Bom Audit
cdxgen/cdxgen
Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…
Author CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM.
$ npx skills add relizaio/rearm --skill vex-authoring -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install relizaio/rearm vex-authoring --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/relizaio/rearm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/vex-authoring .claude/skills/vex-authoring && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "vex-authoring" agent skill from https://github.com/relizaio/rearm/tree/main/skills/vex-authoring into .claude/skills/vex-authoring/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vex-authoring", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/relizaio/rearm/tree/main/skills/vex-authoringType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add relizaio/rearm --skill vex-authoring -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install relizaio/rearm vex-authoring --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/relizaio/rearm.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/vex-authoring .agents/skills/vex-authoring && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "vex-authoring" agent skill from https://github.com/relizaio/rearm/tree/main/skills/vex-authoring into .agents/skills/vex-authoring/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vex-authoring", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add relizaio/rearm --skill vex-authoring -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install relizaio/rearm vex-authoring --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/relizaio/rearm.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/vex-authoring .cursor/skills/vex-authoring && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "vex-authoring" agent skill from https://github.com/relizaio/rearm/tree/main/skills/vex-authoring into .cursor/skills/vex-authoring/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vex-authoring", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/relizaio/rearm.git --path skills/vex-authoring--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add relizaio/rearm --skill vex-authoring -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install relizaio/rearm vex-authoring --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/relizaio/rearm.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/vex-authoring .gemini/skills/vex-authoring && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "vex-authoring" agent skill from https://github.com/relizaio/rearm/tree/main/skills/vex-authoring into .gemini/skills/vex-authoring/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vex-authoring", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install relizaio/rearm vex-authoringInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add relizaio/rearm --skill vex-authoring -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/relizaio/rearm.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/vex-authoring .github/skills/vex-authoring && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "vex-authoring" agent skill from https://github.com/relizaio/rearm/tree/main/skills/vex-authoring into .github/skills/vex-authoring/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vex-authoring", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add relizaio/rearm --skill vex-authoring -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install relizaio/rearm vex-authoring --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/relizaio/rearm.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/vex-authoring .opencode/skills/vex-authoring && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "vex-authoring" agent skill from https://github.com/relizaio/rearm/tree/main/skills/vex-authoring into .opencode/skills/vex-authoring/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vex-authoring", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
vex-authoringAuthor CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM.
Vex Authoring is an agent skill from relizaio/rearm. Author CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM. Use when generating, fixing, or validating a VEX file for upload to a ReARM release, or when a VEX upload reported zero imported statements, unmatched statements, or skipped entries.
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Supply chain security. It works with npm. The repository describes itself as: ReARM - Release Governance Platform. The licence is AGPL-3.0.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 6d45f52. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
python3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Vex Authoring loads about 2.9k tokens when it runs. Until then it costs about 68 tokens; SKILL.md has 1,059 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from relizaio/rearm at commit 6d45f52, republished under its AGPL-3.0 licence (© relizaio). 1,059 words, ~2,899 tokens.
.claude/skills/vex-authoring/SKILL.md (or your agent's skills folder).ReARM imports VEX (Vulnerability Exploitability eXchange) documents in two formats, auto-detected from content:
Import happens synchronously during artifact upload (artifact type VEX on a
release). Each statement is matched against the release's SBOM inventory and
becomes either a Finding Analysis (auto-accept) or a PENDING proposal in the
VEX Proposals inbox (stage). The import outcome (total / staged /
auto-accepted / unmatched / errored counts plus error messages) is reported
back on upload and persisted on the VEX artifact.
This skill covers the producer side: what the document must contain so
statements actually import. For the reviewer side (scopes, import modes,
trust gate, proposals inbox), see
documentation_site/docs/workflows/importing-vex.md.
pkg:npm/minimist@1.2.6, a statement about pkg:npm/minimist (no
version) or pkg:npm/minimist@1.2.5 will NOT match and is counted as
unmatched. Copy purl values verbatim from the SBOM you are writing
VEX against.{
"bomFormat": "CycloneDX",
"specVersion": "1.6",
"serialNumber": "urn:uuid:<uuid4>",
"version": 1,
"vulnerabilities": [ ... ]
}This is the single most common authoring mistake. In CycloneDX, a
vulnerabilities[] entry without analysis is a plain vulnerability
report (what a scanner emits), not a VEX statement -- it carries no
exploitability assertion, so ReARM skips it and reports it as
"skipped: no analysis block". A document whose entries all lack analysis
imports zero statements.
"analysis": {
"state": "not_affected",
"justification": "code_not_reachable",
"detail": "optional free-text explanation of the assessment"
}state -- required. One of:
not_affected, exploitable, in_triage, resolved,
resolved_with_pedigree (imported as resolved), false_positive.justification -- provide it whenever state is not_affected. One of:
code_not_present, code_not_reachable, requires_configuration,
requires_dependency, requires_environment, protected_by_compiler,
protected_at_runtime, protected_at_perimeter,
protected_by_mitigating_control.response -- optional array, e.g. ["will_not_fix"], ["update"].Each entry's affects[] names the product(s) the statement is about. Two
accepted forms:
Direct identifier -- a pkg: PURL or cpe: string:
"affects": [{"ref": "pkg:npm/minimist@1.2.6"}]
bom-ref into this same document -- the ref must match the bom-ref
of an entry in the VEX document's own top-level components[] array, and
that component must carry a purl:
"components": [
{"type": "library", "name": "minimist", "version": "1.2.6",
"purl": "pkg:npm/minimist@1.2.6", "bom-ref": "comp-minimist"}
],
"vulnerabilities": [
{"id": "CVE-...", "affects": [{"ref": "comp-minimist"}],
"analysis": {...}}
]Refs pointing into another document -- e.g. the SBOM's BOM-Link form
urn:cdx:<serial>/1#<ref> -- do NOT resolve and the statement matches
nothing.
Every accepted analysis needs a severity. Put the severity in the statement:
"ratings": [{"severity": "high"}]With multiple ratings, ReARM takes the highest. If the statement has no
rating, ReARM falls back to existing Finding Analysis rows for the same CVE,
then to the org's canonical vulnerability record; if all three are empty an
auto-accept import demotes the statement to STAGE with a SEVERITY_MISSING
banner. Supplying ratings[] avoids the demotion.
{
"bomFormat": "CycloneDX",
"specVersion": "1.6",
"serialNumber": "urn:uuid:2c1f4a60-0000-4000-8000-000000000001",
"version": 1,
"vulnerabilities": [
{
"id": "CVE-2021-44906",
"ratings": [{"severity": "critical"}],
"affects": [{"ref": "pkg:npm/minimist@1.2.5"}],
"analysis": {
"state": "not_affected",
"justification": "code_not_reachable",
"detail": "The vulnerable prototype-pollution path is never invoked with attacker-controlled input."
}
}
]
}OpenVEX statements are validated per the 0.2.0 spec. Each statement needs a
vulnerability name (CVE id), product @ids (PURLs -- same exact-match rule
as above), and a valid status:
| status | Required | Forbidden |
|---|---|---|
not_affected | justification OR impact_statement | action_statement |
affected | action_statement | justification, impact_statement |
fixed | -- | justification, impact_statement, action_statement |
under_investigation | -- | justification, impact_statement, action_statement |
Valid justification values (OpenVEX vocabulary):
component_not_present, vulnerable_code_not_present,
vulnerable_code_not_in_execute_path,
vulnerable_code_cannot_be_controlled_by_adversary,
inline_mitigations_already_exist.
Statements that violate these rules are counted as errored with a per- statement message; the rest of the document still imports. Note OpenVEX has no severity field, so the fallback chain above always applies -- expect SEVERITY_MISSING demotions for CVEs the org has never seen.
Not every accepted statement applies immediately. ReARM distinguishes code properties (true regardless of deployment) from conditional claims (true only while some consumer-side control is in place):
not_affected with one of requires_configuration,
requires_environment, protected_by_compiler, protected_at_runtime,
protected_at_perimeter, protected_by_mitigating_controlexploitable with a workaround (text or a workaround_available
response)These are accepted but their Finding Analysis write is deferred behind a
PENDING Mitigation Attestation: someone must attest that the environmental
control / workaround is actually in place (Mitigation Attestations inbox)
before the analysis applies and finding counts change. This is by design,
not a dropped statement -- do not "fix" it by swapping the justification to
code_not_reachable or code_not_present; use those only when they are the
true assessment. not_affected with code_not_present /
code_not_reachable applies immediately.
The upload response (and the VEX artifact record) carries the outcome summary. Symptom-to-fix table:
| Outcome | Cause | Fix |
|---|---|---|
| "No VEX statements imported" / total = 0 | No vulnerabilities[] entries carry an analysis block, or the document is not parseable as CDX/OpenVEX | Add analysis to each entry (see above); check the envelope |
| "N vulnerability entries skipped: no analysis block" | Those entries are scanner findings, not VEX statements | Add analysis.state (+ justification for not_affected) reflecting the real assessment |
N unmatched, no proposals | Product PURLs / versions do not correspond to any component in the release's SBOM | Copy PURLs verbatim (including version) from the SBOM; check bom-refs resolve inside the VEX document itself |
| "doc parse failed: ..." | Malformed JSON or wrong schema | Validate the JSON; check bomFormat / OpenVEX @context |
| "Cannot import VEX: release has no SBOM components yet" | Upload order | Upload and reconcile the SBOM first, then the VEX |
| Statement staged despite Auto-accept | Trust gate (issuer class) or missing severity demoted it | Expected; supply ratings[] and review the proposal, or adjust issuer class if you authored the VEX yourself |
| Statement accepted but finding state / counts unchanged | Conditional claim (environmental justification or workaround) -- analysis write deferred behind a PENDING Mitigation Attestation | By design; attest the control in the Mitigation Attestations inbox and the analysis applies. See "Conditional justifications defer to attestation" |
Do not invent an analysis state to force an import: state is an
assertion about exploitability. If no assessment exists yet, use
in_triage (CycloneDX) or under_investigation (OpenVEX) -- that is
exactly what those states are for.
Run this against the VEX file (and the target SBOM) to catch the common failures locally:
python3 - vex.cdx.json sbom.cdx.json <<'EOF'
import json, sys
vex = json.load(open(sys.argv[1]))
sbom_purls = set()
if len(sys.argv) > 2:
sbom = json.load(open(sys.argv[2]))
sbom_purls = {c.get("purl") for c in sbom.get("components", []) if c.get("purl")}
own_refs = {c.get("bom-ref"): c.get("purl") for c in vex.get("components", [])}
problems = []
vulns = vex.get("vulnerabilities", [])
if not vulns:
problems.append("no vulnerabilities[] entries at all")
for v in vulns:
vid = v.get("id", "?")
if not v.get("analysis", {}).get("state"):
problems.append(f"{vid}: missing analysis.state (entry will be skipped)")
if v.get("analysis", {}).get("state") == "not_affected" and not v["analysis"].get("justification"):
problems.append(f"{vid}: not_affected without justification")
if not v.get("ratings"):
problems.append(f"{vid}: no ratings[] (severity may need manual review)")
for a in v.get("affects", []):
ref = a.get("ref", "")
purl = ref if ref.startswith(("pkg:", "cpe:")) else own_refs.get(ref)
if not purl:
problems.append(f"{vid}: affects ref '{ref}' resolves to no PURL")
elif sbom_purls and purl not in sbom_purls:
problems.append(f"{vid}: '{purl}' not in SBOM inventory (will be unmatched)")
print("\n".join(problems) if problems else "OK: all statements look importable")
EOFVEX -> attach the file.
Extra controls appear: Scope (default Component), Import mode (default
Auto-accept; pick "Stage all for review" to keep a human in the loop),
Issuer class (default Vendor).rearm-cli addartifact with "type": "VEX" in the
artifacts JSON; optional vexScope, vexImportMode,
userIssuerClassOverride fields (rearm-cli 26.05+). Full example in
documentation_site/docs/workflows/importing-vex.md.© relizaio, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/vex-authoring of relizaio/rearm.
Open the folder on GitHubat commit 6d45f52
Vex Authoring next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Vex Authoring this skillrelizaio/rearm | 127 | — | ~2.9k | Automated safety check: Pass | AGPL-3.0 | |
| Bom Auditcdxgen/cdxgen | 1.1k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| Dependency Update Auditbacknotprop/plannotator | 9.3k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Supply Chain Risk Auditortrailofbits/skills | 7.5k | — | ~1.7k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Corpus Sweepnubjs/nub | 4.4k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Dependency Auditbriiirussell/cybersecurity-skills | 413 | — | ~3.2k | Automated safety check: Warn | MIT |
cdxgen/cdxgen
Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…
backnotprop/plannotator
Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.
trailofbits/skills
Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration…
nubjs/nub
Run a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run).
briiirussell/cybersecurity-skills
Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns.
inkline/inkline
Inkline's platform & trust surface — the styleframe license boundary, supply-chain and secrets hygiene, npm distribution integrity, and the future Studio/commercial direction.
Works with
Categories
Author CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM. Vex Authoring is an agent skill from relizaio/rearm. Author CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM.
Vex Authoring fits situations like: validating a VEX file for upload to a ReARM release; A VEX upload reported zero imported statements; unmatched statements; skipped entries.
Run `npx skills add relizaio/rearm --skill vex-authoring -a claude-code`. Or copy the skill folder (skills/vex-authoring in relizaio/rearm) into .claude/skills/vex-authoring in your project. Claude Code loads it when a task matches its description.
Run `npx skills add relizaio/rearm --skill vex-authoring -a codex`. Or copy the skill folder (skills/vex-authoring in relizaio/rearm) into .agents/skills/vex-authoring in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add relizaio/rearm --skill vex-authoring -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vex-authoring, .gemini/skills/vex-authoring, .github/skills/vex-authoring and .opencode/skills/vex-authoring in your project.
Going by SKILL.md and its folder, Vex Authoring needs the command-line tools its instructions call (python3). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Vex Authoring is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Vex Authoring: Bom Audit (cdxgen/cdxgen, 1.1k stars), Dependency Update Audit (backnotprop/plannotator, 9.3k stars), Supply Chain Risk Auditor (trailofbits/skills, 7.5k stars) and Corpus Sweep (nubjs/nub, 4.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
relizaio (a GitHub organization) maintains it in relizaio/rearm, which has 127 GitHub stars. The repository was last updated on October 10, 2026.
Source: relizaio/rearm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.