Which AI Agent Frameworks Are Supported by SkillSpector?
SkillSpector supports four CLI-based AI agent frameworks: Claude (Anthropic), Codex (OpenAI), Gemini (Google), and Antigravity (AWS), with each framework registered in the internal provider registry at src/skillspector/providers/_agent_cli.py.
NVIDIA's SkillSpector is a security analysis tool designed to evaluate AI agent skills that execute through command-line interfaces. Understanding which AI agent frameworks are supported by SkillSpector is essential for developers who want to scan their agent implementations for vulnerabilities. The tool discovers the appropriate CLI binary automatically from skill metadata while allowing users to configure the semantic analysis backend separately.
Supported AI Agent Frameworks
SkillSpector currently integrates with four major AI agent providers through dedicated CLI wrappers. Each framework maps to a specific provider module and binary name in the internal registry.
Claude (Anthropic)
- Provider Module:
skillspector.providers.claude_cli - CLI Binary:
claude - Implementation:
src/skillspector/providers/claude_cli/provider.py
This wrapper enables SkillSpector to invoke and analyze skills built for Anthropic's Claude CLI agent.
Codex (OpenAI)
- Provider Module:
skillspector.providers.codex_cli - CLI Binary:
codex - Implementation:
src/skillspector/providers/codex_cli/provider.py
OpenAI's Codex CLI agent is supported through this provider module, allowing analysis of Codex-based agent implementations.
Gemini (Google)
- Provider Module:
skillspector.providers.gemini_cli - CLI Binary:
gemini - Implementation:
src/skillspector/providers/gemini_cli/provider.py
Google's Gemini CLI agent framework is registered under this provider for security scanning.
Antigravity (AWS)
- Provider Module:
skillspector.providers.antigravity_cli - CLI Binary:
agy(registered as "agy" in the internal registry) - Implementation:
src/skillspector/providers/antigravity_cli/provider.py
The AWS Antigravity framework uses the abbreviated binary name agy in the SkillSpector registry.
Framework Registration and Detection
The registry of supported CLI agents lives in src/skillspector/providers/_agent_cli.py, which contains an internal _REGISTRY mapping framework identifiers to their respective CLI binaries. This registry explicitly references the four primary agents and serves as the source of truth for available frameworks.
When SkillSpector analyzes a skill, it uses the run_agent_cli hardened subprocess helper to safely invoke the detected CLI binary. The framework is automatically discovered from the skill's SKILL.md file, ensuring the correct binary—whether claude, codex, gemini, or agy—is launched via the secure wrapper.
Configuring the Analysis Backend
While SkillSpector automatically detects which CLI framework to use for skill execution, you can configure the LLM backend for semantic analysis separately using the SKILLSPECTOR_PROVIDER environment variable.
To perform a basic scan without LLM analysis:
import subprocess
subprocess.run(
["skillspector", "scan", "./my-skill/"],
check=True,
)
To enable LLM-augmented analysis with a specific provider:
import os
import subprocess
# Set the backend for semantic analysis
os.environ["SKILLSPECTOR_PROVIDER"] = "anthropic" # Options include anthropic, openai, google, etc.
subprocess.run(
["skillspector", "scan", "./my-skill/", "--llm"],
check=True,
)
The same scan commands work regardless of which CLI framework your skill uses—the provider detection operates independently from the semantic analysis backend.
Provider Module Implementation
Each supported framework is implemented as a thin wrapper in the providers directory:
src/skillspector/providers/_agent_cli.py: Core hardened subprocess helper and central registry for all supported CLI agentssrc/skillspector/providers/claude_cli/provider.py: Claude CLI registrationsrc/skillspector/providers/codex_cli/provider.py: Codex CLI registrationsrc/skillspector/providers/gemini_cli/provider.py: Gemini CLI registrationsrc/skillspector/providers/antigravity_cli/provider.py: Antigravity CLI registration
These modules collectively define the AI agent frameworks that SkillSpector can safely evaluate.
Summary
- SkillSpector supports four CLI-based AI agent frameworks: Claude (Anthropic), Codex (OpenAI), Gemini (Google), and Antigravity (AWS).
- Framework binaries (
claude,codex,gemini,agy) are registered insrc/skillspector/providers/_agent_cli.py. - The
run_agent_climethod provides a hardened subprocess wrapper for safe CLI invocation. - Framework detection is automatic based on the skill's
SKILL.mdfile. - The
SKILLSPECTOR_PROVIDERenvironment variable configures the LLM backend for semantic analysis independently from the CLI framework.
Frequently Asked Questions
How does SkillSpector determine which CLI binary to use for my agent?
SkillSpector automatically detects the appropriate CLI binary by reading your skill's SKILL.md file. It then references the internal _REGISTRY in src/skillspector/providers/_agent_cli.py to map the framework to the correct binary name—whether that's claude, codex, gemini, or agy for Antigravity.
Can I add support for a new AI agent framework to SkillSpector?
Yes, but it requires modifying the source code. You must register the new CLI-based agent in the _REGISTRY dictionary within src/skillspector/providers/_agent_cli.py and create a corresponding provider module following the pattern used by the existing claude_cli, codex_cli, gemini_cli, or antigravity_cli implementations.
What is the difference between the CLI framework and the SKILLSPECTOR_PROVIDER environment variable?
The CLI framework (detected via SKILL.md) determines which binary SkillSpector executes to run your agent skill—this is the actual AI agent being analyzed. The SKILLSPECTOR_PROVIDER environment variable selects which LLM backend performs the semantic security analysis of that skill's code. They operate independently: you could analyze a Claude-based skill using OpenAI's backend for semantic analysis, or vice versa.
Is the Antigravity CLI binary name different from its framework name?
Yes, while the framework is called Antigravity (AWS), it is registered in the SkillSpector internal registry with the binary name agy rather than the full framework name. This abbreviation is defined in src/skillspector/providers/antigravity_cli/provider.py and referenced in the central registry at src/skillspector/providers/_agent_cli.py.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →