CtrlK
BlogDocsLog inGet started
Tessl Logo

image-inspect

Fetch container image labels, validate registry ownership, resolve tag/digest via SBOM, and report the SBOM artifact reference for a Red Hat container image.

65

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./ocp-admin/skills/image-inspect/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with executable commands and complete output templates, organized in a clear sequenced workflow; its main gaps are a missing validate_input.py invocation step and minor redundancy.

Suggestions

Add an explicit step that runs validate_input.py (e.g., 'python $SCRIPTS_DIR/validate_input.py [IMAGE_REFERENCE]') before Steps 2–3 reference its output.

Consolidate the repeated 'Do NOT use version or release labels' caution into a single authoritative note to trim redundancy.

DimensionReasoningScore

Conciseness

Operational and free of concept-over-explanation, but carries minor redundancy such as the 'Do NOT use version or release labels' caution repeated across Steps 1, 4, and the CVE notes.

4 / 5

Actionability

Provides copy-paste-ready commands (inspect_image.py, download_sbom.py, regctl login, cosign download attestation) and fully specified markdown/JSON/CSV output templates covering the common cases.

5 / 5

Workflow Clarity

Clear 5-step sequence with input validation and an auth-failure retry feedback loop, but validate_input.py is referenced in Steps 2–3 without ever being explicitly invoked.

4 / 5

Progressive Disclosure

Single well-organized file with clear sections; bundled scripts are referenced via $SCRIPTS_DIR/ and verified present, with no nested references — though the large output templates are inlined rather than split out.

4 / 5

Total

17

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concrete, third-person, and well-scoped to a distinct Red Hat container-image niche, but it omits an explicit 'when to use' trigger clause, which caps its completeness.

Suggestions

Append an explicit trigger clause such as 'Use when the user asks to inspect or check metadata for a Red Hat container image' to raise completeness.

Add natural synonyms (e.g., 'inspect', 'image metadata') alongside 'container image' to broaden trigger-term coverage.

DimensionReasoningScore

Specificity

Lists four concrete actions — 'Fetch container image labels', 'validate registry ownership', 'resolve tag/digest via SBOM', and 'report the SBOM artifact reference' — giving comprehensive coverage of the niche.

5 / 5

Completeness

Has a clear 'what' but no explicit 'Use when…' trigger clause; per the rubric guideline, a missing explicit trigger guidance caps completeness at 3.

3 / 5

Trigger Term Quality

Includes natural terms like 'container image', 'Red Hat', 'SBOM', and 'tag/digest', but lacks common synonyms a user might say such as 'inspect' or 'metadata'.

4 / 5

Distinctiveness Conflict Risk

Scoped to 'Red Hat container image' with SBOM/registry-ownership anchors — a clear niche with distinct triggers and minimal overlap risk.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
RHEcosystemAppEng/agentic-plugins
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.