Agent skill

Dependency Track Upload

by cdxgen in cdxgen/cdxgen

Publishes CycloneDX BOMs to Dependency-Track or a TEA (Transparency Exchange API) server from cdxgen, and runs cdxgen in HTTP server mode to generate BOMs on demand for local paths, Git URLs, or…

Apache-2.0Auto-check passedSecurity

Install Dependency Track Upload

skills CLI
$ npx skills add cdxgen/cdxgen --skill dependency-track-upload -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cdxgen/cdxgen dependency-track-upload --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude-plugin/skills/dependency-track-upload .claude/skills/dependency-track-upload && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-track-upload
GitHub stars
1.1k
Token cost
~1.9k tokens
SKILL.md length
640 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
Apache-2.0

At a glance

Publishes CycloneDX BOMs to Dependency-Track or a TEA (Transparency Exchange API) server from cdxgen, and runs cdxgen in HTTP server mode to generate BOMs on demand for local paths, Git URLs, or…

  • Works in 3 steps: Confirm the destination URL with the user. → Confirm the project name, version, and… → Confirm the BOM contents are safe to…
  • Asked to upload
  • SKILL.md covers Confirm before uploading, Credentials, Dependency-Track submission and TEA publishing, plus 2 more sections
  • Calls docker; needs TEA_TOKEN and GITHUB_TOKEN

What it does

Dependency Track Upload is an agent skill from cdxgen/cdxgen. Publishes CycloneDX BOMs to Dependency-Track or a TEA (Transparency Exchange API) server from cdxgen, and runs cdxgen in HTTP server mode to generate BOMs on demand for local paths, Git URLs, or package URLs. Use when asked to upload or submit an SBOM to Dependency-Track, register a project or parent-child project hierarchy, publish to a TEA collection, or run cdxgen as an SBOM service or API.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Supply chain security. It works with Git. The repository describes itself as: Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with…. The licence is Apache-2.0.

When your agent uses it

  • Asked to upload
  • Submit an SBOM to Dependency-Track
  • Register a project
  • Parent-child project hierarchy

Example prompts

  • “Use the dependency-track-upload skill to publish CycloneDX BOMs to Dependency-Track or a TEA (Transparency Exchange API) server from cdxgen, and…”
  • “/dependency-track-upload”

Requirements

  • Docker
  • A credential in TEA_TOKEN
  • A credential in GITHUB_TOKEN

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Confirm the destination URL with the user.
  2. Confirm the project name, version, and parent, since a wrong value creates or overwrites the wrong project.
  3. Confirm the BOM contents are safe to send — a BOM may carry AI/MCP configuration, host inventory, or trust material. Review emitted…

What it can do on your machine

Read from SKILL.md and the folder at commit e256966. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cdxgen.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • TEA_TOKEN
    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependency Track Upload loads about 1.9k tokens when it runs. Until then it costs about 105 tokens; SKILL.md has 640 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~105
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cdxgen/cdxgen at commit e256966, republished under its Apache-2.0 licence (© cdxgen). 640 words, ~1,939 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-track-upload/SKILL.md (or your agent's skills folder).
name
dependency-track-upload
description
Publishes CycloneDX BOMs to Dependency-Track or a TEA (Transparency Exchange API) server from cdxgen, and runs cdxgen in HTTP server mode to generate BOMs on demand for local paths, Git URLs, or package URLs. Use when asked to upload or submit an SBOM to Dependency-Track, register a project or parent-child project hierarchy, publish to a TEA collection, or run cdxgen as an SBOM service or API.

Publish BOMs and run cdxgen as a service

Two related capabilities: pushing a BOM to a platform, and exposing cdxgen over HTTP.

Read reference/safety.md first. Both halves of this skill touch the network and credentials, so the constraints below are not optional.

Confirm before uploading

Uploading a BOM publishes it to an external system. Before any submission:

  1. Confirm the destination URL with the user.
  2. Confirm the project name, version, and parent, since a wrong value creates or overwrites the wrong project.
  3. Confirm the BOM contents are safe to send — a BOM may carry AI/MCP configuration, host inventory, or trust material. Review emitted properties first.

Never invent a server URL, project ID, or API key. If a value is missing, ask.

Credentials

Never ask the user to paste an API key into the conversation, and never write one into a command line or a file. Pass credentials through the environment that cdxgen already reads, and let the user set it in their own shell:

bash
cdxgen -o /absolute/path/to/bom.json \
  --server-url https://deptrack.example.com \
  --project-name my-app --project-version 1.2.3 \
  /absolute/path/to/project

with CDXGEN_*/TEA_TOKEN-style variables set by the user beforehand. The TEA bearer token in particular is designed for this: it is sent only as an Authorization header, never logged, and can come from TEA_TOKEN.

If a key does appear in your context anyway, do not echo it back.

Dependency-Track submission

bash
cdxgen -o /absolute/path/to/bom.json \
  --server-url https://deptrack.example.com \
  --project-name my-app \
  --project-version 1.2.3 \
  /absolute/path/to/project
FlagPurpose
--server-urlDependency-Track URL
--api-keyAPI key (prefer the environment; see above)
--project-nameProject name; defaults to the directory name
--project-versionProject version
--project-idProject ID — supply this or name and version together
--project-tagProject tag; repeatable
--project-groupProject group
--parent-project-idParent project ID
--parent-project-nameParent project name
--parent-project-versionParent project version
--auto-createLet Dependency-Track create the project if absent
--is-latestMark this version as latest
--skip-dt-tls-checkSkip TLS verification

Identify the project either by --project-id or by --project-name plus --project-version together. Half of the latter pair is not enough.

--skip-dt-tls-check disables certificate verification. Only suggest it for a known-internal host with a self-signed certificate, and say what it turns off.

Monorepo hierarchies

Use the parent flags to nest per-module projects under one parent, so Dependency-Track shows the aggregate:

bash
cdxgen -o /absolute/path/to/module-bom.json \
  --server-url https://deptrack.example.com \
  --parent-project-name my-platform --parent-project-version 2026.1 \
  --project-name my-platform-api --project-version 1.2.3 \
  /absolute/path/to/module
Host allowlisting

Keep CDXGEN_ALLOWED_HOSTS narrow. Server-side Dependency-Track submission interprets a wildcard entry such as *.example.com as real subdomains only, never as a suffix match — so *.example.com will not match evil-example.com, and it also will not match example.com itself. Prefer exact hosts.

Show full SKILL.md (254 more words)Show less

TEA publishing

Publish the BOM as a TEA Artifact in a Collection (draft publisher API):

bash
cdxgen -o /absolute/path/to/bom.json \
  --tea-publish https://tea.example.com \
  --tea-collection-name "my-app sbom" \
  --tea-author-name "Prabhu Subramanian" \
  --tea-author-email prabhu@appthreat.com \
  /absolute/path/to/project
FlagPurpose
--tea-publishTEA server URL
--tea-collection-nameArtifact name; defaults to <project> sbom
--tea-leaf-identifierLeaf identifier
--tea-artifact-urlArtifact URL
--tea-author-name, --tea-author-emailAttribution
--tea-reasonReason recorded with the publication
--tea-tokenBearer token; prefer TEA_TOKEN in the environment
--tea-fetchFetch from a TEA server

This is a draft publisher API. Tell the user it may change.

Server mode

bash
cdxgen --server
cdxgen --server --server-host 0.0.0.0 --server-port 8080

Default bind is 127.0.0.1:9090. Via the container image:

bash
docker run --rm -v /tmp:/tmp -p 9090:9090 -v $(pwd):/app:rw \
  -t ghcr.io/cdxgen/cdxgen -r /app --server --server-host 0.0.0.0

--server-host 0.0.0.0 exposes the service on every interface. Only suggest it for a container or a host where that is intended, and say so — the default loopback bind exists for a reason.

Using the API

Poll /health first, then POST to /sbom with a JSON body or query parameters. Arguments mirror the CLI: path, url, type, and the rest.

url accepts Git URLs (https://...git, ssh://..., git@...) and package URLs (pkg:npm/..., pkg:pypi/..., pkg:gem/..., pkg:cargo/..., pkg:pub/..., pkg:github/..., pkg:bitbucket/..., pkg:maven/... with a version, pkg:composer/..., pkg:generic/... with vcs_url or download_url).

Pass GITHUB_TOKEN via the environment when scanning private repositories.

API specification: lib/server/openapi.yaml in the repository, viewable in Swagger Editor.

Server mode is a remote code path

The server generates BOMs for paths and URLs it is given, which means it clones repositories and may run package managers on request. Treat it as a privileged service:

  • keep it bound to loopback unless there is a reason not to
  • keep CDXGEN_ALLOWED_HOSTS narrow
  • do not expose it to untrusted callers

Reference

© cdxgen, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in claude-plugin/skills/dependency-track-upload of cdxgen/cdxgen.

