# What Programming Languages Does SkillSpector Support?

> Discover the programming languages SkillSpector supports, including Python for its core engine and TypeScript for its agent extension. Analyze code effectively.

- Repository: [NVIDIA Corporation/SkillSpector](https://github.com/NVIDIA/SkillSpector)
- Tags: getting-started
- Published: 2026-07-10

---

**SkillSpector is a dual-language open-source project built primarily in Python for the core security scanning engine and TypeScript for the Pi-coding-agent extension wrapper.**

NVIDIA SkillSpector is a security analysis tool for AI agent skills that leverages two distinct programming languages to separate heavy-duty analysis logic from lightweight integration interfaces. Understanding what programming languages SkillSpector supports helps developers choose the right integration path—whether calling the Python API directly or using the TypeScript extension for external agent tooling. The codebase follows a clear architectural split with Python handling all executable scanning logic and TypeScript providing a thin wrapper for third-party tool registration.

## Python: The Core Analysis Engine

**Python serves as the primary implementation language** for SkillSpector's security scanning capabilities, encompassing the CLI, static analyzers, AST parsers, LLM integrations, and graph-based workflow orchestration. All executable business logic resides in Python modules under `src/skillspector/`, making it the dominant language by functionality and codebase volume.

### Key Python Source Files

The Python implementation is organized into specialized modules:

- **[`src/skillspector/cli.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/cli.py)** — Entry point for the `skillspector` command-line interface
- **[`src/skillspector/graph.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/graph.py)** — Orchestrates the two-stage scanning pipeline (static analysis followed by optional LLM evaluation)
- **[`src/skillspector/llm_utils.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/llm_utils.py)** — Helper utilities for interacting with LLM providers and processing model responses

These modules handle complex tasks including risk scoring, dependency parsing, and security pattern matching against theSkillSpector model registry.

### Python API Integration Example

For programmatic access to the scanning engine, import the graph module and invoke the analysis workflow directly:

```python
from skillspector import graph

# Run a full scan (static + optional LLM analysis)

result = graph.invoke({
    "input_path": "/path/to/skill",
    "output_format": "json",    # terminal | json | markdown | sarif

    "use_llm": True,            # set False for static-only scans

})

print(f"Risk Score: {result['risk_score']}/100")
print(f"Severity: {result['risk_severity']}")
print(f"Recommendation: {result['risk_recommendation']}")

```

This implementation in [`src/skillspector/graph.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/graph.py) exposes the complete scanning pipeline without requiring subprocess calls to the CLI.

## TypeScript: Extension and Tool Integration

**TypeScript powers the extension layer** that allows external coding agents to invoke SkillSpector as a registered tool. This implementation is isolated to a single file and serves as a bridge between the Python CLI and JavaScript-based agent environments like the Pi-coding-agent.

### Extension Architecture

The TypeScript code performs three critical functions:

1. **Binary Resolution** — Locates the local SkillSpector CLI executable
2. **Argument Building** — Constructs CLI arguments from typed parameters
3. **Tool Registration** — Registers the `skillspector_scan` command with the agent's extension API

The entire TypeScript implementation lives in [`extensions/skillspector.ts`](https://github.com/NVIDIA/SkillSpector/blob/main/extensions/skillspector.ts) and intentionally maintains minimal logic, delegating all security analysis to the Python subprocess.

### TypeScript Extension Implementation

When integrated with the Pi-coding-agent, the extension registers a callable tool that wraps the Python CLI:

```typescript
import type { ExtensionAPI } from "@earendil-works/pi-coding-agent";

export default function (pi: ExtensionAPI) {
  pi.registerTool({
    name: "skillspector_scan",
    label: "SkillSpector Scan",
    description:
      "Scan agent skills, directories, zip files, URLs, or Git repos for security risks using the local SkillSpector CLI.",
    parameters: /* see scanSchema in the source */,
    async execute(_toolCallId, params, _signal, onUpdate, ctx) {
      const bin = findSkillSpectorBin();               // resolves the CLI binary
      const args = buildScanArgs(params, ctx.cwd);     // builds CLI args
      const result = await pi.exec(bin, args, { cwd: ctx.cwd });
      // ...process result, redact secrets, and return text...
    },
  });
}

```

This pattern allows agent frameworks written in TypeScript to invoke Python-based security analysis without native language bindings.

## Declarative Configuration Files

While not executable programming languages, the repository contains declarative configuration files that support the build and packaging process:

- **[`pyproject.toml`](https://github.com/NVIDIA/SkillSpector/blob/main/pyproject.toml)** — Defines Python dependencies, build metadata, and entry points
- **[`package.json`](https://github.com/NVIDIA/SkillSpector/blob/main/package.json)** — Specifies Node.js dependencies for the TypeScript extension
- **[`model_registry.yaml`](https://github.com/NVIDIA/SkillSpector/blob/main/model_registry.yaml)** — Configures security model definitions and rule sets

These files are essential for deployment but do not contain runtime logic for security scanning.

## Summary

- **SkillSpector supports two primary programming languages**: Python for the core engine and TypeScript for the extension layer.
- **Python handles all security analysis** including static scanning, AST parsing, LLM integration, and graph workflow orchestration in `src/skillspector/`.
- **TypeScript provides a thin wrapper** in [`extensions/skillspector.ts`](https://github.com/NVIDIA/SkillSpector/blob/main/extensions/skillspector.ts) that registers the `skillspector_scan` tool for external coding agents.
- **Direct API access** requires Python, while **agent integration** typically uses the TypeScript extension to spawn the Python CLI.
- **Declarative files** like [`pyproject.toml`](https://github.com/NVIDIA/SkillSpector/blob/main/pyproject.toml) and [`package.json`](https://github.com/NVIDIA/SkillSpector/blob/main/package.json) manage dependencies but do not implement scanning logic.

## Frequently Asked Questions

### Is SkillSpector written entirely in Python?

No. While the core security scanning engine, CLI, and analysis workflows are implemented in Python under `src/skillspector/`, the repository includes a TypeScript extension in [`extensions/skillspector.ts`](https://github.com/NVIDIA/SkillSpector/blob/main/extensions/skillspector.ts) that allows the Pi-coding-agent to invoke SkillSpector as a registered tool. Python remains the dominant language by code volume and functionality.

### What is the TypeScript extension used for?

The TypeScript extension acts as a bridge between JavaScript-based coding agents and the Python CLI. It registers a `skillspector_scan` command that resolves the SkillSpector binary, builds CLI arguments from typed parameters, and executes the Python process. This allows agent frameworks written in TypeScript to leverage Python-based security analysis without requiring Python-native plugin systems.

### Can I use SkillSpector without the TypeScript extension?

Yes. The TypeScript extension is optional and only required if you are integrating with the Pi-coding-agent or similar TypeScript-based tooling. You can run SkillSpector directly using the Python CLI entry point in [`src/skillspector/cli.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/cli.py) or import the `graph` module programmatically as shown in the Python API examples above.

### Are there any other programming languages used in the repository?

No. Beyond Python and TypeScript, the repository contains only declarative configuration files such as [`pyproject.toml`](https://github.com/NVIDIA/SkillSpector/blob/main/pyproject.toml), [`package.json`](https://github.com/NVIDIA/SkillSpector/blob/main/package.json), and [`model_registry.yaml`](https://github.com/NVIDIA/SkillSpector/blob/main/model_registry.yaml). These files define packaging metadata and model configurations but do not contain executable program logic implemented in other languages.