CtrlK
BlogDocsLog inGet started
Tessl Logo

create-sbom

Add an SBOM (Software Bill of Materials) generation step to an existing Harness pipeline using Harness SCS SscaOrchestration (SBOM Orchestration). Supports container images and code repositories. Sources: docker, ECR, GCR, GAR, ACR, Harness AR (har), repository, and local workspace. Syft or cdxgen, SPDX or CycloneDX, optional SBOM attestation. Only works with existing pipelines. Use when asked to create an SBOM, generate a bill of materials, add SBOM to a pipeline, scan a container image or repo for components, or set up SBOM Orchestration. Trigger phrases: create SBOM, generate SBOM, add SBOM step, SBOM for image, SBOM for repo, scan for dependencies, SBOM Orchestration, add Generate SBOM step.

70

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

73%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable and exceptionally well-sequenced with validation checkpoints, and its references are real and one level deep. Its main weakness is verbosity from restating the CD-placement and Phase-3-mandatory rules across six sections and a Performance Notes block that largely rehashes already-stated mandates.

Suggestions

Collapse the repeated CD containerized-step-group rule into a single canonical statement in the CD edge case and have later sections link to it ("see CD edge case") instead of restating the rule each time.

Move the eight per-provider source YAML snippets out of SKILL.md into references/sbom-orchestration-step.md, keeping only the default docker example inline, to reduce token cost and tighten conciseness.

Trim the Performance Notes section to the few items not already mandated in the Interaction model (e.g. sequential SBOM/SLSA, image-tag inference) and drop the restated wizard/placement rules.

DimensionReasoningScore

Conciseness

The ~580-line body restates the same mandatory rules repeatedly — the CD containerized-step-group requirement and "Phase 3 placement is never optional" appear across the Interaction model, the phase table, the CD edge case, Insert-step rules, and Performance Notes, which is padded redundancy Claude already has once it reads the first statement.

2 / 5

Actionability

Provides fully executable, copy-paste-ready YAML for all eight source types (docker, Ecr, gcr, gar, acr, har, local, repository) plus a complete CD stage and the concrete harness_update MCP call with parameters — covering the common cases and edge cases.

5 / 5

Workflow Clarity

A numbered 10-phase wizard with explicit validation checkpoints (fetch-before-configure in Phase 1, confirm-before-write in Phase 10, retry on validation errors) and feedback loops for the destructive harness_update step, satisfying the top anchor for sequenced risky operations.

5 / 5

Progressive Disclosure

Body points to three real one-level-deep references (interactive-wizard-flow.md, sbom-orchestration-step.md, cd-containerized-step-group.md, all verified present in references/) with clear in-body signaling, but still inlines substantial per-provider YAML that could live entirely in sbom-orchestration-step.md.

4 / 5

Total

16

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is third-person, dense, and concrete: it names the exact Harness step type, the supported sources/tools, the attestation option, and supplies a full trigger-phrase list. It cleanly satisfies the what/when requirement with minimal padding. Voice is consistently third person, so no specificity penalty applies.

DimensionReasoningScore

Specificity

Lists multiple concrete actions ("Add an SBOM generation step", "scan a container image or repo for components", "optional SBOM attestation") plus a specific tool (Harness SCS SscaOrchestration) and enumerated source registries — comprehensive coverage of the capability surface.

5 / 5

Completeness

Clearly answers "what" (add SscaOrchestration SBOM step to an existing Harness pipeline, supported sources and tools) and "when" ("Use when asked to create an SBOM, generate a bill of materials...") with concrete trigger phrases, matching the top anchor.

5 / 5

Trigger Term Quality

An explicit "Trigger phrases:" list includes natural variations users would say ("create SBOM", "generate SBOM", "add SBOM step", "SBOM for image", "scan for dependencies") with both the acronym and long form covered.

5 / 5

Distinctiveness Conflict Risk

Tightly scoped to Harness SCS SBOM Orchestration on existing pipelines with explicit "Only works with existing pipelines" — a clear niche with distinct triggers and minimal overlap with adjacent scan/CI skills.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (602 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
harness/harness-ai
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.