Open the folder on GitHubat commit e256966

Compare with similar skills

Dependency Track Upload next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Track Upload compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Track Upload this skillcdxgen/cdxgen1.1k—~1.9kAutomated safety check: PassApache-2.0
Dependenciesalpha-omega-security/scrutineer231—~596Automated safety check: PassMIT
Sbomalpha-omega-security/scrutineer231—~290Automated safety check: PassMIT
Securitynotque/vexjoy-agent438—~2.6kAutomated safety check: NotesMIT
Sbom Supply Chain Auditorptn1411/skill219—~445Automated safety check: PassNone
Vibe CI Supply Chainmistralai/mistral-vibe5.1k—~1kAutomated safety check: PassApache-2.0

Similar skills

  • Dependencies

    alpha-omega-security/scrutineer

    Run git-pkgs list and sbom against the repository and emit one envelope with per-section status.

    231 GitHub stars~596 tokensUpdated today
    SecurityAuto-check passed
  • Sbom

    alpha-omega-security/scrutineer

    Generate a CycloneDX SBOM for the repository via git-pkgs sbom.

    231 GitHub stars~290 tokensUpdated today
    SecurityAuto-check passed
  • Security

    notque/vexjoy-agent

    Security: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks.

    438 GitHub stars~2.6k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Audit dependency manifests and lockfiles for SBOM extraction, risky install scripts, unpinned versions, remote/git dependency sources, dependency-confusion and typosquat/known-malicious package…

    219 GitHub stars~445 tokensUpdated 16 days ago
    SecurityAuto-check passed
  • Vibe CI Supply Chain

    mistralai/mistral-vibe

    Official

    Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe.

    5.1k GitHub stars~1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Performing Container Security Scanning With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

    34k GitHub stars~818 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from cdxgen/cdxgen

All 17 skills in this repo
  • AI Bom

    cdxgen/cdxgen

    Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…

    1.1k GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Bom Audit

    cdxgen/cdxgen

    Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…

    1.1k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Bom Evidence

    cdxgen/cdxgen

    Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…

    1.1k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Bom Explore

    cdxgen/cdxgen

    Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…

    1.1k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Bom Signing

    cdxgen/cdxgen

    Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures…

    1.1k GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…

    1.1k GitHub stars~1.5k tokensUpdated today
    Auto-check: warnings

Works with

Categories

Questions about Dependency Track Upload

What does Dependency Track Upload do?

Publishes CycloneDX BOMs to Dependency-Track or a TEA (Transparency Exchange API) server from cdxgen, and runs cdxgen in HTTP server mode to generate BOMs on demand for local paths, Git URLs, or…. Dependency Track Upload is an agent skill from cdxgen/cdxgen. Publishes CycloneDX BOMs to Dependency-Track or a TEA (Transparency Exchange API) server from cdxgen, and runs cdxgen in HTTP server mode to generate BOMs on demand for local paths, Git URLs, or package URLs.

When should I use Dependency Track Upload?

Dependency Track Upload fits situations like: asked to upload; submit an SBOM to Dependency-Track; register a project; parent-child project hierarchy.

How do I install Dependency Track Upload in Claude Code?

Run `npx skills add cdxgen/cdxgen --skill dependency-track-upload -a claude-code`. Or copy the skill folder (claude-plugin/skills/dependency-track-upload in cdxgen/cdxgen) into .claude/skills/dependency-track-upload in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Track Upload in Codex?

Run `npx skills add cdxgen/cdxgen --skill dependency-track-upload -a codex`. Or copy the skill folder (claude-plugin/skills/dependency-track-upload in cdxgen/cdxgen) into .agents/skills/dependency-track-upload in your project. Codex loads it when a task matches its description.

Can I use Dependency Track Upload in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cdxgen/cdxgen --skill dependency-track-upload -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-track-upload, .gemini/skills/dependency-track-upload, .github/skills/dependency-track-upload and .opencode/skills/dependency-track-upload in your project.

What does Dependency Track Upload need to run?

Going by SKILL.md and its folder, Dependency Track Upload needs the command-line tools its instructions call (docker) and credentials named TEA_TOKEN and GITHUB_TOKEN. Our summary lists: Docker; A credential in TEA_TOKEN; A credential in GITHUB_TOKEN.

Does Dependency Track Upload access the network?

SKILL.md names 1 domain. As links in the text: cdxgen.github.io. This is read from the text; nothing was executed.

Is Dependency Track Upload safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependency Track Upload use?

Dependency Track Upload is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Track Upload use?

About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependency Track Upload?

Skills that share tags, products or a category with Dependency Track Upload: Dependencies (alpha-omega-security/scrutineer, 231 stars), Sbom (alpha-omega-security/scrutineer, 231 stars), Security (notque/vexjoy-agent, 438 stars) and Sbom Supply Chain Auditor (ptn1411/skill, 219 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Track Upload?

cdxgen (a GitHub organization) maintains it in cdxgen/cdxgen, which has 1,085 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 7, 2026.

Source: cdxgen/cdxgen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.