings embedded while the BOM is generatedcdxgen --bom-audit
Analysis of a BOM that already existscdx-audit
Forward-looking review prioritization for npm/PyPIcdx-audit (predictive)
Rule evaluation against the supplied BOM itselfcdx-audit --direct-bom-audit

Read reference/safety.md first. Predictive auditing clones upstream repositories and generates child SBOMs, so it does real network work — confirm with the user before a large run.

Predictive audit of an existing BOM

bash
cdx-audit --bom /absolute/path/to/bom.json
cdx-audit --bom-dir /absolute/path/to/boms --report json --report-file /absolute/path/to/audit.json
cdx-audit --bom /absolute/path/to/bom.json --report sarif --report-file /absolute/path/to/audit.sarif

Reporters: console (default), json, sarif. Use SARIF for code-scanning uploads.

Predictive mode extracts npm and PyPI package URLs from the BOM's components, generates a child SBOM for each upstream, and evaluates compromise posture. Cargo/Rust BOMs are also worth auditing this way when the goal is upstream review prioritization.

Exit code 3 means at least one target reached --fail-severity (default high) or above. That is a policy signal, not a crash — report it as such.

Start narrow

For large BOMs or a triage-first workflow:

bash
cdx-audit --bom /absolute/path/to/bom.json --scope required --max-targets 25
FlagEffect
--scope requiredOnly components with CycloneDX scope=required; a missing scope is treated as required
--scope allDefault
--max-targets <n>Safety limit on unique npm/PyPI purls analyzed
--min-severityFilter console/SARIF output (low, medium, high, critical)
--fail-severitySeverity that triggers exit code 3 (default high)
Trusted publishing
bash
# broader baseline, including packages that already carry trusted publishing metadata
cdx-audit --bom /absolute/path/to/bom.json --scope required --include-trusted --max-targets 50

# inspect only that subset
cdx-audit --bom /absolute/path/to/bom.json --only-trusted

Never pass --include-trusted together with --only-trusted. Use --include-trusted only when the user explicitly wants the broader baseline.

Reuse work across runs
bash
cdx-audit --bom /absolute/path/to/bom.json \
  --workspace-dir /absolute/path/to/workspace \
  --reports-dir /absolute/path/to/reports

--workspace-dir reuses cloned repositories and cached child SBOMs. --reports-dir persists per-target artifacts plus an aggregate JSON report. Use both when the user expects iterative analysis.

Other useful flags: --allowlist-file (purl prefixes to exclude from target selection, on top of the built-in allowlist), --skip-default-branch-recheck, --prioritize-direct-runtime, --rules-dir for custom rules, and --introspect for a per-BOM build-fidelity verdict inferred from BOM structure alone.

How the queue is ordered

Queue order is explainable. When trimmed, it prioritizes:

  1. direct runtime dependencies
  2. explicit CycloneDX scope=required
  3. stronger source evidence via evidence.occurrences
  4. non-development ahead of development-only packages
  5. non-platform-specific ahead of platform-constrained packages

These affect which packages are audited first, not final severity. Final severity comes from child SBOM findings plus conservative corroboration logic. Do not present queue position as a risk score.

Score rationale
bash
CDXGEN_THINK_MODE=true cdx-audit --bom /absolute/path/to/bom.json --scope required --max-targets 10

Prints lightweight score and rationale summaries per package.

Direct BOM audit

Evaluate rules against the supplied BOM itself rather than generating child SBOMs:

bash
cdx-audit --bom /absolute/path/to/bom.json --direct-bom-audit
cdx-audit --bom /absolute/path/to/hbom.json --direct-bom-audit --categories hbom
cdx-audit --bom /absolute/path/to/aibom.json --direct-bom-audit --categories ai-bom
cdx-audit --bom /absolute/path/to/bom.evinse.json --direct-bom-audit --categories golem

In direct mode, --categories applies to the supplied BOM. Default is obom-runtime for OBOMs and all categories otherwise. In predictive mode it applies to the generated child SBOMs, defaulting to ai-agent, ci-permission, dependency-source, package-integrity.

Embedded audit during generation

bash
cdxgen -o /absolute/path/to/bom.json --bom-audit /absolute/path/to/project
cdxgen -o /absolute/path/to/bom.json --bom-audit --bom-audit-categories ci-permission /absolute/path/to/project

Findings land in the BOM's annotations[]. Related flags mirror cdx-audit: --bom-audit-categories, --bom-audit-min-severity, --bom-audit-fail-severity, --bom-audit-scope, --bom-audit-max-targets, --bom-audit-include-trusted, --bom-audit-only-trusted, --bom-audit-rules-dir.

Unknown categories are rejected, not ignored. Aliases such as ai-inventory and hbom expand to their built-in category sets.

Show full SKILL.md (277 more words)Show less

Rule categories

CategoryCovers
ci-permissionGitHub Actions/GitLab CI privilege and supply-chain risk
dependency-sourceNon-registry, local, or mutable dependency sources
package-integrityDeprecated, yanked, tampered, or suspicious packages
golem-securityGo Evinse/Golem evidence findings
asar-archiveElectron ASAR archive integrity and contents
container-riskContainer image risk
rootfs-hardeningOffline host repository trust, privileged helpers, service drift
obom-runtimeLive OS runtime artifacts
hbom-securityHardware security posture
host-topologyMerged hardware plus runtime host view
mcp-serverMCP server exposure and auth posture
ai-agentAI instruction and skill files
ai-inventoryAlias for ai-agent + mcp-server
ai-bomUmbrella AI-BOM pack
ai-security, ai-governance, ai-performanceAI-specific rule packs
ai-provenanceAlias enabling ai-provenance + ai-oversight
cbom-security, cbom-complianceWeak crypto, cipher modes, key sizes, protocol versions
vscode-extension, chrome-extensionIDE and browser extension risk

Aliases worth remembering: cbom / crypto-bom for both CBOM packs, hbom for the full HBOM pack, ai-inventory for AI agent plus MCP.

Full rule tables with IDs and severities: https://cdxgen.github.io/cdxgen/#/BOM_AUDIT.

License policy

bash
cdx-audit --bom /absolute/path/to/bom.json --license-policy /absolute/path/to/policy.yaml

Evaluates every component license and reports prohibited and warning-level violations as a separate table. Error-level (prohibited) violations cause a non-zero exit, independent of --fail-severity.

cdxgen --license-policy applies the same policy at generation time.

Dry-run-friendly categories

In dry-run mode the formulation-centric categories are the ones that still produce meaningful output, since they read declared configuration rather than resolved dependency trees. ci-permission is the clearest example.

Reporting findings to the user

  • Lead with what reached --fail-severity, not with the total count.
  • Name the rule ID (CI-002, PKG-007) so the user can look it up.
  • Say when a clean result reflects conservative analysis rather than proven absence — especially for MCP and AI categories.
  • If exit code 3 fired, state which target caused it.

Exploring findings

In cdxi (see bom-explore): .auditfindings and .auditactions.

© cdxgen, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in claude-plugin/skills/bom-audit of cdxgen/cdxgen.

Open the folder on GitHubat commit e256966

Compare with similar skills

Bom Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bom Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bom Audit this skillcdxgen/cdxgen1.1k—~2.4kAutomated safety check: PassApache-2.0
Vex Authoringrelizaio/rearm127—~2.9kAutomated safety check: PassAGPL-3.0
Dependency Update Auditbacknotprop/plannotator9.2k—~1.8kAutomated safety check: PassApache-2.0
Supply Chain Risk Auditortrailofbits/skills7.4k—~1.7kAutomated safety check: NotesCC-BY-SA-4.0
Corpus Sweepnubjs/nub4.4k—~2.4kAutomated safety check: PassMIT
Dependency Auditbriiirussell/cybersecurity-skills413—~3.2kAutomated safety check: WarnMIT

Similar skills

  • Vex Authoring

    relizaio/rearm

    Author CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM.

    127 GitHub stars~2.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • Dependency Update Audit

    backnotprop/plannotator

    Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.

    9.2k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • Supply Chain Risk Auditor

    trailofbits/skills

    Official

    Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration…

    7.4k GitHub stars~1.7k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Corpus Sweep

    nubjs/nub

    Run a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run).

    4.4k GitHub stars~2.4k tokensUpdated yesterday
    SecurityAuto-check passed
  • Dependency Audit

    briiirussell/cybersecurity-skills

    Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns.

    413 GitHub stars~3.2k tokensUpdated 4 mo ago
    SecurityAuto-check: warnings
  • Platform Trust

    inkline/inkline

    Inkline's platform & trust surface — the styleframe license boundary, supply-chain and secrets hygiene, npm distribution integrity, and the future Studio/commercial direction.

    1.5k GitHub stars~1.1k tokensUpdated 27 days ago
    SecurityAuto-check passed

More from cdxgen/cdxgen

All 17 skills in this repo
  • AI Bom

    cdxgen/cdxgen

    Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…

    1.1k GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Bom Evidence

    cdxgen/cdxgen

    Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…

    1.1k GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Bom Explore

    cdxgen/cdxgen

    Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…

    1.1k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Bom Signing

    cdxgen/cdxgen

    Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures…

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check: warnings
  • Bom Slimmer

    cdxgen/cdxgen

    Reviews a codebase's direct dependencies and designs lightweight, low-risk, zero-dependency custom replacements using cdxgen SBOM evidence, occurrence/callstack usage data, and license and…

    1.1k GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Bom Audit

What does Bom Audit do?

Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…. Bom Audit is an agent skill from cdxgen/cdxgen. Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk, dependency source integrity, license policy violations, and SARIF or JSON reporting for code scanning.

When should I use Bom Audit?

Bom Audit fits situations like: asked to audit an SBOM; assess supply-chain; dependency risk; check for compromised.

How do I install Bom Audit in Claude Code?

Run `npx skills add cdxgen/cdxgen --skill bom-audit -a claude-code`. Or copy the skill folder (claude-plugin/skills/bom-audit in cdxgen/cdxgen) into .claude/skills/bom-audit in your project. Claude Code loads it when a task matches its description.

How do I install Bom Audit in Codex?

Run `npx skills add cdxgen/cdxgen --skill bom-audit -a codex`. Or copy the skill folder (claude-plugin/skills/bom-audit in cdxgen/cdxgen) into .agents/skills/bom-audit in your project. Codex loads it when a task matches its description.

Can I use Bom Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cdxgen/cdxgen --skill bom-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bom-audit, .gemini/skills/bom-audit, .github/skills/bom-audit and .opencode/skills/bom-audit in your project.

What does Bom Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Bom Audit is instructions for the agent only.

Does Bom Audit access the network?

SKILL.md names 1 domain. As links in the text: cdxgen.github.io. This is read from the text; nothing was executed.

Is Bom Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bom Audit use?

Bom Audit is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bom Audit use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bom Audit?

Skills that share tags, products or a category with Bom Audit: Vex Authoring (relizaio/rearm, 127 stars), Dependency Update Audit (backnotprop/plannotator, 9.2k stars), Supply Chain Risk Auditor (trailofbits/skills, 7.4k stars) and Corpus Sweep (nubjs/nub, 4.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bom Audit?

cdxgen (a GitHub organization) maintains it in cdxgen/cdxgen, which has 1,085 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 7, 2026.

Source: cdxgen/cdxgen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.