Agent skill

Cyclonedx Spec Reviewer

by cdxgen in cdxgen/cdxgen

Reviews cdxgen changes for CycloneDX schema compliance, semantic field correctness, and unnecessary custom properties across spec versions 1.5 through 2.0, including AI-BOM modeling via formulation…

Apache-2.0Auto-check passedDevelopment

Install Cyclonedx Spec Reviewer

skills CLI
$ npx skills add cdxgen/cdxgen --skill cyclonedx-spec-reviewer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cdxgen/cdxgen cyclonedx-spec-reviewer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/cyclonedx-spec-reviewer .claude/skills/cyclonedx-spec-reviewer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cyclonedx-spec-reviewer
GitHub stars
1.1k
Token cost
~2.5k tokens
SKILL.md length
1,193 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
Apache-2.0

At a glance

Reviews cdxgen changes for CycloneDX schema compliance, semantic field correctness, and unnecessary custom properties across spec versions 1.5 through 2.0, including AI-BOM modeling via formulation…

  • Works in 5 steps: Prefer standard fields over custom… → Reject ambiguous or risky custom… → Check semantic field use → …
  • A pull request changes CycloneDX output
  • SKILL.md covers Sources of truth, AI-BOM focus areas, What to check and Review procedure, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Cyclonedx Spec Reviewer is an agent skill from cdxgen/cdxgen. Reviews cdxgen changes for CycloneDX schema compliance, semantic field correctness, and unnecessary custom properties across spec versions 1.5 through 2.0, including AI-BOM modeling via formulation, modelCard, pedigree, and evidence. Use when a pull request changes CycloneDX output, schema handling, validators, package-manager integrations, BOM enrichment, or custom properties.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Pull requests. The repository describes itself as: Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with…. The licence is Apache-2.0.

When your agent uses it

  • A pull request changes CycloneDX output
  • Schema handling
  • Package-manager integrations
  • Custom properties

Example prompts

  • “Use the cyclonedx-spec-reviewer skill to review cdxgen changes for CycloneDX schema compliance, semantic field correctness, and unnecessary custom…”
  • “/cyclonedx-spec-reviewer”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Prefer standard fields over custom properties
  2. Reject ambiguous or risky custom properties
  3. Check semantic field use
  4. Check new ecosystem/package-manager integrations
  5. Check AI-BOM and AI/ML modeling

What it can do on your machine

Read from SKILL.md and the folder at commit eb00071. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cyclonedx Spec Reviewer loads about 2.5k tokens when it runs. Until then it costs about 101 tokens; SKILL.md has 1,193 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~101
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cdxgen/cdxgen at commit eb00071, republished under its Apache-2.0 licence (© cdxgen). 1,193 words, ~2,477 tokens.

Download SKILL.mdSave it as .claude/skills/cyclonedx-spec-reviewer/SKILL.md (or your agent's skills folder).
name
cyclonedx-spec-reviewer
description
Reviews cdxgen changes for CycloneDX schema compliance, semantic field correctness, and unnecessary custom properties across spec versions 1.5 through 2.0, including AI-BOM modeling via formulation, modelCard, pedigree, and evidence. Use when a pull request changes CycloneDX output, schema handling, validators, package-manager integrations, BOM enrichment, or custom properties.

CycloneDX specification reviewer

Use this skill when a pull request changes CycloneDX output, schema handling, validators, package-manager integrations, BOM enrichment, or custom properties.

Sources of truth

Review in this order:

  1. Local schemas in data/bom-1.5.schema.json, data/bom-1.6.schema.json, data/bom-1.7.schema.json
  2. Other local schemas when relevant, especially data/cyclonedx-2.0-bundled.schema.json
  3. Official CycloneDX documentation and property-taxonomy guidance

JSON-schema validity is only the starting point. Also review semantic correctness.

AI-BOM focus areas

When a change introduces AI-BOM, model inventory, prompt/config discovery, or agent/MCP inventory, explicitly review the standard AI/ML fields already present in CycloneDX 1.5, 1.6, 1.7, and 2.0.

