Agent skill

Container Sbom

by cdxgen in cdxgen/cdxgen

Generates CycloneDX BOMs for container images, OCI archives, mounted root filesystems, Electron ASAR archives, caxa executables, binaries, and Kubernetes or Dockerfile manifests using OWASP cdxgen…

Apache-2.0Auto-check passedDevOps & Cloud

Install Container Sbom

skills CLI
$ npx skills add cdxgen/cdxgen --skill container-sbom -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cdxgen/cdxgen container-sbom --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude-plugin/skills/container-sbom .claude/skills/container-sbom && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
container-sbom
GitHub stars
1.1k
Token cost
~1.5k tokens
SKILL.md length
584 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
Apache-2.0

At a glance

Generates CycloneDX BOMs for container images, OCI archives, mounted root filesystems, Electron ASAR archives, caxa executables, binaries, and Kubernetes or Dockerfile manifests using OWASP cdxgen…

  • Asked to scan a Docker
  • SKILL.md covers Container images, Mounted or reconstructed root…, What container and rootfs… and Enrichment from optional…, plus 6 more sections
  • Calls docker
  • Produce an SBOM for a container

What it does

Container Sbom is an agent skill from cdxgen/cdxgen. Generates CycloneDX BOMs for container images, OCI archives, mounted root filesystems, Electron ASAR archives, caxa executables, binaries, and Kubernetes or Dockerfile manifests using OWASP cdxgen post-build scanning. Use when asked to scan a Docker or OCI image, produce an SBOM for a container or golden image, inventory a rootfs, audit a packaged Electron app, or analyse Dockerfiles and Kubernetes manifests.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Containers and Supply chain security. It works with Docker, Kubernetes and Electron. The repository describes itself as: Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with…. The licence is Apache-2.0.

When your agent uses it

  • Asked to scan a Docker
  • Produce an SBOM for a container
  • Inventory a rootfs
  • Audit a packaged Electron app

Example prompts

  • “Use the container-sbom skill to generate CycloneDX BOMs for container images, OCI archives, mounted root filesystems, Electron ASAR archives, caxa…”
  • “/container-sbom”

Requirements

  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit 5497d57. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Container Sbom loads about 1.5k tokens when it runs. Until then it costs about 107 tokens; SKILL.md has 584 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cdxgen/cdxgen at commit 5497d57, republished under its Apache-2.0 licence (© cdxgen). 584 words, ~1,472 tokens.

Download SKILL.mdSave it as .claude/skills/container-sbom/SKILL.md (or your agent's skills folder).
name
container-sbom
description
Generates CycloneDX BOMs for container images, OCI archives, mounted root filesystems, Electron ASAR archives, caxa executables, binaries, and Kubernetes or Dockerfile manifests using OWASP cdxgen post-build scanning. Use when asked to scan a Docker or OCI image, produce an SBOM for a container or golden image, inventory a rootfs, audit a packaged Electron app, or analyse Dockerfiles and Kubernetes manifests.

Container, image, and binary BOMs

Use this skill when the target is a built artifact rather than a source tree. For source repositories use sbom-generate; for a live running host use os-hardware-inventory.

Read reference/safety.md first.

Container images

bash
cdxgen -t docker myimage:latest -o /absolute/path/to/bom.json

Types oci, docker, podman, container, and oci-dir all reach the same pipeline. Use oci-dir for an unpacked OCI layout on disk.

Container scans belong to the post-build lifecycle. cdxgen sets that automatically for image targets, but pass it explicitly when scripting:

bash
cdxgen -t oci --lifecycle post-build myimage:latest -o /absolute/path/to/bom.json

Mounted or reconstructed root filesystems

bash
cdxgen /absolute/path/to/rootfs -t rootfs -o /absolute/path/to/bom.json

This is the right approach for golden images, forensic mounts, and any host you cannot run osquery on. Add a hardening review without needing live collection:

bash
cdxgen /absolute/path/to/rootfs -t rootfs \
  --bom-audit --bom-audit-categories rootfs-hardening \
  -o /absolute/path/to/bom.json

The rootfs-hardening category checks repository trust, privileged helpers, and service drift offline.

What container and rootfs scans include beyond packages

These scans are deliberately broader than a package list. Expect:

  • OS package components with purls
  • package-owned files and installed commands
  • repository source records, modelled as ordinary data components
  • trusted keys and certificates, modelled as cryptographic-asset components — these do not have purls, so do not treat a missing purl as a defect
  • cdx:container:unpackagedExecutableCount and cdx:container:unpackagedSharedLibraryCount metadata properties

Those last two matter: they count native files that could not be traced to any OS package. A high count means the image ships binaries outside package management, which is worth surfacing to the user.

In cdxi, isolate them with .unpackagedbins and .unpackagedlibs (see bom-explore).

Enrichment from optional binaries

When @cdxgen/cdxgen-plugins-bin is installed, container and rootfs scans gain Trivy-powered package metadata, Linux GTFOBins runtime context, platform trust posture, and — via trustinspector — macOS code-signing/notarization and Windows Authenticode/WDAC properties across large path inventories.

When those binaries are absent the BOM is still valid, just less enriched. Say that plainly rather than reporting a failure.

Electron ASAR archives

bash
cdxgen -t asar /absolute/path/to/app.asar \
  --bom-audit --bom-audit-categories asar-archive \
  -o /absolute/path/to/bom.json

Prefer -t asar (aliases electron, electron-asar) for packaged Electron releases: it adds archive file inventory, integrity verification, and analysis of the embedded Node manifest, none of which appear if you scan the surrounding directory as a plain JavaScript project.

Show full SKILL.md (255 more words)Show less

caxa executables

bash
cdxgen -t caxa /absolute/path/to/dir-with-metadata -o /absolute/path/to/bom.json

Reads the *metadata.json file that caxa writes next to a binary when it builds it (--metadata-file, default binary-metadata.json); the binary itself carries no BOM, so pointing -t caxa at it finds nothing. Add --caxa-app-dir <extracted app> to also record the native tools, the vendored PHP, Ruby and Java packages, and the npm hashes found in the app the binary extracts.

Binaries without a package manager

Several types accept a compiled binary directly rather than a manifest: go, rust, csharp/dotnet, and jar/war/ear. Evidence quality is lower than a lockfile scan — component identity comes from what is embedded in the binary.

bash
cdxgen -t go /absolute/path/to/compiled-binary -o /absolute/path/to/bom.json

Cache-scanning types inventory a build cache rather than one project: maven-cache, gradle-cache, sbt-cache, cargo-cache, helm-index.

Container and orchestration manifests

For declared images rather than built ones:

bash
cdxgen -t containerfile /absolute/path/to/project -o /absolute/path/to/bom.json

Covers dockerfile, containerfile, docker-compose, kubernetes, openshift, kustomize, skaffold, swarm, tekton, operator, yaml-manifest, and universal. These describe intended images, so the BOM records references, not resolved layer contents. Use an image scan when the user needs what actually shipped.

Container-specific audit categories

bash
cdxgen -t oci myimage:latest \
  --bom-audit --bom-audit-categories container-risk \
  -o /absolute/path/to/bom.json

Relevant categories here: container-risk, rootfs-hardening, asar-archive, package-integrity, dependency-source. See bom-audit.

Practical notes

  • --deep improves OS and OCI parsing but costs time; enable it when the user cares about completeness over speed.
  • Image scans need the image present locally or pullable. Confirm registry access before blaming cdxgen.
  • The cdxgen container image is often the easier path for scanning images, since the helper binaries are preinstalled: docker run --rm -v $(pwd):/app:rw -t ghcr.io/cdxgen/cdxgen:master /app.
  • For golden-image and offline host review, prefer the rootfs + rootfs-hardening combination over attempting live collection.

© cdxgen, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in claude-plugin/skills/container-sbom of cdxgen/cdxgen.

Open the folder on GitHubat commit 5497d57

Compare with similar skills

Container Sbom next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Container Sbom compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Container Sbom this skillcdxgen/cdxgen1.1k—~1.5kAutomated safety check: PassApache-2.0
CI/CD Pipeline Principlesirahardianto/awesome-agv157—~2.7kAutomated safety check: NotesMIT
Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.0
Container Securityhardw00t/ai-security-arsenal104—~2.8kAutomated safety check: PassNone
Sca TrivyAgentSecOps/SecOpsAgentKit2192 repos~3.7kAutomated safety check: PassCustom licence
Container Security Hardeningsickn33/agentic-awesome-skills47k1 repos~1kAutomated safety check: NotesMIT

Similar skills

  • CI/CD Pipeline Principles

    irahardianto/awesome-agv

    Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.

    157 GitHub stars~2.7k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Performing Container Security Scanning With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

    34k GitHub stars~818 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    104 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    219 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • Container Security Hardening

    sickn33/agentic-awesome-skills

    Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.

    47k GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check: notes
  • Alibabacloud Ecs Sec Userspace

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。

    148 GitHub stars~2.6k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes

More from cdxgen/cdxgen

All 17 skills in this repo
  • AI Bom

    cdxgen/cdxgen

    Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…

    1.1k GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Bom Audit

    cdxgen/cdxgen

    Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…

    1.1k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Bom Evidence

    cdxgen/cdxgen

    Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…

    1.1k GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Bom Explore

    cdxgen/cdxgen

    Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…

    1.1k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Bom Signing

    cdxgen/cdxgen

    Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures…

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check: warnings

Questions about Container Sbom

What does Container Sbom do?

Generates CycloneDX BOMs for container images, OCI archives, mounted root filesystems, Electron ASAR archives, caxa executables, binaries, and Kubernetes or Dockerfile manifests using OWASP cdxgen…. Container Sbom is an agent skill from cdxgen/cdxgen. Generates CycloneDX BOMs for container images, OCI archives, mounted root filesystems, Electron ASAR archives, caxa executables, binaries, and Kubernetes or Dockerfile manifests using OWASP cdxgen post-build scanning.

When should I use Container Sbom?

Container Sbom fits situations like: asked to scan a Docker; produce an SBOM for a container; inventory a rootfs; audit a packaged Electron app.

How do I install Container Sbom in Claude Code?

Run `npx skills add cdxgen/cdxgen --skill container-sbom -a claude-code`. Or copy the skill folder (claude-plugin/skills/container-sbom in cdxgen/cdxgen) into .claude/skills/container-sbom in your project. Claude Code loads it when a task matches its description.

How do I install Container Sbom in Codex?

Run `npx skills add cdxgen/cdxgen --skill container-sbom -a codex`. Or copy the skill folder (claude-plugin/skills/container-sbom in cdxgen/cdxgen) into .agents/skills/container-sbom in your project. Codex loads it when a task matches its description.

Can I use Container Sbom in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cdxgen/cdxgen --skill container-sbom -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/container-sbom, .gemini/skills/container-sbom, .github/skills/container-sbom and .opencode/skills/container-sbom in your project.

What does Container Sbom need to run?

Going by SKILL.md and its folder, Container Sbom needs the command-line tools its instructions call (docker). Our summary lists: Docker.

Does Container Sbom access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Container Sbom safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Container Sbom use?

Container Sbom is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Container Sbom use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Container Sbom?

Skills that share tags, products or a category with Container Sbom: CI/CD Pipeline Principles (irahardianto/awesome-agv, 157 stars), Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Container Security (hardw00t/ai-security-arsenal, 104 stars) and Sca Trivy (AgentSecOps/SecOpsAgentKit, 219 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Container Sbom?

cdxgen (a GitHub organization) maintains it in cdxgen/cdxgen, which has 1,085 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 6, 2026.

Source: cdxgen/cdxgen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.