Agent skill

Os Hardware Inventory

by cdxgen in cdxgen/cdxgen

Collects live operating-system inventory (OBOM) and host hardware inventory (HBOM) as CycloneDX documents using the cdxgen obom and hbom commands, including osquery-backed runtime artifacts, Linux…

Apache-2.0Auto-check passedSecurity

Install Os Hardware Inventory

skills CLI
$ npx skills add cdxgen/cdxgen --skill os-hardware-inventory -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cdxgen/cdxgen os-hardware-inventory --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude-plugin/skills/os-hardware-inventory .claude/skills/os-hardware-inventory && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
os-hardware-inventory
GitHub stars
1.1k
Token cost
~1.5k tokens
SKILL.md length
549 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
Apache-2.0

At a glance

Collects live operating-system inventory (OBOM) and host hardware inventory (HBOM) as CycloneDX documents using the cdxgen obom and hbom commands, including osquery-backed runtime artifacts, Linux…

  • Asked to inventory a live machine
  • SKILL.md covers The hard rule, OBOM: live operating-system…, HBOM: host hardware inventory and Exploring the results, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Audit a running hosts packages

What it does

Os Hardware Inventory is an agent skill from cdxgen/cdxgen. Collects live operating-system inventory (OBOM) and host hardware inventory (HBOM) as CycloneDX documents using the cdxgen obom and hbom commands, including osquery-backed runtime artifacts, Linux hardening snapshots, GTFOBins enrichment, firmware and bus topology, and macOS permission troubleshooting. Use when asked to inventory a live machine, audit a running host's packages or services, produce a hardware BOM, or check host trust posture.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. It works with Linux and macOS. The repository describes itself as: Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with…. The licence is Apache-2.0.

When your agent uses it

  • Asked to inventory a live machine
  • Audit a running hosts packages
  • Produce a hardware BOM
  • Check host trust posture

Example prompts

  • “Use the os-hardware-inventory skill to collect live operating-system inventory (OBOM) and host hardware inventory (HBOM) as CycloneDX documents…”
  • “/os-hardware-inventory”

What it can do on your machine

Read from SKILL.md and the folder at commit e256966. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cdxgen.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Os Hardware Inventory loads about 1.5k tokens when it runs. Until then it costs about 117 tokens; SKILL.md has 549 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~117
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cdxgen/cdxgen at commit e256966, republished under its Apache-2.0 licence (© cdxgen). 549 words, ~1,528 tokens.

Download SKILL.mdSave it as .claude/skills/os-hardware-inventory/SKILL.md (or your agent's skills folder).
name
os-hardware-inventory
description
Collects live operating-system inventory (OBOM) and host hardware inventory (HBOM) as CycloneDX documents using the cdxgen obom and hbom commands, including osquery-backed runtime artifacts, Linux hardening snapshots, GTFOBins enrichment, firmware and bus topology, and macOS permission troubleshooting. Use when asked to inventory a live machine, audit a running host's packages or services, produce a hardware BOM, or check host trust posture.

Live OS and hardware inventory

Two distinct documents, two distinct commands. Do not mix them.

WantCommand
Software on a running machineobom (cdxgen -t os)
Physical hardware of the hosthbom
Offline host from a mounted disk-t rootfs (see container-sbom)

Read reference/safety.md first. Live host collection reads far more of the machine than a project scan, so the dry-run-and-confirm step matters more here, not less.

The hard rule

Never combine hbom / hardware with software project types such as js, java, python, os, or oci in one invocation. Generate them separately. If the user wants one merged host document, use hbom --include-runtime rather than stacking -t flags.

OBOM: live operating-system inventory

bash
obom -o /absolute/path/to/obom.json --deep

obom is an alias for cdxgen -t os. Aliases osquery, windows, linux, mac, macos, darwin reach the same pipeline.

With a runtime audit:

bash
obom -o /absolute/path/to/obom.json --deep \
  --bom-audit --bom-audit-categories obom-runtime
What Linux OBOM adds
  • osquery-derived runtime artifacts: processes, listening ports, users, services, scheduled jobs
  • sysctl_hardening and mount_hardening snapshots
  • GTFOBins enrichment on privileged and network-active runtime rows — a shell-escape-capable binary running privileged or listening on the network is the signal worth escalating
macOS OBOM

Collection uses the bundled osquery binary in shell mode, which avoids the older /var/osquery startup failure. Some tables still require Full Disk Access or elevated privileges.

