Does SkillSpector Support Remote Repositories? Git URL Scanning Guide
Yes, SkillSpector fully supports remote repositories by automatically detecting Git URLs, cloning them into temporary directories, and scanning the contents without modifying your local filesystem.
SkillSpector is an open-source skill analysis tool developed by NVIDIA that can evaluate code repositories directly from remote Git hosts. Understanding how to leverage SkillSpector remote repositories functionality allows you to audit public and private skills without manually downloading them first.
How SkillSpector Detects Remote Git Repositories
The remote repository support is implemented in the InputHandler class located in src/skillspector/input_handler.py. When you provide a URL to the scan command, the system determines whether the input string represents a local path or a remote Git repository through a multi-step validation process.
Git URL Validation via _is_git_url
The _is_git_url function (lines 44-56 in src/skillspector/input_handler.py) performs the initial detection by checking two criteria:
- Scheme validation: Verifies the URL uses
http,https, orgit@protocols - Hostname filtering: Parses the hostname and confirms it exists in the allowed list defined in
ALLOWED_GIT_HOSTS
This function specifically filters out raw file URLs to ensure only valid Git repository endpoints are processed.
Shallow Cloning with _clone_git
Once validated, the _clone_git method (lines 93-117 in src/skillspector/input_handler.py) executes the repository retrieval:
- Validates the host against
ALLOWED_GIT_HOSTSfromsrc/skillspector/constants.py - Creates a temporary directory isolated from your working environment
- Performs a shallow clone using
git clone --depth 1to minimize bandwidth and storage - Returns the temporary path as the scan source
This approach ensures SkillSpector never modifies your local filesystem and automatically cleans up temporary directories after the scan completes.
Scanning Remote Repositories via CLI
The scan command in src/skillspector/cli.py (lines 70-78) accepts an input_path argument that can be either a local directory or a remote Git URL. The command forwards the input directly to InputHandler.resolve, which handles the cloning transparently.
Scan a public GitHub repository without LLM analysis:
skillspector scan https://github.com/NVIDIA/SkillSpector.git --no-llm
Scan a GitLab repository with LLM analysis enabled:
skillspector scan https://gitlab.com/example/skill-repo
Programmatic Usage with InputHandler
You can also trigger remote repository scans directly through the Python API:
from skillspector.input_handler import InputHandler
handler = InputHandler()
repo_path, source_type = handler.resolve("https://github.com/NVIDIA/SkillSpector.git")
print(f"Cloned to {repo_path} (source={source_type})")
# Output: Cloned to /tmp/skillspector_XXXX/repo (source=git)
The resolve method returns a tuple containing the temporary repository path and the source type identifier (git), allowing your application to handle remote and local inputs uniformly.
Supported Git Hosts and Configuration
By default, SkillSpector restricts remote cloning to major Git hosting providers for security. The ALLOWED_GIT_HOSTS constant in src/skillspector/constants.py defines the permitted hostnames:
github.comgitlab.combitbucket.org
To support additional Git forges or self-hosted instances, modify the ALLOWED_GIT_HOSTS list in src/skillspector/constants.py before running your scan.
Summary
- SkillSpector supports remote repositories through automatic Git URL detection and shallow cloning
_is_git_urlvalidates URLs by checking schemes and hostnames against an allowlist_clone_gitexecutesgit clone --depth 1into temporary directories that are automatically cleaned up- CLI usage requires only passing the HTTPS or SSH URL to the
scancommand - Security is maintained through the
ALLOWED_GIT_HOSTSrestriction insrc/skillspector/constants.py
Frequently Asked Questions
Does SkillSpector support private remote repositories?
SkillSpector uses standard Git commands for cloning, so it respects your system's SSH keys and Git credentials. If your environment has access to a private repository via SSH keys or credential helpers, SkillSpector can clone and scan it. HTTPS URLs with embedded credentials are not recommended for security reasons.
What Git hosts are supported by default?
According to the source code in src/skillspector/constants.py, SkillSpector allows cloning from github.com, gitlab.com, and bitbucket.org by default. You can extend support to other hosts by adding them to the ALLOWED_GIT_HOSTS list.
How does SkillSpector handle repository cleanup after scanning?
The _clone_git implementation in src/skillspector/input_handler.py creates a temporary directory using the system's temp folder utilities. This directory serves as the scan source and is typically removed after the analysis completes, ensuring no persistent clones remain on your filesystem.
Can I scan a specific branch or tag from a remote repository?
The current implementation performs a shallow clone of the default branch (--depth 1). To scan specific branches or tags, you would need to clone the repository manually, checkout the specific reference, and then provide the local path to SkillSpector's scan command.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →