Sail
pillar-labs/sail-skill
Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents.
Generates a CycloneDX SBOM from source code with OWASP cdxgen, covering project-type selection across 30+ ecosystems, monorepo recursion, lifecycle phases, generation profiles, component filtering…
$ npx skills add cdxgen/cdxgen --skill sbom-generate -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install cdxgen/cdxgen sbom-generate --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude-plugin/skills/sbom-generate .claude/skills/sbom-generate && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "sbom-generate" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/sbom-generate into .claude/skills/sbom-generate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sbom-generate", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/sbom-generateType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add cdxgen/cdxgen --skill sbom-generate -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install cdxgen/cdxgen sbom-generate --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .agents/skills && cp -r skills-src/claude-plugin/skills/sbom-generate .agents/skills/sbom-generate && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "sbom-generate" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/sbom-generate into .agents/skills/sbom-generate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sbom-generate", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cdxgen/cdxgen --skill sbom-generate -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install cdxgen/cdxgen sbom-generate --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/claude-plugin/skills/sbom-generate .cursor/skills/sbom-generate && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "sbom-generate" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/sbom-generate into .cursor/skills/sbom-generate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sbom-generate", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/cdxgen/cdxgen.git --path claude-plugin/skills/sbom-generate--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add cdxgen/cdxgen --skill sbom-generate -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install cdxgen/cdxgen sbom-generate --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/claude-plugin/skills/sbom-generate .gemini/skills/sbom-generate && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "sbom-generate" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/sbom-generate into .gemini/skills/sbom-generate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sbom-generate", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install cdxgen/cdxgen sbom-generateInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add cdxgen/cdxgen --skill sbom-generate -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .github/skills && cp -r skills-src/claude-plugin/skills/sbom-generate .github/skills/sbom-generate && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "sbom-generate" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/sbom-generate into .github/skills/sbom-generate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sbom-generate", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cdxgen/cdxgen --skill sbom-generate -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install cdxgen/cdxgen sbom-generate --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/claude-plugin/skills/sbom-generate .opencode/skills/sbom-generate && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "sbom-generate" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/sbom-generate into .opencode/skills/sbom-generate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sbom-generate", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
sbom-generateGenerates a CycloneDX SBOM from source code with OWASP cdxgen, covering project-type selection across 30+ ecosystems, monorepo recursion, lifecycle phases, generation profiles, component filtering…
Sbom Generate is an agent skill from cdxgen/cdxgen. Generates a CycloneDX SBOM from source code with OWASP cdxgen, covering project-type selection across 30+ ecosystems, monorepo recursion, lifecycle phases, generation profiles, component filtering, and spec-version targeting. Use when asked to create an SBOM or BOM for a repository or directory, produce a dependency inventory, resolve licenses, or export SPDX from source.
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Supply chain security, Monorepo tooling and Regulatory compliance. The repository describes itself as: Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with…. The licence is Apache-2.0.
2 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e256966. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
javaFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
cdxgen.github.ioFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Sbom Generate loads about 2.5k tokens when it runs. Until then it costs about 97 tokens; SKILL.md has 778 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from cdxgen/cdxgen at commit e256966, republished under its Apache-2.0 licence (© cdxgen). 778 words, ~2,538 tokens.
.claude/skills/sbom-generate/SKILL.md (or your agent's skills folder).Use this skill for the common case: a user wants a CycloneDX SBOM for a
repository or directory. For containers and binaries use container-sbom; for
live hosts use os-hardware-inventory; to improve an SBOM that came back thin
use sbom-fidelity-loop.
Read reference/safety.md before running anything. The dry-run-first rule and the absolute-path rule are not optional.
cdxgen [path] [options]path defaults to .. Every boolean flag accepts a --no- prefix to invert it.
cdxgen /absolute/path/to/project --dry-run --activity-report jsonSummarize what the run would read, write, execute, and fetch. Ask before the
real run. Pay particular attention to whether the preview shows package-manager
installs; if it does, offer --no-install-deps or --lifecycle pre-build.
cdxgen /absolute/path/to/project -o /absolute/path/to/bom.jsonAuto-detection handles most projects. Reach for flags when it does not.
Omit -t and let cdxgen detect. Pass it when detection is wrong, when you want
to constrain a large monorepo, or when the target is not source code.
# Restrict a polyglot repo to two ecosystems
cdxgen -t java -t python -o /absolute/path/to/bom.json /absolute/path/to/project
# Exclude one ecosystem instead of listing the rest
cdxgen --exclude-type mcp -o /absolute/path/to/bom.json /absolute/path/to/projectCommon aliases (the full matrix is at https://cdxgen.github.io/cdxgen/#/PROJECT_TYPES):
| Ecosystem | Types |
|---|---|
| Node.js | npm, pnpm, yarn, bun, deno, js, ts, nodejs, rush |
| JVM | java, kotlin, scala, groovy, gradle, maven, sbt, mill |
| Python | python, uv, poetry, pdm, hatch, pixi, rye, conda |
| Go | go, golang, gomod |
| Rust | rust, cargo, rs |
| .NET | csharp, dotnet, vbnet, fsharp |
| Ruby | ruby, bundler, gems |
| PHP | php, composer, wordpress |
| C/C++ | c, cpp, conan, collider |
| Others | dart, elixir, haskell, clojure, nix, zig, gleam, mojo |
| CI/config | github, actions, helm |
Pinned toolchains are supported as types too: java21, python312,
maven3.9.9, gradle8.14, ruby3.4.0. cdxgen installs the pinned tool with
sdkman and uses it instead of the project's wrapper. This is the fix when a
project's wrapper is broken or targets an unsupported JDK.
--recurse defaults to true. For large repos this is often the wrong default:
# Single project at the root only
cdxgen --no-recurse -t java -o /absolute/path/to/bom.json /absolute/path/to/projectCombine --no-recurse with explicit -t values, or use --exclude to skip
directories. See https://cdxgen.github.io/cdxgen/#/MONOREPO.
| Phase | Behavior |
|---|---|
pre-build | No package installations. Manifests and lockfiles only. |
build | Default. May invoke the package manager. |
post-build | Binaries and containers rather than source. |
cdxgen --lifecycle pre-build -o /absolute/path/to/bom.json /absolute/path/to/projectpre-build is the right choice for CI, containers, air-gapped hosts, and any
run where modifying the project is unacceptable.
--profile presets a bundle of flags for an intended audience.
| Profile | Intent |
|---|---|
generic | Default |
appsec | Application-security review |
research | Deep security research, maximum evidence |
operational | Operations and runtime inventory |
threat-modeling | Threat-model inputs |
license-compliance | License resolution and compliance |
ml / ml-deep / ml-tiny | Machine-learning inventory at three depths |
introspect | Grade the scan's own fidelity and rank remediations |
cdxgen --profile license-compliance -o /absolute/path/to/bom.json /absolute/path/to/project
cdxgen --profile research --evidence -o /absolute/path/to/bom.json /absolute/path/to/projectUse --profile introspect when the user's real question is "why is my SBOM
incomplete?" — then follow sbom-fidelity-loop.
| Flag | Effect |
|---|---|
--required-only | Production/non-dev dependencies only |
--filter <text> | Exclude components matching the text in purl or property values |
--only <text> | Include only components matching the text in the purl |
--exclude <glob> | Skip paths |
--exclude-type <t> | Drop an ecosystem or overlay from the result |
cdxgen --required-only -o /absolute/path/to/bom.json /absolute/path/to/project--spec-version defaults to 1.7. Accepted generation targets are 1.6,
1.7, and 2.0. 1.4 and 1.5 are rejected as generation targets — if a
consumer needs a legacy document, generate at a supported version and downgrade
the serialized output with cdx-convert (see bom-convert-validate).
# SPDX 3.0.1 JSON-LD directly
cdxgen --format spdx -o /absolute/path/to/bom.spdx.json /absolute/path/to/project
# Protobuf export alongside JSON
cdxgen --export-proto --proto-bin-file /absolute/path/to/bom.cdx -o /absolute/path/to/bom.json /absolute/path/to/projectOther output controls: -p / --print for a human-readable table or tree,
--json-pretty, --tui for the interactive terminal view, --quiet.
| Flag | Adds |
|---|---|
--evidence | Occurrence and callstack evidence; produces a SaaSBOM |
--include-crypto | Cryptographic assets and certificates (see crypto-bom) |
--include-formulation | Git metadata and build-tool versions |
--include-release-notes | Release notes for resolved components |
--resolve-class | Class-to-namespace mapping; writes <output>.map |
--deep | Deep parsing for C/C++, OS, OCI, and live systems |
--bom-audit | Embed supply-chain findings during generation (see bom-audit) |
--tlp-classification | CLEAR, GREEN, AMBER, AMBER_AND_STRICT, RED |
--license-policy | Evaluate against a license policy file |
--validate is on by default; the BOM is schema-checked before cdxgen exits.
