CI/CD Pipeline Principles
irahardianto/awesome-agv
Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.
Generates CycloneDX BOMs for container images, OCI archives, mounted root filesystems, Electron ASAR archives, caxa executables, binaries, and Kubernetes or Dockerfile manifests using OWASP cdxgen…
$ npx skills add cdxgen/cdxgen --skill container-sbom -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install cdxgen/cdxgen container-sbom --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude-plugin/skills/container-sbom .claude/skills/container-sbom && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "container-sbom" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/container-sbom into .claude/skills/container-sbom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "container-sbom", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/container-sbomType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add cdxgen/cdxgen --skill container-sbom -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install cdxgen/cdxgen container-sbom --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .agents/skills && cp -r skills-src/claude-plugin/skills/container-sbom .agents/skills/container-sbom && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "container-sbom" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/container-sbom into .agents/skills/container-sbom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "container-sbom", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cdxgen/cdxgen --skill container-sbom -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install cdxgen/cdxgen container-sbom --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/claude-plugin/skills/container-sbom .cursor/skills/container-sbom && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "container-sbom" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/container-sbom into .cursor/skills/container-sbom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "container-sbom", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/cdxgen/cdxgen.git --path claude-plugin/skills/container-sbom--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add cdxgen/cdxgen --skill container-sbom -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install cdxgen/cdxgen container-sbom --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/claude-plugin/skills/container-sbom .gemini/skills/container-sbom && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "container-sbom" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/container-sbom into .gemini/skills/container-sbom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "container-sbom", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install cdxgen/cdxgen container-sbomInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add cdxgen/cdxgen --skill container-sbom -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .github/skills && cp -r skills-src/claude-plugin/skills/container-sbom .github/skills/container-sbom && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "container-sbom" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/container-sbom into .github/skills/container-sbom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "container-sbom", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cdxgen/cdxgen --skill container-sbom -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install cdxgen/cdxgen container-sbom --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/claude-plugin/skills/container-sbom .opencode/skills/container-sbom && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "container-sbom" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/container-sbom into .opencode/skills/container-sbom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "container-sbom", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
container-sbomGenerates CycloneDX BOMs for container images, OCI archives, mounted root filesystems, Electron ASAR archives, caxa executables, binaries, and Kubernetes or Dockerfile manifests using OWASP cdxgen…
Container Sbom is an agent skill from cdxgen/cdxgen. Generates CycloneDX BOMs for container images, OCI archives, mounted root filesystems, Electron ASAR archives, caxa executables, binaries, and Kubernetes or Dockerfile manifests using OWASP cdxgen post-build scanning. Use when asked to scan a Docker or OCI image, produce an SBOM for a container or golden image, inventory a rootfs, audit a packaged Electron app, or analyse Dockerfiles and Kubernetes manifests.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Containers and Supply chain security. It works with Docker, Kubernetes and Electron. The repository describes itself as: Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with…. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 5497d57. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
dockerFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Container Sbom loads about 1.5k tokens when it runs. Until then it costs about 107 tokens; SKILL.md has 584 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from cdxgen/cdxgen at commit 5497d57, republished under its Apache-2.0 licence (© cdxgen). 584 words, ~1,472 tokens.
.claude/skills/container-sbom/SKILL.md (or your agent's skills folder).Use this skill when the target is a built artifact rather than a source tree.
For source repositories use sbom-generate; for a live running host use
os-hardware-inventory.
Read reference/safety.md first.
cdxgen -t docker myimage:latest -o /absolute/path/to/bom.jsonTypes oci, docker, podman, container, and oci-dir all reach the same
pipeline. Use oci-dir for an unpacked OCI layout on disk.
Container scans belong to the post-build lifecycle. cdxgen sets that
automatically for image targets, but pass it explicitly when scripting:
cdxgen -t oci --lifecycle post-build myimage:latest -o /absolute/path/to/bom.jsoncdxgen /absolute/path/to/rootfs -t rootfs -o /absolute/path/to/bom.jsonThis is the right approach for golden images, forensic mounts, and any host you cannot run osquery on. Add a hardening review without needing live collection:
cdxgen /absolute/path/to/rootfs -t rootfs \
--bom-audit --bom-audit-categories rootfs-hardening \
-o /absolute/path/to/bom.jsonThe rootfs-hardening category checks repository trust, privileged helpers, and
service drift offline.
These scans are deliberately broader than a package list. Expect:
data componentscryptographic-asset components — these do not have purls, so do not treat a missing purl as a defectcdx:container:unpackagedExecutableCount and cdx:container:unpackagedSharedLibraryCount metadata propertiesThose last two matter: they count native files that could not be traced to any OS package. A high count means the image ships binaries outside package management, which is worth surfacing to the user.
In cdxi, isolate them with .unpackagedbins and .unpackagedlibs
(see bom-explore).
When @cdxgen/cdxgen-plugins-bin is installed, container and rootfs scans gain
Trivy-powered package metadata, Linux GTFOBins runtime context, platform trust
posture, and — via trustinspector — macOS code-signing/notarization and
Windows Authenticode/WDAC properties across large path inventories.
