Official agent skill

Sbom

by NVIDIA in NVIDIA/OpenShell

Generate and manage Software Bill of Materials (SBOMs) for the OpenShell project.

OfficialApache-2.0Auto-check passedSecurity

Install Sbom

skills CLI
$ npx skills add NVIDIA/OpenShell --skill sbom -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install NVIDIA/OpenShell sbom --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/NVIDIA/OpenShell.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/sbom .claude/skills/sbom && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sbom
GitHub stars
15k
Token cost
~1.3k tokens
SKILL.md length
481 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
Apache-2.0

At a glance

Generate and manage Software Bill of Materials (SBOMs) for the OpenShell project.

  • Works in 3 steps: Generate (sbom:generate): Syft scans the… → Resolve (sbom:resolve): Public registry… → CSV (sbom:csv): JSON SBOMs are converted…
  • Keywords - SBOM
  • SKILL.md covers Overview, Prerequisites, Inspecting an Image SBOM and Inspecting an Auditable Image…, plus 8 more sections
  • Calls mise, uv and docker

What it does

Sbom is an agent skill from NVIDIA/OpenShell, published by the product's own GitHub organization. Generate and manage Software Bill of Materials (SBOMs) for the OpenShell project. Covers SBOM generation with Syft, license resolution via public registries, and CSV export for compliance review. Trigger keywords - SBOM, sbom, bill of materials, license audit, license resolution, generate sbom, sbom csv, dependency license, supply chain, license scan.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Supply chain security and Regulatory compliance. The repository describes itself as: OpenShell is the safe, private runtime for autonomous AI agents. The licence is Apache-2.0.

When your agent uses it

  • Keywords - SBOM
  • Bill of materials
  • License resolution
  • Dependency license

Example prompts

  • “/sbom”

Requirements

  • Python 3
  • Docker

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Generate (sbom:generate): Syft scans the workspace source tree and produces a CycloneDX JSON SBOM
  2. Resolve (sbom:resolve): Public registry APIs fill in missing or hash-based licenses in the JSON
  3. CSV (sbom:csv): JSON SBOMs are converted to CSV for review

What it can do on your machine

Read from SKILL.md and the folder at commit 277f922. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • mise
    • uv
    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv and docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sbom loads about 1.3k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 481 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from NVIDIA/OpenShell at commit 277f922, republished under its Apache-2.0 licence (© NVIDIA). 481 words, ~1,316 tokens.

Download SKILL.mdSave it as .claude/skills/sbom/SKILL.md (or your agent's skills folder).
name
sbom
description
Generate and manage Software Bill of Materials (SBOMs) for the OpenShell project. Covers SBOM generation with Syft, license resolution via public registries, and CSV export for compliance review. Trigger keywords - SBOM, sbom, bill of materials, license audit, license resolution, generate sbom, sbom csv, dependency license, supply chain, license scan.
metadata.internal
true

SBOM Generation and License Resolution

Generate CycloneDX SBOMs, resolve missing licenses, and export to CSV for compliance review.

Overview

The OpenShell SBOM tooling produces source-tree CycloneDX JSON SBOMs using Syft, resolves missing or hash-based licenses by querying public registries (crates.io, npm, PyPI), and exports the results to CSV for stakeholder review.

SBOMs are release artifacts only -- they are generated on demand and not committed to the repository. Output lands in deploy/sbom/output/ (gitignored).

Pushed gateway, sandbox, and supervisor images carry an SPDX SBOM and minimal SLSA provenance as OCI attestations. Branch E2E, Release Dev, and Release Tag image binaries embed cargo-auditable metadata, so their image SBOMs include linked Rust crates.

Prerequisites

  • mise install has been run (installs Syft and other tools)
  • The repository is checked out at the root

Inspecting an Image SBOM

BuildKit uses its default Syft scanner and attaches one SPDX document per platform. Read one without pulling the image:

bash
docker buildx imagetools inspect ghcr.io/nvidia/openshell/gateway:latest \
  --format '{{ json (index .SBOM "linux/amd64").SPDX }}'

Validate the final attestation, requiring a Cargo package for an auditable image:

bash
tasks/scripts/verify-image-sbom.sh ghcr.io/nvidia/openshell/gateway:latest --require-cargo

Inspecting an Auditable Image Binary

Opt into auditable metadata when staging a local image binary:

bash
OPENSHELL_AUDITABLE=1 PREBUILT_ARCH=amd64 \
  tasks/scripts/stage-prebuilt-binaries.sh gateway

Scan the staged binary rather than the source tree:

bash
mise x -- syft \
  "file:deploy/docker/.build/prebuilt-binaries/amd64/openshell-gateway" \
  -o cyclonedx-json

This output is limited to packages Syft discovers from that binary. Use mise run sbom for the broader source-tree license-compliance inventory.

Workflow 1: Full SBOM Generation (One Command)

bash
mise run sbom

This single command chains three stages:

  1. Generate (sbom:generate): Syft scans the workspace source tree and produces a CycloneDX JSON SBOM
  2. Resolve (sbom:resolve): Public registry APIs fill in missing or hash-based licenses in the JSON
  3. CSV (sbom:csv): JSON SBOMs are converted to CSV for review

Output directory: deploy/sbom/output/

After running, the user can find:

  • deploy/sbom/output/*.cdx.json -- full CycloneDX SBOMs
  • deploy/sbom/output/*.csv -- CSV exports ready for spreadsheet review

Workflow 2: Individual Stages

Run stages independently when debugging or iterating:

bash
mise run sbom:generate   # Generate JSON SBOMs only (requires Syft)
mise run sbom:resolve    # Resolve licenses in existing JSONs (queries APIs)
mise run sbom:csv        # Convert existing JSONs to CSV
Show full SKILL.md (188 more words)Show less

Workflow 3: License Check (CI Advisory)

bash
mise run sbom:check

Reports unresolved licenses without failing. Intended for PR CI as a non-blocking advisory check. Requires that SBOMs have already been generated (mise run sbom:generate).

Workflow 4: Processing External SBOMs

The Python scripts accept explicit file paths, so they can process SBOMs from any source (e.g., NVIDIA nSpect pipeline output):

bash
uv run python deploy/sbom/resolve_licenses.py /path/to/external-sbom.json
uv run python deploy/sbom/sbom_to_csv.py /path/to/external-sbom.json

License Resolution Details

The resolver queries these public registries:

RegistryPackage URL prefixMethod
crates.iopkg:cargo/*REST API
npmpkg:npm/*Registry API
PyPIpkg:pypi/*JSON API
Go modulespkg:golang/*Known license map (no API)
Debian/Ubuntupkg:deb/*Known license map

Components from private registries (e.g., @openclaw/* npm packages) are not resolved and will appear in the "unresolved" report.

Output Files

PatternDescription
deploy/sbom/output/openshell-source-{version}.cdx.jsonCycloneDX JSON SBOM
deploy/sbom/output/openshell-source-{version}.csvCSV export (name, version, type, purl, licenses, bom-ref)

Key Files

FilePurpose
deploy/sbom/resolve_licenses.pyLicense resolution script
deploy/sbom/sbom_to_csv.pyJSON-to-CSV converter
tasks/sbom.tomlMise task definitions
mise.tomlSyft tool definition (under [tools])

Quick Reference

TaskCommand
Full pipelinemise run sbom
Generate onlymise run sbom:generate
Resolve licensesmise run sbom:resolve
Export CSVmise run sbom:csv
CI license checkmise run sbom:check
Process external SBOMuv run python deploy/sbom/resolve_licenses.py <file>

© NVIDIA, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/sbom of NVIDIA/OpenShell.

Open the folder on GitHubat commit 277f922

Compare with similar skills

Sbom next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sbom compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sbom this skillNVIDIA/OpenShell15k—~1.3kAutomated safety check: PassApache-2.0
Kesekit Checkcdppcorp/KESE-KIT361—~1.3kAutomated safety check: PassMIT
Bom Slimmercdxgen/cdxgen1.1k—~1.6kAutomated safety check: PassApache-2.0
Sca TrivyAgentSecOps/SecOpsAgentKit2202 repos~3.7kAutomated safety check: PassCustom licence
Sbom SyftAgentSecOps/SecOpsAgentKit2201 repos~3.5kAutomated safety check: PassCustom licence
Managing Vulnerabilitiesancoleman/ai-design-components526—~3.8kAutomated safety check: PassMIT

Similar skills

  • Kesekit Check

    cdppcorp/KESE-KIT

    Run a pre-deployment security compliance checklist based on KISA guidelines.

    361 GitHub stars~1.3k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Bom Slimmer

    cdxgen/cdxgen

    Reviews a codebase's direct dependencies and designs lightweight, low-risk, zero-dependency custom replacements using cdxgen SBOM evidence, occurrence/callstack usage data, and license and…

    1.1k GitHub stars~1.6k tokensUpdated today
    SecurityAuto-check passed
  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    220 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • Sbom Syft

    AgentSecOps/SecOpsAgentKit

    Software Bill of Materials (SBOM) generation using Syft for container images, filesystems, and archives.

    220 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check passed
  • Managing Vulnerabilities

    ancoleman/ai-design-components

    Implementing multi-layer security scanning (container, SAST, DAST, SCA, secrets), SBOM generation, and risk-based vulnerability prioritization in CI/CD pipelines.

    526 GitHub stars~3.8k tokensUpdated 10 mo ago
    SecurityAuto-check passed
  • Atmos Sbom

    cloudposse/atmos

    Atmos SBOM provenance: CycloneDX and SPDX generation from vendor and Terraform evidence, coverage diagnostics, NTIA validation, and native CI workflow-artifact publication

    1.4k GitHub stars~1.4k tokensUpdated today
    SecurityAuto-check passed

More from NVIDIA/OpenShell

All 23 skills in this repo
  • Official

    Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.

    15k GitHub stars~4.9k tokensUpdated today
    Auto-check passed
  • Create GitHub Issue

    NVIDIA/OpenShell

    Official

    Create GitHub issues using the gh CLI. An agent skill from NVIDIA/OpenShell.

    15k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Create GitHub PR

    NVIDIA/OpenShell

    Official

    Create GitHub pull requests using the gh CLI. An agent skill from NVIDIA/OpenShell.

    15k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Debug Inference

    NVIDIA/OpenShell

    Official

    Debug inference clients that use an attached provider and its native endpoint, including hosted APIs and host-local Ollama, vLLM, SGLang, TRT-LLM, LM Studio, or NIM.

    15k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Debug Openshell Cluster

    NVIDIA/OpenShell

    Official

    Debug why an OpenShell gateway deployment is unhealthy, unreachable, or unable to create sandboxes.

    15k GitHub stars~19k tokensUpdated today
    Auto-check: notes
  • Gator Gate

    NVIDIA/OpenShell

    Official

    Validate and monitor OpenShell GitHub issues and PRs using the gator: state machine.

    15k GitHub stars~19k tokensUpdated today
    Auto-check passed

Categories

Questions about Sbom

What does Sbom do?

Generate and manage Software Bill of Materials (SBOMs) for the OpenShell project. Sbom is an agent skill from NVIDIA/OpenShell, published by the product's own GitHub organization. Generate and manage Software Bill of Materials (SBOMs) for the OpenShell project.

When should I use Sbom?

Sbom fits situations like: keywords - SBOM; bill of materials; license resolution; dependency license.

How do I install Sbom in Claude Code?

Run `npx skills add NVIDIA/OpenShell --skill sbom -a claude-code`. Or copy the skill folder (.agents/skills/sbom in NVIDIA/OpenShell) into .claude/skills/sbom in your project. Claude Code loads it when a task matches its description.

How do I install Sbom in Codex?

Run `npx skills add NVIDIA/OpenShell --skill sbom -a codex`. Or copy the skill folder (.agents/skills/sbom in NVIDIA/OpenShell) into .agents/skills/sbom in your project. Codex loads it when a task matches its description.

Can I use Sbom in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add NVIDIA/OpenShell --skill sbom -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sbom, .gemini/skills/sbom, .github/skills/sbom and .opencode/skills/sbom in your project.

What does Sbom need to run?

Going by SKILL.md and its folder, Sbom needs the command-line tools its instructions call (mise, uv and docker). Our summary lists: Python 3; Docker.

Does Sbom access the network?

SKILL.md contains no URLs. Its commands use uv and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Sbom safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sbom use?

Sbom is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sbom use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sbom?

Skills that share tags, products or a category with Sbom: Kesekit Check (cdppcorp/KESE-KIT, 361 stars), Bom Slimmer (cdxgen/cdxgen, 1.1k stars), Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars) and Sbom Syft (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sbom?

NVIDIA (a GitHub organization, an official publisher) maintains it in NVIDIA/OpenShell, which has 15,338 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 8, 2026.

Source: NVIDIA/OpenShell on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.