ai-bom
Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents…
Reviews a codebase's direct dependencies and designs lightweight, low-risk, zero-dependency custom replacements using cdxgen SBOM evidence, occurrence/callstack usage data, and license and supply-chain risk evaluation. Use when asked to shrink node_modules, reduce dependency
$ npx -y skills add cdxgen/cdxgen --skill bom-slimmer --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/bom-slimmerContext preview
The summary Claude sees to decide when to auto-load this skill.
Reviews a codebase's direct dependencies and designs lightweight, low-risk, zero-dependency custom replacements using cdxgen SBOM evidence, occurrence/callstack usage data, and license and supply-chain risk evaluation. Use when asked to shrink node_modules, reduce dependency
name: bom-slimmer description: Reviews a codebase's direct dependencies and designs lightweight, low-risk, zero-dependency custom replacements using cdxgen SBOM evidence, occurrence/callstack usage data, and license and supply-chain risk evaluation. Use when asked to shrink node_modules, reduce dependency bloat or copyleft exposure, or replace utility packages with native or built-in implementations.
This skill guides a local LLM through analyzing a project's direct dependencies, identifying high-overhead packages, and designing low-risk, zero-dependency custom replacements.
---
A CycloneDX SBOM generated by `cdxgen` (`bom.json`) provides a complete, normalized, and machine-readable inventory of all direct and transitive dependencies. Use it as your primary source of truth:
1. **Locate Direct Dependencies**: Look under `bom.metadata.component` (the parent package) and trace its relationships in the `dependencies` array. 2. **Trace Dependency Trees**: Find the `dependencies` block at the root of the SBOM. Each entry maps a package `ref` to its direct dependency `dependsOn` refs:
{
"ref": "pkg:npm/foo@1.0.0",
"dependsOn": ["pkg:npm/bar@2.0.0", "pkg:npm/baz@1.5.0"]
}3. **Calculate Transitive Footprint**: For any candidate direct dependency, traverse the `dependsOn` graph in the SBOM to identify how many total sub-packages will be completely purged from `node_modules` if that direct dependency is removed. 4. **Inspect Metadata**: Filter out `type: "development"` components or dev-only scopes if you are optimizing production boot time and install footprint.
---
When `cdxgen` is run under `--profile research` (or during deep Evinse executions), it populates components with schema-valid **occurrences** and **callstacks** under `evidence`:
Use the following additional SBOM metadata to guide the business and legal aspects of the replacement:
---
Evaluate candidates against these key replacement archetypes:
For viable candidates, design a zero-dependency JS/TS snippet. Follow these requirements:
1. **Compatibility**: Ensure the new implementation supports the exact same input/output formats and signatures as the replaced library APIs. 2. **Standards**: Avoid complex regexes that could cause backtracking vulnerabilities (e.g. ReDoS). Prefer simple string splitting, slice operations, and standard built-ins. 3. **Cross-Platform**: Support Node.js, Bun, and Deno by using global/web-standard APIs (`globalThis`) where possible.
---
Assign a risk category to each proposed replacement:
| Risk Category | Criteria | Example | | :-------------- | :------------------------------------------------------------------------------------------------------------------------ | :---------------------------------------------------------------------------- | | **Low Risk** | Standard built-in exists; utility does basic string formatting/math; isolated to a single non-critical utility. | Replacing `uuid` with `crypto.randomUUID()` or `yoctocolors` with ANSI codes. | | **Medium Risk** | Requires writing custom parsing logic for standard formats; used in core execution paths; handl
cdxgen is a CLI tool, library, REPL, and server to create, validate, sign, and verify software BOMs. It generates CycloneDX JSON BOMs and supports SPDX 3.0.1 JSON-LD export.
Repo: cdxgen/cdxgen
Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents…
Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and…
Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with…
Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and…
Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in…
Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF)…