CtrlK
BlogDocsLog inGet started
Tessl Logo

sbom

Generate and manage Software Bill of Materials (SBOMs) for the OpenShell project. Covers SBOM generation with Syft, license resolution via public registries, and CSV export for compliance review. Trigger keywords - SBOM, sbom, bill of materials, license audit, license resolution, generate sbom, sbom csv, dependency license, supply chain, license scan.

68

Quality

84%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An efficient, highly actionable SKILL body built around concrete commands and clear workflow stages. Its main gap is the absence of an explicit validation/verification checkpoint in the main generation pipeline, which keeps workflow clarity below the top anchor.

Suggestions

Add an explicit verify step after 'mise run sbom' (e.g., confirm the .cdx.json/.csv files exist and run 'mise run sbom:check' to surface unresolved licenses) to close the validation gap for the batch generation workflow.

Trim the Overview paragraph so it does not restate the frontmatter description, tightening token efficiency.

DimensionReasoningScore

Conciseness

Mostly lean with executable commands and compact tables, assuming Claude's competence; the Overview paragraph partially restates the description and could be trimmed, but no padded concept explanations.

4 / 5

Actionability

Fully executable, copy-paste-ready commands throughout — 'mise run sbom', 'docker buildx imagetools inspect ...', 'mise x -- syft ...', 'uv run python deploy/sbom/resolve_licenses.py /path/to/external-sbom.json' — covering the common cases.

5 / 5

Workflow Clarity

Workflow 1 clearly sequences Generate -> Resolve -> CSV stages with chained and per-stage commands and lists expected output files; the image-SBOM section includes an explicit validation step, but the main generation pipeline lacks an explicit verify/validate checkpoint after the batch scan.

4 / 5

Progressive Disclosure

No bundle files exist, so the body is self-contained with well-organized sections (Overview, Prerequisites, Workflows, tables, Quick Reference) and easy navigation; good structure with only minor organization gaps, though some detail tables could conceptually live in references.

4 / 5

Total

17

/

20

Passed

Description

86%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that names concrete actions and tools and supplies an explicit trigger-keyword list. The main weakness is the 'when' guidance being a keyword dump rather than natural contextual 'Use when...' phrasing.

Suggestions

Rewrite the trigger guidance as a natural 'Use when the user mentions SBOMs, a bill of materials, a license audit, or supply-chain compliance' clause rather than a bare 'Trigger keywords -' list.

Replace the generic leading verb 'Generate and manage' with the specific concrete actions that follow, so the opening is not padded.

DimensionReasoningScore

Specificity

Lists several concrete actions — 'SBOM generation with Syft', 'license resolution via public registries', 'CSV export for compliance review' — with named tools, though the leading 'Generate and manage' is slightly generic, leaving minor coverage gaps versus a fully comprehensive list.

4 / 5

Completeness

Explicitly states what (generate/resolve/export SBOMs with named tools) and provides explicit trigger guidance via the 'Trigger keywords -' list, but the 'when' is a keyword dump rather than contextual 'Use when...' phrasing, so it is not maximally explicit.

4 / 5

Trigger Term Quality

Comprehensive natural-term coverage including synonyms and phrasings a user would actually say: 'bill of materials', 'license audit', 'license resolution', 'supply chain', 'license scan'.

5 / 5

Distinctiveness Conflict Risk

Clear niche — OpenShell SBOM tooling with Syft/CycloneDX and license compliance — with distinct, domain-specific triggers that minimally overlap with other skills.

5 / 5

Total

18

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
NVIDIA/OpenShell
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.