Agent skill

Sbom Generate

by cdxgen in cdxgen/cdxgen

Generates a CycloneDX SBOM from source code with OWASP cdxgen, covering project-type selection across 30+ ecosystems, monorepo recursion, lifecycle phases, generation profiles, component filtering…

Apache-2.0Auto-check passedSecurity

Install Sbom Generate

skills CLI
$ npx skills add cdxgen/cdxgen --skill sbom-generate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cdxgen/cdxgen sbom-generate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude-plugin/skills/sbom-generate .claude/skills/sbom-generate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sbom-generate
GitHub stars
1.1k
Token cost
~2.5k tokens
SKILL.md length
778 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
Apache-2.0

At a glance

Generates a CycloneDX SBOM from source code with OWASP cdxgen, covering project-type selection across 30+ ecosystems, monorepo recursion, lifecycle phases, generation profiles, component filtering…

  • Works in 2 steps: preview → generate
  • Asked to create an SBOM
  • SKILL.md covers Core syntax, Step 1: preview, Step 2: generate and Choosing a project type, plus 8 more sections
  • Calls java

What it does

Sbom Generate is an agent skill from cdxgen/cdxgen. Generates a CycloneDX SBOM from source code with OWASP cdxgen, covering project-type selection across 30+ ecosystems, monorepo recursion, lifecycle phases, generation profiles, component filtering, and spec-version targeting. Use when asked to create an SBOM or BOM for a repository or directory, produce a dependency inventory, resolve licenses, or export SPDX from source.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Supply chain security, Monorepo tooling and Regulatory compliance. The repository describes itself as: Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with…. The licence is Apache-2.0.

When your agent uses it

  • Asked to create an SBOM
  • BOM for a repository
  • Produce a dependency inventory
  • Resolve licenses

Example prompts

  • “Use the sbom-generate skill to generate a CycloneDX SBOM from source code with OWASP cdxgen, covering project-type selection across 30+ ecosystems…”
  • “/sbom-generate”

Requirements

  • Python 3
  • Node.js

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. preview
  2. generate

What it can do on your machine

Read from SKILL.md and the folder at commit e256966. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • java

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cdxgen.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sbom Generate loads about 2.5k tokens when it runs. Until then it costs about 97 tokens; SKILL.md has 778 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~97
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cdxgen/cdxgen at commit e256966, republished under its Apache-2.0 licence (© cdxgen). 778 words, ~2,538 tokens.

Download SKILL.mdSave it as .claude/skills/sbom-generate/SKILL.md (or your agent's skills folder).
name
sbom-generate
description
Generates a CycloneDX SBOM from source code with OWASP cdxgen, covering project-type selection across 30+ ecosystems, monorepo recursion, lifecycle phases, generation profiles, component filtering, and spec-version targeting. Use when asked to create an SBOM or BOM for a repository or directory, produce a dependency inventory, resolve licenses, or export SPDX from source.

Generate an SBOM from source

Use this skill for the common case: a user wants a CycloneDX SBOM for a repository or directory. For containers and binaries use container-sbom; for live hosts use os-hardware-inventory; to improve an SBOM that came back thin use sbom-fidelity-loop.

Read reference/safety.md before running anything. The dry-run-first rule and the absolute-path rule are not optional.

Core syntax

bash
cdxgen [path] [options]

path defaults to .. Every boolean flag accepts a --no- prefix to invert it.

Step 1: preview

bash
cdxgen /absolute/path/to/project --dry-run --activity-report json

Summarize what the run would read, write, execute, and fetch. Ask before the real run. Pay particular attention to whether the preview shows package-manager installs; if it does, offer --no-install-deps or --lifecycle pre-build.

Step 2: generate

bash
cdxgen /absolute/path/to/project -o /absolute/path/to/bom.json

Auto-detection handles most projects. Reach for flags when it does not.

Choosing a project type

Omit -t and let cdxgen detect. Pass it when detection is wrong, when you want to constrain a large monorepo, or when the target is not source code.

bash
# Restrict a polyglot repo to two ecosystems
cdxgen -t java -t python -o /absolute/path/to/bom.json /absolute/path/to/project

# Exclude one ecosystem instead of listing the rest
cdxgen --exclude-type mcp -o /absolute/path/to/bom.json /absolute/path/to/project

Common aliases (the full matrix is at https://cdxgen.github.io/cdxgen/#/PROJECT_TYPES):

EcosystemTypes
Node.jsnpm, pnpm, yarn, bun, deno, js, ts, nodejs, rush
JVMjava, kotlin, scala, groovy, gradle, maven, sbt, mill
Pythonpython, uv, poetry, pdm, hatch, pixi, rye, conda
Gogo, golang, gomod
Rustrust, cargo, rs
.NETcsharp, dotnet, vbnet, fsharp
Rubyruby, bundler, gems
PHPphp, composer, wordpress
C/C++c, cpp, conan, collider
Othersdart, elixir, haskell, clojure, nix, zig, gleam, mojo
CI/configgithub, actions, helm

Pinned toolchains are supported as types too: java21, python312, maven3.9.9, gradle8.14, ruby3.4.0. cdxgen installs the pinned tool with sdkman and uses it instead of the project's wrapper. This is the fix when a project's wrapper is broken or targets an unsupported JDK.

Monorepos

--recurse defaults to true. For large repos this is often the wrong default:

bash
# Single project at the root only
cdxgen --no-recurse -t java -o /absolute/path/to/bom.json /absolute/path/to/project

Combine --no-recurse with explicit -t values, or use --exclude to skip directories. See https://cdxgen.github.io/cdxgen/#/MONOREPO.

Lifecycle phases

PhaseBehavior
pre-buildNo package installations. Manifests and lockfiles only.
buildDefault. May invoke the package manager.
post-buildBinaries and containers rather than source.
bash
cdxgen --lifecycle pre-build -o /absolute/path/to/bom.json /absolute/path/to/project

pre-build is the right choice for CI, containers, air-gapped hosts, and any run where modifying the project is unacceptable.

Generation profiles

--profile presets a bundle of flags for an intended audience.

ProfileIntent
genericDefault
appsecApplication-security review
researchDeep security research, maximum evidence
operationalOperations and runtime inventory
threat-modelingThreat-model inputs
license-complianceLicense resolution and compliance
ml / ml-deep / ml-tinyMachine-learning inventory at three depths
introspectGrade the scan's own fidelity and rank remediations
bash
cdxgen --profile license-compliance -o /absolute/path/to/bom.json /absolute/path/to/project
cdxgen --profile research --evidence -o /absolute/path/to/bom.json /absolute/path/to/project

Use --profile introspect when the user's real question is "why is my SBOM incomplete?" — then follow sbom-fidelity-loop.

Filtering the component set

FlagEffect
--required-onlyProduction/non-dev dependencies only
--filter <text>Exclude components matching the text in purl or property values
--only <text>Include only components matching the text in the purl
--exclude <glob>Skip paths
--exclude-type <t>Drop an ecosystem or overlay from the result
bash
cdxgen --required-only -o /absolute/path/to/bom.json /absolute/path/to/project
Show full SKILL.md (311 more words)Show less

Spec version and output format

--spec-version defaults to 1.7. Accepted generation targets are 1.6, 1.7, and 2.0. 1.4 and 1.5 are rejected as generation targets — if a consumer needs a legacy document, generate at a supported version and downgrade the serialized output with cdx-convert (see bom-convert-validate).

bash
# SPDX 3.0.1 JSON-LD directly
cdxgen --format spdx -o /absolute/path/to/bom.spdx.json /absolute/path/to/project

# Protobuf export alongside JSON
cdxgen --export-proto --proto-bin-file /absolute/path/to/bom.cdx -o /absolute/path/to/bom.json /absolute/path/to/project

Other output controls: -p / --print for a human-readable table or tree, --json-pretty, --tui for the interactive terminal view, --quiet.

Enrichment worth knowing about

FlagAdds
--evidenceOccurrence and callstack evidence; produces a SaaSBOM
--include-cryptoCryptographic assets and certificates (see crypto-bom)
--include-formulationGit metadata and build-tool versions
--include-release-notesRelease notes for resolved components
--resolve-classClass-to-namespace mapping; writes <output>.map
--deepDeep parsing for C/C++, OS, OCI, and live systems
--bom-auditEmbed supply-chain findings during generation (see bom-audit)
--tlp-classificationCLEAR, GREEN, AMBER, AMBER_AND_STRICT, RED
--license-policyEvaluate against a license policy file

--validate is on by default; the BOM is schema-checked before cdxgen exits.

When a run goes wrong

SymptomFirst thing to check
Hangs or exits with a thin BOMAtom availability. Native-binary platforms need no JDK; on jar-based triples (darwin-amd64, windows-arm64, linux-arm64-musl) check java -version — Java >= 23 is required and fails silently below that.
Registry or network timeoutsSet HTTP_PROXY / HTTPS_PROXY; cdxgen's HTTP client honors them automatically. Do not auto-retry without asking.
Only direct dependenciesThe build tool could not resolve transitives. Run --profile introspect and follow sbom-fidelity-loop.
Fails in CI or a container--install-deps defaulted on. Use --no-install-deps or --lifecycle pre-build.
Missing build toolchainSuggest the container image, or a pinned type such as -t java21.
Permission errorsCheck whether CDXGEN_SECURE_MODE is set; see reference/safety.md.

More at https://cdxgen.github.io/cdxgen/#/TROUBLESHOOTING.

After generating

Offer the natural next step rather than stopping at the file:

  • Explore it interactively — bom-explore
  • Audit supply-chain exposure — bom-audit
  • Sign it for distribution — bom-signing
  • Convert to SPDX or another spec version — bom-convert-validate
  • Add usage and callstack evidence — bom-evidence
  • Improve its accuracy — sbom-fidelity-loop
  • Upload to Dependency-Track — dependency-track-upload

© cdxgen, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in claude-plugin/skills/sbom-generate of cdxgen/cdxgen.

Open the folder on GitHubat commit e256966

Compare with similar skills

Sbom Generate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sbom Generate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sbom Generate this skillcdxgen/cdxgen1.1k—~2.5kAutomated safety check: PassApache-2.0
Sailpillar-labs/sail-skill113—~5.1kAutomated safety check: PassCustom licence
Expert SecurityReJeCtAll/ExpertTeam-Codex113—~780Automated safety check: PassMIT
Agent Owasp Compliancegithub/awesome-copilot40k1 repos~3kAutomated safety check: PassMIT
Sbom Generate686f6c61/alfred-dev117—~780Automated safety check: PassMIT
Codebase Cleanup Deps Auditaiskillstore/marketplace4307 repos~490Automated safety check: PassNone

Similar skills

  • Sail

    pillar-labs/sail-skill

    Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents.

    113 GitHub stars~5.1k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Expert Security

    ReJeCtAll/ExpertTeam-Codex

    安全专家入口。用于 Codex CLI 的 $expert-security 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex.

    113 GitHub stars~780 tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Agent Owasp Compliance

    github/awesome-copilot

    Official

    Check any AI agent codebase against the OWASP Agentic Security Initiative (ASI) Top 10 risks.

    40k GitHub starsUsed in 1 repo~3k tokens
    SecurityAuto-check passed
  • Sbom Generate

    686f6c61/alfred-dev

    Usar para generar Software Bill of Materials para cumplimiento del CRA.

    117 GitHub stars~780 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Codebase Cleanup Deps Audit

    aiskillstore/marketplace

    You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security.

    430 GitHub starsUsed in 7 repos~490 tokens
    SecurityAuto-check passed
  • Open source governance, security posture badges, license compliance, SBOM generation, and vulnerability management for transparency-driven development

    239 GitHub stars~4.6k tokensUpdated today
    SecurityAuto-check passed

More from cdxgen/cdxgen

All 17 skills in this repo
  • AI Bom

    cdxgen/cdxgen

    Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…

    1.1k GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Bom Audit

    cdxgen/cdxgen

    Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…

    1.1k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Bom Evidence

    cdxgen/cdxgen

    Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…

    1.1k GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Bom Explore

    cdxgen/cdxgen

    Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…

    1.1k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Bom Signing

    cdxgen/cdxgen

    Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures…

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check: warnings

Categories

Questions about Sbom Generate

What does Sbom Generate do?

Generates a CycloneDX SBOM from source code with OWASP cdxgen, covering project-type selection across 30+ ecosystems, monorepo recursion, lifecycle phases, generation profiles, component filtering…. Sbom Generate is an agent skill from cdxgen/cdxgen. Generates a CycloneDX SBOM from source code with OWASP cdxgen, covering project-type selection across 30+ ecosystems, monorepo recursion, lifecycle phases, generation profiles, component filtering, and spec-version targeting.

When should I use Sbom Generate?

Sbom Generate fits situations like: asked to create an SBOM; BOM for a repository; produce a dependency inventory; resolve licenses.

How do I install Sbom Generate in Claude Code?

Run `npx skills add cdxgen/cdxgen --skill sbom-generate -a claude-code`. Or copy the skill folder (claude-plugin/skills/sbom-generate in cdxgen/cdxgen) into .claude/skills/sbom-generate in your project. Claude Code loads it when a task matches its description.

How do I install Sbom Generate in Codex?

Run `npx skills add cdxgen/cdxgen --skill sbom-generate -a codex`. Or copy the skill folder (claude-plugin/skills/sbom-generate in cdxgen/cdxgen) into .agents/skills/sbom-generate in your project. Codex loads it when a task matches its description.

Can I use Sbom Generate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cdxgen/cdxgen --skill sbom-generate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sbom-generate, .gemini/skills/sbom-generate, .github/skills/sbom-generate and .opencode/skills/sbom-generate in your project.

What does Sbom Generate need to run?

Going by SKILL.md and its folder, Sbom Generate needs the command-line tools its instructions call (java). Our summary lists: Python 3; Node.js.

Does Sbom Generate access the network?

SKILL.md names 1 domain. As links in the text: cdxgen.github.io. This is read from the text; nothing was executed.

Is Sbom Generate safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sbom Generate use?

Sbom Generate is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sbom Generate use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sbom Generate?

Skills that share tags, products or a category with Sbom Generate: Sail (pillar-labs/sail-skill, 113 stars), Expert Security (ReJeCtAll/ExpertTeam-Codex, 113 stars), Agent Owasp Compliance (github/awesome-copilot, 40k stars) and Sbom Generate (686f6c61/alfred-dev, 117 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sbom Generate?

cdxgen (a GitHub organization) maintains it in cdxgen/cdxgen, which has 1,085 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 8, 2026.

Source: cdxgen/cdxgen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.