# Does SkillSpector Support Remote Repositories? Git URL Scanning Guide

> SkillSpector supports remote Git repositories by automatically cloning and scanning URLs without altering your local files. Discover how Git URL scanning works.

- Repository: [NVIDIA Corporation/SkillSpector](https://github.com/NVIDIA/SkillSpector)
- Tags: how-to-guide
- Published: 2026-07-10

---

**Yes, SkillSpector fully supports remote repositories by automatically detecting Git URLs, cloning them into temporary directories, and scanning the contents without modifying your local filesystem.**

SkillSpector is an open-source skill analysis tool developed by NVIDIA that can evaluate code repositories directly from remote Git hosts. Understanding how to leverage **SkillSpector remote repositories** functionality allows you to audit public and private skills without manually downloading them first.

## How SkillSpector Detects Remote Git Repositories

The remote repository support is implemented in the `InputHandler` class located in [`src/skillspector/input_handler.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/input_handler.py). When you provide a URL to the `scan` command, the system determines whether the input string represents a local path or a remote Git repository through a multi-step validation process.

### Git URL Validation via `_is_git_url`

The `_is_git_url` function (lines 44-56 in [`src/skillspector/input_handler.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/input_handler.py)) performs the initial detection by checking two criteria:

- **Scheme validation**: Verifies the URL uses `http`, `https`, or `git@` protocols
- **Hostname filtering**: Parses the hostname and confirms it exists in the allowed list defined in `ALLOWED_GIT_HOSTS`

This function specifically filters out raw file URLs to ensure only valid Git repository endpoints are processed.

### Shallow Cloning with `_clone_git`

Once validated, the `_clone_git` method (lines 93-117 in [`src/skillspector/input_handler.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/input_handler.py)) executes the repository retrieval:

- Validates the host against `ALLOWED_GIT_HOSTS` from [`src/skillspector/constants.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/constants.py)
- Creates a temporary directory isolated from your working environment
- Performs a shallow clone using `git clone --depth 1` to minimize bandwidth and storage
- Returns the temporary path as the scan source

This approach ensures SkillSpector never modifies your local filesystem and automatically cleans up temporary directories after the scan completes.

## Scanning Remote Repositories via CLI

The `scan` command in [`src/skillspector/cli.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/cli.py) (lines 70-78) accepts an `input_path` argument that can be either a local directory or a remote Git URL. The command forwards the input directly to `InputHandler.resolve`, which handles the cloning transparently.

Scan a public GitHub repository without LLM analysis:

```bash
skillspector scan https://github.com/NVIDIA/SkillSpector.git --no-llm

```

Scan a GitLab repository with LLM analysis enabled:

```bash
skillspector scan https://gitlab.com/example/skill-repo

```

## Programmatic Usage with InputHandler

You can also trigger remote repository scans directly through the Python API:

```python
from skillspector.input_handler import InputHandler

handler = InputHandler()
repo_path, source_type = handler.resolve("https://github.com/NVIDIA/SkillSpector.git")
print(f"Cloned to {repo_path} (source={source_type})")

# Output: Cloned to /tmp/skillspector_XXXX/repo (source=git)

```

The `resolve` method returns a tuple containing the temporary repository path and the source type identifier (`git`), allowing your application to handle remote and local inputs uniformly.

## Supported Git Hosts and Configuration

By default, SkillSpector restricts remote cloning to major Git hosting providers for security. The `ALLOWED_GIT_HOSTS` constant in [`src/skillspector/constants.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/constants.py) defines the permitted hostnames:

- `github.com`
- `gitlab.com`
- `bitbucket.org`

To support additional Git forges or self-hosted instances, modify the `ALLOWED_GIT_HOSTS` list in [`src/skillspector/constants.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/constants.py) before running your scan.

## Summary

- **SkillSpector supports remote repositories** through automatic Git URL detection and shallow cloning
- **`_is_git_url`** validates URLs by checking schemes and hostnames against an allowlist
- **`_clone_git`** executes `git clone --depth 1` into temporary directories that are automatically cleaned up
- **CLI usage** requires only passing the HTTPS or SSH URL to the `scan` command
- **Security** is maintained through the `ALLOWED_GIT_HOSTS` restriction in [`src/skillspector/constants.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/constants.py)

## Frequently Asked Questions

### Does SkillSpector support private remote repositories?

SkillSpector uses standard Git commands for cloning, so it respects your system's SSH keys and Git credentials. If your environment has access to a private repository via SSH keys or credential helpers, SkillSpector can clone and scan it. HTTPS URLs with embedded credentials are not recommended for security reasons.

### What Git hosts are supported by default?

According to the source code in [`src/skillspector/constants.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/constants.py), SkillSpector allows cloning from `github.com`, `gitlab.com`, and `bitbucket.org` by default. You can extend support to other hosts by adding them to the `ALLOWED_GIT_HOSTS` list.

### How does SkillSpector handle repository cleanup after scanning?

The `_clone_git` implementation in [`src/skillspector/input_handler.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/input_handler.py) creates a temporary directory using the system's temp folder utilities. This directory serves as the scan source and is typically removed after the analysis completes, ensuring no persistent clones remain on your filesystem.

### Can I scan a specific branch or tag from a remote repository?

The current implementation performs a shallow clone of the default branch (`--depth 1`). To scan specific branches or tags, you would need to clone the repository manually, checkout the specific reference, and then provide the local path to SkillSpector's `scan` command.