What Programming Languages Does SkillSpector Support?
SkillSpector is a dual-language open-source project built primarily in Python for the core security scanning engine and TypeScript for the Pi-coding-agent extension wrapper.
NVIDIA SkillSpector is a security analysis tool for AI agent skills that leverages two distinct programming languages to separate heavy-duty analysis logic from lightweight integration interfaces. Understanding what programming languages SkillSpector supports helps developers choose the right integration path—whether calling the Python API directly or using the TypeScript extension for external agent tooling. The codebase follows a clear architectural split with Python handling all executable scanning logic and TypeScript providing a thin wrapper for third-party tool registration.
Python: The Core Analysis Engine
Python serves as the primary implementation language for SkillSpector's security scanning capabilities, encompassing the CLI, static analyzers, AST parsers, LLM integrations, and graph-based workflow orchestration. All executable business logic resides in Python modules under src/skillspector/, making it the dominant language by functionality and codebase volume.
Key Python Source Files
The Python implementation is organized into specialized modules:
src/skillspector/cli.py— Entry point for theskillspectorcommand-line interfacesrc/skillspector/graph.py— Orchestrates the two-stage scanning pipeline (static analysis followed by optional LLM evaluation)src/skillspector/llm_utils.py— Helper utilities for interacting with LLM providers and processing model responses
These modules handle complex tasks including risk scoring, dependency parsing, and security pattern matching against theSkillSpector model registry.
Python API Integration Example
For programmatic access to the scanning engine, import the graph module and invoke the analysis workflow directly:
from skillspector import graph
# Run a full scan (static + optional LLM analysis)
result = graph.invoke({
"input_path": "/path/to/skill",
"output_format": "json", # terminal | json | markdown | sarif
"use_llm": True, # set False for static-only scans
})
print(f"Risk Score: {result['risk_score']}/100")
print(f"Severity: {result['risk_severity']}")
print(f"Recommendation: {result['risk_recommendation']}")
This implementation in src/skillspector/graph.py exposes the complete scanning pipeline without requiring subprocess calls to the CLI.
TypeScript: Extension and Tool Integration
TypeScript powers the extension layer that allows external coding agents to invoke SkillSpector as a registered tool. This implementation is isolated to a single file and serves as a bridge between the Python CLI and JavaScript-based agent environments like the Pi-coding-agent.
Extension Architecture
The TypeScript code performs three critical functions:
- Binary Resolution — Locates the local SkillSpector CLI executable
- Argument Building — Constructs CLI arguments from typed parameters
- Tool Registration — Registers the
skillspector_scancommand with the agent's extension API
The entire TypeScript implementation lives in extensions/skillspector.ts and intentionally maintains minimal logic, delegating all security analysis to the Python subprocess.
TypeScript Extension Implementation
When integrated with the Pi-coding-agent, the extension registers a callable tool that wraps the Python CLI:
import type { ExtensionAPI } from "@earendil-works/pi-coding-agent";
export default function (pi: ExtensionAPI) {
pi.registerTool({
name: "skillspector_scan",
label: "SkillSpector Scan",
description:
"Scan agent skills, directories, zip files, URLs, or Git repos for security risks using the local SkillSpector CLI.",
parameters: /* see scanSchema in the source */,
async execute(_toolCallId, params, _signal, onUpdate, ctx) {
const bin = findSkillSpectorBin(); // resolves the CLI binary
const args = buildScanArgs(params, ctx.cwd); // builds CLI args
const result = await pi.exec(bin, args, { cwd: ctx.cwd });
// ...process result, redact secrets, and return text...
},
});
}
This pattern allows agent frameworks written in TypeScript to invoke Python-based security analysis without native language bindings.
Declarative Configuration Files
While not executable programming languages, the repository contains declarative configuration files that support the build and packaging process:
pyproject.toml— Defines Python dependencies, build metadata, and entry pointspackage.json— Specifies Node.js dependencies for the TypeScript extensionmodel_registry.yaml— Configures security model definitions and rule sets
These files are essential for deployment but do not contain runtime logic for security scanning.
Summary
- SkillSpector supports two primary programming languages: Python for the core engine and TypeScript for the extension layer.
- Python handles all security analysis including static scanning, AST parsing, LLM integration, and graph workflow orchestration in
src/skillspector/. - TypeScript provides a thin wrapper in
extensions/skillspector.tsthat registers theskillspector_scantool for external coding agents. - Direct API access requires Python, while agent integration typically uses the TypeScript extension to spawn the Python CLI.
- Declarative files like
pyproject.tomlandpackage.jsonmanage dependencies but do not implement scanning logic.
Frequently Asked Questions
Is SkillSpector written entirely in Python?
No. While the core security scanning engine, CLI, and analysis workflows are implemented in Python under src/skillspector/, the repository includes a TypeScript extension in extensions/skillspector.ts that allows the Pi-coding-agent to invoke SkillSpector as a registered tool. Python remains the dominant language by code volume and functionality.
What is the TypeScript extension used for?
The TypeScript extension acts as a bridge between JavaScript-based coding agents and the Python CLI. It registers a skillspector_scan command that resolves the SkillSpector binary, builds CLI arguments from typed parameters, and executes the Python process. This allows agent frameworks written in TypeScript to leverage Python-based security analysis without requiring Python-native plugin systems.
Can I use SkillSpector without the TypeScript extension?
Yes. The TypeScript extension is optional and only required if you are integrating with the Pi-coding-agent or similar TypeScript-based tooling. You can run SkillSpector directly using the Python CLI entry point in src/skillspector/cli.py or import the graph module programmatically as shown in the Python API examples above.
Are there any other programming languages used in the repository?
No. Beyond Python and TypeScript, the repository contains only declarative configuration files such as pyproject.toml, package.json, and model_registry.yaml. These files define packaging metadata and model configurations but do not contain executable program logic implemented in other languages.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →