CtrlK
BlogDocsLog inGet started
Tessl Logo

ai-inventory

Generate and analyze AI Bill of Materials (AIBOM) for Python projects using AI/ML components. Identifies AI models, datasets, tools, and frameworks for security and compliance tracking. Use this skill when: - User asks to scan for AI components - User wants to know what AI models a project uses - User mentions "AI BOM", "AI inventory", or "ML security" - User is working with Python AI/ML projects (PyTorch, TensorFlow, HuggingFace) - User needs AI component compliance documentation

75

Quality

92%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly actionable skill body with a clearly phased workflow, explicit validation checkpoints, and concrete error-recovery guidance. Its weaknesses are minor: the Quick Start duplicates Phase 2 content, and some secondary material (compliance report template) could be split into reference files.

Suggestions

Remove the duplicated tool invocation code blocks in Quick Start and point directly to Phase 2, keeping only a one-line summary of the flow.

Move the full Phase 5 compliance-report template and detailed risk-assessment guidance into a references/ file, keeping a short summary and pointer in SKILL.md.

Consider trimming the Phase 3 report template to the table headers only, since Claude can populate structure from the column definitions.

DimensionReasoningScore

Conciseness

The body is efficient with no explanations of concepts Claude already knows, but the Quick Start block duplicates the exact Phase 2 tool invocations and the full Phase 5 compliance-report template is bulk that could be trimmed or referenced — minor instances of redundancy.

4 / 5

Actionability

Tool invocations are copy-paste ready with exact syntax and kwargs (e.g. mcp_snyk_snyk_aibom(path="...", json_file_output="...")), errors come with concrete recovery steps, and report templates are fully specified with placeholders for scan results.

5 / 5

Workflow Clarity

Five clearly sequenced phases each with a stated goal, an explicit validation checkpoint ('verify the returned JSON is valid and contains at least one component entry... do not continue'), error-recovery blocks for network/access failures, and a stop-and-report path for non-Python projects.

5 / 5

Progressive Disclosure

Well-organized single-file structure (Quick Start, Phases 1-5, Use Cases, Constraints) with no nested references, but at ~225 lines the Phase 5 compliance-report template and risk-assessment details are candidates for separate reference files that don't exist — minor organization gaps.

4 / 5

Total

18

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that clearly states concrete capabilities and provides an explicit, well-structured 'Use this skill when' clause with natural trigger terms and framework names. The only weakness is slight overlap risk with generic SBOM/security-scanning requests.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions — 'Generate and analyze AI Bill of Materials (AIBOM)' and 'Identifies AI models, datasets, tools, and frameworks' — with comprehensive coverage of the skill's capabilities, matching the anchor for multiple specific concrete actions.

5 / 5

Completeness

It explicitly answers both questions: a clear 'what' (generate/analyze AIBOM, identify models, datasets, tools, frameworks) followed by an explicit 'Use this skill when:' clause with five concrete trigger conditions, all in third person.

5 / 5

Trigger Term Quality

Natural trigger phrases like 'scan for AI components', 'AI BOM', 'AI inventory', 'ML security', and concrete framework names (PyTorch, TensorFlow, HuggingFace) give comprehensive coverage including synonyms users would actually say.

5 / 5

Distinctiveness Conflict Risk

The niche (Snyk AIBOM for Python AI/ML projects) is clear with distinct triggers, but a user asking for a generic 'BOM', 'SBOM', or security scan could overlap with adjacent dependency-audit skills — minor overlap risk.

4 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
snyk/studio-recipes
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.