Agent skill

Bom Evidence

by cdxgen in cdxgen/cdxgen

Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…

Apache-2.0Auto-check passedSecurity

Install Bom Evidence

skills CLI
$ npx skills add cdxgen/cdxgen --skill bom-evidence -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cdxgen/cdxgen bom-evidence --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude-plugin/skills/bom-evidence .claude/skills/bom-evidence && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bom-evidence
GitHub stars
1.1k
Token cost
~1.9k tokens
SKILL.md length
597 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
Apache-2.0

At a glance

Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…

  • Asked which dependencies are actually used
  • SKILL.md covers Basic flow, Evidence dimensions, SaaSBOM: services and endpoints and Go: Golem, plus 3 more sections
  • Calls docker
  • API endpoint inventory

What it does

Bom Evidence is an agent skill from cdxgen/cdxgen. Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and produces SaaSBOM service and endpoint inventory. Use when asked which dependencies are actually used or reachable, for callstack or usage evidence, a SaaSBOM, API endpoint inventory, data-flow or taint analysis, or to distinguish real from declared dependency usage.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering REST APIs and Static analysis and SAST. It works with Rust. The repository describes itself as: Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with…. The licence is Apache-2.0.

When your agent uses it

  • Asked which dependencies are actually used
  • API endpoint inventory
  • Distinguish real from declared dependency usage

Example prompts

  • “Use the bom-evidence skill to enrich an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using…”
  • “/bom-evidence”

Requirements

  • Node.js
  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit e256966. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cdxgen.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bom Evidence loads about 1.9k tokens when it runs. Until then it costs about 119 tokens; SKILL.md has 597 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~119
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cdxgen/cdxgen at commit e256966, republished under its Apache-2.0 licence (© cdxgen). 597 words, ~1,877 tokens.

Download SKILL.mdSave it as .claude/skills/bom-evidence/SKILL.md (or your agent's skills folder).
name
bom-evidence
description
Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and produces SaaSBOM service and endpoint inventory. Use when asked which dependencies are actually used or reachable, for callstack or usage evidence, a SaaSBOM, API endpoint inventory, data-flow or taint analysis, or to distinguish real from declared dependency usage.

Add evidence to a BOM

evinse answers a question a plain SBOM cannot: which declared dependencies the code actually uses, where, and along what data paths. Run it on a BOM that already exists.

Read reference/safety.md first. The rule about never surfacing raw Golem values is a hard constraint, restated below.

Basic flow

bash
# 1. generate
cdxgen -t go -o /absolute/path/to/bom.json /absolute/path/to/project

# 2. enrich
evinse -i /absolute/path/to/bom.json -o /absolute/path/to/bom.evinse.json \
  -l go /absolute/path/to/project

-l / --language defaults to java. Supported: java, jar, js, ts, javascript, nodejs, py, python, android, go, golang, rust, rs, csharp, cs, c, cpp, dotnet, php, swift, ios, ruby, scala, vb.

Evidence dimensions

FlagAdds
--with-reachablesReachability slices
--with-data-flowData-flow evidence
--deepDeeper analysis across dimensions
--annotateRecord findings as BOM annotations
--print, -pHuman-readable summary
--openapi-spec-fileCorrelate discovered endpoints against an OpenAPI spec
--forceRe-run even when cached slices exist

Slice outputs can be written or reused via --usages-slices-file, --reachables-slices-file, --data-flow-slices-file, --semantics-slices-file, and --deps-slices-file. Pass these when the user will iterate — regenerating slices is the expensive part.

--with-deep-jar-collector and --skip-maven-collector tune JVM collection.

SaaSBOM: services and endpoints

bash
saasbom /absolute/path/to/project -o /absolute/path/to/saasbom.json

saasbom sets --evidence and --deep, and defaults the spec version to 1.7. Equivalent from source:

bash
cdxgen --evidence --deep -o /absolute/path/to/bom.json /absolute/path/to/project

Be candid about SaaSBOM's success rate. Service and endpoint collection depends on atom and atom-tools, and outside the cdxgen container image the chances of a complete collection are low unless the user has set those up themselves. cdxgen itself warns about this when not running in a container. Recommend the container image:

bash
docker run --rm -v $(pwd):/app:rw -t ghcr.io/cdxgen/cdxgen:master /app --evidence -o /app/bom.json

Inspect results in cdxi with .services and .occurrences.

Go: Golem

Golem provides semantic evidence for Go, from the optional @cdxgen/cdxgen-plugins-bin package. When the platform binary is absent, evinse still runs but without Golem evidence — say so rather than reporting failure.

bash
evinse -i /absolute/path/to/bom.json -o /absolute/path/to/bom.evinse.json \
  -l go --golem-callgraph static /absolute/path/to/project

cdx-audit --bom /absolute/path/to/bom.evinse.json --direct-bom-audit --categories golem
Call graph modes

--golem-callgraph: none, static (default), cha, rta, vta. Precision and cost both rise across that list. Start with static.

Data-flow modes

--golem-dataflow: none, security, crypto, all. Defaults to all with --with-data-flow, --profile research, or --deep; none otherwise.

Bounded crypto-flow analysis:

bash
evinse -i /absolute/path/to/bom.json -o /absolute/path/to/bom.evinse.crypto.json \
  -l go --with-data-flow \
  --golem-dataflow crypto --golem-dataflow-pattern-packs crypto \
  /absolute/path/to/project
Bounding cost

Go data-flow analysis is the most expensive thing in this skill. Keep it bounded in CI: --golem-dataflow-workers, --golem-max-procs, --golem-memory-limit, --golem-dataflow-max-slices, --golem-dataflow-max-trace-nodes, --golem-dataflow-max-trace-edges, --golem-dataflow-max-function-instructions, --golem-dataflow-large-repo-functions, --golem-dataflow-skip-generated, --golem-dataflow-skip-tests, --golem-progress.

Set explicit limits rather than letting an unbounded run consume a CI runner.

Show full SKILL.md (246 more words)Show less
Reviewing Golem output

Start high, then drill down. In cdxi: .golemsummary, .golemhotspots, .golemcoverage, .golemtips — then .occurrences, .callstack, and .inspect <component>.

For crypto flow, prioritize components with cdx:golem:cryptoDataFlow=true and cdx:golem:cryptoDataFlowCount, then pivot on the rendered cryptographic-asset algorithms.

Golem also surfaces Go-specific supply-chain facts: local replace directives, vendoring and license evidence, usage scopes, and security-sensitive API signals.

The Golem disclosure rule

Never surface raw go:generate commands, environment values, HTTP parameter values, key material, plaintext, ciphertext, embedded file contents, generated source contents, or secrets. Review exclusively through the emitted cdx:golem:* counts, categories, rule IDs, taint kinds, scopes, call-stack frames, crypto algorithm/OID pivots, and module facts.

This is not a style preference. Golem's raw output can contain the secrets it found, and repeating them into a chat transcript or a BOM shared downstream spreads them.

Threat model: https://cdxgen.github.io/cdxgen/#/GO_EVINSE_GOLEM_THREAT_MODEL.

Rust: Rusi

bash
evinse -i /absolute/path/to/bom.json -o /absolute/path/to/bom.evinse.json \
  -l rust --rusi-mode analyze /absolute/path/to/project
FlagChoices
--rusi-modeanalyze (default), cryptos
--rusi-backendstable (default), compiler
--rusi-toolchainauto (default), nightly, stable
--rusi-callgraph, --rusi-dataflow, --rusi-patternsanalysis tuning

Use --rusi-mode cryptos when the question is cryptographic usage rather than general dependency usage.

In cdxi: .cargohotspots and .cargoworkflows.

Reporting evidence honestly

  • Absence of an occurrence is not proof a dependency is unused. Reflection, dynamic dispatch, and generated code defeat static analysis.
  • Say which analysis mode you used. static call graphs miss what vta finds.
  • When Golem or Rusi binaries were unavailable, state that the evidence layer did not run rather than presenting a thinner BOM as complete.

Reference

© cdxgen, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in claude-plugin/skills/bom-evidence of cdxgen/cdxgen.

Open the folder on GitHubat commit e256966

Compare with similar skills

Bom Evidence next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bom Evidence compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bom Evidence this skillcdxgen/cdxgen1.1k—~1.9kAutomated safety check: PassApache-2.0
Cairo Vulnerability Scannertrailofbits/skills7.4k—~3.3kAutomated safety check: PassCC-BY-SA-4.0
Pyspector Security AuditParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0
SkepticRaoFoundation/subtensor389—~660Automated safety check: PassApache-2.0
Constant-Time Analysistrailofbits/skills7.4k—~3.3kAutomated safety check: NotesCC-BY-SA-4.0
Audit Prep Assistanttrailofbits/skills7.4k—~2.5kAutomated safety check: PassCC-BY-SA-4.0

Similar skills

  • Cairo Vulnerability Scanner

    trailofbits/skills

    Official

    Scans Cairo and StarkNet contracts for 6 vulnerability patterns, including felt252 overflow, L1 to L2 messaging faults, address conversion and signature replay.

    7.4k GitHub stars~3.3k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Pyspector Security Audit

    ParzivalHack/PySpector

    Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

    151 GitHub stars~3.5k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Skeptic

    RaoFoundation/subtensor

    Run the security-focused Skeptic persona on the local working tree's diff against a base branch.

    389 GitHub stars~660 tokensUpdated yesterday
    SecurityAuto-check passed
  • Constant-Time Analysis

    trailofbits/skills

    Official

    Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets.

    7.4k GitHub stars~3.3k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Audit Prep Assistant

    trailofbits/skills

    Official

    Gets your own codebase ready for an external security review: sets review goals, runs static analysis, raises test coverage, removes dead code and writes documentation.

    7.4k GitHub stars~2.5k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Phy Regex Audit

    LeoYeAI/openclaw-master-skills

    Static ReDoS (Regular Expression Denial of Service) vulnerability scanner and regex quality auditor for codebases.

    2.2k GitHub stars~5.1k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from cdxgen/cdxgen

All 17 skills in this repo
  • AI Bom

    cdxgen/cdxgen

    Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…

    1.1k GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Bom Audit

    cdxgen/cdxgen

    Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…

    1.1k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Bom Explore

    cdxgen/cdxgen

    Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…

    1.1k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Bom Signing

    cdxgen/cdxgen

    Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures…

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check: warnings
  • Bom Slimmer

    cdxgen/cdxgen

    Reviews a codebase's direct dependencies and designs lightweight, low-risk, zero-dependency custom replacements using cdxgen SBOM evidence, occurrence/callstack usage data, and license and…

    1.1k GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Bom Evidence

What does Bom Evidence do?

Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…. Bom Evidence is an agent skill from cdxgen/cdxgen. Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and produces SaaSBOM service and endpoint inventory.

When should I use Bom Evidence?

Bom Evidence fits situations like: asked which dependencies are actually used; API endpoint inventory; distinguish real from declared dependency usage.

How do I install Bom Evidence in Claude Code?

Run `npx skills add cdxgen/cdxgen --skill bom-evidence -a claude-code`. Or copy the skill folder (claude-plugin/skills/bom-evidence in cdxgen/cdxgen) into .claude/skills/bom-evidence in your project. Claude Code loads it when a task matches its description.

How do I install Bom Evidence in Codex?

Run `npx skills add cdxgen/cdxgen --skill bom-evidence -a codex`. Or copy the skill folder (claude-plugin/skills/bom-evidence in cdxgen/cdxgen) into .agents/skills/bom-evidence in your project. Codex loads it when a task matches its description.

Can I use Bom Evidence in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cdxgen/cdxgen --skill bom-evidence -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bom-evidence, .gemini/skills/bom-evidence, .github/skills/bom-evidence and .opencode/skills/bom-evidence in your project.

What does Bom Evidence need to run?

Going by SKILL.md and its folder, Bom Evidence needs the command-line tools its instructions call (docker). Our summary lists: Node.js; Docker.

Does Bom Evidence access the network?

SKILL.md names 1 domain. As links in the text: cdxgen.github.io. This is read from the text; nothing was executed.

Is Bom Evidence safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bom Evidence use?

Bom Evidence is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bom Evidence use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bom Evidence?

Skills that share tags, products or a category with Bom Evidence: Cairo Vulnerability Scanner (trailofbits/skills, 7.4k stars), Pyspector Security Audit (ParzivalHack/PySpector, 151 stars), Skeptic (RaoFoundation/subtensor, 389 stars) and Constant-Time Analysis (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bom Evidence?

cdxgen (a GitHub organization) maintains it in cdxgen/cdxgen, which has 1,085 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 8, 2026.

Source: cdxgen/cdxgen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.