  • formulation
  • pedigree
  • modelCard
  • data components and componentData
  • services
  • evidence
  • externalReferences

Treat AI-BOM as CycloneDX-first modeling, not as permission to shift standard semantics into custom properties.

What to check

1. Prefer standard fields over custom properties

Flag a change when it introduces or preserves a custom property for data that already fits a standard field such as:

  • supplier, manufacturer, authors, publisher
  • externalReferences
  • evidence.identity
  • evidence.occurrences
  • pedigree
  • hashes
  • licenses
  • scope
  • properties registered in public taxonomy when applicable

If a custom property is still necessary, require a clear namespace and a narrow purpose.

2. Reject ambiguous or risky custom properties

Flag custom properties that are:

  • unnamespaced
  • duplicates of existing CycloneDX fields
  • host-specific or non-reproducible
  • likely to leak local paths, usernames, secrets, or environment-specific details
  • packing structured data into comma-delimited strings when a structured field exists
  • likely to confuse downstream consumers about meaning
3. Check semantic field use

Review whether attributes are used for the right purpose:

  • manufacturer for the entity that created the component
  • supplier for the entity that supplied or distributed it
  • authors for people, not organizations
  • deprecated author only as a compatibility holdover and preferably not in new output
  • publisher only when publication semantics are actually intended
  • externalReferences[].type matches the URL purpose
  • scope is semantically correct for required, optional, excluded, or runtime-only style data
  • bom-ref values are unique and resolvable
4. Check new ecosystem/package-manager integrations

When a PR adds or changes ecosystem support, check whether emitted components and services are missing expected data that cdxgen can usually infer:

  • stable bom-ref
  • type, name, version
  • purl when a native package identity exists
  • dependency edges
  • hashes when resolved artifacts or lockfile integrity data are available
  • licenses when manifest or registry metadata provides them
  • externalReferences for distribution or VCS when directly available
  • evidence fields when provenance or file-location evidence is collected

Flag missing data as a gap when the source material is already available to the integration.

5. Check AI-BOM and AI/ML modeling

Review whether AI-related output uses the standard CycloneDX AI/ML structures correctly:

  • formulation should describe how something was created, trained, assembled, deployed, or otherwise brought into its current form. Do not treat it as a generic dumping ground for unrelated inventory.
  • formulation.workflows, tasks, and steps should represent real process information. If the PR only discovered runtime usage or file-level evidence, verify that this is not being overstated as build/training lineage.
  • machine-learning-model components should prefer modelCard for task, architecture, datasets, and metrics.
  • training or evaluation datasets should prefer modelCard.modelParameters.datasets, ideally via ref to stable type: data components when the BOM already has a stable dataset identity.
  • model lineage such as fine-tunes, distillations, adapters, merges, and quantized derivatives should prefer pedigree.ancestors, pedigree.variants, commits, or patches. Notes may supplement this but should not be the only place where lineage is captured when a structured relation is known.
  • inference endpoints belong in services, not components.
  • prompt files, agent instructions, model config files, and notebooks are usually best represented as file components plus evidence, unless the spec clearly supports a richer standard structure.
  • component.data must only be present for type: data components.
  • component.modelCard should only be present for type: machine-learning-model.
  • service evidence and any 2.0-only structures must be reviewed for spec-version downgrade behavior so that 1.5/1.6/1.7 output does not silently become semantically misleading.

Also review AI-specific custom properties carefully. A namespaced property is still a finding if it duplicates a standard field that now exists in the schema.

Show full SKILL.md (541 more words)Show less

Review procedure

  1. Identify the spec version(s) affected by the change.
  2. Compare changed output fields against the local schema definitions.
  3. Check whether any new custom property could be replaced by a standard field.
  4. Check whether any deprecated field is newly introduced or expanded.
  5. Check whether any new package-manager integration omits expected attributes that cdxgen already emits for comparable ecosystems.
  6. For AI-BOM changes, compare every emitted AI field against formulation, modelCard, pedigree, componentData, services, and evidence in the local schemas.
  7. Check whether AI-specific custom properties duplicate standard fields such as model type, task, lineage, datasets, provider, or runtime endpoints.
  8. Check spec-version downgrade and upgrade paths, especially 1.5/1.6/1.7 versus 2.0 behavior for AI-BOM structures.
  9. Produce findings in four groups: spec violation, semantic misuse, unnecessary customization, and expected data missing.

Expected review output

For every finding, include:

  • exact field or property name
  • why it is a problem
  • preferred CycloneDX field or modeling approach
  • schema/spec basis
  • whether it is a repo-wide legacy pattern or introduced by the PR

Repo calibration findings

These repo-specific findings were identified while calibrating this skill and should be treated as known review heuristics.

  • Self-generated BOMs for this repository currently expose three unnamespaced custom property names: internal:SrcFile, internal:ImportedModules, and internal:LocalNodeModulesPath.
Iteration 1: legacy internal:SrcFile property
  • Current cdxgen output emits unnamespaced internal:SrcFile properties.
  • In self-generated BOMs this often duplicates evidence.identity[].methods[].value.
  • When the intent is to show where a component was found, evidence.occurrences[].location is the more semantically correct field.
Iteration 2: legacy internal:ImportedModules property
  • Current cdxgen output emits unnamespaced internal:ImportedModules.
  • The value is packed as CSV-like text and mixes module names with symbol-like data.
  • This is hard for downstream tooling to interpret and should be reviewed against evidence.occurrences plus symbol, or replaced with a clearly namespaced property if no standard field fits.
Iteration 3: legacy internal:LocalNodeModulesPath property
  • Current cdxgen output emits unnamespaced internal:LocalNodeModulesPath.
  • It can contain absolute host paths, which are environment-specific and potentially sensitive.
  • Treat this as a strong signal for removal or redesign rather than a property to preserve.
Iteration 4: deprecated and incomplete producer metadata
  • Current output may rely on deprecated metadata.component.author instead of authors or manufacturer.
  • Root BOM metadata commonly has metadata.authors but not metadata.supplier.
  • For published artifacts, review whether supplier and contact/manufacturer data should be emitted instead of or in addition to author-style fields.
Iteration 5: completeness gaps for emitted components
  • Self-validation of a generated BOM for this repository still shows components missing license data and at least one component missing hashes/dependency linkage.
  • When reviewing new integrations, treat missing license, hash, and dependency information as expected completeness checks, not optional polish, if the upstream ecosystem exposes that data.
Iteration 6: AI-BOM review heuristics
  • cdx:ai:* properties are namespaced and therefore better than unnamespaced properties, but they should still be challenged when they duplicate standard CycloneDX AI/ML fields.
  • In particular, review whether task, lineage, datasets, provider identity, runtime identity, and variant classification should move to modelCard, pedigree, externalReferences, services, or evidence.
  • When a stable Hugging Face, model, or dataset identity is available, prefer durable references (bom-ref, purl, externalReferences, dataset refs) over free-text notes.
  • If lineage is known only from model-repository metadata, pedigree.notes may be acceptable as supplemental context, but not as the sole representation when the relation itself is structured and reproducible.

© cdxgen, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/cyclonedx-spec-reviewer of cdxgen/cdxgen.

Open the folder on GitHubat commit eb00071

Compare with similar skills

Cyclonedx Spec Reviewer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cyclonedx Spec Reviewer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cyclonedx Spec Reviewer this skillcdxgen/cdxgen1.1k—~2.5kAutomated safety check: PassApache-2.0
Finishing a Development Branchobra/superpowers297k5 repos~1.9kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Check PRonyx-dot-app/onyx32k2 repos~2.3kAutomated safety check: PassMIT
PR Design DocOpenHands/OpenHands91k—~2.4kAutomated safety check: PassMIT
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Check PR

    onyx-dot-app/onyx

    Checks a GitHub, GitLab, or Perforce (p4) pull request (or merge request, or shelved changelist) for unresolved review comments, failing status checks, and incomplete PR descriptions.

