Files
SkillSpector will run on changed files with the following names:SKILL.mdmcp.jsonmcp-config.jsonclaude_desktop_config.json.cursorrulescodex.yaml
Configuration
SkillSpector is enabled by default.- Using configuration file
- Using web interface
Security policy and restrictions
CodeRabbit runs SkillSpector inside the sandbox with LLM analysis disabled. It uses static analysis and does not make LLM or network calls. When multiple supported files change in the same directory, CodeRabbit may scan that directory once and attribute findings only to changed files.When we skip SkillSpector
CodeRabbit will skip running SkillSpector when:- SkillSpector is disabled in CodeRabbit settings or
.coderabbit.yaml. - No changed files match the supported file names.
- A candidate path is absolute or contains
..,|, a newline, or a null byte.
Profile behavior
SkillSpector uses the same rules in Chill and Assertive modes.Whatâs next
Tool catalog
Browse all linters, security analyzers, and CI/CD integrations by category and technology.
Tools reference
Explore detailed specifications and configuration options for CodeRabbit tools.