CtrlK
BlogDocsLog inGet started
Tessl Logo

sbom-analyzer

Software Bill of Materials (SBOM) security analysis for vulnerability assessment and third-party risk management. Validates SBOMs from vendors or generates SBOMs for internal projects. Use this skill when: - User asks to analyze an SBOM file - User mentions "third-party risk" or "vendor security" - User needs to validate a supplier's SBOM - User wants to check SBOM for vulnerabilities - User asks about CycloneDX or SPDX formats

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

77%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable skill body with a clearly sequenced workflow and an explicit validation gate before scanning. Its weaknesses are verbosity from sample-filled templates and an orphaned reference file that is never linked from the overview, leaving format detail duplicated inline.

Suggestions

Link to references/sbom-formats.md from the 'Supported SBOM Formats' / Phase 1 sections and move the detailed CycloneDX/SPDX JSON structures and validation field tables into that reference, keeping the body as a concise overview.

Replace the illustrative sample-data report/remediation/vendor-email templates with skeletal placeholder templates (e.g. | <Component> | <Version> | <CVE> |) and remove the 'Core Principle' tagline to cut tokens without losing clarity.

Add a one-line 'See references/sbom-formats.md for full format specs, purl syntax, and conversion commands' navigation pointer so the existing bundle is discoverable rather than orphaned.

DimensionReasoningScore

Conciseness

Mostly operational, but padded with sample-data-filled report/remediation/email templates (e.g. log4j-core CVE-2021-44228 rows) and a fluff "Core Principle: Know what's in your software supply chain." tagline; format-detail also duplicates references/sbom-formats.md and could be tightened.

2 / 3

Actionability

Provides fully executable, copy-paste-ready guidance such as `mcp_snyk_snyk_sbom_scan(file="path/to/sbom.json", severity_threshold="medium")` and `snyk sbom --format=cyclonedx1.5+json > sbom.json`, plus concrete output templates and field tables.

3 / 3

Workflow Clarity

Clear five-step Quick Start and sequenced Phases 1–4, with Phase 1 acting as an explicit validation gate ("Ensure the SBOM is valid and complete before analysis") and an Error Handling section providing recovery solutions for invalid format, missing purls, and unsupported versions.

3 / 3

Progressive Disclosure

references/sbom-formats.md exists but is never linked or signaled from the body (no .md references appear in the content), and detailed format-structure JSON / validation field tables that could live in that reference are instead inline, matching the "references present but not clearly signaled; content that should be separate is inline" anchor.

2 / 3

Total

10

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that states concrete capabilities in third person and pairs them with explicit, natural-language trigger guidance, cleanly answering both what the skill does and when to use it. No meaningful weakness across the four dimensions.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — "security analysis for vulnerability assessment and third-party risk management" and "Validates SBOMs from vendors or generates SBOMs for internal projects" — rather than vague language, matching the multiple-specific-actions anchor.

3 / 3

Completeness

Explicitly states what it does (SBOM vulnerability assessment / validation / generation) and follows with "Use this skill when:" plus five explicit triggers, answering both what and when.

3 / 3

Trigger Term Quality

Covers natural user terms a person would actually say — "analyze an SBOM file", "third-party risk", "vendor security", "check SBOM for vulnerabilities", and "CycloneDX or SPDX formats" — giving good keyword coverage.

3 / 3

Distinctiveness Conflict Risk

The SBOM / CycloneDX / SPDX / vendor-risk niche is distinct and the triggers are specific enough that it is unlikely to fire for an unrelated skill.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
snyk/studio-recipes
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.