Does SkillSpector Support Remote Repositories? Git URL Scanning Guide

Yes, SkillSpector fully supports remote repositories by automatically detecting Git URLs, cloning them into temporary directories, and scanning the contents without modifying your local filesystem.

SkillSpector is an open-source skill analysis tool developed by NVIDIA that can evaluate code repositories directly from remote Git hosts. Understanding how to leverage SkillSpector remote repositories functionality allows you to audit public and private skills without manually downloading them first.

How SkillSpector Detects Remote Git Repositories

The remote repository support is implemented in the InputHandler class located in src/skillspector/input_handler.py. When you provide a URL to the scan command, the system determines whether the input string represents a local path or a remote Git repository through a multi-step validation process.

Git URL Validation via _is_git_url

The _is_git_url function (lines 44-56 in src/skillspector/input_handler.py) performs the initial detection by checking two criteria:

  • Scheme validation: Verifies the URL uses http, https, or git@ protocols
  • Hostname filtering: Parses the hostname and confirms it exists in the allowed list defined in ALLOWED_GIT_HOSTS

This function specifically filters out raw file URLs to ensure only valid Git repository endpoints are processed.

Shallow Cloning with _clone_git

Once validated, the _clone_git method (lines 93-117 in src/skillspector/input_handler.py) executes the repository retrieval:

  • Validates the host against ALLOWED_GIT_HOSTS from src/skillspector/constants.py
  • Creates a temporary directory isolated from your working environment
  • Performs a shallow clone using git clone --depth 1 to minimize bandwidth and storage
  • Returns the temporary path as the scan source

This approach ensures SkillSpector never modifies your local filesystem and automatically cleans up temporary directories after the scan completes.

Scanning Remote Repositories via CLI

The scan command in src/skillspector/cli.py (lines 70-78) accepts an input_path argument that can be either a local directory or a remote Git URL. The command forwards the input directly to InputHandler.resolve, which handles the cloning transparently.

Scan a public GitHub repository without LLM analysis:

skillspector scan https://github.com/NVIDIA/SkillSpector.git --no-llm

Scan a GitLab repository with LLM analysis enabled:

skillspector scan https://gitlab.com/example/skill-repo

Programmatic Usage with InputHandler

You can also trigger remote repository scans directly through the Python API:

from skillspector.input_handler import InputHandler

handler = InputHandler()
repo_path, source_type = handler.resolve("https://github.com/NVIDIA/SkillSpector.git")
print(f"Cloned to {repo_path} (source={source_type})")

# Output: Cloned to /tmp/skillspector_XXXX/repo (source=git)

The resolve method returns a tuple containing the temporary repository path and the source type identifier (git), allowing your application to handle remote and local inputs uniformly.

Supported Git Hosts and Configuration

By default, SkillSpector restricts remote cloning to major Git hosting providers for security. The ALLOWED_GIT_HOSTS constant in src/skillspector/constants.py defines the permitted hostnames:

  • github.com
  • gitlab.com
  • bitbucket.org

To support additional Git forges or self-hosted instances, modify the ALLOWED_GIT_HOSTS list in src/skillspector/constants.py before running your scan.

Summary

  • SkillSpector supports remote repositories through automatic Git URL detection and shallow cloning
  • _is_git_url validates URLs by checking schemes and hostnames against an allowlist
  • _clone_git executes git clone --depth 1 into temporary directories that are automatically cleaned up
  • CLI usage requires only passing the HTTPS or SSH URL to the scan command
  • Security is maintained through the ALLOWED_GIT_HOSTS restriction in src/skillspector/constants.py

Frequently Asked Questions

Does SkillSpector support private remote repositories?

SkillSpector uses standard Git commands for cloning, so it respects your system's SSH keys and Git credentials. If your environment has access to a private repository via SSH keys or credential helpers, SkillSpector can clone and scan it. HTTPS URLs with embedded credentials are not recommended for security reasons.

What Git hosts are supported by default?

According to the source code in src/skillspector/constants.py, SkillSpector allows cloning from github.com, gitlab.com, and bitbucket.org by default. You can extend support to other hosts by adding them to the ALLOWED_GIT_HOSTS list.

How does SkillSpector handle repository cleanup after scanning?

The _clone_git implementation in src/skillspector/input_handler.py creates a temporary directory using the system's temp folder utilities. This directory serves as the scan source and is typically removed after the analysis completes, ensuring no persistent clones remain on your filesystem.

Can I scan a specific branch or tag from a remote repository?

The current implementation performs a shallow clone of the default branch (--depth 1). To scan specific branches or tags, you would need to clone the repository manually, checkout the specific reference, and then provide the local path to SkillSpector's scan command.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →