Kesekit Check
cdppcorp/KESE-KIT
Run a pre-deployment security compliance checklist based on KISA guidelines.
Generate and manage Software Bill of Materials (SBOMs) for the OpenShell project.
$ npx skills add NVIDIA/OpenShell --skill sbom -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install NVIDIA/OpenShell sbom --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/NVIDIA/OpenShell.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/sbom .claude/skills/sbom && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "sbom" agent skill from https://github.com/NVIDIA/OpenShell/tree/main/.agents/skills/sbom into .claude/skills/sbom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sbom", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/NVIDIA/OpenShell/tree/main/.agents/skills/sbomType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add NVIDIA/OpenShell --skill sbom -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install NVIDIA/OpenShell sbom --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/NVIDIA/OpenShell.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/sbom .agents/skills/sbom && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "sbom" agent skill from https://github.com/NVIDIA/OpenShell/tree/main/.agents/skills/sbom into .agents/skills/sbom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sbom", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add NVIDIA/OpenShell --skill sbom -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install NVIDIA/OpenShell sbom --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/NVIDIA/OpenShell.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/sbom .cursor/skills/sbom && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "sbom" agent skill from https://github.com/NVIDIA/OpenShell/tree/main/.agents/skills/sbom into .cursor/skills/sbom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sbom", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/NVIDIA/OpenShell.git --path .agents/skills/sbom--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add NVIDIA/OpenShell --skill sbom -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install NVIDIA/OpenShell sbom --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/NVIDIA/OpenShell.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/sbom .gemini/skills/sbom && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "sbom" agent skill from https://github.com/NVIDIA/OpenShell/tree/main/.agents/skills/sbom into .gemini/skills/sbom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sbom", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install NVIDIA/OpenShell sbomInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add NVIDIA/OpenShell --skill sbom -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/NVIDIA/OpenShell.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/sbom .github/skills/sbom && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "sbom" agent skill from https://github.com/NVIDIA/OpenShell/tree/main/.agents/skills/sbom into .github/skills/sbom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sbom", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add NVIDIA/OpenShell --skill sbom -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install NVIDIA/OpenShell sbom --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/NVIDIA/OpenShell.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/sbom .opencode/skills/sbom && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "sbom" agent skill from https://github.com/NVIDIA/OpenShell/tree/main/.agents/skills/sbom into .opencode/skills/sbom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sbom", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
sbomGenerate and manage Software Bill of Materials (SBOMs) for the OpenShell project.
Sbom is an agent skill from NVIDIA/OpenShell, published by the product's own GitHub organization. Generate and manage Software Bill of Materials (SBOMs) for the OpenShell project. Covers SBOM generation with Syft, license resolution via public registries, and CSV export for compliance review. Trigger keywords - SBOM, sbom, bill of materials, license audit, license resolution, generate sbom, sbom csv, dependency license, supply chain, license scan.
Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Supply chain security and Regulatory compliance. The repository describes itself as: OpenShell is the safe, private runtime for autonomous AI agents. The licence is Apache-2.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 277f922. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
miseuvdockerFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use uv and docker, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Sbom loads about 1.3k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 481 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from NVIDIA/OpenShell at commit 277f922, republished under its Apache-2.0 licence (© NVIDIA). 481 words, ~1,316 tokens.
.claude/skills/sbom/SKILL.md (or your agent's skills folder).Generate CycloneDX SBOMs, resolve missing licenses, and export to CSV for compliance review.
The OpenShell SBOM tooling produces source-tree CycloneDX JSON SBOMs using Syft, resolves missing or hash-based licenses by querying public registries (crates.io, npm, PyPI), and exports the results to CSV for stakeholder review.
SBOMs are release artifacts only -- they are generated on demand and not committed to the repository. Output lands in deploy/sbom/output/ (gitignored).
Pushed gateway, sandbox, and supervisor images carry an SPDX SBOM and minimal SLSA provenance as OCI attestations. Branch E2E, Release Dev, and Release Tag image binaries embed cargo-auditable metadata, so their image SBOMs include linked Rust crates.
mise install has been run (installs Syft and other tools)BuildKit uses its default Syft scanner and attaches one SPDX document per platform. Read one without pulling the image:
docker buildx imagetools inspect ghcr.io/nvidia/openshell/gateway:latest \
--format '{{ json (index .SBOM "linux/amd64").SPDX }}'Validate the final attestation, requiring a Cargo package for an auditable image:
tasks/scripts/verify-image-sbom.sh ghcr.io/nvidia/openshell/gateway:latest --require-cargoOpt into auditable metadata when staging a local image binary:
OPENSHELL_AUDITABLE=1 PREBUILT_ARCH=amd64 \
tasks/scripts/stage-prebuilt-binaries.sh gatewayScan the staged binary rather than the source tree:
mise x -- syft \
"file:deploy/docker/.build/prebuilt-binaries/amd64/openshell-gateway" \
-o cyclonedx-jsonThis output is limited to packages Syft discovers from that binary. Use
mise run sbom for the broader source-tree license-compliance inventory.
mise run sbomThis single command chains three stages:
sbom:generate): Syft scans the workspace source tree and produces a CycloneDX JSON SBOMsbom:resolve): Public registry APIs fill in missing or hash-based licenses in the JSONsbom:csv): JSON SBOMs are converted to CSV for reviewOutput directory: deploy/sbom/output/
After running, the user can find:
deploy/sbom/output/*.cdx.json -- full CycloneDX SBOMsdeploy/sbom/output/*.csv -- CSV exports ready for spreadsheet reviewRun stages independently when debugging or iterating:
mise run sbom:generate # Generate JSON SBOMs only (requires Syft)
mise run sbom:resolve # Resolve licenses in existing JSONs (queries APIs)
mise run sbom:csv # Convert existing JSONs to CSVmise run sbom:checkReports unresolved licenses without failing. Intended for PR CI as a non-blocking advisory check. Requires that SBOMs have already been generated (mise run sbom:generate).
The Python scripts accept explicit file paths, so they can process SBOMs from any source (e.g., NVIDIA nSpect pipeline output):
uv run python deploy/sbom/resolve_licenses.py /path/to/external-sbom.json
uv run python deploy/sbom/sbom_to_csv.py /path/to/external-sbom.jsonThe resolver queries these public registries:
| Registry | Package URL prefix | Method |
|---|---|---|
| crates.io | pkg:cargo/* | REST API |
| npm | pkg:npm/* | Registry API |
| PyPI | pkg:pypi/* | JSON API |
| Go modules | pkg:golang/* | Known license map (no API) |
| Debian/Ubuntu | pkg:deb/* | Known license map |
Components from private registries (e.g., @openclaw/* npm packages) are not resolved and will appear in the "unresolved" report.
| Pattern | Description |
|---|---|
deploy/sbom/output/openshell-source-{version}.cdx.json | CycloneDX JSON SBOM |
deploy/sbom/output/openshell-source-{version}.csv | CSV export (name, version, type, purl, licenses, bom-ref) |
| File | Purpose |
|---|---|
deploy/sbom/resolve_licenses.py | License resolution script |
deploy/sbom/sbom_to_csv.py | JSON-to-CSV converter |
tasks/sbom.toml | Mise task definitions |
mise.toml | Syft tool definition (under [tools]) |
| Task | Command |
|---|---|
| Full pipeline | mise run sbom |
| Generate only | mise run sbom:generate |
| Resolve licenses | mise run sbom:resolve |
| Export CSV | mise run sbom:csv |
| CI license check | mise run sbom:check |
| Process external SBOM | uv run python deploy/sbom/resolve_licenses.py <file> |
© NVIDIA, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/sbom of NVIDIA/OpenShell.
Open the folder on GitHubat commit 277f922
Sbom next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Sbom this skillNVIDIA/OpenShell | 15k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Kesekit Checkcdppcorp/KESE-KIT | 361 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Bom Slimmercdxgen/cdxgen | 1.1k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| Sca TrivyAgentSecOps/SecOpsAgentKit | 220 | 2 repos | ~3.7k | Automated safety check: Pass | Custom licence | |
| Sbom SyftAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~3.5k | Automated safety check: Pass | Custom licence | |
| Managing Vulnerabilitiesancoleman/ai-design-components | 526 | — | ~3.8k | Automated safety check: Pass | MIT |
cdppcorp/KESE-KIT
Run a pre-deployment security compliance checklist based on KISA guidelines.
cdxgen/cdxgen
Reviews a codebase's direct dependencies and designs lightweight, low-risk, zero-dependency custom replacements using cdxgen SBOM evidence, occurrence/callstack usage data, and license and…
AgentSecOps/SecOpsAgentKit
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…
AgentSecOps/SecOpsAgentKit
Software Bill of Materials (SBOM) generation using Syft for container images, filesystems, and archives.
ancoleman/ai-design-components
Implementing multi-layer security scanning (container, SAST, DAST, SCA, secrets), SBOM generation, and risk-based vulnerability prioritization in CI/CD pipelines.
cloudposse/atmos
Atmos SBOM provenance: CycloneDX and SPDX generation from vendor and Terraform evidence, coverage diagnostics, NTIA validation, and native CI workflow-artifact publication
NVIDIA/OpenShell
Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.
NVIDIA/OpenShell
Create GitHub issues using the gh CLI. An agent skill from NVIDIA/OpenShell.
NVIDIA/OpenShell
Create GitHub pull requests using the gh CLI. An agent skill from NVIDIA/OpenShell.
NVIDIA/OpenShell
Debug inference clients that use an attached provider and its native endpoint, including hosted APIs and host-local Ollama, vLLM, SGLang, TRT-LLM, LM Studio, or NIM.
NVIDIA/OpenShell
Debug why an OpenShell gateway deployment is unhealthy, unreachable, or unable to create sandboxes.
NVIDIA/OpenShell
Validate and monitor OpenShell GitHub issues and PRs using the gator: state machine.
Categories
Generate and manage Software Bill of Materials (SBOMs) for the OpenShell project. Sbom is an agent skill from NVIDIA/OpenShell, published by the product's own GitHub organization. Generate and manage Software Bill of Materials (SBOMs) for the OpenShell project.
Sbom fits situations like: keywords - SBOM; bill of materials; license resolution; dependency license.
Run `npx skills add NVIDIA/OpenShell --skill sbom -a claude-code`. Or copy the skill folder (.agents/skills/sbom in NVIDIA/OpenShell) into .claude/skills/sbom in your project. Claude Code loads it when a task matches its description.
Run `npx skills add NVIDIA/OpenShell --skill sbom -a codex`. Or copy the skill folder (.agents/skills/sbom in NVIDIA/OpenShell) into .agents/skills/sbom in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add NVIDIA/OpenShell --skill sbom -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sbom, .gemini/skills/sbom, .github/skills/sbom and .opencode/skills/sbom in your project.
Going by SKILL.md and its folder, Sbom needs the command-line tools its instructions call (mise, uv and docker). Our summary lists: Python 3; Docker.
SKILL.md contains no URLs. Its commands use uv and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Sbom is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Sbom: Kesekit Check (cdppcorp/KESE-KIT, 361 stars), Bom Slimmer (cdxgen/cdxgen, 1.1k stars), Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars) and Sbom Syft (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
NVIDIA (a GitHub organization, an official publisher) maintains it in NVIDIA/OpenShell, which has 15,338 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 8, 2026.
Source: NVIDIA/OpenShell on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.