# CycloneDX SBOM Generator

> Generates Software Bill of Materials in CycloneDX format using cdxgen and Syft. Scans npm, pip, and Go modules for known CVEs via OSV.dev API integration.

- Skill: `agentskillexchange/cyclonedx-sbom-generator` (Agent Skill)
- Install (CLI): `npx skillmds@latest add agentskillexchange/cyclonedx-sbom-generator`
- Raw SKILL.md: https://api.skillmd.com/api/skills/agentskillexchange/cyclonedx-sbom-generator/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Integrations & APIs
- Author: agentskillexchange (https://skillmd.com/u/agentskillexchange)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/agentskillexchange/cyclonedx-sbom-generator

---


# CycloneDX SBOM Generator

Generates Software Bill of Materials in CycloneDX format using cdxgen and Syft. Scans npm, pip, and Go modules for known CVEs via OSV.dev API integration.

## Installation

Use the upstream install or setup path that matches your environment:
- npm install -g @cyclonedx/cdxgen
- $ brew install cdxgen
- docker run --rm -e CDXGEN_DEBUG_MODE=debug -v /tmp:/tmp -v $(pwd):/app:rw -t ghcr.io/cyclonedx/cdxgen:master -r /app -o /app/bom.json
- docker run --rm -e CDXGEN_DEBUG_MODE=debug -v /tmp:/tmp -v $(pwd):/app:rw -t ghcr.io/cyclonedx/cdxgen-deno:master -r /app -o /app/bom.json

Requirements and caveats from upstream:
- Software-as-a-Service (SaaSBOM) - For Java, Python, JavaScript, TypeScript, and PHP projects.
- You can also use the cdxgen container image with node, deno, or bun runtime versions.
- The default version uses Node.js 23

Basic usage or getting-started notes:
- | **Developers** | Generate a CycloneDX BOM from a local repo, git URL, purl, or container image | cdxgen -o bom.json . | [CLI Usage][docs-cli], [Supported Project Types][docs-project-types] |
- | **AppSec** | Enrich BOMs with evidence, run BOM audit rules, and feed downstream security workflows | cdxgen -o bom.json --profile appsec --evidence --bom-audit . | [BOM Audit](docs/BOM_AUDIT.md), [Threat Model](doc...
- | **SOC analysts** | Build OBOM inventories for live hosts and triage runtime posture issues | obom -o obom.json --deep --bom-audit --bom-audit-categories obom-runtime | [OBOM lessons](docs/OBOM_LESSONS.md), [Server U...

- Source: https://github.com/cdxgen/cdxgen
- Extracted from upstream docs: https://raw.githubusercontent.com/cdxgen/cdxgen/HEAD/README.md

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/cyclonedx-sbom-generator/)

