cyclonedx-spec

Explain CycloneDX specification concepts, schemas, and governance for SBOMs.

31|2|Updated Mar 10, 2026
One-click install
npx skills add https://github.com/CycloneDX/skills --skill cyclonedx-spec
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cyclonedx-spec
Source: https://github.com/CycloneDX/skills/tree/main
Command: npx skills add https://github.com/CycloneDX/skills --skill cyclonedx-spec

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Provides authoritative guidance on the CycloneDX specification, schemas, and governance to help Claude answer questions about SBOMs and related BOMs with accuracy.

Core Features & Use Cases

  • Comprehensive scope across CycloneDX versions 1.6 and 1.7 (SBOM, CBOM, MBOM, VDR, VEX, attestations, BOM-Link).
  • References official guides, conventions, and the CycloneDX property taxonomy to ensure consistency and correctness.
  • Supports scenario-specific guidance for specification prose, modeling, and validation tasks.

Quick Start

Use the CycloneDX-spec skill to fetch authoritative guidance for CycloneDX 1.6 and 1.7.

Frequently Asked Questions about cyclonedx-spec

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I model SBOM data using the CycloneDX JSON schema?

Model SBOM data using the CycloneDX JSON schema by referencing the official property taxonomy and specification prose for versions 1.6 and 1.7 to ensure structural correctness and consistency.

What is the difference between VDR and VEX in CycloneDX attestations?

VEX and VDR in CycloneDX attestations represent vulnerability exploitability exchange and vulnerability disclosure reports respectively, both governed by official specification conventions for distinct risk modeling scenarios.

How do I validate a CycloneDX BOM-Link reference?

Validate a CycloneDX BOM-Link reference by checking the relationship against the official JSON schema definitions and property taxonomy provided for specification versions 1.6 and 1.7.

Can I use CycloneDX specifications for cryptographic bill of materials?

Yes, you can use CycloneDX specifications for cryptographic bill of materials as the core scope explicitly supports CBOM alongside SBOM and MBOM modeling scenarios using official guides.

Does CycloneDX 1.7 include updates to the property taxonomy?

CycloneDX 1.7 includes updates to the property taxonomy and JSON schema, building upon the 1.6 specification to provide authoritative guidance for SBOM, VDR, VEX, and attestation modeling.

Why does my CycloneDX SBOM validation fail against the JSON schema?

CycloneDX SBOM validation fails against the JSON schema when data modeling does not adhere to the official specification prose, property taxonomy, and ISO House Style conventions defined for versions 1.6 and 1.7.