Write Skill Cards People Can Trust
A scan report tells reviewers what automated checks found. A signature tells users whether the artifact changed. A skill card tells humans what they are accepting.
The Skills Card is the per-skill release record described below. Authors can generate one by running the Skill Card.md skill published at NVIDIA/Trustworthy-AI, which walks through each section interactively. The card should be completed before a skill is broadly shared, especially when the skill can run tools, call APIs, write files, or influence production workflows.
What a Skill Card Should Answer
Minimum Useful Card
Use this as the minimum release template:
Connect the Card to the Release
The card should point to the same evidence reviewers used:
- SkillSpector scan report or CI job
- Source repository and release tag
- Signing identifier or
skill.oms.siglocation - Any model cards or dependency documentation behind the skill
- Known limitations and accepted risks
Good Risk Statements
Avoid vague risks like “model may be wrong.” Make risks actionable:
Approval Rule
A skill card is complete when a reviewer can understand the skill’s purpose, owner, output, risks, and release evidence without opening the source code first.