If tables come back empty or permission-gated, that is a host configuration issue, not a cdxgen bug. Point the user at https://cdxgen.github.io/cdxgen/#/OBOM_MACOS_TROUBLESHOOTING rather than retrying the same command.

For live-host triage patterns generally, see https://cdxgen.github.io/cdxgen/#/OBOM_LESSONS.

OS trust inventory modelling

Understand the split before interpreting the output:

  • Repository sources are ordinary data components.
  • Trusted keys and certificates are cryptographic-asset components, and they have no purls. A missing purl here is correct, not a gap.

HBOM: host hardware inventory

bash
hbom -o /absolute/path/to/hbom.json

Hardware collection comes from the optional @cdxgen/cdx-hbom library, loaded only when requested. Supported hosts:

  • darwin/arm64 (Apple Silicon macOS)
  • linux/amd64
  • linux/arm64

On an unsupported host, say so directly rather than producing an empty document and calling it a success.

The equivalent library path is cdxgen -t hbom ., but prefer the dedicated command.

Show full SKILL.md (217 more words)Show less
Merged hardware plus runtime host view
bash
hbom --include-runtime -o /absolute/path/to/host-view.json

This is the supported way to get one document covering both. It also extends the default audit categories to include host-topology.

Diagnosing missing collectors
bash
hbom diagnostics

Reports missing native utilities and permission-sensitive enrichments. Run this first when an HBOM comes back sparse — the usual cause is an absent host command, not a collection bug.

Useful hbom flags
FlagEffect
--include-runtimeMerge runtime host inventory into the hardware document
--privilegedEnable collectors that need elevated privileges
--sensitiveInclude sensitive identifiers (ask the user first)
--plist-enrichmentmacOS property-list enrichment
--no-command-enrichmentSkip host command invocation
--timeoutBound collector runtime
--export-protoProtobuf output via --proto-bin-file
--dry-runPreview collection without writing

Treat --sensitive as a confirm-first flag. It widens what lands in a document the user may share.

HBOM audit behaviour

For hbom / hardware targets, cdxgen skips the predictive dependency audit entirely and defaults the audit categories to hbom-security,hbom-performance,hbom-compliance. With --include-runtime it adds host-topology.

bash
hbom -o /absolute/path/to/hbom.json --bom-audit
cdx-audit --bom /absolute/path/to/hbom.json --direct-bom-audit --categories hbom

The hbom alias expands to the full HBOM review pack in one switch.

Exploring the results

cdxi has dedicated commands for both document types (see bom-explore):

  • OBOM: .osinfocategories, .obomtips, .trusted, .instrumented
  • HBOM: .hbomsummary, .hbomclasses, .hbomevidence, .hbomdiagnostics, .hbomfirmware, .hbombuses, .hbompower, .hbomtips

Start with .hbomsummary or .osinfocategories before drilling into specifics.

Reference

© cdxgen, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in claude-plugin/skills/os-hardware-inventory of cdxgen/cdxgen.

Open the folder on GitHubat commit e256966

Compare with similar skills

Os Hardware Inventory next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Os Hardware Inventory compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Os Hardware Inventory this skillcdxgen/cdxgen1.1k—~1.5kAutomated safety check: PassApache-2.0
Game Automationrehan-remade/universal-modder5.3k—~1.9kAutomated safety check: PassMIT
Ctf Cryptoljagiello/ctf-skills3.4k—~11kAutomated safety check: NotesMIT
Forensics OsqueryAgentSecOps/SecOpsAgentKit2201 repos~4.9kAutomated safety check: NotesCustom licence
Bumblebeesickn33/agentic-awesome-skills47k1 repos~2.5kAutomated safety check: NotesMIT
Performing Memory Forensics With Volatility3 Pluginsmukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.0

Similar skills

  • Game Automation

    rehan-remade/universal-modder

    Launch, see and drive a real game so an agent can test its own mods.