    32k GitHub starsUsed in 2 repos~2.3k tokens
    DevelopmentAuto-check passed
  • PR Design Doc

    OpenHands/OpenHands

    For a non-trivial pull request, write a self-contained HTML design doc under the temporary .pr/ directory and link a visibility-appropriate preview in the PR description, so maintainers grasp the…

    91k GitHub stars~2.4k tokensUpdated today
    DevelopmentAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Record PR Demo

    payloadcms/payload

    A skill your agent uses when a Payload pull request needs a concise visual walkthrough for reviewers.

    45k GitHub stars~1k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from cdxgen/cdxgen

All 17 skills in this repo
  • AI Bom

    cdxgen/cdxgen

    Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…

    1.1k GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Bom Audit

    cdxgen/cdxgen

    Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…

    1.1k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Bom Evidence

    cdxgen/cdxgen

    Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…

    1.1k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Bom Explore

    cdxgen/cdxgen

    Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…

    1.1k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Bom Signing

    cdxgen/cdxgen

    Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures…

    1.1k GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…

    1.1k GitHub stars~1.5k tokensUpdated today
    Auto-check: warnings

Categories

Questions about Cyclonedx Spec Reviewer

What does Cyclonedx Spec Reviewer do?

Reviews cdxgen changes for CycloneDX schema compliance, semantic field correctness, and unnecessary custom properties across spec versions 1.5 through 2.0, including AI-BOM modeling via formulation…. Cyclonedx Spec Reviewer is an agent skill from cdxgen/cdxgen.0, including AI-BOM modeling via formulation, modelCard, pedigree, and evidence.

When should I use Cyclonedx Spec Reviewer?

Cyclonedx Spec Reviewer fits situations like: A pull request changes CycloneDX output; schema handling; package-manager integrations; custom properties.

How do I install Cyclonedx Spec Reviewer in Claude Code?

Run `npx skills add cdxgen/cdxgen --skill cyclonedx-spec-reviewer -a claude-code`. Or copy the skill folder (.agents/skills/cyclonedx-spec-reviewer in cdxgen/cdxgen) into .claude/skills/cyclonedx-spec-reviewer in your project. Claude Code loads it when a task matches its description.

How do I install Cyclonedx Spec Reviewer in Codex?

Run `npx skills add cdxgen/cdxgen --skill cyclonedx-spec-reviewer -a codex`. Or copy the skill folder (.agents/skills/cyclonedx-spec-reviewer in cdxgen/cdxgen) into .agents/skills/cyclonedx-spec-reviewer in your project. Codex loads it when a task matches its description.

Can I use Cyclonedx Spec Reviewer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cdxgen/cdxgen --skill cyclonedx-spec-reviewer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cyclonedx-spec-reviewer, .gemini/skills/cyclonedx-spec-reviewer, .github/skills/cyclonedx-spec-reviewer and .opencode/skills/cyclonedx-spec-reviewer in your project.

What does Cyclonedx Spec Reviewer need to run?

SKILL.md names no scripts, command-line tools or credentials: Cyclonedx Spec Reviewer is instructions for the agent only.

Does Cyclonedx Spec Reviewer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cyclonedx Spec Reviewer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cyclonedx Spec Reviewer use?

Cyclonedx Spec Reviewer is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cyclonedx Spec Reviewer use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cyclonedx Spec Reviewer?

Skills that share tags, products or a category with Cyclonedx Spec Reviewer: Finishing a Development Branch (obra/superpowers, 297k stars), PR Babysitter (openinterpreter/openinterpreter, 69k stars), Check PR (onyx-dot-app/onyx, 32k stars) and PR Design Doc (OpenHands/OpenHands, 91k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cyclonedx Spec Reviewer?

cdxgen (a GitHub organization) maintains it in cdxgen/cdxgen, which has 1,085 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 10, 2026.

Source: cdxgen/cdxgen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.