Skip to content
Cisco AI Defense logo
CiscoAI Security

Installation — Skill Scanner

Installation

Prerequisites

DependencyVersionNotes
PythonCPython 3.11–3.14Required for the CLI and all analyzers
uvLatestRecommended package manager (install)
pipLatestAlternative to uv

Prebuilt wheels cover:

  • glibc Linux x86-64 and ARM64
  • macOS x86-64 and ARM64 (macOS 14 or newer, because of the YARA-X wheel floor)
  • Windows x86-64

On other platforms pip falls back to the source distribution, which needs Go 1.27.1+ to build the CEL helper. Alpine/musl, PyPy, Windows ARM, Python 3.10 and Python 3.15+ are unsupported.


Install from PyPI

# Using uv (recommended)
uv pip install cisco-ai-skill-scanner

# As a standalone command-line tool, isolated from your projects
uv tool install cisco-ai-skill-scanner
pipx install cisco-ai-skill-scanner

# Using pip
pip install cisco-ai-skill-scanner

# Pin a version in CI
pip install "cisco-ai-skill-scanner==2.2.1"

The low-noise and quiet presets and the other settings on Recommended Settings need 2.2.0 or newer.

Homebrew (macOS)

brew tap cisco-ai-defense/skill-scanner https://github.com/cisco-ai-defense/skill-scanner
brew install cisco-ai-defense/skill-scanner/skill-scanner

The formula needs macOS 14 or newer and installs a pinned, prebuilt wheel for every dependency, so it takes a minute or two. It is regenerated from the PyPI release after each version is published, so it can trail PyPI by a short time. Upgrade with brew upgrade skill-scanner.

If Homebrew reports that it could not link python@3.12 because files such as /usr/local/bin/python3.12 already exist (a python.org install on an Intel Mac), run brew link --overwrite python@3.12 and then brew install again.

Cloud Provider Extras

Install optional extras for managed LLM cloud services:

# AWS Bedrock support (IAM credentials)
pip install cisco-ai-skill-scanner[bedrock]

# Google AI Studio (Gemini API key) support
pip install cisco-ai-skill-scanner[google]

# Google Vertex AI support
pip install cisco-ai-skill-scanner[vertex]

# Azure OpenAI support (managed identity)
pip install cisco-ai-skill-scanner[azure]

# On-device Apple Foundation Model (experimental: macOS 26+, Apple Intelligence, full Xcode)
pip install "apple-fm-sdk>=0.2.1,<0.3"

# All cloud providers
pip install cisco-ai-skill-scanner[all]

Without the matching extra, --use-llm stops with an error instead of quietly falling back to rules only.

Install from Source

Use this if you want to contribute or run the latest development version:

Source builds require Go 1.27.1+ and compile the pinned official cel-go v0.32.0 helper for the host.

git clone https://github.com/cisco-ai-defense/skill-scanner
cd skill-scanner
uv sync --all-extras

To rebuild the helper explicitly:

uv run python scripts/build_cel_helper.py --in-place

Run commands with uv run skill-scanner when using a source install.


Verify Installation

skill-scanner --help
skill-scanner list-analyzers
skill-scanner validate-rules

GitHub release artifacts are published with build-provenance attestations and an SBOM. For controlled environments, verify the release attestation before installing a downloaded artifact and retain the SBOM with your software inventory.


Environment Configuration

All configuration is done through environment variables. No config files are required for basic scanning.

LLM Analyzer and Meta-Analyzer

VariableDescription
SKILL_SCANNER_LLM_API_KEYAPI key for the LLM provider
SKILL_SCANNER_LLM_MODELModel as provider/model. Default: anthropic/claude-sonnet-5-5
SKILL_SCANNER_LLM_PROVIDEROptional routing override, such as openai-compatible for gateways and local servers
SKILL_SCANNER_LLM_BASE_URLBase URL for an OpenAI-compatible endpoint
SKILL_SCANNER_LLM_USEROptional raw Chat Completions user field for OpenAI-compatible routes
SKILL_SCANNER_LLM_TEMPERATUREOptional temperature override. Use none to omit it. Models that reject temperature get none by default
SKILL_SCANNER_ADJUDICATOR_LLM_MODELOptional model override for --adjudicate

External Analyzers

VariableDescriptionRequired for
VIRUSTOTAL_API_KEYVirusTotal API key--use-virustotal
AI_DEFENSE_API_KEYCisco AI Defense API key--use-aidefense
AI_DEFENSE_API_URLCisco AI Defense endpoint URL--use-aidefense

Quick Setup

# The LLM judge (every recommended setup uses it; see LLM Providers for local models)
export SKILL_SCANNER_LLM_API_KEY="your_api_key"
export SKILL_SCANNER_LLM_MODEL="anthropic/claude-sonnet-5-5"

# Optional: VirusTotal binary scanning
export VIRUSTOTAL_API_KEY="your_virustotal_api_key"

# Optional: Cisco AI Defense
export AI_DEFENSE_API_KEY="your_aidefense_api_key"

LLM Provider Setup

The LLM judge works with Anthropic (the default), OpenAI, AWS Bedrock, Google Vertex AI and Gemini, Azure OpenAI, any OpenAI-compatible gateway or local server, Ollama, and, experimentally, the on-device Apple Foundation Model.

ProviderModel stringExtra
Anthropicanthropic/claude-sonnet-5-5None
OpenAIopenai/<model>None
AWS Bedrockbedrock/us.anthropic.claude-sonnet-5-5[bedrock]
AWS Bedrock mantlebedrock-mantle/google.gemma-4-26b-a4b[bedrock]
Google Vertex AIvertex_ai/<model>[vertex]
Google AI Studiogemini/<model>[google]
Azure OpenAIazure/<deployment>[azure]
OpenAI-compatible gateway or vLLMany name, with SKILL_SCANNER_LLM_PROVIDER=openai-compatible and SKILL_SCANNER_LLM_BASE_URLNone
Ollamaollama/<model>None
Apple Foundation Model (experimental)apple-fm/systempip install "apple-fm-sdk>=0.2.1,<0.3"

See LLM Providers for credentials, the vLLM settings that keep JSON intact, and the measured model.

OSV.dev dependency scanning (--use-osv) needs network access but no API key or optional package.