CtrlK
BlogDocsLog inGet started
Tessl Logo

sbom-analyzer

Software Bill of Materials (SBOM) security analysis for vulnerability assessment and third-party risk management. Validates SBOMs from vendors or generates SBOMs for internal projects. Use this skill when: - User asks to analyze an SBOM file - User mentions "third-party risk" or "vendor security" - User needs to validate a supplier's SBOM - User wants to check SBOM for vulnerabilities - User asks about CycloneDX or SPDX formats

68

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-structured and highly actionable, with a clearly sequenced four-phase workflow, an explicit validation gate before scanning, and error-recovery guidance. Its main weaknesses are the orphaned bundle reference file (never linked from the body, with overlapping content inlined instead) and a few gaps like the unexplained risk-score computation and repeated version/format listings.

Suggestions

Link references/sbom-formats.md from the 'Supported SBOM Formats' section (e.g., 'See [sbom-formats.md](references/sbom-formats.md) for full format structure and field mappings') so the 274-line reference is actually discoverable.

Move the inlined CycloneDX/SPDX structural JSON and field-completeness table into the reference file, keeping only detection essentials in SKILL.md, and consolidate the triplicated supported-version information into one place.

Specify how the Risk Score (e.g., 78/100) is derived or state that it comes from the scan result, so the report template is reproducible.

DimensionReasoningScore

Conciseness

The body is efficient — no explanations of concepts Claude already knows (it never defines SBOM, CVE, or CVSS), and it uses compact tables, tool calls, and templates. Minor trimming opportunities exist: supported format/version info is repeated three times (Supported SBOM Formats table, the Unsupported Version error section, and frontmatter compatibility), and the illustrative report templates carry somewhat long sample data (log4j, spring-core rows).

4 / 5

Actionability

Concrete, mostly executable guidance throughout: exact tool invocations (`mcp_snyk_snyk_sbom_scan(file="path/to/sbom.json", severity_threshold="medium")`), runnable CLI commands (`snyk sbom --format=cyclonedx1.5+json > sbom.json`), format-detection JSON indicators, and copy-ready report templates. Minor gaps keep it below anchor 5: the "Risk Score: 78/100 (High Risk)" is shown in a template but no method for computing it is given, and how to determine 'Fixed Version' values is left to the scan output.

4 / 5

Workflow Clarity

The Quick Start gives a 5-step sequence, expanded into four ordered phases with explicit goals. Phase 1 is a genuine validation checkpoint ("Ensure the SBOM is valid and complete before analysis") with a failure path (report issues, "Request updated SBOM from supplier"), and the Error Handling section supplies validate→fix→retry feedback loops for parse errors, missing purls, and unsupported versions. This is a read-only analysis skill, so the destructive/batch cap does not apply.

5 / 5

Progressive Disclosure

A bundle reference file exists (references/sbom-formats.md, 274 lines) but the body never mentions or links to it — grep finds no reference to it or to the references/ directory anywhere in the markdown. Meanwhile format-structure details (CycloneDX/SPDX JSON indicators, the completeness-validation table) are inlined in the body when they overlap with what the reference file covers. This matches anchor 3: references present but not clearly signaled, and content that could live separately is inline.

3 / 5

Total

16

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it states concrete capabilities in third person and provides an explicit, bulleted 'Use this skill when' trigger list covering natural user phrasings. The only gaps are minor — a few capability details (reporting, remediation) and file-extension trigger terms are omitted.

Suggestions

Add file-extension/keyword triggers such as 'sbom.json', '.cdx.json', or 'software supply chain' to broaden natural match coverage.

Mention the downstream deliverables (risk report, prioritized remediation guidance, vendor communication) so the 'what' fully reflects the skill's capabilities.

DimensionReasoningScore

Specificity

The description names the domain and several concrete actions — "Validates SBOMs from vendors or generates SBOMs for internal projects" plus "vulnerability assessment and third-party risk management" — but coverage is not fully comprehensive (e.g., no mention of remediation guidance or risk reporting that the skill body actually delivers). It sits between anchor 4 (several specific actions, minor gaps) and anchor 5, matching 4 more closely since remediation/reporting capabilities are unstated.

4 / 5

Completeness

Clearly answers both questions: the 'what' is explicit ("security analysis for vulnerability assessment and third-party risk management. Validates SBOMs... or generates SBOMs...") and the 'when' is an explicit "Use this skill when:" list of five concrete triggers. This matches the anchor-5 good example structurally and in concreteness.

5 / 5

Trigger Term Quality

Good natural keyword coverage: "analyze an SBOM file", "third-party risk", "vendor security", "CycloneDX or SPDX", "check SBOM for vulnerabilities" — phrases users would genuinely say. Missing some variations and file extensions (e.g., "software bill of materials" as a standalone phrase is present, but no ".json", "sbom.json", or "supply chain" synonyms), so it falls short of the anchor-5 'including synonyms and file extensions' example.

4 / 5

Distinctiveness Conflict Risk

Clear niche (SBOM/security supply-chain analysis) with distinct triggers — CycloneDX, SPDX, supplier SBOM validation — that are unlikely to fire for unrelated skills. Minimal overlap risk with generic vulnerability-scanning skills because the SBOM-specific terminology dominates.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
snyk/studio-recipes
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.