ai-bom
Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents…
Collects live operating-system inventory (OBOM) and host hardware inventory (HBOM) as CycloneDX documents using the cdxgen obom and hbom commands, including osquery-backed runtime artifacts, Linux hardening snapshots, GTFOBins enrichment, firmware and bus topology, and macOS
$ npx -y skills add cdxgen/cdxgen --skill os-hardware-inventory --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/os-hardware-inventoryContext preview
The summary Claude sees to decide when to auto-load this skill.
Collects live operating-system inventory (OBOM) and host hardware inventory (HBOM) as CycloneDX documents using the cdxgen obom and hbom commands, including osquery-backed runtime artifacts, Linux hardening snapshots, GTFOBins enrichment, firmware and bus topology, and macOS
name: os-hardware-inventory description: Collects live operating-system inventory (OBOM) and host hardware inventory (HBOM) as CycloneDX documents using the cdxgen obom and hbom commands, including osquery-backed runtime artifacts, Linux hardening snapshots, GTFOBins enrichment, firmware and bus topology, and macOS permission troubleshooting. Use when asked to inventory a live machine, audit a running host's packages or services, produce a hardware BOM, or check host trust posture.
Two distinct documents, two distinct commands. Do not mix them.
| Want | Command | | --------------------------------- | -------------------------------- | | Software on a running machine | `obom` (`cdxgen -t os`) | | Physical hardware of the host | `hbom` | | Offline host from a mounted disk | `-t rootfs` (see `container-sbom`) |
Read [reference/safety.md](../../reference/safety.md) first. Live host collection reads far more of the machine than a project scan, so the dry-run-and-confirm step matters more here, not less.
Never combine `hbom` / `hardware` with software project types such as `js`, `java`, `python`, `os`, or `oci` in one invocation. Generate them separately. If the user wants one merged host document, use `hbom --include-runtime` rather than stacking `-t` flags.
obom -o /absolute/path/to/obom.json --deep
`obom` is an alias for `cdxgen -t os`. Aliases `osquery`, `windows`, `linux`, `mac`, `macos`, `darwin` reach the same pipeline.
With a runtime audit:
obom -o /absolute/path/to/obom.json --deep \ --bom-audit --bom-audit-categories obom-runtime
Collection uses the bundled osquery binary in **shell mode**, which avoids the older `/var/osquery` startup failure. Some tables still require Full Disk Access or elevated privileges.
If tables come back empty or permission-gated, that is a host configuration issue, not a cdxgen bug. Point the user at <https://cdxgen.github.io/cdxgen/#/OBOM_MACOS_TROUBLESHOOTING> rather than retrying the same command.
For live-host triage patterns generally, see <https://cdxgen.github.io/cdxgen/#/OBOM_LESSONS>.
Understand the split before interpreting the output:
hbom -o /absolute/path/to/hbom.json
Hardware collection comes from the optional `@cdxgen/cdx-hbom` library, loaded only when requested. Supported hosts:
On an unsupported host, say so directly rather than producing an empty document and calling it a success.
The equivalent library path is `cdxgen -t hbom .`, but prefer the dedicated command.
hbom --include-runtime -o /absolute/path/to/host-view.json
This is the supported way to get one document covering both. It also extends the default audit categories to include `host-topology`.
hbom diagnostics
Reports missing native utilities and permission-sensitive enrichments. Run this first when an HBOM comes back sparse — the usual cause is an absent host command, not a collection bug.
| Flag | Effect | | ------------------------- | ---------------------------------------------------------- | | `--include-runtime` | Merge runtime host inventory into the hardware document | | `--privileged` | Enable collectors that need elevated privileges | | `--sensitive` | Include sensitive identifiers (ask the user first) | | `--plist-enrichment` | macOS property-list enrichment | | `--no-command-enrichment` | Skip host command invocation | | `--timeout` | Bound collector runtime | | `--export-proto` | Protobuf output via `--proto-bin-file` | | `--dry-run` | Preview collection without writing |
Treat `--sensitive` as a confirm-first flag. It widens what lands in a document the user may share.
For `hbom` / `hardware` targets, cdxgen **skips the predictive dependency audit entirely** and defaults the audit categories to `hbom-security,hbom-performance,hbom-compliance`. With `--include-runtime` it adds `host-topology`.
hbom -o /absolute/path/to/hbom.json --bom-audit cdx-audit --bom /absolute/path/to/hbom.json --direct-bom-audit --categories hbom
The `hbom` alias expands to the full HBOM review pack in one switch.
`cdxi` has dedicated commands for both document types (see `bom-explore`):
Start with `.hbomsummary` or `.osinfocategories` before drilling into specifics.
cdxgen is a CLI tool, library, REPL, and server to create, validate, sign, and verify software BOMs. It generates CycloneDX JSON BOMs and supports SPDX 3.0.1 JSON-LD export.
Repo: cdxgen/cdxgen
Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents…
Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and…
Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with…
Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and…
Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in…
Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF)…