# Is SkillSpector Open Source? License, Architecture, and Code Examples

> Discover if SkillSpector is open source. Explore its Apache 2.0 license, architecture, and code examples in the NVIDIA/SkillSpector repository. Contribute today.

- Repository: [NVIDIA Corporation/SkillSpector](https://github.com/NVIDIA/SkillSpector)
- Tags: getting-started
- Published: 2026-07-10

---

**Yes, SkillSpector is fully open-source software released under the Apache 2.0 license, with the complete codebase—including static analyzers, LLM providers, and the LangGraph pipeline—available for inspection and contribution in the NVIDIA/SkillSpector repository.**

If you are wondering whether SkillSpector is open source, the answer is definitively yes. NVIDIA has released the entire project under the permissive Apache 2.0 license, making it free to use, modify, and distribute. The repository contains a comprehensive two-stage security scanner for AI-agent skills, with all implementation details visible in the `src/skillspector/` directory.

## License and Open Source Status

SkillSpector is officially licensed under the **Apache 2.0** license. You can verify this by examining the `LICENSE` file in the repository root, which contains the full license text, and by the license badge displayed in the README. This permissive license allows commercial use, modification, distribution, and private use, provided that you include the original copyright notice and license terms.

The open-source nature of the project means that every component—from the CLI entry point to the LLM provider implementations—is publicly accessible. This transparency allows security researchers and developers to audit the scanning logic, contribute improvements, or fork the project for custom use cases.

## Architecture Overview

SkillSpector operates as a **two-stage security scanner** designed to evaluate AI-agent skills for potential vulnerabilities. The architecture separates high-speed static analysis from deeper semantic analysis performed by Large Language Models (LLMs).

### Static Analysis Stage

The first stage performs rapid, deterministic security checks using pattern matching and vulnerability databases. This includes:

- **Regex-based pattern matching** for detecting tool misuse and dangerous code patterns
- **AST inspection** to analyze code structure and data flow
- **YARA scanning** for malware detection
- **Live dependency vulnerability lookups** via OSV.dev

These capabilities are implemented in the static analysis nodes, specifically in files such as [`src/skillspector/nodes/analyzers/static_yara.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/nodes/analyzers/static_yara.py), [`src/skillspector/nodes/analyzers/static_patterns_tool_misuse.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/nodes/analyzers/static_patterns_tool_misuse.py), and [`src/skillspector/nodes/analyzers/static_runner.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/nodes/analyzers/static_runner.py).

### LLM Semantic Analysis Stage

The optional second stage uses configurable LLM providers to evaluate intent, filter false positives, and generate human-readable explanations. The provider abstraction layer resides in `src/skillspector/providers/`, with concrete implementations like [`src/skillspector/providers/openai/provider.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/openai/provider.py). Shared LLM utilities are centralized in [`src/skillspector/llm_utils.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/llm_utils.py) and [`src/skillspector/llm_analyzer_base.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/llm_analyzer_base.py).

## Key Components and Source Files

Understanding the open-source codebase requires familiarity with its modular structure. The following components form the core of the application:

### CLI Interface ([`src/skillspector/cli.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/cli.py))

The command-line interface serves as the entry point for users. Located at [`src/skillspector/cli.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/cli.py), this module handles argument parsing, builds the initial state for the analysis pipeline, invokes the LangGraph workflow, and formats results. It also manages exit codes and baseline handling logic around lines 70-120.

### LangGraph Pipeline ([`src/skillspector/graph.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/graph.py))

The orchestration layer is defined in [`src/skillspector/graph.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/graph.py). This file constructs a LangChain-compatible runnable that wires together static analyzers, optional LLM calls, and result aggregation. The graph manages the flow of data between analysis nodes and ensures findings are properly collected and scored.

### Analysis Nodes (`src/skillspector/nodes/`)

Each directory under `src/skillspector/nodes/` encapsulates a specific analysis step. Key nodes include:

- **[`meta_analyzer.py`](https://github.com/NVIDIA/SkillSpector/blob/main/meta_analyzer.py)**: Aggregates findings from all analyzers, calculates the final risk score, and produces the structured report
- **[`analyzers/static_yara.py`](https://github.com/NVIDIA/SkillSpector/blob/main/analyzers/static_yara.py)**: Implements YARA-based malware detection
- **[`analyzers/static_runner.py`](https://github.com/NVIDIA/SkillSpector/blob/main/analyzers/static_runner.py)**: Coordinates the execution of static analysis tools

### LLM Providers (`src/skillspector/providers/`)

This directory contains abstraction layers for various LLM backends. The codebase supports multiple providers including OpenAI, Anthropic, Bedrock, and NVIDIA build. Each provider implements a uniform `run` interface, allowing seamless swapping of backend services without changing the core analysis logic.

### Data Models and Suppression ([`src/skillspector/models.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/models.py) and [`suppression.py`](https://github.com/NVIDIA/SkillSpector/blob/main/suppression.py))

The `Finding` data class, defined in [`src/skillspector/models.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/models.py), provides the standardized schema for security findings throughout the pipeline. The [`src/skillspector/suppression.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/suppression.py) module implements baseline generation and suppression logic, enabling users to mark known findings as accepted and exclude them from future reports.

## How to Use SkillSpector

Because SkillSpector is open source, you can interact with it through multiple interfaces: the command-line tool, the MCP server for programmatic access, or directly via the Python API.

### Scanning Skills via CLI

The primary method for scanning AI-agent skills uses the `skillspector scan` command:

```bash

# Scan a local skill directory with default terminal output

skillspector scan ./my-skill/

# Scan a skill and output JSON to a file

skillspector scan ./my-skill/ --format json --output report.json

# Scan without LLM analysis (static-only, faster execution)

skillspector scan ./my-skill/ --no-llm

```

### Running the MCP Server

SkillSpector includes an MCP (Model Context Protocol) server that allows AI agents to request scans programmatically:

```bash

# Start the MCP server using stdio transport (for local CLI agents)

skillspector mcp

# Start the MCP server with HTTP transport (for remote callers)

skillspector mcp --transport http --host 0.0.0.0 --port 8000

```

### Generating Baselines

To suppress known findings across scans, generate a baseline file:

```bash

# Create a baseline from current findings

skillspector baseline ./my-skill/ -o .skillspector-baseline.yaml

# Use the baseline in future scans

skillspector scan ./my-skill/ --baseline .skillspector-baseline.yaml

```

### Python API Integration

For custom integrations, invoke the LangGraph workflow directly:

```python
from skillspector import graph

# Invoke the LangGraph workflow programmatically

result = graph.invoke({
    "input_path": "./my-skill/",
    "output_format": "json",
    "use_llm": True,
})

print(f"Risk score: {result['risk_score']}/100")
print(f"Severity: {result['risk_severity']}")

for finding in result.get("filtered_findings", []):
    print(f"[{finding['severity']}] {finding['rule_id']}: {finding['message']}")

```

## Summary

- **SkillSpector is open-source** under the Apache 2.0 license, confirmed by the `LICENSE` file and repository documentation
- The architecture consists of **static analysis** (regex, AST, YARA, OSV.dev) and **optional LLM semantic analysis** stages
- Key source files include [`src/skillspector/cli.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/cli.py) for the interface, [`src/skillspector/graph.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/graph.py) for orchestration, and `src/skillspector/nodes/` for analysis logic
- **Multiple access methods** are available: CLI, MCP server, and direct Python API
- The entire codebase is available in the **NVIDIA/SkillSpector** repository for audit, modification, and contribution

## Frequently Asked Questions

### What license is SkillSpector released under?

SkillSpector is released under the **Apache 2.0** license. This is a permissive open-source license that allows commercial use, modification, distribution, and private use, provided you include the original copyright notice and license terms. The full license text is available in the `LICENSE` file at the repository root.

### Can I modify and redistribute SkillSpector?

Yes, the Apache 2.0 license explicitly permits you to modify the source code and redistribute copies, including modified versions. You can integrate SkillSpector into commercial products or internal tools, though you must preserve the original copyright notices and include a copy of the license with any distribution.

### Does the open-source version include LLM analysis capabilities?

Yes, the open-source repository includes complete LLM analysis capabilities. The code in `src/skillspector/providers/` contains implementations for OpenAI, Anthropic, Bedrock, and NVIDIA build providers. However, using these features requires you to provide your own API keys or endpoints, as the open-source code does not include proprietary model weights or hosted inference.

### Where can I find the source code for the static analyzers?

The static analysis implementations are located in `src/skillspector/nodes/analyzers/`. Key files include [`static_yara.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_yara.py) for malware detection, [`static_patterns_tool_misuse.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_tool_misuse.py) for dangerous pattern matching, and [`static_runner.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_runner.py) for coordinating the analysis execution. These files are fully accessible for review and modification in the open-source repository.