| Symptom | First thing to check |
|---|---|
| Hangs or exits with a thin BOM | Atom availability. Native-binary platforms need no JDK; on jar-based triples (darwin-amd64, windows-arm64, linux-arm64-musl) check java -version — Java >= 23 is required and fails silently below that. |
| Registry or network timeouts | Set HTTP_PROXY / HTTPS_PROXY; cdxgen's HTTP client honors them automatically. Do not auto-retry without asking. |
| Only direct dependencies | The build tool could not resolve transitives. Run --profile introspect and follow sbom-fidelity-loop. |
| Fails in CI or a container | --install-deps defaulted on. Use --no-install-deps or --lifecycle pre-build. |
| Missing build toolchain | Suggest the container image, or a pinned type such as -t java21. |
| Permission errors | Check whether CDXGEN_SECURE_MODE is set; see reference/safety.md. |
More at https://cdxgen.github.io/cdxgen/#/TROUBLESHOOTING.
Offer the natural next step rather than stopping at the file:
bom-explorebom-auditbom-signingbom-convert-validatebom-evidencesbom-fidelity-loopdependency-track-upload© cdxgen, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in claude-plugin/skills/sbom-generate of cdxgen/cdxgen.
Open the folder on GitHubat commit e256966
Sbom Generate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Sbom Generate this skillcdxgen/cdxgen | 1.1k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | |
| Sailpillar-labs/sail-skill | 113 | — | ~5.1k | Automated safety check: Pass | Custom licence | |
| Expert SecurityReJeCtAll/ExpertTeam-Codex | 113 | — | ~780 | Automated safety check: Pass | MIT | |
| Agent Owasp Compliancegithub/awesome-copilot | 40k | 1 repos | ~3k | Automated safety check: Pass | MIT | |
| Sbom Generate686f6c61/alfred-dev | 117 | — | ~780 | Automated safety check: Pass | MIT | |
| Codebase Cleanup Deps Auditaiskillstore/marketplace | 430 | 7 repos | ~490 | Automated safety check: Pass | None |
pillar-labs/sail-skill
Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents.
ReJeCtAll/ExpertTeam-Codex
安全专家入口。用于 Codex CLI 的 $expert-security 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex.
github/awesome-copilot
Check any AI agent codebase against the OWASP Agentic Security Initiative (ASI) Top 10 risks.
686f6c61/alfred-dev
Usar para generar Software Bill of Materials para cumplimiento del CRA.
aiskillstore/marketplace
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security.
Hack23/cia
Open source governance, security posture badges, license compliance, SBOM generation, and vulnerability management for transparency-driven development
cdxgen/cdxgen
Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…
cdxgen/cdxgen
Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…
cdxgen/cdxgen
Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…
cdxgen/cdxgen
Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…
cdxgen/cdxgen
Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures…
cdxgen/cdxgen
Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…
Categories
Generates a CycloneDX SBOM from source code with OWASP cdxgen, covering project-type selection across 30+ ecosystems, monorepo recursion, lifecycle phases, generation profiles, component filtering…. Sbom Generate is an agent skill from cdxgen/cdxgen. Generates a CycloneDX SBOM from source code with OWASP cdxgen, covering project-type selection across 30+ ecosystems, monorepo recursion, lifecycle phases, generation profiles, component filtering, and spec-version targeting.
Sbom Generate fits situations like: asked to create an SBOM; BOM for a repository; produce a dependency inventory; resolve licenses.
Run `npx skills add cdxgen/cdxgen --skill sbom-generate -a claude-code`. Or copy the skill folder (claude-plugin/skills/sbom-generate in cdxgen/cdxgen) into .claude/skills/sbom-generate in your project. Claude Code loads it when a task matches its description.
Run `npx skills add cdxgen/cdxgen --skill sbom-generate -a codex`. Or copy the skill folder (claude-plugin/skills/sbom-generate in cdxgen/cdxgen) into .agents/skills/sbom-generate in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cdxgen/cdxgen --skill sbom-generate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sbom-generate, .gemini/skills/sbom-generate, .github/skills/sbom-generate and .opencode/skills/sbom-generate in your project.
Going by SKILL.md and its folder, Sbom Generate needs the command-line tools its instructions call (java). Our summary lists: Python 3; Node.js.
SKILL.md names 1 domain. As links in the text: cdxgen.github.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Sbom Generate is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Sbom Generate: Sail (pillar-labs/sail-skill, 113 stars), Expert Security (ReJeCtAll/ExpertTeam-Codex, 113 stars), Agent Owasp Compliance (github/awesome-copilot, 40k stars) and Sbom Generate (686f6c61/alfred-dev, 117 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
cdxgen (a GitHub organization) maintains it in cdxgen/cdxgen, which has 1,085 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 8, 2026.
Source: cdxgen/cdxgen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.