@nx-devkit/skillspector
v0.1.19
Published
Nx plugin for SkillSpector security scanning: any SKILL.md gets a scan target reporting vulnerabilities, secrets, and risky patterns — with SARIF output and CI annotations.
Downloads
6,215
Maintainers
Readme
@nx-devkit/skillspector
Nx plugin for SkillSpector security scanning: any directory containing SKILL.md becomes a project with a scan target that analyzes skill code for vulnerabilities, secrets, and risky patterns. No project.json needed.
Part of nx-devkit.
Install
bun add -D @nx-devkit/skillspectorDepends on @nx/devkit ^22 || ^23 (installed automatically) and a skillspector binary reachable on PATH — or point the skillspectorBin option at any install.
Register
nx add @nx-devkit/skillspector # runs the init generator — registers the plugin in nx.jsonOr manually:
// nx.json
{ "plugins": ["@nx-devkit/skillspector"] }What it infers
| Trigger | Target | Executor |
|---|---|---|
| SKILL.md | scan | @nx-devkit/skillspector:scan — spawns the skillspector binary via execFile, no shell |
Inspect
npx nx show projects
npx nx show project <name>
npx nx run <name>:scanOptions
{
"plugins": [
["@nx-devkit/skillspector", {
"scanTargetName": "scan",
"noLlm": true,
"annotations": true,
"failOnError": true,
"skillspectorBin": "skillspector",
"sarif": "reports/skillspector.sarif",
"baseline": ".skillspector-baseline.json"
}]
]
}| Option | Default | Effect |
|---|---|---|
| scanTargetName | scan | Name of the inferred scan target. |
| noLlm | true | Disable LLM-based analysis (static checks only). |
| annotations | true | Write annotations-<projectName>.txt with ::error workflow-command lines for code findings (skipped on a clean scan). |
| failOnError | true | Fail the target when HIGH or CRITICAL findings are present. |
| skillspectorBin | skillspector | Binary to invoke — override for local dev or vendored installs. |
| sarif | — | Path prefix for the SARIF 2.1.0 report — -<projectName>.sarif is appended (any .sarif suffix is stripped first), so reports/scan.sarif produces reports/scan-<name>.sarif. |
| baseline | — | Path to a baseline file suppressing known findings. |
CI integration
- Annotations — with
annotations: true(default) and at least one code finding, the executor writesannotations-<projectName>.txtat the workspace root containing::error file=…,line=…::workflow-command lines (findings-only; the file is not created on a clean scan). Surface them in CI bycating the files into the step output or uploading them as an artifact — they are not emitted to stdout automatically. - SARIF — set
sarifto a path and upload it withgithub/codeql-action/upload-sarif, or convert to annotations with a SARIF-to-annotations step. - Gating —
failOnErrorfails CI on HIGH/CRITICAL; usebaselineto ratchet down existing debt.
Skip rules
SKILL.mdinsidenode_modulesis skipped.SKILL.mdat the workspace root is skipped.SKILL.mdescaping the workspace root is skipped.
Project naming
Like @nx-devkit/skill, project names are slug + a 12-hex-char SHA-256 suffix of the project root — collision-resistant in practice (birthday bound applies, not a guarantee).
License
MIT