When those binaries are absent the BOM is still valid, just less enriched. Say that plainly rather than reporting a failure.
cdxgen -t asar /absolute/path/to/app.asar \
--bom-audit --bom-audit-categories asar-archive \
-o /absolute/path/to/bom.jsonPrefer -t asar (aliases electron, electron-asar) for packaged Electron
releases: it adds archive file inventory, integrity verification, and analysis
of the embedded Node manifest, none of which appear if you scan the surrounding
directory as a plain JavaScript project.
cdxgen -t caxa /absolute/path/to/dir-with-metadata -o /absolute/path/to/bom.jsonReads the *metadata.json file that caxa writes next to a binary when it builds
it (--metadata-file, default binary-metadata.json); the binary itself
carries no BOM, so pointing -t caxa at it finds nothing. Add
--caxa-app-dir <extracted app> to also record the native tools, the vendored
PHP, Ruby and Java packages, and the npm hashes found in the app the binary
extracts.
Several types accept a compiled binary directly rather than a manifest: go,
rust, csharp/dotnet, and jar/war/ear. Evidence quality is lower than
a lockfile scan — component identity comes from what is embedded in the binary.
cdxgen -t go /absolute/path/to/compiled-binary -o /absolute/path/to/bom.jsonCache-scanning types inventory a build cache rather than one project:
maven-cache, gradle-cache, sbt-cache, cargo-cache, helm-index.
For declared images rather than built ones:
cdxgen -t containerfile /absolute/path/to/project -o /absolute/path/to/bom.jsonCovers dockerfile, containerfile, docker-compose, kubernetes,
openshift, kustomize, skaffold, swarm, tekton, operator,
yaml-manifest, and universal. These describe intended images, so the BOM
records references, not resolved layer contents. Use an image scan when the
user needs what actually shipped.
cdxgen -t oci myimage:latest \
--bom-audit --bom-audit-categories container-risk \
-o /absolute/path/to/bom.jsonRelevant categories here: container-risk, rootfs-hardening,
asar-archive, package-integrity, dependency-source. See bom-audit.
--deep improves OS and OCI parsing but costs time; enable it when the user cares about completeness over speed.docker run --rm -v $(pwd):/app:rw -t ghcr.io/cdxgen/cdxgen:master /app.rootfs + rootfs-hardening combination over attempting live collection.© cdxgen, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in claude-plugin/skills/container-sbom of cdxgen/cdxgen.
Open the folder on GitHubat commit 5497d57
Container Sbom next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Container Sbom this skillcdxgen/cdxgen | 1.1k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| CI/CD Pipeline Principlesirahardianto/awesome-agv | 157 | — | ~2.7k | Automated safety check: Notes | MIT | |
| Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~818 | Automated safety check: Pass | Apache-2.0 | |
| Container Securityhardw00t/ai-security-arsenal | 104 | — | ~2.8k | Automated safety check: Pass | None | |
| Sca TrivyAgentSecOps/SecOpsAgentKit | 219 | 2 repos | ~3.7k | Automated safety check: Pass | Custom licence | |
| Container Security Hardeningsickn33/agentic-awesome-skills | 47k | 1 repos | ~1k | Automated safety check: Notes | MIT |
irahardianto/awesome-agv
Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.
mukul975/Anthropic-Cybersecurity-Skills
Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…
hardw00t/ai-security-arsenal
Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…
AgentSecOps/SecOpsAgentKit
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…
sickn33/agentic-awesome-skills
Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.
aliyun/alibabacloud-ecs-troubleshoot-skills
Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。
cdxgen/cdxgen
Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…
cdxgen/cdxgen
Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…
cdxgen/cdxgen
Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…
cdxgen/cdxgen
Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…
cdxgen/cdxgen
Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures…
cdxgen/cdxgen
Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…
Works with
Categories
Generates CycloneDX BOMs for container images, OCI archives, mounted root filesystems, Electron ASAR archives, caxa executables, binaries, and Kubernetes or Dockerfile manifests using OWASP cdxgen…. Container Sbom is an agent skill from cdxgen/cdxgen. Generates CycloneDX BOMs for container images, OCI archives, mounted root filesystems, Electron ASAR archives, caxa executables, binaries, and Kubernetes or Dockerfile manifests using OWASP cdxgen post-build scanning.
Container Sbom fits situations like: asked to scan a Docker; produce an SBOM for a container; inventory a rootfs; audit a packaged Electron app.
Run `npx skills add cdxgen/cdxgen --skill container-sbom -a claude-code`. Or copy the skill folder (claude-plugin/skills/container-sbom in cdxgen/cdxgen) into .claude/skills/container-sbom in your project. Claude Code loads it when a task matches its description.
Run `npx skills add cdxgen/cdxgen --skill container-sbom -a codex`. Or copy the skill folder (claude-plugin/skills/container-sbom in cdxgen/cdxgen) into .agents/skills/container-sbom in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cdxgen/cdxgen --skill container-sbom -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/container-sbom, .gemini/skills/container-sbom, .github/skills/container-sbom and .opencode/skills/container-sbom in your project.
Going by SKILL.md and its folder, Container Sbom needs the command-line tools its instructions call (docker). Our summary lists: Docker.
SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Container Sbom is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Container Sbom: CI/CD Pipeline Principles (irahardianto/awesome-agv, 157 stars), Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Container Security (hardw00t/ai-security-arsenal, 104 stars) and Sca Trivy (AgentSecOps/SecOpsAgentKit, 219 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
cdxgen (a GitHub organization) maintains it in cdxgen/cdxgen, which has 1,085 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 6, 2026.
Source: cdxgen/cdxgen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.