CtrlK
BlogDocsLog inGet started
Tessl Logo

sbom-analyzer

Software Bill of Materials (SBOM) security analysis for vulnerability assessment and third-party risk management. Validates SBOMs from vendors or generates SBOMs for internal projects. Use this skill when: - User asks to analyze an SBOM file - User mentions "third-party risk" or "vendor security" - User needs to validate a supplier's SBOM - User wants to check SBOM for vulnerabilities - User asks about CycloneDX or SPDX formats

63

Quality

74%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./command_directives/synchronous_remediation/skills/sbom-analyzer/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-organized and actionable with concrete tool calls and templates, but it does not leverage its existing reference bundle via clear links and lacks an explicit scan-validation feedback loop for batch operations. Signaling the reference file and adding a post-scan validation/retry checkpoint would lift the lowest dimensions.

Suggestions

Link to references/sbom-formats.md from the 'Supported SBOM Formats' section (e.g., 'See references/sbom-formats.md for full field mappings') and move the inlined JSON indicators there to improve progressive disclosure.

Add an explicit validation feedback loop in Phase 2/3: if the scan errors or components are skipped, re-request a corrected SBOM and re-run the scan before generating the risk report.

Trim the illustrative example report tables in Phase 3/4 to minimal skeleton templates to reduce token weight while preserving the output format.

DimensionReasoningScore

Conciseness

Tight tables, code blocks, and section headers assume Claude knows SBOM concepts with no padding; minor over-illustration in example report blocks keeps it just below lean.

4 / 5

Actionability

Provides concrete executable tool calls (mcp_snyk_snyk_sbom_scan with parameters) and snyk sbom generation commands plus JSON indicators, with only minor fill-in-the-blank gaps in templates.

4 / 5

Workflow Clarity

A clear 5-step Quick Start and four phases give sequence, but batch component scanning lacks an explicit validate-fix-retry feedback loop after the scan, which caps batch-operation workflows at 3.

3 / 5

Progressive Disclosure

Structure is reasonable and a one-level-deep references/sbom-formats.md bundle exists, but the body never signals or links to it and inlines format details instead, leaving references present but not clearly signaled.

3 / 5

Total

14

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly states what the skill does and provides explicit, natural trigger phrases for when to use it. It is concrete and well-scoped, with only minor room to add a few more action verbs and file-extension synonyms.

DimensionReasoningScore

Specificity

Lists several concrete actions ('Validates SBOMs from vendors', 'generates SBOMs for internal projects', 'vulnerability assessment', 'third-party risk management') with only minor coverage gaps, short of the comprehensive multi-action list of a 5.

4 / 5

Completeness

Explicitly answers both what (SBOM security analysis, validate/generate SBOMs) and when via a concrete 'Use this skill when:' list of five triggers, matching the 5 anchor pattern.

5 / 5

Trigger Term Quality

Strong natural triggers ('analyze an SBOM file', 'third-party risk', 'vendor security', 'validate a supplier's SBOM', 'CycloneDX or SPDX formats') users would actually say; a few extension/synonym variants are missing.

4 / 5

Distinctiveness Conflict Risk

SBOM/third-party-risk niche with format-specific CycloneDX/SPDX triggers is mostly distinct with only minor overlap risk against general vulnerability-scanning skills.

4 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
snyk/studio-recipes
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.