CtrlK
BlogDocsLog inGet started
Tessl Logo

testland/cyclonedx-format

Reference for the CycloneDX v1.6 software bill of materials (SBOM) specification - OWASP-curated, security-focused format covering software components, services, dependencies, vulnerabilities, formulation, machine learning models, and SaaS BOMs; supports XML / JSON / Protobuf encodings; per-language generators for npm, pip, Maven, Gradle, Go, etc.; integrates with CI via generate + sign + attest workflow. Use when the user asks to generate or write a software bill of materials / SBOM in CycloneDX form, or when the team adopts CycloneDX as its primary SBOM format (preferred for security-focused use cases vs SPDX's licensing focus).

77

Quality

97%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Overview
Quality
Evals
Security
Files

Quality

Content

92%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured reference skill: executable examples, an explicit validated workflow, and a clean one-level reference split. The only weakness is mild prose restatement of context Claude already knows, which could be trimmed for token efficiency.

Suggestions

Tighten the Overview paragraph and 'When to use' prose to remove context Claude can infer (e.g. restating that CycloneDX is OWASP-curated/security-focused), keeping only the differentiating bullets.

Move the required-fields table (Step 2) into the existing references file alongside the component-type/tooling tables to keep SKILL.md as a lean overview.

DimensionReasoningScore

Conciseness

Body is dense and reference-style with minimal conceptual padding and complete code blocks, but the Overview and a few prose passages ('CycloneDX is an OWASP-curated, security-focused SBOM format') restate context Claude could infer. Mostly efficient with light tightening possible.

2.5 / 3

Actionability

Provides a complete executable CycloneDX 1.6 JSON BOM, concrete validate commands, a copy-paste CI YAML job, and a worked example with exact tool invocations. Fully executable and copy-paste ready.

3 / 3

Workflow Clarity

Numbered Steps 1–6 are explicitly sequenced, with validation as Step 4, an explicit checkpoint ('Validation catches structural issues ... before publishing'), and error-recovery framing in the Anti-patterns table. Clear sequence with validation checkpoints.

3 / 3

Progressive Disclosure

SKILL.md is an overview with a single one-level-deep reference (references/component-types-and-tooling.md) that is clearly signaled and actually present, splitting out the component-type and per-language-tooling tables appropriately.

3 / 3

Total

11.5

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A high-quality, third-person description that covers capabilities, encodings, tooling, and an explicit 'Use when' trigger with a contrast against SPDX. It is somewhat dense but every clause carries information rather than fluff.

DimensionReasoningScore

Specificity

Lists multiple concrete capabilities (components, services, dependencies, vulnerabilities, formulation, ML/SaaS BOMs) plus concrete actions (per-language generators for npm/pip/Maven/Gradle/Go, CI generate+sign+attest workflow). Matches the 'lists multiple specific concrete actions' anchor.

3 / 3

Completeness

Explicitly answers what (reference for the CycloneDX v1.6 SBOM spec) and when ('Use when the user asks to generate or write a software bill of materials / SBOM in CycloneDX form'). Both clauses present with explicit triggers.

3 / 3

Trigger Term Quality

Includes natural phrases a user would say — 'software bill of materials / SBOM', 'generate or write ... SBOM in CycloneDX form', 'adopts CycloneDX as its primary SBOM format' — alongside spec terms. Good coverage of natural trigger terms.

3 / 3

Distinctiveness Conflict Risk

Niche is clearly CycloneDX-specific and explicitly contrasted with SPDX's licensing focus, making overlap with other SBOM skills unlikely.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Reviewed

Table of Contents