cyclonedx-spec-reviewer

Review cdxgen changes for CycloneDX schema compliance and semantic correctness.

1.0k|255|Updated Dec 30, 2019
One-click install
npx skills add https://github.com/cdxgen/cdxgen --skill cyclonedx-spec-reviewer
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cyclonedx-spec-reviewer
Source: https://github.com/cdxgen/cdxgen/tree/main/.github/skills/cyclonedx-spec-reviewer
Command: npx skills add https://github.com/cdxgen/cdxgen --skill cyclonedx-spec-reviewer

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill streamlines the review of cdxgen changes for CycloneDX schema compliance and semantic correctness, making BOM review more efficient and accurate.

Core Features & Use Cases

  • Schema Compliance Review: Validates changes against CycloneDX schemas and property-taxonomy guidance.
  • Semantic Correctness: Ensures that attributes are used for the right purpose and that custom properties are necessary.
  • AI-BOM Focus Areas: Reviews AI-related output for AI/ML modeling adherence to CycloneDX standards.
  • Review Procedure: Provides a structured review procedure for affected spec versions, output fields, new integrations, and AI-BOM changes.
  • Expected Review Output: Offers a clear format for findings, including field names, problems, preferred approaches, and schema basis.

Quick Start

Run the cyclonedx-spec-reviewer skill on the latest pull request to review changes in CycloneDX schema handling, validators, package-manager integrations, BOM enrichment, or custom properties.

Frequently Asked Questions about cyclonedx-spec-reviewer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I validate CycloneDX schema compliance for cdxgen changes?

To validate CycloneDX schema compliance for cdxgen changes, review changes against CycloneDX schemas and property-taxonomy guidance to ensure attributes are used for the correct purpose and custom properties are necessary.

What is semantic correctness in a CycloneDX BOM review?

Semantic correctness in a CycloneDX BOM review ensures that BOM attributes are used for their intended purpose and that any custom properties added are genuinely necessary for accurate data representation.

How do I review AI/ML modeling components in a CycloneDX BOM?

Review AI/ML modeling components in a CycloneDX BOM by checking AI-related output for adherence to CycloneDX standards, ensuring standard field usage and data completeness for AI-BOM changes.

Does this CycloneDX spec reviewer support custom properties and BOM enrichment?

Yes, this CycloneDX spec reviewer supports custom properties and BOM enrichment by validating changes against property-taxonomy guidance and ensuring custom properties are semantically necessary.

What is the expected output format for a CycloneDX BOM review?

The expected output format for a CycloneDX BOM review provides clear findings including field names, identified problems, preferred approaches, and the schema basis for each issue.

When do I need to run a CycloneDX schema compliance review?

You need to run a CycloneDX schema compliance review when evaluating pull requests that modify CycloneDX schema handling, validators, package-manager integrations, BOM enrichment, or custom properties.