Agent skill

Bom Convert Validate

by cdxgen in cdxgen/cdxgen

Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…

Apache-2.0Auto-check: warningsSecurity

Install Bom Convert Validate

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add cdxgen/cdxgen --skill bom-convert-validate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cdxgen/cdxgen bom-convert-validate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude-plugin/skills/bom-convert-validate .claude/skills/bom-convert-validate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bom-convert-validate
GitHub stars
1.1k
Token cost
~1.5k tokens
SKILL.md length
417 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
Apache-2.0

At a glance

Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…

  • Works in 3 steps: Schema validation — CycloneDX JSON schema → Deep validation — metadata, purl,… → Compliance rule packs — OWASP SCVS (all…
  • Asked to convert an SBOM to SPDX
  • SKILL.md covers Convert, Validate, Validation during generation and Reference
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Bom Convert Validate is an agent skill from cdxgen/cdxgen. Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber Resilience Act compliance benchmarks with cdx-validate, emitting SARIF for code scanning. Use when asked to convert an SBOM to SPDX, downgrade or upgrade a BOM spec version, validate or lint a BOM, check SCVS or CRA compliance, or score SBOM quality.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Regulatory compliance, Supply chain security and Web application vulnerabilities. The repository describes itself as: Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with…. The licence is Apache-2.0.

When your agent uses it

  • Asked to convert an SBOM to SPDX
  • Upgrade a BOM spec version
  • Score SBOM quality

Example prompts

  • “Use the bom-convert-validate skill to convert CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and…”
  • “/bom-convert-validate”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Schema validation — CycloneDX JSON schema
  2. Deep validation — metadata, purl, bom-ref, and property consistency
  3. Compliance rule packs — OWASP SCVS (all 87 controls across L1/L2/L3) and EU Cyber Resilience Act SBOM expectations (8 controls)

What it can do on your machine

Read from SKILL.md and the folder at commit e256966. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cdxgen.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bom Convert Validate loads about 1.5k tokens when it runs. Until then it costs about 116 tokens; SKILL.md has 417 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~116
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningContains instruction-override wording (e.g. “without asking the user”)SKILL.md:125
    generation does not run. Do not tell the user their BOM is "already validated"

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cdxgen/cdxgen at commit e256966, republished under its Apache-2.0 licence (© cdxgen). 417 words, ~1,498 tokens.

Download SKILL.mdSave it as .claude/skills/bom-convert-validate/SKILL.md (or your agent's skills folder).
name
bom-convert-validate
description
Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber Resilience Act compliance benchmarks with cdx-validate, emitting SARIF for code scanning. Use when asked to convert an SBOM to SPDX, downgrade or upgrade a BOM spec version, validate or lint a BOM, check SCVS or CRA compliance, or score SBOM quality.

Convert and validate BOMs

Two post-processing commands for BOMs that already exist.

Read reference/safety.md first.

Convert

bash
# CycloneDX to SPDX 3.0.1 JSON-LD (default target)
cdx-convert -i /absolute/path/to/bom.json -o /absolute/path/to/bom.spdx.json

# Cross-convert between CycloneDX spec versions
cdx-convert -i /absolute/path/to/bom.json --to 1.6 -o /absolute/path/to/bom.1.6.json
FlagPurpose
-i, --inputSource BOM
-o, --outputDestination
--tospdx (default) or a CycloneDX version: 1.5, 1.6, 1.7
--validateValidate the conversion result
--json-prettyPretty-print output
The legacy spec-version path

cdxgen rejects 1.4 and 1.5 as generation targets — only 1.6, 1.7 (default), and 2.0 are accepted. When a consumer needs an older document, the supported route is to generate at a valid version and downgrade the serialized output here:

bash
cdxgen -o /absolute/path/to/bom.json /absolute/path/to/project
cdx-convert -i /absolute/path/to/bom.json --to 1.5 -o /absolute/path/to/bom.1.5.json

Tell the user that a downgrade drops fields the older schema cannot express. A 1.5 document converted from 1.7 is not the same document.

SPDX directly from source

If SPDX is the only target, skip the round trip:

bash
cdxgen --format spdx -o /absolute/path/to/bom.spdx.json /absolute/path/to/project

spdxgen is the dedicated command for the same thing. Use cdx-convert when the CycloneDX document already exists or is also wanted.

Validate

bash
cdx-validate -i /absolute/path/to/bom.json

Three layers run together:

  1. Schema validation — CycloneDX JSON schema
  2. Deep validation — metadata, purl, bom-ref, and property consistency
  3. Compliance rule packs — OWASP SCVS (all 87 controls across L1/L2/L3) and EU Cyber Resilience Act SBOM expectations (8 controls)

Protobuf input works too:

bash
cdx-validate -i /absolute/path/to/bom.cdx
Compliance benchmarks
bash
cdx-validate -i /absolute/path/to/bom.json --benchmark scvs-l2 -r sarif -o /absolute/path/to/results.sarif

Benchmark aliases: scvs, scvs-l1, scvs-l2, scvs-l3, cra. Defaults to all. Categories: compliance-scvs, compliance-cra.

Rules that cannot be decided from a BOM alone — "SBOMs are required for new procurements", for example — are surfaced as manual-review items so coverage is still tracked. Include them with --include-manual.

This matters when reporting a score: a control marked manual-review is neither passing nor failing. Do not fold it into either bucket.

Show full SKILL.md (160 more words)Show less
Validation flags
FlagPurpose
--schema / --no-schemaJSON-schema layer, on by default
--deepDeep consistency checks
--benchmark, -bCompliance benchmarks to score
--categoriesCompliance rule categories
--strictTreat warnings as failures
--min-severityMinimum severity to report
--fail-severitySeverity that causes a non-zero exit
--include-manualInclude manual-review controls in output
--include-passShow passing controls, not just failures
--report, -rsarif and other formats
--report-file, -oWrite the report to a file
--public-keyVerify the JSF signature during validation
--require-signatureFail validation when no signature is present
--platformPlatform-specific validation behaviour
Release-gate pattern
bash
cdx-validate -i /absolute/path/to/bom.json \
  --benchmark scvs-l2,cra \
  --public-key /absolute/path/to/public.pem --require-signature \
  --strict \
  -r sarif -o /absolute/path/to/results.sarif

Schema, deep consistency, SCVS L2, CRA, and signature presence in one gate.

Validation during generation

cdxgen --validate is on by default, so a generated BOM is already schema-checked. cdx-validate adds the deep and compliance layers, which generation does not run. Do not tell the user their BOM is "already validated" when they are asking about SCVS or CRA coverage.

Rule details: https://cdxgen.github.io/cdxgen/#/VALIDATION_RULES.

Reference

© cdxgen, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in claude-plugin/skills/bom-convert-validate of cdxgen/cdxgen.

Open the folder on GitHubat commit e256966

Compare with similar skills

Bom Convert Validate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bom Convert Validate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bom Convert Validate this skillcdxgen/cdxgen1.1k—~1.5kAutomated safety check: WarnApache-2.0
Sailpillar-labs/sail-skill113—~5.1kAutomated safety check: PassCustom licence
Sbom Generate686f6c61/alfred-dev117—~780Automated safety check: PassMIT
Codebase Cleanup Deps Auditaiskillstore/marketplace4307 repos~490Automated safety check: PassNone
Open Source PolicyHack23/cia239—~4.6kAutomated safety check: PassApache-2.0
Dependency AuditMathews-Tom/armory328—~2.7kAutomated safety check: PassMIT

Similar skills

  • Sail

    pillar-labs/sail-skill

    Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents.

    113 GitHub stars~5.1k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Sbom Generate

    686f6c61/alfred-dev

    Usar para generar Software Bill of Materials para cumplimiento del CRA.

    117 GitHub stars~780 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Codebase Cleanup Deps Audit

    aiskillstore/marketplace

    You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security.

    430 GitHub starsUsed in 7 repos~490 tokens
    SecurityAuto-check passed
  • Open source governance, security posture badges, license compliance, SBOM generation, and vulnerability management for transparency-driven development

    239 GitHub stars~4.6k tokensUpdated today
    SecurityAuto-check passed
  • Dependency Audit

    Mathews-Tom/armory

    Audits direct and transitive dependencies for license compliance, maintenance health, CVEs, abandoned packages, and bloat.

    328 GitHub stars~2.7k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Oss Review

    zhou210712/claude-for-legal-ZH

    开源许可证合规检查——对依赖列表、单个库或对外发布代码. An agent skill from zhou210712/claude-for-legal-ZH.

    224 GitHub stars~2k tokensUpdated 4 mo ago
    SecurityAuto-check passed

More from cdxgen/cdxgen

All 17 skills in this repo
  • AI Bom

    cdxgen/cdxgen

    Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…

    1.1k GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Bom Audit

    cdxgen/cdxgen

    Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…

    1.1k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Bom Evidence

    cdxgen/cdxgen

    Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…

    1.1k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Bom Explore

    cdxgen/cdxgen

    Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…

    1.1k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Bom Signing

    cdxgen/cdxgen

    Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures…

    1.1k GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Bom Slimmer

    cdxgen/cdxgen

    Reviews a codebase's direct dependencies and designs lightweight, low-risk, zero-dependency custom replacements using cdxgen SBOM evidence, occurrence/callstack usage data, and license and…

    1.1k GitHub stars~1.6k tokensUpdated today
    Auto-check passed

Questions about Bom Convert Validate

What does Bom Convert Validate do?

Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…. Bom Convert Validate is an agent skill from cdxgen/cdxgen.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber Resilience Act compliance benchmarks with cdx-validate, emitting SARIF for code scanning.

When should I use Bom Convert Validate?

Bom Convert Validate fits situations like: asked to convert an SBOM to SPDX; upgrade a BOM spec version; score SBOM quality.

How do I install Bom Convert Validate in Claude Code?

Run `npx skills add cdxgen/cdxgen --skill bom-convert-validate -a claude-code`. Or copy the skill folder (claude-plugin/skills/bom-convert-validate in cdxgen/cdxgen) into .claude/skills/bom-convert-validate in your project. Claude Code loads it when a task matches its description.

How do I install Bom Convert Validate in Codex?

Run `npx skills add cdxgen/cdxgen --skill bom-convert-validate -a codex`. Or copy the skill folder (claude-plugin/skills/bom-convert-validate in cdxgen/cdxgen) into .agents/skills/bom-convert-validate in your project. Codex loads it when a task matches its description.

Can I use Bom Convert Validate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cdxgen/cdxgen --skill bom-convert-validate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bom-convert-validate, .gemini/skills/bom-convert-validate, .github/skills/bom-convert-validate and .opencode/skills/bom-convert-validate in your project.

What does Bom Convert Validate need to run?

SKILL.md names no scripts, command-line tools or credentials: Bom Convert Validate is instructions for the agent only.

Does Bom Convert Validate access the network?

SKILL.md names 1 domain. As links in the text: cdxgen.github.io. This is read from the text; nothing was executed.

Is Bom Convert Validate safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): contains instruction-override wording (e.g. “without asking the user”). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Bom Convert Validate use?

Bom Convert Validate is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bom Convert Validate use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bom Convert Validate?

Skills that share tags, products or a category with Bom Convert Validate: Sail (pillar-labs/sail-skill, 113 stars), Sbom Generate (686f6c61/alfred-dev, 117 stars), Codebase Cleanup Deps Audit (aiskillstore/marketplace, 430 stars) and Open Source Policy (Hack23/cia, 239 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bom Convert Validate?

cdxgen (a GitHub organization) maintains it in cdxgen/cdxgen, which has 1,085 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 7, 2026.

Source: cdxgen/cdxgen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.