Agent skill

Sbom Fidelity Loop

by cdxgen in cdxgen/cdxgen

Runs the cdxgen SBOM fidelity loop: scan with --introspect or --profile introspect, read the cdxgen fidelity report, execute its ranked remediations (the catalog spans the mainstream build…

Apache-2.0Auto-check passedSecurity

Install Sbom Fidelity Loop

skills CLI
$ npx skills add cdxgen/cdxgen --skill sbom-fidelity-loop -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cdxgen/cdxgen sbom-fidelity-loop --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/sbom-fidelity-loop .claude/skills/sbom-fidelity-loop && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sbom-fidelity-loop
GitHub stars
1.1k
Token cost
~4.5k tokens
SKILL.md length
1,897 words
Files
3
Skills in repo
17
Repo updated
First seen
Licence
Apache-2.0

At a glance

Runs the cdxgen SBOM fidelity loop: scan with --introspect or --profile introspect, read the cdxgen fidelity report, execute its ranked remediations (the catalog spans the mainstream build…

  • Works in 4 steps: The action changes the host or the shell… → The reasoning is recorded in… → If the repair installs anything or runs… → …
  • Improving SBOM accuracy
  • SKILL.md covers What this loop can and cannot do, The loop, Stop conditions — report which… and Rules for executing actions, plus 2 more sections
  • Calls uv and poetry

What it does

Sbom Fidelity Loop is an agent skill from cdxgen/cdxgen. Runs the cdxgen SBOM fidelity loop: scan with --introspect or --profile introspect, read the cdxgen fidelity report, execute its ranked remediations (the catalog spans the mainstream build ecosystems, and the loop may add one evidence-driven host repair the catalog missed), and re-scan until the fidelity tiers stop improving. Use when improving SBOM accuracy or completeness, fixing missing transitive dependencies in a generated BOM, build tool setup for SBOM generation, or interpreting a cdxgen…

Its SKILL.md is about 4.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files (for example `reference/remediation-actions.md` and `reference/report-schema.md`).

It sits in Security, covering Supply chain security. It works with Rust. The repository describes itself as: Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with…. The licence is Apache-2.0.

When your agent uses it

  • Improving SBOM accuracy
  • Fixing missing transitive dependencies in a generated BOM
  • Build tool setup for SBOM generation
  • Interpreting a cdxgen fidelity/introspection report

Example prompts

  • “/sbom-fidelity-loop”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. The action changes the host or the shell environment only — never a file
  2. The reasoning is recorded in history.attempted with inferred: true,
  3. If the repair installs anything or runs a container, the ask-first rule
  4. Verification is by the next report exactly as with a catalog fix — an

What it can do on your machine

Read from SKILL.md and the folder at commit e256966. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv
    • poetry

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sbom Fidelity Loop loads about 4.5k tokens when it runs. Until then it costs about 137 tokens; SKILL.md has 1,897 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~137
When it runs · the whole SKILL.md, loaded when a task matches
~4.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cdxgen/cdxgen at commit e256966, republished under its Apache-2.0 licence (© cdxgen). 1,897 words, ~4,511 tokens.

Download SKILL.mdSave it as .claude/skills/sbom-fidelity-loop/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
sbom-fidelity-loop
description
Runs the cdxgen SBOM fidelity loop: scan with --introspect or --profile introspect, read the cdxgen fidelity report, execute its ranked remediations (the catalog spans the mainstream build ecosystems, and the loop may add one evidence-driven host repair the catalog missed), and re-scan until the fidelity tiers stop improving. Use when improving SBOM accuracy or completeness, fixing missing transitive dependencies in a generated BOM, build tool setup for SBOM generation, or interpreting a cdxgen fidelity/introspection report.

SBOM fidelity loop

Use this skill to raise a cdxgen SBOM from a shallow scan (direct dependencies only) to a fully resolved one. cdxgen --introspect grades each scanned ecosystem against a fidelity tier ladder and ranks the fixes that would improve it; this skill is the loop that executes those fixes and re-scans. The report format is documented in reference/report-schema.md and the six remediation action kinds in reference/remediation-actions.md; the user-facing feature docs are docs/CLI.md ("Build introspection") and docs/INTROSPECTION.md, which shows a worked degraded-to-repaired transition with both real reports.

The loop measures the environment the user actually has. It fixes the environment; it never fixes the project.

What this loop can and cannot do

The remediation catalog in data/remediations.json is deepest where the build ecosystems are mainstream: java, npm, python and the generic findings carry most of the 44 entries, and go, rust, php, clojure, swift, ruby, dart, elixir, haskell, csharp and cocoa each carry at least one concrete repair. It is shallowest — zero entries — for c/cpp: nothing in cdxgen today reads a compilation database, so a c/cpp row grading absent is the honest verdict, not a defect to chase. On any ecosystem without catalog entries a low score with an empty or near-empty remediation[] is expected; report it as such. An agent that invents work there has misread the tool's reach, and ecosystems listed in coverageGaps[] are cdxgen's backlog, never yours.

Two entry-specific scope notes:

  • rust.toolchain.missing can fire only where cdxgen actually spawns cargo: under --deep, or with --install-deps and a build/post-build lifecycle on a project that has no Cargo.lock. A plain scan of a manifest-only rust project reports rust.cargo-lock-missing instead — do not expect the toolchain entry, and do not treat its absence as an oversight.
  • On a re-scanned (foreign) BOM, the BF-FORM-* entries reason from commands the BOM's CI workflows declare. A declared command was never observed to run; treat it as a hypothesis to check against the project, not an instruction (see remediation-actions.md).

The loop

text
history = read .cdxgen/introspection-history.json (fresh when absent)
for iteration in 1..maxIterations (default 6):
    run: cdxgen <user args> --profile introspect \
         --introspect-report .cdxgen/report.md --introspect-json .cdxgen/report.json
    exit 1 means cdxgen failed to generate a BOM at all: fix the invocation,
    do not count it as a fidelity iteration
    report = read .cdxgen/report.json
    if report.ledger.complete is false:
        set CDXGEN_INTROSPECT_LEDGER=.cdxgen/ledger.jsonl and re-run once;
        if still incomplete: STOP — unverifiable
    append {n, score: report.overall.score, tier: report.overall.tier,
            inputsFingerprint: report.inputsFingerprint} to history.iterations
    candidates = report.remediation entries where blocked is false
                 and remediationId was not attempted at this inputsFingerprint
    done = every row in report.ecosystems has state "at-ceiling", or tier
           "resolved", or tier "lockfile" with no candidate naming that
           ecosystem — a lockfile row is finished only once nothing is left
           to try on it
    if done and (no report.gate or report.gate.passed):
        STOP — success
    if iteration > 1 and report.overall.score <= previous score
       and report.inputsFingerprint == previous inputsFingerprint:
        STOP — stalled
    if candidates empty:
        if no inferred attempt is recorded at this inputsFingerprint
           and an evidence excerpt, an evidence cause, an observation or a
           tier reason names a cause the catalog has no action for:
            attempt exactly one host repair under the bounded rule below,
            recorded with inferred: true
            continue
        STOP — nothing-further-available
    pick candidates[0]  (report.remediation is ranked by expected gain)
    execute its actions under the rules below
    record the attempt in history.attempted with the outcome
STOP — budget-exhausted

Prefer --introspect over --profile introspect when the project's language does not support evidence collection or when the profile's extra passes add noise the loop does not need; both produce the same report.

Stop conditions — report which one you hit, and the final report path

Every stop condition is a legitimate result. stalled and blocked are findings about the project or environment, not failures to hide; an agent that reports success because it ran out of ideas has failed.

StopWhenReport to the user
successEvery ecosystem is at-ceiling or at resolved/lockfile and the gate (if configured) passedFinal score and report path
stalledA re-run with the same inputsFingerprint did not raise the score — the applied fix did not change the inputsThe attempted remediation id; the fix did not take effect
blockedEvery remaining candidate is blocked: true (secure mode, offline, dry-run, in-container)The blockedReason values; these are facts for the human, not work for you
nothing-further-availableNo unblocked, unattempted candidate remains and no diagnosable evidence block earns the one inferred repair (or that repair is already spent) — including a score below 100 with an empty remediation[]The score and the reason no action exists; never improvise a fix to close the gap
unverifiableThe ledger is incomplete even after the sidecar retry, or the report cannot be read/parsedSay the verdict cannot be trusted and what is missing
budget-exhaustedmaxIterations reached with work still rankedWhat would be attempted next

A score below 100 with an empty report.remediation[] is real: the deduction has no catalog entry yet (a bare missing interpreter on PATH behaves this way today). Before declaring nothing-further-available, check the report for a diagnosable cause — an evidence excerpt or cause, an observation or a tier reason that names one earns exactly one inferred host repair under the bounded rule below, judged by the next report like any catalog fix. With that repair spent or no such evidence present, the stop stands: report it, leave the project untouched, and take no second guess at the same inputsFingerprint.

Rules for executing actions

  • Ask before installing. install and container actions change the user's machine. Present the planned actions and wait, unless the user said to run unattended. In CI with an explicit mandate, proceed.
  • Never modify the project to make a rule pass. Do not add a lockfile the project does not have, do not edit pom.xml/build.sbt/manifests to pin versions, do not touch source files. The goal is an accurate SBOM of the project as it is; adding a lockfile the project does not carry falsifies the subject of the measurement. Where a remediation's fix is a project change (config actions), surface it to the human as advice instead of executing it. The same prohibition covers the subtler shapes: do not create wrapper scripts (mvnw, gradlew) the project does not ship; do not add toolchain pin files (.java-version, .tool-versions) the project does not carry — these look like environment setup and are project changes; and do not write compile_commands.json, which nothing in cdxgen reads — that is fabricated work on top of being a project change.
  • Beyond the catalog you may repair the environment the run measured, and you must say how. The catalog is not omniscient. Once no unblocked, unattempted candidate remains — the candidates empty branch of the loop above, never alongside a ranked action — and an evidence.outputExcerpt, an evidence.cause, an observation or a tier reason names a cause the catalog has no action for, you may act on that evidence to fix the host: set JAVA_HOME, install a toolchain the error names, start a required daemon, configure a registry mirror the excerpt shows is unreachable. Every condition below holds every time:
    1. The action changes the host or the shell environment only — never a file inside the project (the absolute rule above).
    2. The reasoning is recorded in history.attempted with inferred: true, a remediationId prefixed inferred:, and the evidence quote it rests on (schema below). No quote, no action.
    3. If the repair installs anything or runs a container, the ask-first rule above applies unchanged.
    4. Verification is by the next report exactly as with a catalog fix — an inferred repair that does not move the report is no-change and is never retried at the same inputsFingerprint. Cap: one inferred repair per inputsFingerprint. A second guess at the same inputs is churn, not diagnosis.
  • Never weaken the measurement. Do not pass --skip-* flags, do not lower --introspect-fail-below, do not disable rules. If you find yourself wanting to, stop and report blocked. The bounded latitude above does not reach here: no excerpt, however clear, licenses a weaker scan.
  • Prefer container over host installs when the report offers both and the environment can run containers — a container run is reversible.
  • Verify on the next iteration. After executing actions, judge the fix by the next report's entry verify clause (rules stopped firing, tier reached) — never by the action's exit code. Record the outcome in history.attempted; a no-change or failed outcome is never retried at the same inputsFingerprint.
Show full SKILL.md (734 more words)Show less

Reading the report

tiermeaningkeep going?
resolvedWorking build/resolver; full dependency graph capturedNo — done
lockfilePinned versions captured, graph not fully resolvedDone when nothing is actionable; a remediation may still target resolved
manifestDirect declarations onlyYes — the highest-gain remediation usually lives here
heuristicComponents inferred from build artifactsYes
absentNothing was produced for the ecosystemYes
  • A row with state: "at-ceiling" is done regardless of tier: the ecosystem already parses at the best fidelity cdxgen can achieve for it (helm charts are manifest forever). Do not try to improve one.
  • Rows named in coverageGaps are cdxgen's backlog, not your work.
  • confidence: "low" means the verdict rests on thin evidence: set CDXGEN_INTROSPECT_LEDGER to a sidecar path, re-run, and only then act on remediations.
  • Ledger-derived entries carry an evidence block: failedCommand, exitCode, cause, and outputExcerpt — the command's own output, redacted, at most its last 2000 characters, and suppressed entirely when the operator sets CDXGEN_INTROSPECT_NO_OUTPUT=true. Read it before acting on the entry; it is what the bounded repair rule rests on. Field notes: report-schema.md.
  • Placeholders in action commands ({{version}}, {{major}}) are resolved by the report itself when it can — from the build's own mismatch report first, then the project's pin files, then anything else the run recorded; each action's versionFrom and versionSource say which answered. An action carrying versionSourceMissing: true (or versionFrom: "unresolved") keeps the placeholder on purpose: ask the user which version to install; never silently invent one.
  • Build commands are shaped for the project: the report names the wrapper (./mvnw, ./gradlew), the Python manager (uv lock, poetry lock) or the project's own ./composer.phar it detected, and shapedBy on the action says so. Run the command as emitted; an agent that "knows better" and substitutes mvn for ./mvnw — or picks a manager the report did not name — is wrong. An unresolved {{pythonManager}} means two managers compete: ask the user which one governs the project before locking.
  • On a re-scanned (foreign) BOM, rule entries carry evidence.attemptedCommand with attemptedCommandSource: "formulation" — a command the BOM's CI workflows declare. A declared command was never observed to run: it is a hypothesis to check against the project, not an instruction and not history. A same-run report carries none of these — there the ledger recorded what actually ran.

Keep loop state in .cdxgen/introspection-history.json so other agents and later sessions share it. Schema version 1.1 separates catalog-driven attempts from agent-inferred ones:

json
{
  "schemaVersion": "1.1",
  "iterations": [
    {
      "n": 1,
      "score": 45,
      "tier": "manifest",
      "inputsFingerprint": "sha256:4c734642d88a9bc75b9496f2840397d14320cd3bb28a3ba14d45b00c5e3d69c6",
      "at": "2026-08-30T13:21:11.300Z"
    }
  ],
  "attempted": [
    {
      "remediationId": "jvm.maven.manifest-fallback",
      "inputsFingerprint": "sha256:4c734642d88a9bc75b9496f2840397d14320cd3bb28a3ba14d45b00c5e3d69c6",
      "at": "2026-08-30T13:25:00.000Z",
      "actions": ["sdk install maven 3.9.9", "mvn -q package -DskipTests"],
      "outcome": "verified",
      "detail": "BF-JVM-001 no longer fires; java graded resolved"
    },
    {
      "remediationId": "inferred:jvm.java-home-invalid",
      "inferred": true,
      "inputsFingerprint": "sha256:4c734642d88a9bc75b9496f2840397d14320cd3bb28a3ba14d45b00c5e3d69c6",
      "evidence": {
        "from": "observations[0].detail",
        "quote": "JAVA_HOME is set to an invalid directory: /opt/jdk17"
      },
      "at": "2026-08-30T13:31:00.000Z",
      "actions": ["export JAVA_HOME=/opt/jdk21"],
      "outcome": "no-change",
      "detail": "the next report still graded manifest at 45; not retried at this fingerprint"
    }
  ]
}

outcome is one of verified, no-change, failed for both entry kinds. A catalog-driven attempt is the plain first entry: the remediationId the report emitted and the actions as run, keyed by the inputsFingerprint they were made at. An agent-inferred attempt — the bounded repair rule above — additionally carries:

  • inferred: true;
  • a remediationId prefixed inferred: — a short slug naming the cause, chosen by you; it is not a catalog id;
  • an evidence block: from names where in the report the fact lives (remediation[0].evidence.outputExcerpt, observations[0].detail, ecosystems[0].tierReasons[0].detail), and quote is the exact excerpt that justified the action.

An inferred entry with no evidence.quote is malformed. The quote is what makes the latitude auditable: a reader who was not present must be able to trace every host change back to a fact the report carried. At most one inferred: true entry may exist per inputsFingerprint. A 1.0 history file (catalog entries only, no inferred flags, no evidence blocks) is still valid and needs no migration. The history file is written by the agent, never by cdxgen. .cdxgen/ is scratch state, not project content: add it to the target repo's .gitignore and never commit it.

Worked example

Measured on a real Java project (java-sec-code) scanned without Maven. The environment variable forces the degradation any machine can reproduce:

sh
MVN_CMD=/nonexistent cdxgen --profile introspect --introspect-fail-below 70 \
  -t java -o /tmp/d09/x.bom.json --no-install-deps ~/sandbox/java-sec-code

The run falls back to parsing pom.xml, then prints:

text
Falling back to parsing pom.xml files. Only direct dependencies would get included!
Multiple errors occurred while building this project with maven. The SBOM is therefore incomplete!
✔ Generating BOM  58 components  0.2s
Build introspection: overall manifest (45/100), confidence high
Build introspection: 2 remediation(s) ranked
Build introspection: markdown report: /tmp/d09/x.bom.json.introspection.md
Build introspection: json report: /tmp/d09/x.bom.json.introspection.json
Build introspection: score 45 is below the --introspect-fail-below threshold 70.

Exit code 4: the BOM and both reports were written, and the gate failed. report.remediation[0] is jvm.maven.manifest-fallback, 45 → 100, with two install actions, one build, and a rerun; it subsumes BF-JVM-001, so fixing it clears that finding too. The install commands carry {{version}} placeholders because this run recorded no expected version. Per the rules: the agent presents the actions to the user instead of installing unprompted. Here the machine already had Java 25 and Maven under SDKMAN (visible in ecosystems[0].tools.resolved), so no install was needed; the loop re-runs the same command for iteration 2:

text
✔ Generating BOM  204 components  4.7s
Build introspection: overall resolved (100/100), confidence medium
Build introspection: 0 remediation(s) ranked
Build introspection: markdown report: /tmp/d09/x.bom.json.introspection.md
Build introspection: json report: /tmp/d09/x.bom.json.introspection.json

Exit code 0. Every row is resolved and the gate passes: STOP — success, 204 components against 58 before, report at the same path.

© cdxgen, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in .agents/skills/sbom-fidelity-loop of cdxgen/cdxgen.

  • SKILL.md
  • reference/remediation-actions.md
  • reference/report-schema.md

Open the folder on GitHubat commit e256966

Compare with similar skills

Sbom Fidelity Loop next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sbom Fidelity Loop compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sbom Fidelity Loop this skillcdxgen/cdxgen1.1k—~4.5kAutomated safety check: PassApache-2.0
Interlinked Supply ChainQuentinCody/interlinked-cli178—~2.8kAutomated safety check: PassMIT
Supply Chain Guarddavila7/claude-code-templates32k—~1.7kAutomated safety check: NotesMIT
Detecting Typosquatting Packagesmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Dependency Auditorborghei/Claude-Skills886—~1.8kAutomated safety check: PassMIT
Rust Securitymohitmishra786/low-level-dev-skills253—~1.6kAutomated safety check: PassMIT

Similar skills

  • Interlinked Supply Chain

    QuentinCody/interlinked-cli

    Respond to blocked package installs and manage the Interlinked supply-chain allowlist.

    178 GitHub stars~2.8k tokensUpdated 7 days ago
    SecurityAuto-check passed
  • Supply Chain Guard

    davila7/claude-code-templates

    Detect and remediate software supply chain attacks in npm, PyPI, crates.io, GitHub Actions, and CI/CD pipelines by scanning for known compromised packages, malicious versions, filesystem IOCs, C2…

    32k GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Detecting Typosquatting Packages

    mukul975/Anthropic-Cybersecurity-Skills

    Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation, using edit-distance, keyboard-proximity, and known-target corpus matching with…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Dependency Auditor

    borghei/Claude-Skills

    Scan project dependencies for vulnerabilities, license issues, and upgrade opportunities across Python, Node.js, Go, and Rust.

    886 GitHub stars~1.8k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Rust Security

    mohitmishra786/low-level-dev-skills

    Rust security skill for supply chain safety and memory-safe development.

    253 GitHub stars~1.6k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Supply Chain

    padamson/playwright-rust

    Procedure for keeping playwright-rust's cargo audit / cargo deny / cargo vet checks green when bumping the project's own version, when external crates change, and when a security advisory drops.

    154 GitHub stars~722 tokensUpdated 4 days ago
    Testing & QAAuto-check passed

More from cdxgen/cdxgen

All 17 skills in this repo
  • AI Bom

    cdxgen/cdxgen

    Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…

    1.1k GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Bom Audit

    cdxgen/cdxgen

    Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…

    1.1k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Bom Evidence

    cdxgen/cdxgen

    Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…

    1.1k GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Bom Explore

    cdxgen/cdxgen

    Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…

    1.1k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Bom Signing

    cdxgen/cdxgen

    Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures…

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check: warnings

Works with

Categories

Questions about Sbom Fidelity Loop

What does Sbom Fidelity Loop do?

Runs the cdxgen SBOM fidelity loop: scan with --introspect or --profile introspect, read the cdxgen fidelity report, execute its ranked remediations (the catalog spans the mainstream build…. Sbom Fidelity Loop is an agent skill from cdxgen/cdxgen. Runs the cdxgen SBOM fidelity loop: scan with --introspect or --profile introspect, read the cdxgen fidelity report, execute its ranked remediations (the catalog spans the mainstream build ecosystems, and the loop may add one evidence-driven host repair the catalog missed), and re-scan until the fidelity tiers stop improving.

When should I use Sbom Fidelity Loop?

Sbom Fidelity Loop fits situations like: improving SBOM accuracy; fixing missing transitive dependencies in a generated BOM; build tool setup for SBOM generation; interpreting a cdxgen fidelity/introspection report.

How do I install Sbom Fidelity Loop in Claude Code?

Run `npx skills add cdxgen/cdxgen --skill sbom-fidelity-loop -a claude-code`. Or copy the skill folder (.agents/skills/sbom-fidelity-loop in cdxgen/cdxgen) into .claude/skills/sbom-fidelity-loop in your project. Claude Code loads it when a task matches its description.

How do I install Sbom Fidelity Loop in Codex?

Run `npx skills add cdxgen/cdxgen --skill sbom-fidelity-loop -a codex`. Or copy the skill folder (.agents/skills/sbom-fidelity-loop in cdxgen/cdxgen) into .agents/skills/sbom-fidelity-loop in your project. Codex loads it when a task matches its description.

Can I use Sbom Fidelity Loop in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cdxgen/cdxgen --skill sbom-fidelity-loop -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sbom-fidelity-loop, .gemini/skills/sbom-fidelity-loop, .github/skills/sbom-fidelity-loop and .opencode/skills/sbom-fidelity-loop in your project.

What does Sbom Fidelity Loop need to run?

Going by SKILL.md and its folder, Sbom Fidelity Loop needs the command-line tools its instructions call (uv and poetry). Our summary lists: Python 3.

Does Sbom Fidelity Loop access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Sbom Fidelity Loop safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sbom Fidelity Loop use?

Sbom Fidelity Loop is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sbom Fidelity Loop use?

About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sbom Fidelity Loop?

Skills that share tags, products or a category with Sbom Fidelity Loop: Interlinked Supply Chain (QuentinCody/interlinked-cli, 178 stars), Supply Chain Guard (davila7/claude-code-templates, 32k stars), Detecting Typosquatting Packages (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Dependency Auditor (borghei/Claude-Skills, 886 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sbom Fidelity Loop?

cdxgen (a GitHub organization) maintains it in cdxgen/cdxgen, which has 1,085 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 8, 2026.

Source: cdxgen/cdxgen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.