Cairo Vulnerability Scanner
trailofbits/skills
Scans Cairo and StarkNet contracts for 6 vulnerability patterns, including felt252 overflow, L1 to L2 messaging faults, address conversion and signature replay.
Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…
$ npx skills add cdxgen/cdxgen --skill bom-evidence -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install cdxgen/cdxgen bom-evidence --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude-plugin/skills/bom-evidence .claude/skills/bom-evidence && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "bom-evidence" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/bom-evidence into .claude/skills/bom-evidence/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bom-evidence", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/bom-evidenceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add cdxgen/cdxgen --skill bom-evidence -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install cdxgen/cdxgen bom-evidence --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .agents/skills && cp -r skills-src/claude-plugin/skills/bom-evidence .agents/skills/bom-evidence && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "bom-evidence" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/bom-evidence into .agents/skills/bom-evidence/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bom-evidence", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cdxgen/cdxgen --skill bom-evidence -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install cdxgen/cdxgen bom-evidence --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/claude-plugin/skills/bom-evidence .cursor/skills/bom-evidence && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "bom-evidence" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/bom-evidence into .cursor/skills/bom-evidence/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bom-evidence", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/cdxgen/cdxgen.git --path claude-plugin/skills/bom-evidence--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add cdxgen/cdxgen --skill bom-evidence -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install cdxgen/cdxgen bom-evidence --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/claude-plugin/skills/bom-evidence .gemini/skills/bom-evidence && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "bom-evidence" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/bom-evidence into .gemini/skills/bom-evidence/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bom-evidence", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install cdxgen/cdxgen bom-evidenceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add cdxgen/cdxgen --skill bom-evidence -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .github/skills && cp -r skills-src/claude-plugin/skills/bom-evidence .github/skills/bom-evidence && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "bom-evidence" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/bom-evidence into .github/skills/bom-evidence/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bom-evidence", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cdxgen/cdxgen --skill bom-evidence -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install cdxgen/cdxgen bom-evidence --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/claude-plugin/skills/bom-evidence .opencode/skills/bom-evidence && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "bom-evidence" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/bom-evidence into .opencode/skills/bom-evidence/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bom-evidence", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
bom-evidenceEnriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…
Bom Evidence is an agent skill from cdxgen/cdxgen. Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and produces SaaSBOM service and endpoint inventory. Use when asked which dependencies are actually used or reachable, for callstack or usage evidence, a SaaSBOM, API endpoint inventory, data-flow or taint analysis, or to distinguish real from declared dependency usage.
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering REST APIs and Static analysis and SAST. It works with Rust. The repository describes itself as: Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with…. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit e256966. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
dockerFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
cdxgen.github.ioFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Bom Evidence loads about 1.9k tokens when it runs. Until then it costs about 119 tokens; SKILL.md has 597 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from cdxgen/cdxgen at commit e256966, republished under its Apache-2.0 licence (© cdxgen). 597 words, ~1,877 tokens.
.claude/skills/bom-evidence/SKILL.md (or your agent's skills folder).evinse answers a question a plain SBOM cannot: which declared dependencies
the code actually uses, where, and along what data paths. Run it on a BOM that
already exists.
Read reference/safety.md first. The rule about never surfacing raw Golem values is a hard constraint, restated below.
# 1. generate
cdxgen -t go -o /absolute/path/to/bom.json /absolute/path/to/project
# 2. enrich
evinse -i /absolute/path/to/bom.json -o /absolute/path/to/bom.evinse.json \
-l go /absolute/path/to/project-l / --language defaults to java. Supported: java, jar, js, ts,
javascript, nodejs, py, python, android, go, golang, rust, rs,
csharp, cs, c, cpp, dotnet, php, swift, ios, ruby, scala,
vb.
| Flag | Adds |
|---|---|
--with-reachables | Reachability slices |
--with-data-flow | Data-flow evidence |
--deep | Deeper analysis across dimensions |
--annotate | Record findings as BOM annotations |
--print, -p | Human-readable summary |
--openapi-spec-file | Correlate discovered endpoints against an OpenAPI spec |
--force | Re-run even when cached slices exist |
Slice outputs can be written or reused via --usages-slices-file,
--reachables-slices-file, --data-flow-slices-file, --semantics-slices-file,
and --deps-slices-file. Pass these when the user will iterate — regenerating
slices is the expensive part.
--with-deep-jar-collector and --skip-maven-collector tune JVM collection.
saasbom /absolute/path/to/project -o /absolute/path/to/saasbom.jsonsaasbom sets --evidence and --deep, and defaults the spec version to
1.7. Equivalent from source:
cdxgen --evidence --deep -o /absolute/path/to/bom.json /absolute/path/to/projectBe candid about SaaSBOM's success rate. Service and endpoint collection
depends on atom and atom-tools, and outside the cdxgen container image the
chances of a complete collection are low unless the user has set those up
themselves. cdxgen itself warns about this when not running in a container.
Recommend the container image:
docker run --rm -v $(pwd):/app:rw -t ghcr.io/cdxgen/cdxgen:master /app --evidence -o /app/bom.jsonInspect results in cdxi with .services and .occurrences.
Golem provides semantic evidence for Go, from the optional
@cdxgen/cdxgen-plugins-bin package. When the platform binary is absent,
evinse still runs but without Golem evidence — say so rather than reporting
failure.
evinse -i /absolute/path/to/bom.json -o /absolute/path/to/bom.evinse.json \
-l go --golem-callgraph static /absolute/path/to/project
cdx-audit --bom /absolute/path/to/bom.evinse.json --direct-bom-audit --categories golem--golem-callgraph: none, static (default), cha, rta, vta. Precision
and cost both rise across that list. Start with static.
--golem-dataflow: none, security, crypto, all. Defaults to all with
--with-data-flow, --profile research, or --deep; none otherwise.
Bounded crypto-flow analysis:
evinse -i /absolute/path/to/bom.json -o /absolute/path/to/bom.evinse.crypto.json \
-l go --with-data-flow \
--golem-dataflow crypto --golem-dataflow-pattern-packs crypto \
/absolute/path/to/projectGo data-flow analysis is the most expensive thing in this skill. Keep it
bounded in CI: --golem-dataflow-workers, --golem-max-procs,
--golem-memory-limit, --golem-dataflow-max-slices,
--golem-dataflow-max-trace-nodes, --golem-dataflow-max-trace-edges,
--golem-dataflow-max-function-instructions,
--golem-dataflow-large-repo-functions, --golem-dataflow-skip-generated,
--golem-dataflow-skip-tests, --golem-progress.
Set explicit limits rather than letting an unbounded run consume a CI runner.
Start high, then drill down. In cdxi: .golemsummary, .golemhotspots,
.golemcoverage, .golemtips — then .occurrences, .callstack, and
.inspect <component>.
For crypto flow, prioritize components with cdx:golem:cryptoDataFlow=true and
cdx:golem:cryptoDataFlowCount, then pivot on the rendered
cryptographic-asset algorithms.
Golem also surfaces Go-specific supply-chain facts: local replace directives,
vendoring and license evidence, usage scopes, and security-sensitive API signals.
Never surface raw go:generate commands, environment values, HTTP parameter
values, key material, plaintext, ciphertext, embedded file contents, generated
source contents, or secrets. Review exclusively through the emitted
cdx:golem:* counts, categories, rule IDs, taint kinds, scopes, call-stack
frames, crypto algorithm/OID pivots, and module facts.
This is not a style preference. Golem's raw output can contain the secrets it found, and repeating them into a chat transcript or a BOM shared downstream spreads them.
Threat model: https://cdxgen.github.io/cdxgen/#/GO_EVINSE_GOLEM_THREAT_MODEL.
evinse -i /absolute/path/to/bom.json -o /absolute/path/to/bom.evinse.json \
-l rust --rusi-mode analyze /absolute/path/to/project| Flag | Choices |
|---|---|
--rusi-mode | analyze (default), cryptos |
--rusi-backend | stable (default), compiler |
--rusi-toolchain | auto (default), nightly, stable |
--rusi-callgraph, --rusi-dataflow, --rusi-patterns | analysis tuning |
Use --rusi-mode cryptos when the question is cryptographic usage rather than
general dependency usage.
In cdxi: .cargohotspots and .cargoworkflows.
static call graphs miss what vta finds.© cdxgen, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in claude-plugin/skills/bom-evidence of cdxgen/cdxgen.
Open the folder on GitHubat commit e256966
Bom Evidence next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Bom Evidence this skillcdxgen/cdxgen | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Cairo Vulnerability Scannertrailofbits/skills | 7.4k | — | ~3.3k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Pyspector Security AuditParzivalHack/PySpector | 151 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | |
| SkepticRaoFoundation/subtensor | 389 | — | ~660 | Automated safety check: Pass | Apache-2.0 | |
| Constant-Time Analysistrailofbits/skills | 7.4k | — | ~3.3k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Audit Prep Assistanttrailofbits/skills | 7.4k | — | ~2.5k | Automated safety check: Pass | CC-BY-SA-4.0 |
trailofbits/skills
Scans Cairo and StarkNet contracts for 6 vulnerability patterns, including felt252 overflow, L1 to L2 messaging faults, address conversion and signature replay.
ParzivalHack/PySpector
Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.
RaoFoundation/subtensor
Run the security-focused Skeptic persona on the local working tree's diff against a base branch.
trailofbits/skills
Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets.
trailofbits/skills
Gets your own codebase ready for an external security review: sets review goals, runs static analysis, raises test coverage, removes dead code and writes documentation.
LeoYeAI/openclaw-master-skills
Static ReDoS (Regular Expression Denial of Service) vulnerability scanner and regex quality auditor for codebases.
cdxgen/cdxgen
Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…
cdxgen/cdxgen
Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…
cdxgen/cdxgen
Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…
cdxgen/cdxgen
Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures…
cdxgen/cdxgen
Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…
cdxgen/cdxgen
Reviews a codebase's direct dependencies and designs lightweight, low-risk, zero-dependency custom replacements using cdxgen SBOM evidence, occurrence/callstack usage data, and license and…
Works with
Categories
Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…. Bom Evidence is an agent skill from cdxgen/cdxgen. Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and produces SaaSBOM service and endpoint inventory.
Bom Evidence fits situations like: asked which dependencies are actually used; API endpoint inventory; distinguish real from declared dependency usage.
Run `npx skills add cdxgen/cdxgen --skill bom-evidence -a claude-code`. Or copy the skill folder (claude-plugin/skills/bom-evidence in cdxgen/cdxgen) into .claude/skills/bom-evidence in your project. Claude Code loads it when a task matches its description.
Run `npx skills add cdxgen/cdxgen --skill bom-evidence -a codex`. Or copy the skill folder (claude-plugin/skills/bom-evidence in cdxgen/cdxgen) into .agents/skills/bom-evidence in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cdxgen/cdxgen --skill bom-evidence -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bom-evidence, .gemini/skills/bom-evidence, .github/skills/bom-evidence and .opencode/skills/bom-evidence in your project.
Going by SKILL.md and its folder, Bom Evidence needs the command-line tools its instructions call (docker). Our summary lists: Node.js; Docker.
SKILL.md names 1 domain. As links in the text: cdxgen.github.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Bom Evidence is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Bom Evidence: Cairo Vulnerability Scanner (trailofbits/skills, 7.4k stars), Pyspector Security Audit (ParzivalHack/PySpector, 151 stars), Skeptic (RaoFoundation/subtensor, 389 stars) and Constant-Time Analysis (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
cdxgen (a GitHub organization) maintains it in cdxgen/cdxgen, which has 1,085 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 8, 2026.
Source: cdxgen/cdxgen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.