Where to Find SkillSpector Documentation: A Complete Guide to NVIDIA's AI Security Scanner
SkillSpector documentation is located in the docs/ directory of the NVIDIA/SkillSpector repository, with the README.md providing quick-start instructions and specialized guides covering development, suppression rules, Pi extensions, and LLM analysis.
The NVIDIA/SkillSpector repository hosts comprehensive documentation for this AI-powered security scanning tool. Whether you are installing the CLI for the first time or extending the analyzer pipeline, the SkillSpector documentation offers detailed guidance through Markdown files in the repository's docs/ folder and inline code documentation.
Main Documentation Location
All user-facing SkillSpector documentation resides in the repository's docs/ directory. These Markdown files are rendered automatically in GitHub's web interface, allowing you to read them directly in your browser or clone the repository for local access.
Core Documentation Files
The project includes specialized guides for different use cases:
Development Guide (docs/DEVELOPMENT.md)
The Development Guide covers architecture decisions, package layout, and instructions for extending the analyzer pipeline. This file explains how to modify core components and integrate new scanners into the LangGraph workflow orchestrated by src/skillspector/graph.py.
Suppression Guide (docs/SUPPRESSION.md)
The Suppression Guide details baseline creation, false-positive suppression techniques, and rule syntax. It explains how to generate baseline files to track intentional exceptions and configure suppression rules for your specific deployment needs.
Pi Extension Guide (docs/PI_EXTENSION.md)
The Pi Extension Guide provides instructions for installing SkillSpector as a Pi tool for in-session scanning. This configuration enables real-time vulnerability detection during development workflows and IDE integrations.
LLM Analyzer Base Guide (docs/LLM_ANALYZER_BASE_GUIDE.md)
The LLM Analyzer Base Guide explains how the semantic analysis engine works, including prompt design patterns and model selection strategies. This document references the implementation details found in src/skillspector/llm_utils.py.
Evaluation Datasets (docs/EVAL_DATASETS.md)
The Evaluation Datasets document describes the data used for testing the scanner's accuracy and performance across different vulnerability patterns and edge cases.
SC4 OSV Live Vulnerability Lookups (docs/SC4-osv-live-vulnerability-lookups.md)
This guide covers live dependency CVE checks using the Open Source Vulnerability (OSV) database for real-time security assessment of third-party packages.
Quick Start Reference (README.md)
The root-level README.md provides the quick start guide, feature summaries, and essential CLI usage examples. This is the best starting point for new users before diving into specialized documentation.
Source Code Reference
Understanding the implementation details requires consulting these key source files:
src/skillspector/cli.py– Entry point for theskillspectorcommand-line interfacesrc/skillspector/graph.py– Contains the LangGraph workflow orchestration logic that drives core scanning operationssrc/skillspector/models.py– Defines Pydantic models for JSON and SARIF report schemassrc/skillspector/llm_utils.py– Implements helper functions for LLM provider selection and request handlingsrc/skillspector/input_handler.py– Normalizes various input sources including git URLs, zip files, and local directoriessrc/skillspector/mcp_server.py– Implements the Model Context Protocol (MCP) server mode for IDE integration
Common Usage Examples
The documentation references these practical commands for daily operation:
# Loading the main CLI programmatically
from skillspector import cli
# Run a scan on a local directory (equivalent to `skillspector scan ./my-skill/`)
result = cli.run_cli(["scan", "./my-skill/"])
print(result) # JSON output printed to stdout
# Generate a baseline for false-positive suppression
# Reference: docs/SUPPRESSION.md
skillspector baseline ./my-skill/ -o .skillspector-baseline.yaml
# Scan with specific output format
# Reference: README.md
skillspector scan ./my-skill/ --format json --output report.json
Summary
The NVIDIA/SkillSpector repository provides comprehensive documentation across multiple specialized guides:
- Primary documentation resides in the
docs/directory with seven specialized Markdown files README.mdoffers immediate quick-start guidance for new usersdocs/DEVELOPMENT.mdprovides architectural details for contributorsdocs/SUPPRESSION.mdexplains baseline and false-positive management- Source code in
src/skillspector/contains inline documentation for implementation details
Frequently Asked Questions
Where is the SkillSpector documentation hosted?
The SkillSpector documentation is hosted directly in the GitHub repository at NVIDIA/SkillSpector. All files are located in the docs/ directory and rendered through GitHub's Markdown viewer. You can access them online or clone the repository to read them locally in any Markdown viewer.
How do I create a baseline file for suppressing false positives?
Create a baseline file by running skillspector baseline ./my-skill/ -o .skillspector-baseline.yaml as documented in docs/SUPPRESSION.md. This generates a YAML file tracking known issues that should be excluded from future scan reports. The suppression guide details the rule syntax and configuration options for managing these exceptions.
Which document explains the LLM analyzer implementation?
The LLM analyzer implementation is documented in docs/LLM_ANALYZER_BASE_GUIDE.md, which covers prompt design, model selection, and semantic analysis workflows. The actual implementation code resides in src/skillspector/llm_utils.py and src/skillspector/graph.py, which orchestrates the LangGraph workflow for AI-powered vulnerability detection.
How do I programmatically interact with SkillSpector?
You can import the CLI module directly from Python as shown in src/skillspector/cli.py. Use from skillspector import cli followed by cli.run_cli(["scan", "./my-skill/"]) to execute scans programmatically. This approach returns JSON output that you can process within your Python applications rather than parsing command-line output.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →