Agent skill

Custom Property Author

by cdxgen in cdxgen/cdxgen

Guides defining and emitting new CycloneDX cdx: custom properties in cdxgen output, enforcing namespacing, safe value shapes (booleans, counts, categories instead of raw secrets, URLs, or commands)…

Apache-2.0Auto-check passedSecurity

Install Custom Property Author

skills CLI
$ npx skills add cdxgen/cdxgen --skill custom-property-author -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cdxgen/cdxgen custom-property-author --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/custom-property-author .claude/skills/custom-property-author && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
custom-property-author
GitHub stars
1.1k
Token cost
~964 tokens
SKILL.md length
415 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides defining and emitting new CycloneDX cdx: custom properties in cdxgen output, enforcing namespacing, safe value shapes (booleans, counts, categories instead of raw secrets, URLs, or commands)…

  • Works in 3 steps: Add it to the appropriate… → Add or extend a test asserting the new… → If the property creates an analyst…
  • Internal: properties on components
  • SKILL.md covers Gate 0: prefer standard…, Gate 1: naming, Gate 2: value hygiene and Gate 3: documentation…, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Custom Property Author is an agent skill from cdxgen/cdxgen. Guides defining and emitting new CycloneDX cdx: custom properties in cdxgen output, enforcing namespacing, safe value shapes (booleans, counts, categories instead of raw secrets, URLs, or commands), and the mandatory docs/CUSTOMPROPERTIES.md documentation gate. Use when adding, changing, or reviewing cdx: or internal: properties on components, metadata, services, or evidence.

Its SKILL.md is about 960 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. The repository describes itself as: Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with…. The licence is Apache-2.0.

When your agent uses it

  • Internal: properties on components

Example prompts

  • “Use the custom-property-author skill to guide defining and emitting new CycloneDX cdx: custom properties in cdxgen output, enforcing namespacing…”
  • “/custom-property-author”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Add it to the appropriate property-family table (or inventory section) in docs/CUSTOM_PROPERTIES.md, with the value shape and a…
  2. Add or extend a test asserting the new property is emitted as expected and that secrets are not copied into it.
  3. If the property creates an analyst pivot, check companion surfaces that stay aligned: BOM audit rules in data/rules/*.yaml…

What it can do on your machine

Read from SKILL.md and the folder at commit e256966. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Custom Property Author loads about 964 tokens when it runs. Until then it costs about 101 tokens; SKILL.md has 415 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~101
When it runs · the whole SKILL.md, loaded when a task matches
~964

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cdxgen/cdxgen at commit e256966, republished under its Apache-2.0 licence (© cdxgen). 415 words, ~964 tokens.

Download SKILL.mdSave it as .claude/skills/custom-property-author/SKILL.md (or your agent's skills folder).
name
custom-property-author
description
Guides defining and emitting new CycloneDX cdx: custom properties in cdxgen output, enforcing namespacing, safe value shapes (booleans, counts, categories instead of raw secrets, URLs, or commands), and the mandatory docs/CUSTOM_PROPERTIES.md documentation gate. Use when adding, changing, or reviewing cdx: or internal: properties on components, metadata, services, or evidence.

Custom property author

Use this skill when adding or changing any cdx:* (or internal:*) property emitted into BOM output. The full property inventory and policy guidance is docs/CUSTOM_PROPERTIES.md.

Gate 0: prefer standard CycloneDX fields first

A custom property is a last resort. Before adding one, check whether the data fits a standard field:

  • supplier, manufacturer, authors, publisher — entity data
  • externalReferences — URLs
  • evidence.identity, evidence.occurrences — where a component was found
  • pedigree — lineage
  • hashes — digests (never a property)
  • licenses, scope — licensing and dependency scope
  • modelCard, formulation, component.data — AI/ML data

If a standard field works, use it. If a custom property is still necessary, it needs a clear namespace and a narrow purpose.

Gate 1: naming

  • New properties use the cdx:<ecosystem-or-context>:<field> convention (e.g. cdx:npm:hasInstallScript, cdx:github:workflow:triggers).
  • Legacy unnamespaced properties were migrated to the internal: prefix; do not add new unnamespaced properties, and treat internal:* as unstable implementation detail.
  • oci: and java:modules keep their existing namespaces for historical reasons.

Gate 2: value hygiene

Treat every value as potentially secret-bearing. CycloneDX serializes all property values as strings.

EmitDo NOT emit
Booleans: credentialExposure=trueRaw tokens, passwords, API keys, cookies, session IDs, private keys
Counts: credentialIndicatorCount=3Raw environment variable values or command-line arguments
Categories/field labels: header:AuthorizationThe actual header/parameter values
Safe URL derivatives: scheme, host, basenameURLs with query strings, fragments, userinfo, or signature params (token, sig, X-Amz-Signature, api_key, …)
Redacted markers or executable name onlyFull command lines, generated source contents, embedded file contents

Value shapes already in use (keep consistent): booleans as "true"/"false", numbers as decimal strings, component-level lists comma-separated, BOM-level metadata lists newline-separated, timestamps as ISO 8601, structured payloads as JSON-serialized strings.

Show full SKILL.md (149 more words)Show less

Gate 3: documentation (build-breaking)

lib/customProperties.poku.js scans every string literal matching cdx:... in non-test lib/**/*.js and fails the build if the property is absent from docs/CUSTOM_PROPERTIES.md. When adding a property:

  1. Add it to the appropriate property-family table (or inventory section) in docs/CUSTOM_PROPERTIES.md, with the value shape and a policy-readiness label (hard deny / warning / context only).
  2. Add or extend a test asserting the new property is emitted as expected and that secrets are not copied into it.
  3. If the property creates an analyst pivot, check companion surfaces that stay aligned: BOM audit rules in data/rules/*.yaml, docs/BOM_AUDIT.md, and bin/repl.js commands.

Review quick-check

  • Unnamespaced or new internal: property? Reject.
  • Duplicates a standard CycloneDX field? Move to the standard field.
  • Host-specific, non-reproducible, absolute local paths? Reject or redact.
  • Structured data packed into CSV when a structured field exists? Reject.
  • Secret-bearing value (even namespaced)? Replace with a count, boolean, host, or enum.

© cdxgen, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/custom-property-author of cdxgen/cdxgen.

Open the folder on GitHubat commit e256966

Compare with similar skills

Custom Property Author next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Custom Property Author compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Custom Property Author this skillcdxgen/cdxgen1.1k—~964Automated safety check: PassApache-2.0
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4811 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated today
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    481 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed

More from cdxgen/cdxgen

All 17 skills in this repo
  • AI Bom

    cdxgen/cdxgen

    Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…

    1.1k GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Bom Audit

    cdxgen/cdxgen

    Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…

    1.1k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Bom Evidence

    cdxgen/cdxgen

    Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…

    1.1k GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Bom Explore

    cdxgen/cdxgen

    Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…

    1.1k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Bom Signing

    cdxgen/cdxgen

    Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures…

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check: warnings

Categories

Questions about Custom Property Author

What does Custom Property Author do?

Guides defining and emitting new CycloneDX cdx: custom properties in cdxgen output, enforcing namespacing, safe value shapes (booleans, counts, categories instead of raw secrets, URLs, or commands)…. Custom Property Author is an agent skill from cdxgen/cdxgen.md documentation gate.

When should I use Custom Property Author?

Custom Property Author fits situations like: internal: properties on components.

How do I install Custom Property Author in Claude Code?

Run `npx skills add cdxgen/cdxgen --skill custom-property-author -a claude-code`. Or copy the skill folder (.agents/skills/custom-property-author in cdxgen/cdxgen) into .claude/skills/custom-property-author in your project. Claude Code loads it when a task matches its description.

How do I install Custom Property Author in Codex?

Run `npx skills add cdxgen/cdxgen --skill custom-property-author -a codex`. Or copy the skill folder (.agents/skills/custom-property-author in cdxgen/cdxgen) into .agents/skills/custom-property-author in your project. Codex loads it when a task matches its description.

Can I use Custom Property Author in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cdxgen/cdxgen --skill custom-property-author -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/custom-property-author, .gemini/skills/custom-property-author, .github/skills/custom-property-author and .opencode/skills/custom-property-author in your project.

What does Custom Property Author need to run?

SKILL.md names no scripts, command-line tools or credentials: Custom Property Author is instructions for the agent only.

Does Custom Property Author access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Custom Property Author safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Custom Property Author use?

Custom Property Author is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Custom Property Author use?

About 964 tokens (SKILL.md is roughly 3.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Custom Property Author?

Skills that share tags, products or a category with Custom Property Author: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Custom Property Author?

cdxgen (a GitHub organization) maintains it in cdxgen/cdxgen, which has 1,085 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 8, 2026.

Source: cdxgen/cdxgen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.