bom-audit
Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and…
Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their tools/prompts/resources, agent instruction files, and cdx:ai:codegen provenance signals, then
$ npx -y skills add cdxgen/cdxgen --skill ai-bom --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/ai-bomContext preview
The summary Claude sees to decide when to auto-load this skill.
Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their tools/prompts/resources, agent instruction files, and cdx:ai:codegen provenance signals, then
name: ai-bom description: Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their tools/prompts/resources, agent instruction files, and cdx:ai:codegen provenance signals, then audits them with AI-focused rule packs. Use when asked to inventory AI or ML usage, catalog MCP servers, audit agent instruction or skill files, assess AI supply-chain risk, or detect AI-generated code authorship.
Four related but distinct concerns. Pick the right one before reaching for flags — conflating them produces a document that answers the wrong question.
| Question | Project type | | ----------------------------------------------------- | ------------------------------------- | | What models and inference services does this use? | `ai` / `aibom` / `ai-bom` | | What MCP servers, tools, and configs does this ship? | `mcp` | | What agent instruction and skill files does it ship? | `ai-skill` / `skill` / `skills` | | Was this code written with AI assistance? | `ai-provenance` / `ai-authorship` / `aicode` / `ai-codegen` |
Read [reference/safety.md](../../reference/safety.md) first. The review-before-sharing rule is especially relevant here: AI and MCP inventory is one of the categories most likely to contain credential-bearing configuration.
aibom /absolute/path/to/project
Or explicitly, with the audit pack:
cdxgen -r --include-formulation \ -o /absolute/path/to/aibom.json \ --bom-audit --bom-audit-categories ai-bom \ /absolute/path/to/project
`--include-formulation` matters here: it moves the AI and agentic inventory into the standard CycloneDX `formulation[]` section so downstream tools consume it as formal formulation data rather than ad-hoc top-level enrichment. Prefer it.
`aibom` accepts a model reference rather than a project directory:
aibom pkg:huggingface/deepseek-ai/DeepSeek-R1-Distill-Qwen-7B aibom https://huggingface.co/deepseek-ai/DeepSeek-R1-Distill-Qwen-7B aibom /absolute/path/to/Modelfile aibom /absolute/path/to/model.gguf
Hugging Face model repositories get proper `pkg:huggingface/<namespace>/<name>@<revision>` purls when a compliant repository reference is available. When remote resolution is enabled, cdxgen follows the revision-aware Hub endpoints, so explicit purl revisions, remote popularity/runtime hints, and Space-linked model/dataset relationships are preserved instead of collapsing to an unversioned HEAD lookup. Datasets referenced by model cards get reusable dataset component references with their own Hugging Face purls.
cdxgen --profile ml-tiny -o /absolute/path/to/bom.json /absolute/path/to/project
`ml` / `machine-learning`, `ml-deep` / `deep-learning`, and `ml-tiny` trade depth against runtime. Start with `ml` and escalate only if the inventory is thin.
| Category | Checks | | ---------------- | ------------------------------------------------------------- | | `ai-bom` | Umbrella pack for AI-BOM review | | `ai-security` | Security posture of AI services and model usage | | `ai-governance` | Governance and policy conformance | | `ai-performance` | Performance-relevant model and runtime findings | | `ai-inventory` | Alias enabling both `ai-agent` and `mcp-server` |
cdxgen -t mcp /absolute/path/to/project \ -o /absolute/path/to/bom.json \ --bom-audit --bom-audit-categories mcp-server
By default a plain `-t js` scan **also** reports shipped MCP configuration files and AI instruction/skill files, because both can influence build and post-build lifecycles. Control that overlay:
Config formats recognised include `.vscode/mcp.json`, `.mcp.json`, `claude_desktop_config.json`, and `opencode.json`. Community agent layouts are covered too: OpenCode, Nanocoder, LangGraph, and common CrewAI project files.
# discovered servers
jq '.services[]' /absolute/path/to/bom.json
# MCP primitives
jq '.components[] | select(.properties[]?.name == "cdx:mcp:role")' /absolute/path/to/bom.json
# shipped MCP config files
jq '.components[] | select(.properties[]?.value == "mcp-config")' /absolute/path/to/bom.json
# service-to-primitive links
jq '.dependencies[] | select(.ref | startswith("urn:service:mcp:"))' /absolute/path/to/bom.json
# audit findings
jq '.annotations[]' /absolute/path/to/bom.jsonKey property namespaces: `cdx:mcp:serviceType`, `cdx:mcp:transport`, `cdx:mcp:exposureType`, `cdx:mcp:authPosture`, `cdx:mcp:trustProfile`, `cdx:mcp:credentialExposure`, `cdx:mcp:reviewNeeded`, `cdx:mcp:security:confusedDeputyRisk`, `cdx:mcp:security:tokenPassthroughRisk`.
Escalate these:
cdxgen is a CLI tool, library, REPL, and server to create, validate, sign, and verify software BOMs. It generates CycloneDX JSON BOMs and supports SPDX 3.0.1 JSON-LD export.
Repo: cdxgen/cdxgen
Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and…
Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with…
Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and…
Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in…
Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF)…
Reviews a codebase's direct dependencies and designs lightweight, low-risk, zero-dependency…