    5.3k GitHub stars~1.9k tokensUpdated today
    SecurityAuto-check passed
  • Ctf Crypto

    ljagiello/ctf-skills

    Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.

    3.4k GitHub stars~11k tokensUpdated 25 days ago
    SecurityAuto-check: notes
  • Forensics Osquery

    AgentSecOps/SecOpsAgentKit

    SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.

    220 GitHub starsUsed in 1 repo~4.9k tokens
    SecurityAuto-check: notes
  • Bumblebee

    sickn33/agentic-awesome-skills

    Run Bumblebee supply-chain inventory and exposure scans on macOS/Linux to detect compromised packages, extensions, and MCP host configs.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    SecurityAuto-check: notes
  • Performing Memory Forensics With Volatility3 Plugins

    mukul975/Anthropic-Cybersecurity-Skills

    Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.

    34k GitHub stars~2.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Analyzing Memory Dumps With Volatility

    mukul975/Anthropic-Cybersecurity-Skills

    Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials.

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from cdxgen/cdxgen

All 17 skills in this repo
  • AI Bom

    cdxgen/cdxgen

    Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…

    1.1k GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Bom Audit

    cdxgen/cdxgen

    Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…

    1.1k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Bom Evidence

    cdxgen/cdxgen

    Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…

    1.1k GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Bom Explore

    cdxgen/cdxgen

    Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…

    1.1k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Bom Signing

    cdxgen/cdxgen

    Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures…

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check: warnings

Works with

Categories

Questions about Os Hardware Inventory

What does Os Hardware Inventory do?

Collects live operating-system inventory (OBOM) and host hardware inventory (HBOM) as CycloneDX documents using the cdxgen obom and hbom commands, including osquery-backed runtime artifacts, Linux…. Os Hardware Inventory is an agent skill from cdxgen/cdxgen. Collects live operating-system inventory (OBOM) and host hardware inventory (HBOM) as CycloneDX documents using the cdxgen obom and hbom commands, including osquery-backed runtime artifacts, Linux hardening snapshots, GTFOBins enrichment, firmware and bus topology, and macOS permission troubleshooting.

When should I use Os Hardware Inventory?

Os Hardware Inventory fits situations like: asked to inventory a live machine; audit a running hosts packages; produce a hardware BOM; check host trust posture.

How do I install Os Hardware Inventory in Claude Code?

Run `npx skills add cdxgen/cdxgen --skill os-hardware-inventory -a claude-code`. Or copy the skill folder (claude-plugin/skills/os-hardware-inventory in cdxgen/cdxgen) into .claude/skills/os-hardware-inventory in your project. Claude Code loads it when a task matches its description.

How do I install Os Hardware Inventory in Codex?

Run `npx skills add cdxgen/cdxgen --skill os-hardware-inventory -a codex`. Or copy the skill folder (claude-plugin/skills/os-hardware-inventory in cdxgen/cdxgen) into .agents/skills/os-hardware-inventory in your project. Codex loads it when a task matches its description.

Can I use Os Hardware Inventory in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cdxgen/cdxgen --skill os-hardware-inventory -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/os-hardware-inventory, .gemini/skills/os-hardware-inventory, .github/skills/os-hardware-inventory and .opencode/skills/os-hardware-inventory in your project.

What does Os Hardware Inventory need to run?

SKILL.md names no scripts, command-line tools or credentials: Os Hardware Inventory is instructions for the agent only.

Does Os Hardware Inventory access the network?

SKILL.md names 1 domain. As links in the text: cdxgen.github.io. This is read from the text; nothing was executed.

Is Os Hardware Inventory safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Os Hardware Inventory use?

Os Hardware Inventory is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Os Hardware Inventory use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Os Hardware Inventory?

Skills that share tags, products or a category with Os Hardware Inventory: Game Automation (rehan-remade/universal-modder, 5.3k stars), Ctf Crypto (ljagiello/ctf-skills, 3.4k stars), Forensics Osquery (AgentSecOps/SecOpsAgentKit, 220 stars) and Bumblebee (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Os Hardware Inventory?

cdxgen (a GitHub organization) maintains it in cdxgen/cdxgen, which has 1,085 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 7, 2026.

Source: cdxgen/cdxgen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.