Installation
Prerequisites
| Dependency | Version | Notes |
|---|---|---|
| Python | CPython 3.11–3.14 | Required for the CLI and all analyzers |
| uv | Latest | Recommended package manager (install) |
| pip | Latest | Alternative to uv |
Prebuilt wheels cover:
- glibc Linux x86-64 and ARM64
- macOS x86-64 and ARM64 (macOS 14 or newer, because of the YARA-X wheel floor)
- Windows x86-64
On other platforms pip falls back to the source distribution, which needs Go 1.27.1+ to build the CEL helper. Alpine/musl, PyPy, Windows ARM, Python 3.10 and Python 3.15+ are unsupported.
Install from PyPI
# Using uv (recommended)
uv pip install cisco-ai-skill-scanner
# As a standalone command-line tool, isolated from your projects
uv tool install cisco-ai-skill-scanner
pipx install cisco-ai-skill-scanner
# Using pip
pip install cisco-ai-skill-scanner
# Pin a version in CI
pip install "cisco-ai-skill-scanner==2.2.1"
The low-noise and quiet presets and the other settings on
Recommended Settings need 2.2.0 or newer.
Homebrew (macOS)
brew tap cisco-ai-defense/skill-scanner https://github.com/cisco-ai-defense/skill-scanner
brew install cisco-ai-defense/skill-scanner/skill-scanner
The formula needs macOS 14 or newer and installs a pinned, prebuilt wheel for every dependency, so it
takes a minute or two. It is regenerated from the PyPI release after each version is published, so
it can trail PyPI by a short time. Upgrade with brew upgrade skill-scanner.
If Homebrew reports that it could not link python@3.12 because files such as
/usr/local/bin/python3.12 already exist (a python.org install on an Intel Mac), run
brew link --overwrite python@3.12 and then brew install again.
Cloud Provider Extras
Install optional extras for managed LLM cloud services:
# AWS Bedrock support (IAM credentials)
pip install cisco-ai-skill-scanner[bedrock]
# Google AI Studio (Gemini API key) support
pip install cisco-ai-skill-scanner[google]
# Google Vertex AI support
pip install cisco-ai-skill-scanner[vertex]
# Azure OpenAI support (managed identity)
pip install cisco-ai-skill-scanner[azure]
# On-device Apple Foundation Model (experimental: macOS 26+, Apple Intelligence, full Xcode)
pip install "apple-fm-sdk>=0.2.1,<0.3"
# All cloud providers
pip install cisco-ai-skill-scanner[all]
Without the matching extra, --use-llm stops with an error instead of quietly falling back to rules only.
Install from Source
Use this if you want to contribute or run the latest development version:
Source builds require Go 1.27.1+ and compile the pinned official cel-go
v0.32.0 helper for the host.
git clone https://github.com/cisco-ai-defense/skill-scanner
cd skill-scanner
uv sync --all-extras
To rebuild the helper explicitly:
uv run python scripts/build_cel_helper.py --in-place
Run commands with uv run skill-scanner when using a source install.
Verify Installation
skill-scanner --help
skill-scanner list-analyzers
skill-scanner validate-rules
GitHub release artifacts are published with build-provenance attestations and an SBOM. For controlled environments, verify the release attestation before installing a downloaded artifact and retain the SBOM with your software inventory.
Environment Configuration
All configuration is done through environment variables. No config files are required for basic scanning.
LLM Analyzer and Meta-Analyzer
| Variable | Description |
|---|---|
SKILL_SCANNER_LLM_API_KEY | API key for the LLM provider |
SKILL_SCANNER_LLM_MODEL | Model as provider/model. Default: anthropic/claude-sonnet-5-5 |
SKILL_SCANNER_LLM_PROVIDER | Optional routing override, such as openai-compatible for gateways and local servers |
SKILL_SCANNER_LLM_BASE_URL | Base URL for an OpenAI-compatible endpoint |
SKILL_SCANNER_LLM_USER | Optional raw Chat Completions user field for OpenAI-compatible routes |
SKILL_SCANNER_LLM_TEMPERATURE | Optional temperature override. Use none to omit it. Models that reject temperature get none by default |
SKILL_SCANNER_ADJUDICATOR_LLM_MODEL | Optional model override for --adjudicate |
External Analyzers
| Variable | Description | Required for |
|---|---|---|
VIRUSTOTAL_API_KEY | VirusTotal API key | --use-virustotal |
AI_DEFENSE_API_KEY | Cisco AI Defense API key | --use-aidefense |
AI_DEFENSE_API_URL | Cisco AI Defense endpoint URL | --use-aidefense |
Quick Setup
# The LLM judge (every recommended setup uses it; see LLM Providers for local models)
export SKILL_SCANNER_LLM_API_KEY="your_api_key"
export SKILL_SCANNER_LLM_MODEL="anthropic/claude-sonnet-5-5"
# Optional: VirusTotal binary scanning
export VIRUSTOTAL_API_KEY="your_virustotal_api_key"
# Optional: Cisco AI Defense
export AI_DEFENSE_API_KEY="your_aidefense_api_key"
LLM Provider Setup
The LLM judge works with Anthropic (the default), OpenAI, AWS Bedrock, Google Vertex AI and Gemini, Azure OpenAI, any OpenAI-compatible gateway or local server, Ollama, and, experimentally, the on-device Apple Foundation Model.
| Provider | Model string | Extra |
|---|---|---|
| Anthropic | anthropic/claude-sonnet-5-5 | None |
| OpenAI | openai/<model> | None |
| AWS Bedrock | bedrock/us.anthropic.claude-sonnet-5-5 | [bedrock] |
| AWS Bedrock mantle | bedrock-mantle/google.gemma-4-26b-a4b | [bedrock] |
| Google Vertex AI | vertex_ai/<model> | [vertex] |
| Google AI Studio | gemini/<model> | [google] |
| Azure OpenAI | azure/<deployment> | [azure] |
| OpenAI-compatible gateway or vLLM | any name, with SKILL_SCANNER_LLM_PROVIDER=openai-compatible and SKILL_SCANNER_LLM_BASE_URL | None |
| Ollama | ollama/<model> | None |
| Apple Foundation Model (experimental) | apple-fm/system | pip install "apple-fm-sdk>=0.2.1,<0.3" |
See LLM Providers for credentials, the vLLM settings that keep JSON intact, and the measured model.
OSV.dev dependency scanning (--use-osv) needs network access but no API key or optional package.