What Programming Languages Does SkillSpector Support?

SkillSpector is a dual-language open-source project built primarily in Python for the core security scanning engine and TypeScript for the Pi-coding-agent extension wrapper.

NVIDIA SkillSpector is a security analysis tool for AI agent skills that leverages two distinct programming languages to separate heavy-duty analysis logic from lightweight integration interfaces. Understanding what programming languages SkillSpector supports helps developers choose the right integration path—whether calling the Python API directly or using the TypeScript extension for external agent tooling. The codebase follows a clear architectural split with Python handling all executable scanning logic and TypeScript providing a thin wrapper for third-party tool registration.

Python: The Core Analysis Engine

Python serves as the primary implementation language for SkillSpector's security scanning capabilities, encompassing the CLI, static analyzers, AST parsers, LLM integrations, and graph-based workflow orchestration. All executable business logic resides in Python modules under src/skillspector/, making it the dominant language by functionality and codebase volume.

Key Python Source Files

The Python implementation is organized into specialized modules:

These modules handle complex tasks including risk scoring, dependency parsing, and security pattern matching against theSkillSpector model registry.

Python API Integration Example

For programmatic access to the scanning engine, import the graph module and invoke the analysis workflow directly:

from skillspector import graph

# Run a full scan (static + optional LLM analysis)

result = graph.invoke({
    "input_path": "/path/to/skill",
    "output_format": "json",    # terminal | json | markdown | sarif

    "use_llm": True,            # set False for static-only scans

})

print(f"Risk Score: {result['risk_score']}/100")
print(f"Severity: {result['risk_severity']}")
print(f"Recommendation: {result['risk_recommendation']}")

This implementation in src/skillspector/graph.py exposes the complete scanning pipeline without requiring subprocess calls to the CLI.

TypeScript: Extension and Tool Integration

TypeScript powers the extension layer that allows external coding agents to invoke SkillSpector as a registered tool. This implementation is isolated to a single file and serves as a bridge between the Python CLI and JavaScript-based agent environments like the Pi-coding-agent.

Extension Architecture

The TypeScript code performs three critical functions:

  1. Binary Resolution — Locates the local SkillSpector CLI executable
  2. Argument Building — Constructs CLI arguments from typed parameters
  3. Tool Registration — Registers the skillspector_scan command with the agent's extension API

The entire TypeScript implementation lives in extensions/skillspector.ts and intentionally maintains minimal logic, delegating all security analysis to the Python subprocess.

TypeScript Extension Implementation

When integrated with the Pi-coding-agent, the extension registers a callable tool that wraps the Python CLI:

import type { ExtensionAPI } from "@earendil-works/pi-coding-agent";

export default function (pi: ExtensionAPI) {
  pi.registerTool({
    name: "skillspector_scan",
    label: "SkillSpector Scan",
    description:
      "Scan agent skills, directories, zip files, URLs, or Git repos for security risks using the local SkillSpector CLI.",
    parameters: /* see scanSchema in the source */,
    async execute(_toolCallId, params, _signal, onUpdate, ctx) {
      const bin = findSkillSpectorBin();               // resolves the CLI binary
      const args = buildScanArgs(params, ctx.cwd);     // builds CLI args
      const result = await pi.exec(bin, args, { cwd: ctx.cwd });
      // ...process result, redact secrets, and return text...
    },
  });
}

This pattern allows agent frameworks written in TypeScript to invoke Python-based security analysis without native language bindings.

Declarative Configuration Files

While not executable programming languages, the repository contains declarative configuration files that support the build and packaging process:

  • pyproject.toml — Defines Python dependencies, build metadata, and entry points
  • package.json — Specifies Node.js dependencies for the TypeScript extension
  • model_registry.yaml — Configures security model definitions and rule sets

These files are essential for deployment but do not contain runtime logic for security scanning.

Summary

  • SkillSpector supports two primary programming languages: Python for the core engine and TypeScript for the extension layer.
  • Python handles all security analysis including static scanning, AST parsing, LLM integration, and graph workflow orchestration in src/skillspector/.
  • TypeScript provides a thin wrapper in extensions/skillspector.ts that registers the skillspector_scan tool for external coding agents.
  • Direct API access requires Python, while agent integration typically uses the TypeScript extension to spawn the Python CLI.
  • Declarative files like pyproject.toml and package.json manage dependencies but do not implement scanning logic.

Frequently Asked Questions

Is SkillSpector written entirely in Python?

No. While the core security scanning engine, CLI, and analysis workflows are implemented in Python under src/skillspector/, the repository includes a TypeScript extension in extensions/skillspector.ts that allows the Pi-coding-agent to invoke SkillSpector as a registered tool. Python remains the dominant language by code volume and functionality.

What is the TypeScript extension used for?

The TypeScript extension acts as a bridge between JavaScript-based coding agents and the Python CLI. It registers a skillspector_scan command that resolves the SkillSpector binary, builds CLI arguments from typed parameters, and executes the Python process. This allows agent frameworks written in TypeScript to leverage Python-based security analysis without requiring Python-native plugin systems.

Can I use SkillSpector without the TypeScript extension?

Yes. The TypeScript extension is optional and only required if you are integrating with the Pi-coding-agent or similar TypeScript-based tooling. You can run SkillSpector directly using the Python CLI entry point in src/skillspector/cli.py or import the graph module programmatically as shown in the Python API examples above.

Are there any other programming languages used in the repository?

No. Beyond Python and TypeScript, the repository contains only declarative configuration files such as pyproject.toml, package.json, and model_registry.yaml. These files define packaging metadata and model configurations but do not contain executable program logic implemented in other languages.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →