# SkillSpector | NVIDIA Corporation | Knowledge Base | Instagit

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks.

GitHub Stars: 3.2k

Repository: https://github.com/NVIDIA/SkillSpector

---

## Articles

### [How SkillSpector Handles LLM Authentication for Different Providers](/NVIDIA/SkillSpector/how-does-skillspector-handle-llm-authentication-for-different-providers)

Learn how SkillSpector handles LLM authentication for various providers. Discover credential resolution, discovery, and unified error handling for seamless integration.

- Tags: how-to-guide
- Published: 2026-07-13

### [How SkillSpector Integrates with OSV.dev for Vulnerability Lookup](/NVIDIA/SkillSpector/how-does-skillspector-integrate-with-osv-dev-for-vulnerability-lookup)

Discover how SkillSpector integrates with OSV.dev using its Python client to batch-query the OSV.dev API, cache results, and enrich dependency graphs with live vulnerability data.

- Tags: how-to-guide
- Published: 2026-07-13

### [How Taint Tracking Works in SkillSpector for Security Analysis](/NVIDIA/SkillSpector/how-does-taint-tracking-work-in-skillspector-for-security-analysis)

Explore how SkillSpector's static behavioral taint tracking analyzes Python code. Discover how it finds sensitive data sources, follows taint markers, and detects dangerous sink usage for robust security.

- Tags: how-to-guide
- Published: 2026-07-13

### [What Anti-Refusal Patterns Does SkillSpector Look For? A Complete Guide to AR1-AR3 Detection](/NVIDIA/SkillSpector/what-are-the-anti-refusal-patterns-skillspector-looks-for)

Discover the anti-refusal patterns AR1-AR3 that SkillSpector identifies. Learn how this tool uses regex to detect attempts to suppress model refusals and bypass safety policies.

- Tags: deep-dive
- Published: 2026-07-13

### [How to Configure SkillSpector to Use Local LLMs Like Ollama](/NVIDIA/SkillSpector/can-skillspector-use-local-llms-like-ollama)

Yes SkillSpector supports local LLMs like Ollama. Configure SkillSpector to use local LLMs by setting OPENAI_BASE_URL to your local server endpoint without code changes.

- Tags: how-to-guide
- Published: 2026-07-13

### [What LLM Providers Does NVIDIA SkillSpector Support? A Complete Guide](/NVIDIA/SkillSpector/what-types-of-llm-providers-does-skillspector-support)

Discover which LLM providers NVIDIA SkillSpector supports including OpenAI Anthropic and NVIDIA Build Learn how SkillSpector unifies credential resolution and model management for seamless integration.

- Tags: getting-started
- Published: 2026-07-13

### [How the LangGraph Workflow Orchestrates SkillSpector's Analysis Pipeline](/NVIDIA/SkillSpector/how-does-the-langgraph-workflow-orchestrate-skillspectors-analysis-pipeline)

Discover how the LangGraph workflow stages security analysis in SkillSpector, from input resolution to LLM meta-analysis, optimizing performance with parallel execution and immutable state.

- Tags: how-to-guide
- Published: 2026-07-13

### [How SkillSpector Handles Different Output Formats for Scan Results](/NVIDIA/SkillSpector/how-does-skillspector-handle-different-output-formats-for-scan-results)

SkillSpector expertly manages scan results across multiple formats. Learn how it supports terminal, JSON, Markdown, and SARIF outputs via the `--format` CLI flag for flexible reporting.

- Tags: how-to-guide
- Published: 2026-07-12

### [What Is the `graph.py` File in SkillSpector? DAG Orchestration and Pipeline Execution](/NVIDIA/SkillSpector/what-is-the-graph-py-file-in-skillspector-responsible-for)

Discover the graph.py file in SkillSpector. It orchestrates analysis nodes and executes pipelines, transforming input into SARIF reports using a DAG engine and topological sorting.

- Tags: internals
- Published: 2026-07-12

### [Which LLM Providers Does SkillSpector Support? A Complete Guide to OpenAI, Anthropic, and NVIDIA Build](/NVIDIA/SkillSpector/what-llm-providers-does-skillspector-support)

Discover which LLM providers SkillSpector supports. Explore integrations with OpenAI, Anthropic, and NVIDIA Build for seamless AI development.

- Tags: getting-started
- Published: 2026-07-12

### [Which AI Agent Frameworks Are Supported by SkillSpector?](/NVIDIA/SkillSpector/which-ai-agent-frameworks-are-supported-by-skillspector)

Discover which AI agent frameworks SkillSpector supports including Claude, Codex, Gemini, and Antigravity. Integrate seamlessly with these CLI based frameworks today.

- Tags: getting-started
- Published: 2026-07-12

### [MCP Least Privilege Detection in SkillSpector: Complete Technical Guide](/NVIDIA/SkillSpector/what-is-mcp-least-privilege-detection-in-skillspector)

Master MCP Least Privilege detection in SkillSpector. Learn how this static analysis tool audits Model Control Plane skills, flagging violations by comparing declared vs. actual permissions.

- Tags: deep-dive
- Published: 2026-07-12

### [How SkillSpector's Taint Tracking Works: A Deep Dive into the Behavioral Analyzer](/NVIDIA/SkillSpector/how-does-skillspector-taint-tracking-work)

Discover how SkillSpector's taint tracking uses static behavioral analysis and a seven-stage data-flow to map sensitive data from sources to dangerous sinks without code execution. Understand NVIDIASkillSpector's core functiona...

- Tags: deep-dive
- Published: 2026-07-12

### [The 68 Vulnerability Patterns Detected by SkillSpector: Complete Reference](/NVIDIA/SkillSpector/what-are-the-68-vulnerability-patterns-detected-by-skillspector)

Explore the 68 vulnerability patterns SkillSpector detects. Understand each rule ID for prompt injection, environment variable harvesting, and more from NVIDIA. Enhance your code security.

- Tags: api-reference
- Published: 2026-07-12

### [How to Register SkillSpector with Claude Code: A Complete MCP Setup Guide](/NVIDIA/SkillSpector/how-to-register-skillspector-with-claude-code)

Register SkillSpector with Claude Code for MCP setup. Install extras, launch the server, and execute the command to enable the scan_skill security guardrail. Follow this guide for a complete setup.

- Tags: how-to-guide
- Published: 2026-07-12

### [How to Run SkillSpector MCP Server with HTTP Transport: A Complete Guide](/NVIDIA/SkillSpector/how-to-run-skillspector-mcp-server-with-http-transport)

Master running the SkillSpector MCP server with HTTP transport. This guide details easy steps to expose the scan_skill tool for remote agent communication.

- Tags: how-to-guide
- Published: 2026-07-12

### [How to Install SkillSpector with the MCP Extra: A Complete Guide](/NVIDIA/SkillSpector/how-to-install-skillspector-with-mcp-extra)

Install SkillSpector with the MCP extra using uv tool install for agent integration. Get the complete installation guide for NVIDIA's SkillSpector and enable the Model Context Protocol server.

- Tags: how-to-guide
- Published: 2026-07-12

### [What Is the `scan_skill` Tool in NVIDIA SkillSpector’s MCP Integration?](/NVIDIA/SkillSpector/what-is-the-scan-skill-tool-in-skillspector-mcp-integration)

Discover the `scan_skill` tool in NVIDIA SkillSpector, the core MCP endpoint for AI agents to perform secure code scans with customizable parameters like target path and LLM usage.

- Tags: how-to-guide
- Published: 2026-07-12

### [How to Use SkillSpector as an MCP Server: Complete Setup Guide](/NVIDIA/SkillSpector/how-to-use-skillspector-as-an-mcp-server)

Learn to run SkillSpector as an MCP server. This guide shows how to install the mcp extra and use the skillspector mcp command to expose the scan_skill tool for AI agents.

- Tags: how-to-guide
- Published: 2026-07-12

### [LLM Semantic Analysis in SkillSpector: How AI Detects Security Issues Beyond Static Code](/NVIDIA/SkillSpector/what-is-llm-semantic-analysis-in-skillspector)

Discover how LLM semantic analysis in NVIDIA SkillSpector uncovers security risks like prompt injection and intent mismatches that static code analysis misses. Enhance your security.

- Tags: deep-dive
- Published: 2026-07-12

### [How SkillSpector Integrates with OSV.dev for Vulnerability Lookups](/NVIDIA/SkillSpector/how-does-skillspector-integrate-with-osv-dev)

Learn how SkillSpector integrates with OSV.dev for fast vulnerability lookups. Discover security issues in dependency files with efficient batch HTTP requests and caching.

- Tags: how-to-guide
- Published: 2026-07-12

### [How SkillSpector Performs AST-Based Behavioral Analysis on Python Code](/NVIDIA/SkillSpector/how-does-skillspector-perform-ast-based-behavioral-analysis)

Discover how SkillSpector uses AST-based behavioral analysis on Python code. Learn how it detects dangerous patterns like exec() and eval() for enhanced security.

- Tags: how-to-guide
- Published: 2026-07-12

### [What Supply Chain Vulnerabilities Does SkillSpector Detect? Complete Guide to SC1-SC6 and TR1-TR3](/NVIDIA/SkillSpector/what-types-of-supply-chain-vulnerabilities-does-skillspector-find)

SkillSpector finds nine supply chain vulnerabilities including unpinned dependencies, typosquatting, obfuscated code & CVEs. Learn about SC1-SC6 and TR1-TR3.

- Tags: deep-dive
- Published: 2026-07-12

### [How SkillSpector Detects Prompt Injection Vulnerabilities in SKILL.md Files](/NVIDIA/SkillSpector/how-does-skillspector-detect-prompt-injection-vulnerabilities)

Learn how SkillSpector detects prompt injection vulnerabilities in SKILL.md files. Our tool uses regex pattern matching to identify dangerous construct families like instruction overrides and data exfiltration.

- Tags: how-to-guide
- Published: 2026-07-12

### [SkillSpector Environment Variables: Complete Configuration Guide](/NVIDIA/SkillSpector/what-environment-variables-are-needed-for-skillspector)

Master SkillSpector environment variables. Configure LLM providers, API keys, and runtime settings for optimal performance. Essential guide for NVIDIA/SkillSpector users.

- Tags: how-to-guide
- Published: 2026-07-12

### [How to Configure LLM Providers for SkillSpector: A Complete Guide](/NVIDIA/SkillSpector/how-to-configure-llm-providers-for-skillspector)

Configure LLM providers for SkillSpector with this comprehensive guide. Learn how to leverage environment variables or force specific providers for seamless integration.

- Tags: how-to-guide
- Published: 2026-07-12

### [How SkillSpector's Two-Stage Detection Pipeline Works: Static Analysis + LLM Validation](/NVIDIA/SkillSpector/how-does-skillspector-two-stage-detection-pipeline-work)

Discover how SkillSpector's two-stage pipeline uses static analysis and LLM validation to accurately detect vulnerabilities, reduce false positives, and provide remediation.

- Tags: internals
- Published: 2026-07-12

### [What Are the Main Components of SkillSpector? A Complete Technical Breakdown](/NVIDIA/SkillSpector/what-are-the-main-components-of-skillspector)

Explore SkillSpector's core components: multi-format input parser, two-stage analysis engine with LLM, risk scoring, and more. Understand the technical breakdown of NVIDIA/SkillSpector.

- Tags: deep-dive
- Published: 2026-07-12

### [How to Contribute to SkillSpector: A Developer's Guide to NVIDIA's LangGraph Security Scanner](/NVIDIA/SkillSpector/how-can-i-contribute-to-the-development-of-skillspector)

Contribute to SkillSpector a powerful NVIDIA LangGraph security scanner. Clone the repo install dev dependencies extend the scanning pipeline by adding new analyzer modules.

- Tags: how-to-guide
- Published: 2026-07-11

### [Where to Find the LangGraph Workflow in SkillSpector: Complete Guide](/NVIDIA/SkillSpector/where-can-i-find-the-definition-of-the-langgraph-workflow-in-skillspector)

Locate the LangGraph workflow in SkillSpector within src/skillspector/graph.py. This guide details its integration with analyzer, resolver, and reporter components.

- Tags: how-to-guide
- Published: 2026-07-11

### [Does SkillSpector Execute Scanned AI Agent Skills? A Deep Dive into the Static Analysis Architecture](/NVIDIA/SkillSpector/does-skillspector-execute-scanned-ai-agent-skills)

SkillSpector analyzes AI agent skills through static analysis not execution. Discover its regex AST and LLM text analysis architecture without running code.

- Tags: deep-dive
- Published: 2026-07-11

### [SkillSpector Content Analysis Limitations: 8 Constraints Every Developer Should Know](/NVIDIA/SkillSpector/what-are-the-limitations-of-skillspector-in-terms-of-content-analysis)

Explore SkillSpector limitations in content analysis. Discover 8 key constraints developers must know. Understand what SkillSpector cannot analyze for secure development.

- Tags: deep-dive
- Published: 2026-07-11

### [SkillSpector Scan Exit Codes Explained: A Complete Reference for NVIDIA's CLI](/NVIDIA/SkillSpector/what-are-the-exit-codes-for-skillspector-scans-and-what-do-they-mean)

Understand NVIDIA SkillSpector CLI exit codes 0 1 and 2 for successful scans high risk detections and execution failures. Optimize your CI/CD automation with this complete reference.

- Tags: api-reference
- Published: 2026-07-11

### [How to Get SkillSpector Output in JSON or SARIF Format](/NVIDIA/SkillSpector/how-to-get-skillspector-output-in-json-or-sarif-format)

Learn how to get SkillSpector output in JSON or SARIF format using the --format flag with skillspector scan. Easily direct output to files.

- Tags: how-to-guide
- Published: 2026-07-11

### [SkillSpector Output Formats: JSON, Markdown, SARIF, and Terminal Explained](/NVIDIA/SkillSpector/what-are-the-different-output-formats-supported-by-skillspector)

Explore SkillSpector output formats: JSON, Markdown, SARIF, and Terminal. Understand how to use the `--format` flag and `output_format` parameter to customize your results.

- Tags: api-reference
- Published: 2026-07-11

### [How the SC4 Module in SkillSpector Performs Live Vulnerability Lookups](/NVIDIA/SkillSpector/how-does-the-sc4-module-in-skillspector-perform-live-vulnerability-lookups)

Discover how the SkillSpector SC4 module ensures live vulnerability lookups using the OSV.dev API, CVSS scoring, and offline fallbacks for secure environments.

- Tags: internals
- Published: 2026-07-11

### [How to Integrate SkillSpector into a Python Project Programmatically](/NVIDIA/SkillSpector/how-to-integrate-skillspector-into-a-python-project-programmatically)

Integrate SkillSpector into your Python project programmatically. Import the graph, create a state dictionary, and invoke the analysis pipeline for seamless security scanning without the CLI.

- Tags: how-to-guide
- Published: 2026-07-11

### [How to Secure the SkillSpector MCP Server When Using HTTP Transport](/NVIDIA/SkillSpector/how-to-secure-the-skillspector-mcp-server-when-using-http-transport)

Secure your NVIDIA SkillSpector MCP server with TLS encryption and token authentication. Learn to configure certfile, keyfile and host for enhanced security in HTTP transport.

- Tags: how-to-guide
- Published: 2026-07-11

### [SkillSpector MCP Server Transport Options: stdio vs HTTP Configuration](/NVIDIA/SkillSpector/what-are-the-different-transport-options-for-the-skillspector-mcp-server)

Explore SkillSpector MCP server transport options: stdio for local communication and http for remote access. Understand configuration for NVIDIA SkillSpector.

- Tags: how-to-guide
- Published: 2026-07-11

### [How to Install and Run SkillSpector as an MCP Server](/NVIDIA/SkillSpector/how-to-install-and-run-skillspector-as-an-mcp-server)

Install and run SkillSpector as an MCP server. SkillSpector security scanning pipeline enables MCP agents to evaluate skills before installation via stdio or HTTP transport.

- Tags: how-to-guide
- Published: 2026-07-11

### [What Glob Rules Are Supported for Baseline Suppression in SkillSpector](/NVIDIA/SkillSpector/what-glob-rules-are-supported-for-baseline-suppression-in-skillspector)

Discover the glob rules supported for baseline suppression in SkillSpector. SkillSpector uses standard Unix glob patterns with case-insensitive fnmatch evaluation for effective suppression.

- Tags: api-reference
- Published: 2026-07-11

### [How to Use the SkillSpector Baseline Feature to Suppress Known Findings](/NVIDIA/SkillSpector/how-to-use-the-baseline-feature-in-skillspector-to-suppress-known-findings)

Learn how to use the SkillSpector baseline feature to suppress known findings. Generate a baseline file and filter out accepted issues with ongoing scans.

- Tags: how-to-guide
- Published: 2026-07-11

### [How to Scan a Directory with Multiple AI Agent Skills Using SkillSpector](/NVIDIA/SkillSpector/how-to-scan-a-directory-with-multiple-ai-agent-skills-using-skillspector)

Learn how to scan directories with multiple AI agent skills using SkillSpector and its recursive flag. Automatically detect and audit individual skills for robust security analysis.

- Tags: how-to-guide
- Published: 2026-07-11

### [How to Configure Authentication for Different LLM Providers in SkillSpector](/NVIDIA/SkillSpector/how-to-configure-authentication-for-different-llm-providers-in-skillspector)

Configure authentication for various LLM providers in SkillSpector. Learn how to set up API keys and base URLs using environment variables for seamless integration.

- Tags: how-to-guide
- Published: 2026-07-11

### [Which LLM Providers Does SkillSpector Support for Semantic Analysis?](/NVIDIA/SkillSpector/which-llm-providers-does-skillspector-support-for-semantic-analysis)

Discover which LLM providers SkillSpector supports for semantic analysis including OpenAI Anthropic NVIDIA Build and more Learn how to easily select your provider via the SKILLSPECTOR_PROVIDER environment variable

- Tags: api-reference
- Published: 2026-07-11

### [SkillSpector Severity Levels and Risk Score Ranges Explained](/NVIDIA/SkillSpector/what-are-the-different-severity-levels-and-their-corresponding-risk-score-ranges)

Understand SkillSpector severity levels and risk score ranges including LOW MEDIUM HIGH and CRITICAL with clear thresholds for pass fail statuses.

- Tags: api-reference
- Published: 2026-07-11

### [How SkillSpector Calculates Risk Scores: Algorithm and Implementation](/NVIDIA/SkillSpector/how-is-the-risk-score-calculated-in-skillspector)

Learn how SkillSpector calculates risk scores using its algorithm. Understand severity points, multipliers, and clamping for accurate vulnerability assessment.

- Tags: deep-dive
- Published: 2026-07-11

### [What Types of Vulnerability Patterns Does SkillSpector Identify? A Technical Guide](/NVIDIA/SkillSpector/what-types-of-vulnerability-patterns-does-skillspector-identify)

SkillSpector identifies 10 vulnerability patterns like privilege escalation, SSRF, prompt injection, and supply chain risks using regex-based static analysis. Learn more.

- Tags: deep-dive
- Published: 2026-07-11

### [How NVIDIA SkillSpector Implements Security Scanning with LangGraph: A Workflow Deep Dive](/NVIDIA/SkillSpector/how-is-the-skillspector-workflow-implemented-using-langgraph)

Discover how NVIDIA SkillSpector uses LangGraph to orchestrate its security scanning workflow. Explore the mutable state and parallel execution of analyzers within this deep dive.

- Tags: deep-dive
- Published: 2026-07-11

### [SkillSpector Architecture Explained: Inside NVIDIA’s LangGraph Security Pipeline](/NVIDIA/SkillSpector/what-are-the-main-components-of-the-skillspector-architecture)

Explore the SkillSpector architecture, a deterministic LangGraph pipeline by NVIDIA that orchestrates security analyzers and LLM meta-analysis for efficient skill processing from input to SARIF reporting.

- Tags: architecture
- Published: 2026-07-11

### [How SkillSpector Detects Vulnerabilities in AI Agent Skills: A Three-Stage Pipeline](/NVIDIA/SkillSpector/how-does-skillspector-detect-vulnerabilities-in-ai-agent-skills)

Discover how SkillSpector detects vulnerabilities in AI agent skills using a three-stage pipeline combining static analysis and LLM meta-analysis for actionable insights.

- Tags: deep-dive
- Published: 2026-07-11

### [Can SkillSpector Provide Code Refactoring Suggestions? A Deep Dive into NVIDIA's Security Scanner](/NVIDIA/SkillSpector/can-skillspector-be-used-for-code-refactoring-suggestions)

Discover if SkillSpector offers code refactoring suggestions. Explore NVIDIA's security scanner capabilities and its limitations for AI-agent code analysis.

- Tags: deep-dive
- Published: 2026-07-10

### [Understanding the Performance Implications of Using SkillSpector](/NVIDIA/SkillSpector/what-are-the-performance-implications-of-using-skillspector)

Discover SkillSpector performance implications. Static scans complete in seconds, LLM analysis adds minimal latency. Optimize your NVIDIA/SkillSpector workflow.

- Tags: performance
- Published: 2026-07-10

### [How SkillSpector Handles Large Codebases: Chunking and Token Management Strategy](/NVIDIA/SkillSpector/how-does-skillspector-handle-large-codebases)

SkillSpector processes large codebases by chunking files and managing tokens effectively. Discover its strategy for handling extensive repositories without exceeding model limits.

- Tags: internals
- Published: 2026-07-10

### [Does SkillSpector Support Remote Repositories? Git URL Scanning Guide](/NVIDIA/SkillSpector/does-skillspector-support-remote-repositories)

SkillSpector supports remote Git repositories by automatically cloning and scanning URLs without altering your local files. Discover how Git URL scanning works.

- Tags: how-to-guide
- Published: 2026-07-10

### [How to Contribute to SkillSpector Development: A Complete Guide](/NVIDIA/SkillSpector/how-to-contribute-to-skillspector-development)

Contribute to SkillSpector development by cloning the NVIDIA repository, installing dev dependencies, and adding new analyzers to the LangGraph security pipeline. Follow our guide to contribute now.

- Tags: how-to-guide
- Published: 2026-07-10

### [Where to Find SkillSpector Documentation: A Complete Guide to NVIDIA's AI Security Scanner](/NVIDIA/SkillSpector/where-can-i-find-the-skillspector-documentation)

Find SkillSpector documentation easily in the NVIDIA/SkillSpector repository. Access quick-start guides, development info, suppression rules, and LLM analysis within the docs directory.

- Tags: getting-started
- Published: 2026-07-10

### [Is SkillSpector Open Source? License, Architecture, and Code Examples](/NVIDIA/SkillSpector/is-skillspector-open-source)

Discover if SkillSpector is open source. Explore its Apache 2.0 license, architecture, and code examples in the NVIDIA/SkillSpector repository. Contribute today.

- Tags: getting-started
- Published: 2026-07-10

### [How to Integrate SkillSpector into a CI/CD Pipeline for Automated Security Scanning](/NVIDIA/SkillSpector/how-to-integrate-skillspector-into-a-ci-cd-pipeline)

Automate security scanning with SkillSpector in your CI/CD pipeline. Learn how to integrate SkillSpector for powerful, automated code analysis and vulnerability detection.

- Tags: how-to-guide
- Published: 2026-07-10

### [How to Install SkillSpector: CLI, Source, and Docker Setup Guide](/NVIDIA/SkillSpector/how-to-install-skillspector)

Install SkillSpector easily with our guide covering CLI, source, and Docker setups. Choose the best method for your needs and get started quickly with this powerful tool.

- Tags: getting-started
- Published: 2026-07-10

### [SkillSpector Main Features: AI-Agent Security Scanner by NVIDIA](/NVIDIA/SkillSpector/what-are-the-main-features-of-skillspector)

Discover SkillSpector's main features an AI-agent security scanner by NVIDIA. Find 68 vulnerability patterns with static and LLM analysis before installation.

- Tags: deep-dive
- Published: 2026-07-10

### [What Programming Languages Does SkillSpector Support?](/NVIDIA/SkillSpector/what-programming-languages-does-skillspector-support)

Discover the programming languages SkillSpector supports, including Python for its core engine and TypeScript for its agent extension. Analyze code effectively.

- Tags: getting-started
- Published: 2026-07-10

### [How Does SkillSpector Analyze Code? Inside NVIDIA's LangGraph Security Pipeline](/NVIDIA/SkillSpector/how-does-skillspector-analyze-code)

Discover how SkillSpector analyzes code via a LangGraph pipeline. Learn about its six stages, from input resolution to SARIF reporting, for robust security findings.

- Tags: deep-dive
- Published: 2026-07-10

### [How to Run SkillSpector in Offline or Air-Gapped Environments: Complete Guide](/NVIDIA/SkillSpector/how-to-run-skillspector-offline-air-gapped-environments)

Learn how to run SkillSpector in offline or air-gapped environments. Discover automatic fallback to static lists and LLM analysis disabling for secure, network-free vulnerability scanning.

- Tags: how-to-guide
- Published: 2026-07-09

### [MCP Tool Poisoning Detection Patterns in NVIDIA SkillSpector: A Complete Guide to TP1-TP4](/NVIDIA/SkillSpector/what-are-mcp-tool-poisoning-detection-patterns-skillspector)

Explore MCP tool poisoning detection patterns TP1-TP4 in NVIDIA SkillSpector. Learn to identify hidden instructions, Unicode deception, parameter injection, and LLM mismatches in AI skill manifests.

- Tags: deep-dive
- Published: 2026-07-09

### [How to Configure Baseline Glob Rules for Drift-Tolerant Suppression in SkillSpector](/NVIDIA/SkillSpector/how-to-configure-baseline-glob-rules-drift-tolerant-suppression-skillspector)

Learn to configure baseline glob rules in NVIDIA SkillSpector for drift-tolerant suppression. This enables durable false-positive filtering across code edits without manual updates.

- Tags: how-to-guide
- Published: 2026-07-09

### [Comparing Accuracy Between Static‑Only and Full LLM Analysis in SkillSpector](/NVIDIA/SkillSpector/comparing-accuracy-between-static-only-full-llm-analysis-skillspector)

Compare static-only versus full LLM analysis in NVIDIA SkillSpector. Understand accuracy trade-offs for precise detections versus context-aware reasoning.

- Tags: performance
- Published: 2026-07-09

### [How Taint Tracking Detects Data Exfiltration Paths in SkillSpector](/NVIDIA/SkillSpector/how-does-taint-tracking-detect-data-exfiltration-paths-skillspector)

SkillSpector's taint tracking analyzes Python ASTs to find data exfiltration paths. It identifies flows from sensitive data to dangerous sinks, flagging explicit and implicit paths with rule IDs.

- Tags: deep-dive
- Published: 2026-07-09

### [How to Handle Large Multi-Skill Repositories with SkillSpector: Complete Detection and Processing Guide](/NVIDIA/SkillSpector/how-to-handle-large-multi-skill-repositories-skillspector)

Learn how to handle large multi-skill repositories with SkillSpector. Detect individual skills in sub-directories and process them through isolated LangGraph workflows for efficient analysis.

- Tags: how-to-guide
- Published: 2026-07-09

### [Security Considerations and Trust Model for SkillSpector Scans](/NVIDIA/SkillSpector/security-considerations-trust-model-skillspector-scans)

Explore SkillSpector security considerations and trust model. Learn how SkillSpector defends against attacks with network gating, static analysis, and runtime isolation for secure scans.

- Tags: deep-dive
- Published: 2026-07-09

### [How to Use SkillSpector as a Python Library or API](/NVIDIA/SkillSpector/how-to-use-skillspector-as-python-library-api)

Learn to use SkillSpector as a Python library or API for AI skill security analysis. Invoke the LangGraph workflow programmatically for static and LLM-powered security checks. Avoid the CLI.

- Tags: how-to-guide
- Published: 2026-07-09

### [Understanding Model Slots and Per-Analyzer Configuration in NVIDIA SkillSpector](/NVIDIA/SkillSpector/what-are-model-slots-per-analyzer-model-configuration-managed-skillspector)

Learn how to use SkillSpector model slots to map analyzers to LLM models. Centralized configuration via environment variables and provider defaults simplifies per-analyzer model management.

- Tags: deep-dive
- Published: 2026-07-09

### [How to Debug LLM Analysis Failures and Provider Issues in SkillSpector: A Complete Guide](/NVIDIA/SkillSpector/how-to-debug-llm-analysis-failures-provider-issues-skillspector)

Debug LLM analysis failures and provider issues in SkillSpector. Set log level to DEBUG and validate registry entries/credentials to fix empty findings or timeouts.

- Tags: how-to-guide
- Published: 2026-07-09

### [How OSV.dev Integration Queries Work for CVE Lookups in SkillSpector](/NVIDIA/SkillSpector/how-do-osv-dev-integration-queries-work-cve-lookups-skillspector)

Discover how SkillSpector integrates with OSV.dev for fast CVE lookups using in-memory caching and fallback databases to ensure real-time vulnerability scanning.

- Tags: how-to-guide
- Published: 2026-07-09

### [SkillSpector Output Formats: JSON, SARIF, Markdown, and Terminal Reports](/NVIDIA/SkillSpector/supported-output-formats-skillspector-json-sarif-markdown-terminal)

Explore SkillSpector's output formats: JSON, SARIF, Markdown, and terminal. Learn how to configure your reports using the CLI flag or state key for efficient analysis. Get started now.

- Tags: api-reference
- Published: 2026-07-09

### [How to Scan Multi-Skill Directories with the --recursive Flag in SkillSpector](/NVIDIA/SkillSpector/how-to-scan-multi-skill-directories-recursive-flag-skillspector)

Learn how to scan multi-skill directories using the --recursive flag in SkillSpector. This feature automates batch scanning of multiple skills, detecting sub-directories and running analysis pipelines efficiently.

- Tags: how-to-guide
- Published: 2026-07-09

### [How to Add Custom YARA Rules for Specific Threat Detection in SkillSpector](/NVIDIA/SkillSpector/how-to-add-custom-yara-rules-specific-threat-detection-skillspector)

Learn to add custom YARA rules to NVIDIA SkillSpector for precise threat detection. Enhance your security analysis by integrating your own signatures using the --yara-rules-dir flag.

- Tags: how-to-guide
- Published: 2026-07-09

### [Complete List of 68 SkillSpector Vulnerability Patterns and Severity Levels](/NVIDIA/SkillSpector/complete-list-of-68-vulnerability-patterns-severity-levels-skillspector)

Explore the comprehensive list of 68 SkillSpector vulnerability patterns and their severity levels. Understand AI security risks from Prompt Injection to Supply Chain threats. Learn more today!

- Tags: api-reference
- Published: 2026-07-09

### [How to Run and Configure the MCP Server for Agent Integration with SkillSpector](/NVIDIA/SkillSpector/how-to-run-and-configure-mcp-server-for-agent-integration-skillspector)

Learn how to run and configure the MCP server for agent integration with NVIDIA SkillSpector. Expose the scan_skill tool for security scans via stdio or HTTP.

- Tags: how-to-guide
- Published: 2026-07-09

### [How to Integrate SkillSpector into CI/CD Pipelines Using Exit Codes](/NVIDIA/SkillSpector/how-to-integrate-skillspector-into-ci-cd-pipelines-using-exit-codes)

Integrate SkillSpector into CI CD pipelines with exit codes. Automate AI agent skill package gating using risk scores and machine readable JSON output for seamless deployment.

- Tags: how-to-guide
- Published: 2026-07-09

### [SkillSpector Risk Score Algorithm: How It Calculates Security Risk](/NVIDIA/SkillSpector/what-is-algorithm-for-calculating-skillspectors-risk-score)

Understand the SkillSpector risk score algorithm. Learn how finding severities, script multipliers, and clamping create security risk scores from 0-100 for better recommendations.

- Tags: architecture
- Published: 2026-07-09

### [How to Configure Custom LLM Providers in SkillSpector: A Complete Guide](/NVIDIA/SkillSpector/how-to-configure-custom-llm-providers-skillspector-beyond-default-options)

Learn how to configure custom LLM providers in SkillSpector. This guide shows you how to extend SkillSpector beyond default options with your own backends. Get the complete setup instructions now.

- Tags: how-to-guide
- Published: 2026-07-09

### [How SkillSpector's Two-Stage Static + LLM Analysis Pipeline Works](/NVIDIA/SkillSpector/how-does-skillspector-two-stage-analysis-pipeline-work-static-llm)

Discover how SkillSpector's two-stage analysis pipeline combines static analyzers and LLMs to refine agent skills, filter false positives, and deliver secure structured assessments.

- Tags: internals
- Published: 2026-07-09

### [SkillSpector Anti-Jailbreak Protection: How NVIDIA Prevents Malicious LLM Prompt Manipulation](/NVIDIA/SkillSpector/how-does-skillspector-anti-jailbreak-protection-prevent-malicious-llm-prompt-manipulation)

Discover how SkillSpector's anti-jailbreak protection tackles malicious LLM prompt manipulation. Learn about NVIDIA's dual-layer defense combining regex, YARA, and system prompt guardrails. Protect your LLMs effectively.

- Tags: how-to-guide
- Published: 2026-07-08

### [How to Invoke SkillSpector's LangGraph Workflow Programmatically Using the Python API](/NVIDIA/SkillSpector/how-to-use-python-api-to-invoke-skillspector-langgraph-workflow-programmatically)

Learn to programmatically invoke SkillSpector's LangGraph workflow using the Python API. Import the graph object, create a state dictionary, and execute synchronously or asynchronously.

- Tags: how-to-guide
- Published: 2026-07-08

### [SkillSpector MCP Least Privilege Analysis: Detecting Permission Issues in AI Skills](/NVIDIA/SkillSpector/what-is-skillspector-mcp-least-privilege-analysis-for-detecting-permission-issues)

SkillSpector's MCP least privilege analysis finds AI skill permission issues by comparing declared permissions against actual code capabilities. Ensure exact permission boundaries.

- Tags: deep-dive
- Published: 2026-07-08

### [How to Configure Different LLM Providers Like OpenAI, Anthropic, and Bedrock in SkillSpector](/NVIDIA/SkillSpector/how-to-configure-different-llm-providers-like-openai-anthropic-and-bedrock-in-skillspector)

Easily configure OpenAI, Anthropic, or Bedrock LLM providers in SkillSpector. Set the SKILLSPECTOR_PROVIDER environment variable and credentials to start using your preferred backend seamlessly.

- Tags: how-to-guide
- Published: 2026-07-08

### [What Data Does SkillSpector Send to LLM Providers and OSV.dev During Analysis?](/NVIDIA/SkillSpector/what-data-does-skillspector-send-to-llm-providers-and-osvdev-during-analysis)

Learn what data SkillSpector sends to LLM providers and OSV.dev during analysis. Discover the limited dependency identifiers and code snippets shared, ensuring your secrets remain private.

- Tags: internals
- Published: 2026-07-08

### [What Is MCP Tool Poisoning and How Does SkillSpector Detect Hidden Instructions?](/NVIDIA/SkillSpector/what-is-mcp-tool-poisoning-and-how-does-skillspector-detect-hidden-instructions-in-tool-metadata)

Discover MCP tool poisoning, a supply chain attack, and learn how SkillSpector detects hidden instructions through multi-stage analysis for enhanced security.

- Tags: deep-dive
- Published: 2026-07-08

### [How to Add Custom YARA Rules to SkillSpector for Malware and Hack-Tool Detection](/NVIDIA/SkillSpector/how-to-add-custom-yara-rules-to-skillspector-for-malware-and-hack-tool-detection)

Learn to add custom YARA rules to NVIDIA SkillSpector to enhance malware and hack tool detection. Effortlessly integrate your rules for improved static analysis.

- Tags: how-to-guide
- Published: 2026-07-08

### [How SkillSpector Taint Tracking Analyzes Data Flows from Sources to Sinks](/NVIDIA/SkillSpector/how-does-skillspector-taint-tracking-analyze-data-flows-from-sources-to-sinks)

Discover how SkillSpector's taint tracking analyzes Python data flows from sources to sinks. Learn how it traces credentials, inputs, and sensitive data to detect security risks. Explore TT1-TT5 findings.

- Tags: deep-dive
- Published: 2026-07-08

### [How OSV.dev Live Vulnerability Lookup Handles Offline Fallbacks in NVIDIA SkillSpector](/NVIDIA/SkillSpector/how-does-osvdev-live-vulnerability-lookup-handle-offline-fallback-scenarios-in-skillspector)

Learn how SkillSpector's OSV.dev integration ensures continuous SC4 scanning via offline fallbacks to a static vulnerability database, even in air-gapped environments.

- Tags: internals
- Published: 2026-07-08

### [How to Integrate SkillSpector into CI/CD Pipelines with Exit Codes and JSON Output](/NVIDIA/SkillSpector/how-to-integrate-skillspector-into-ci-cd-pipeline-with-exit-codes-and-json-output)

Integrate SkillSpector into CI/CD pipelines using exit codes and JSON output. Automate security checks for AI agent skill packages and improve your workflow.

- Tags: how-to-guide
- Published: 2026-07-08

### [Understanding the SkillSpector Two-Stage Analysis Pipeline: Static Pattern Matching and LLM Semantic Evaluation](/NVIDIA/SkillSpector/what-is-skillspector-two-stage-analysis-pipeline-combining-static-pattern-matching-and-llm-semantic-evaluation)

Explore the SkillSpector two-stage analysis pipeline. Experience static pattern matching and LLM semantic evaluation for robust agent skill assessment and issue validation.

- Tags: deep-dive
- Published: 2026-07-08

### [How SkillSpector Handles Recursive Directory Scanning for Skill Collections](/NVIDIA/SkillSpector/how-skillspector-handles-recursive-directory-scanning)

Discover how SkillSpector uses recursive directory scanning to find skills. Learn about its LangGraph workflow and CLI flag for efficient skill collection.

- Tags: internals
- Published: 2026-07-07

### [How Multi-Skill Directories Are Detected and Scanned Independently in SkillSpector](/NVIDIA/SkillSpector/how-multi-skill-directories-are-detected-and-scanned)

Learn how SkillSpector detects and scans multi-skill directories independently. Discover the process within the NVIDIA SkillSpector codebase for efficient skill analysis.

- Tags: deep-dive
- Published: 2026-07-07

### [How to Add a Custom LLM Provider to SkillSpector's Provider Registry](/NVIDIA/SkillSpector/how-to-add-custom-llm-provider)

Learn how to add a custom LLM provider to SkillSpector's provider registry. Follow step-by-step instructions for seamless integration and extended functionality. Enhance your SkillSpector experience today.

- Tags: how-to-guide
- Published: 2026-07-07

### [How SkillSpector Integrates with OSV.dev to Query Vulnerable Dependencies](/NVIDIA/SkillSpector/how-osv-dev-integration-queries-vulnerable-dependencies)

Discover how SkillSpector integrates with OSV.dev to query vulnerable dependencies via batched API requests, caching, and fallback lists for robust security.

- Tags: how-to-guide
- Published: 2026-07-07

### [How SkillSpector Tracks Taint Flow from Sources to Sinks in Python Skill Code](/NVIDIA/SkillSpector/how-taint-tracking-flows-data-sources-to-sinks)

SkillSpector parses Python skill code to track taint flow from sources to sinks. Learn how it identifies security vulnerabilities using AST analysis and rule-based findings.

- Tags: internals
- Published: 2026-07-07

### [How Behavioral AST Analysis Identifies Dangerous Code Execution Patterns in SkillSpector](/NVIDIA/SkillSpector/how-behavioral-ast-analysis-identifies-dangerous-code)

SkillSpector's behavioral AST analysis pinpoints dangerous Python code by identifying risky function calls, dynamic imports, and nested execution chains. Learn how it secures your code.

- Tags: deep-dive
- Published: 2026-07-07

### [How to Manage False Positives with SkillSpector Baseline Suppression: A Team Guide](/NVIDIA/SkillSpector/how-baseline-suppression-works-and-manage-false-positives)

Learn how to manage false positives with SkillSpector baseline suppression. Filter CI scan noise using YAML rules and SHA-256 fingerprints for cleaner, shared repositories.

- Tags: how-to-guide
- Published: 2026-07-07

### [How to Configure Custom YARA Rules for Threat Detection in SkillSpector](/NVIDIA/SkillSpector/how-to-configure-custom-yara-rules)

Learn how to configure custom YARA rules in NVIDIA SkillSpector using the --yara-rules-dir flag to enhance threat detection with your own signatures for improved security.

- Tags: how-to-guide
- Published: 2026-07-07

### [SkillSpector Static Analysis Limitations: 7 Critical Constraints Explained](/NVIDIA/SkillSpector/skillspector-static-analysis-limitations)

Discover SkillSpector static analysis limitations including runtime-generated threats and non-English content. Understand critical constraints for effective security.

- Tags: deep-dive
- Published: 2026-06-25

### [How SkillSpector's Anti-Jailbreak Protection Works for LLM Prompts](/NVIDIA/SkillSpector/skillspector-anti-jailbreak-protection-llm-prompts)

Discover how SkillSpector shields LLM prompts from jailbreaks. Learn about its innovative approach using embedded instructions and pre-scanning to block malicious attempts.

- Tags: deep-dive
- Published: 2026-06-25

### [SkillSpector Output Formats: JSON vs SARIF vs Markdown vs Terminal](/NVIDIA/SkillSpector/skillspector-output-formats-use-cases-json-sarif)

Explore SkillSpector output formats: JSON, SARIF, Markdown, & Terminal. Understand each format's use case to streamline your security scanning and reporting workflows.

- Tags: deep-dive
- Published: 2026-06-25

### [How to Run SkillSpector in Docker with API Keys: A Complete Setup Guide](/NVIDIA/SkillSpector/run-skillspector-docker-api-keys)

Learn to run SkillSpector in Docker with API keys. This guide details building the image, mounting directories, and setting LLM credentials for a seamless setup of NVIDIA SkillSpector.

- Tags: how-to-guide
- Published: 2026-06-25

### [SkillSpector Input Types for Scanning: Git, ZIP, URLs, and Local Files Explained](/NVIDIA/SkillSpector/skillspector-supported-input-types-scanning)

Explore SkillSpector input types: Git, ZIP, URLs, and local files. Learn how NVIDIA/SkillSpector normalizes diverse inputs for effective code scanning.

- Tags: how-to-guide
- Published: 2026-06-25

### [How SkillSpector Handles Multiple SKILL.md Files for Multi-Skill Detection](/NVIDIA/SkillSpector/skillspector-multi-skill-detection-multiple-skill-md-files)

Learn how SkillSpector handles multiple SKILL.md files for multi-skill detection by scanning subdirectories and identifying independent skill manifests.

- Tags: internals
- Published: 2026-06-25

### [How to Invoke SkillSpector Programmatically Using the Python API](/NVIDIA/SkillSpector/invoke-skillspector-programmatically-python-api)

Learn how to invoke SkillSpector programmatically using Python API. Import the graph object and call invoke with your SkillspectorState for seamless integration.

- Tags: how-to-guide
- Published: 2026-06-25

### [How to Use Custom YARA Rules with SkillSpector CLI: A Complete Guide](/NVIDIA/SkillSpector/use-custom-yara-rules-skillspector-cli)

Learn to use custom YARA rules with SkillSpector CLI. Enhance security scanning by pointing to your rule directory with the yara rules dir flag, without altering the core repository. Maximize your security insights.

- Tags: how-to-guide
- Published: 2026-06-25

### [SkillSpector YARA Signature Rules for Malware Detection: A Complete Guide](/NVIDIA/SkillSpector/skillspector-yara-signature-rules-malware-detection)

Explore SkillSpector YARA signature rules for robust malware detection. Understand how this NVIDIA tool identifies reverse shells, ransomware, cryptominers, and more.

- Tags: how-to-guide
- Published: 2026-06-25

### [MCP Tool Poisoning Patterns Detected by NVIDIA SkillSpector: TP1-TP4 Analysis](/NVIDIA/SkillSpector/mcp-tool-poisoning-patterns-skillspector)

NVIDIA SkillSpector identifies four MCP tool poisoning patterns TP1 to TP4. Discover how it detects hidden instructions, Unicode deception, parameter injection, and semantic mismatches.

- Tags: analysis
- Published: 2026-06-25

### [How MCP Least Privilege Detection Analyzes Code Capabilities in NVIDIA SkillSpector](/NVIDIA/SkillSpector/mcp-least-privilege-detection-code-capabilities)

Learn how MCP least privilege detection analyzes code capabilities in NVIDIA SkillSpector. It compares declared permissions against actual code using regex for accurate LP1-LP4 findings. Enhance your security posture.

- Tags: deep-dive
- Published: 2026-06-25

### [NVIDIA SkillSpector Behavioral AST Patterns (AST1-AST9): Security Detection Guide](/NVIDIA/SkillSpector/skillspector-behavioral-ast-patterns-ast1-ast9)

Explore NVIDIA SkillSpector's behavioral AST patterns (AST1-AST9) for robust security detection. Learn how it identifies risky Python code by analyzing abstract syntax trees.

- Tags: deep-dive
- Published: 2026-06-25

### [SkillSpector Taint Tracking Patterns (TT1-TT5): A Complete Security Analysis](/NVIDIA/SkillSpector/skillspector-taint-tracking-patterns-tt1-tt5)

Explore SkillSpector's taint tracking patterns TT1-TT5 for security analysis. Detect unsafe data flows from sources to sinks with severity ratings from Medium to Critical. Understand vulnerabilities in NVIDIA/SkillSpector.

- Tags: deep-dive
- Published: 2026-06-25

### [How to Integrate SkillSpector into CI/CD Pipelines: Automated Security Scanning Guide](/NVIDIA/SkillSpector/integrate-skillspector-ci-cd-pipelines)

Integrate SkillSpector into CI/CD pipelines for automated security scanning. Generate SARIF reports and upload to your dashboard for continuous security monitoring. Optimize with --no-llm for static scans.

- Tags: how-to-guide
- Published: 2026-06-25

### [How OSV.dev Live Vulnerability Lookup Works in NVIDIA SkillSpector](/NVIDIA/SkillSpector/osv-dev-live-vulnerability-lookup-skillspector)

Discover how OSV.dev live vulnerability lookup powers NVIDIA SkillSpector's SC4 analyzer. Learn about real-time API checks, caching, severity scoring, and fallback mechanisms.

- Tags: how-to-guide
- Published: 2026-06-25

### [How SkillSpector's Baseline and False-Positive Suppression Work](/NVIDIA/SkillSpector/skillspector-baseline-false-positive-suppression)

Discover how SkillSpector's baseline and false-positive suppression system leverages glob rules and cryptographic fingerprints to deliver accurate scan results. Learn more.

- Tags: internals
- Published: 2026-06-25

### [SkillSpector Risk Scoring Algorithm and Severity Calculation Explained](/NVIDIA/SkillSpector/skillspector-risk-scoring-algorithm-severity-calculation)

Learn about SkillSpector's risk scoring algorithm. Understand how it converts security findings into a 0-100 numeric score, applies multipliers, and maps to severity bands and installation recommendations for NVIDIA.

- Tags: deep-dive
- Published: 2026-06-25

### [How to Configure Multiple LLM Providers in SkillSpector: A Complete Guide](/NVIDIA/SkillSpector/configure-multiple-llm-providers-skillspector)

Easily configure multiple LLM providers in SkillSpector for OpenAI, Anthropic, and NVIDIA APIs. This guide shows you how to set them up via environment variables or direct instantiation for flexible analysis.

- Tags: how-to-guide
- Published: 2026-06-25

### [How MCP Server Integration with Claude Code, Codex CLI, and Gemini CLI Enables Automated Security Scanning](/NVIDIA/SkillSpector/mcp-server-integration-claude-codex-gemini-security-scanning)

Learn how SkillSpector's MCP server integrates with Claude Code, Codex CLI, and Gemini CLI for automated security scanning. Block malicious skills before installation with runtime guardrails.

- Tags: how-to-guide
- Published: 2026-06-25

### [How SkillSpector's LangGraph Workflow Orchestrates Analyzer Nodes for Security Scanning](/NVIDIA/SkillSpector/skillspector-langgraph-workflow-orchestration)

Discover how SkillSpector leverages LangGraph StateGraph to orchestrate over 20 security analyzers in parallel, creating a scalable and dynamic analysis pipeline.

- Tags: architecture
- Published: 2026-06-25

### [SkillSpector Vulnerability Categories and Patterns: Complete Guide to 17 Categories and 68 Detection Rules](/NVIDIA/SkillSpector/skillspector-vulnerability-categories-patterns)

Explore SkillSpector's 17 vulnerability categories and 68 detection rules to secure your LLM skills. Discover how it identifies risks from prompt injection to supply chain attacks.

- Tags: deep-dive
- Published: 2026-06-25

### [How SkillSpector's Two-Stage Analysis Pipeline Improves Vulnerability Detection](/NVIDIA/SkillSpector/how-skillspector-two-stage-analysis-improves-vulnerability-detection)

Discover how SkillSpector's two-stage analysis pipeline enhances vulnerability detection in NVIDIA/SkillSpector. Learn how it maximizes recall and filters false positives for precise security insights.

- Tags: deep-dive
- Published: 2026-06-25

### [SkillSpector Trust Model and Data Egress: A Complete Security Analysis](/NVIDIA/SkillSpector/what-skillspector-trust-model-data-egress)

Analyze SkillSpector's trust model and data egress. Learn how SkillSpector ensures security through static analysis, controlled LLM data transmission, and OSV.dev integration.

- Tags: deep-dive
- Published: 2026-06-24

### [How to Debug SkillSpector Scan Failures with Verbose Logging](/NVIDIA/SkillSpector/how-to-debug-skillspector-scan-failures-verbose-logging)

Debug SkillSpector scan failures effectively. Enable verbose logging with --verbose or SKILLSPECTOR_LOG_LEVEL=DEBUG for detailed traces and error analysis. Resolve issues faster.

- Tags: how-to-guide
- Published: 2026-06-24

### [How the MCP Least Privilege Analyzer Verifies Capability Declarations in SkillSpector](/NVIDIA/SkillSpector/how-mcp-least-privilege-analyzer-verify-capability-declarations)

Discover how the MCP least privilege analyzer verifies capability declarations in SkillSpector by comparing SKILL.md permissions against actual code capabilities using regex.

- Tags: deep-dive
- Published: 2026-06-24

### [Understanding the Limitations of SkillSpector's Static Analysis](/NVIDIA/SkillSpector/what-limitations-skillspector-static-analysis)

Discover the limitations of SkillSpector's static analysis. Learn what it can't detect like runtime code, encrypted payloads, and non-English text. Understand its regex-based approach and potential false positives.

- Tags: deep-dive
- Published: 2026-06-24

### [How the Semantic Developer Intent Analyzer Works in NVIDIA SkillSpector](/NVIDIA/SkillSpector/how-semantic-developer-intent-analyzer-work-skillspector)

Discover how the semantic developer intent analyzer in NVIDIA SkillSpector works. It uses LLMs to find intent violations by comparing skill manifests to code behavior, identifying four categories of issues.

- Tags: how-to-guide
- Published: 2026-06-24

### [How to Run SkillSpector in Docker with LLM API Keys](/NVIDIA/SkillSpector/how-to-run-skillspector-docker-llm-api-keys)

Easily run SkillSpector in Docker with LLM API keys. Mount your code and configure credentials via environment variables for seamless integration. Get started today.

- Tags: how-to-guide
- Published: 2026-06-24

### [How Behavioral AST Analysis Detects Dangerous Code Patterns in SkillSpector](/NVIDIA/SkillSpector/how-behavioral-ast-analysis-detect-dangerous-code-patterns-skillspector)

SkillSpector uses AST analysis to find dangerous code patterns like risky function calls and dynamic imports, preventing arbitrary code execution. Learn how it works.

- Tags: internals
- Published: 2026-06-24

### [How to Scan Multi-Skill Directories Recursively with SkillSpector](/NVIDIA/SkillSpector/how-to-scan-multi-skill-directories-recursively-skillspector)

Learn how to recursively scan multi-skill directories with SkillSpector. Use the --recursive flag to detect and aggregate independent skills efficiently, generating comprehensive reports.

- Tags: how-to-guide
- Published: 2026-06-24

### [How SkillSpector Calculates Its Security Risk Score: Algorithm and Implementation](/NVIDIA/SkillSpector/how-does-skillspector-calculate-risk-score)

Discover how SkillSpector calculates its security risk score. Learn the algorithm and implementation for accurate risk assessment and informed installation decisions.

- Tags: how-to-guide
- Published: 2026-06-24

### [How SkillSpector Implements OSV.dev Integration for CVE Lookups](/NVIDIA/SkillSpector/how-does-osv-dev-integration-work-cve-lookups-skillspector)

Learn how SkillSpector integrates with OSV.dev for efficient CVE lookups on your Python and JavaScript dependencies. Get real-time vulnerability data with caching for speed.

- Tags: how-to-guide
- Published: 2026-06-24

### [How to Configure Custom YARA Rules for SkillSpector: A Complete Guide](/NVIDIA/SkillSpector/how-to-configure-custom-yara-rules-for-skillspector)

Learn to configure custom YARA rules for NVIDIA SkillSpector using the --yara-rules-dir flag. Enhance your malware analysis by adding your own detection patterns without altering default rules.

- Tags: how-to-guide
- Published: 2026-06-24

### [How SkillSpector's Two-Stage Static and LLM Analysis Pipeline Works](/NVIDIA/SkillSpector/how-does-skillspector-two-stage-static-llm-analysis-pipeline-work)

Discover how SkillSpector's two-stage pipeline unites static analysis and LLM validation to find AI agent skill vulnerabilities, ensuring critical findings are never missed.

- Tags: internals
- Published: 2026-06-24

### [What Types of Prompt Injection Vulnerabilities Can SkillSpector Find: The Four Pattern Families Explained](/NVIDIA/SkillSpector/what-types-of-prompt-injection-vulnerabilities-can-skill-spector-find)

Discover the four prompt injection vulnerability families SkillSpector detects: Instruction Override, Hidden Instructions, Exfiltration Commands, and Behavior Manipulation. Secure LLM agents now.

- Tags: deep-dive
- Published: 2026-06-23

### [How Many Vulnerability Patterns Does SkillSpector Detect? A Complete Breakdown of NVIDIA's LLM Security Rules](/NVIDIA/SkillSpector/how-many-vulnerability-patterns-does-skill-spector-detect)

SkillSpector detects 59 vulnerability patterns in NVIDIA's LLM security rules. Discover each pattern and enhance your code security with this comprehensive guide.

- Tags: deep-dive
- Published: 2026-06-23

### [Understanding Severity Levels for Risks Detected by SkillSpector](/NVIDIA/SkillSpector/what-are-the-severity-levels-for-risks-detected-by-skill-spector)

Discover SkillSpector's four severity levels LOW MEDIUM HIGH CRITICAL used to classify security risks. Understand how these levels help prioritize analysis findings.

- Tags: getting-started
- Published: 2026-06-23

### [What Is the Maximum Risk Score Computed by SkillSpector?](/NVIDIA/SkillSpector/what-is-the-maximum-risk-score-computed-by-skill-spector)

Discover the maximum risk score of 100 in NVIDIA SkillSpector. Learn how it combines base vulnerability severity with an executable-script multiplier for a clear risk assessment.

- Tags: faq
- Published: 2026-06-23

### [SkillSpectorState Fields: Complete TypedDict Reference for NVIDIA SkillSpector](/NVIDIA/SkillSpector/what-are-the-fields-defined-in-skill-spector-state)

Explore the SkillSpectorState TypedDict reference for NVIDIA SkillSpector. Understand its 23 fields, the shared schema for LangGraph workflows, and type-safe data passing.

- Tags: api-reference
- Published: 2026-06-23

### [What Is the meta_analyzer Node in SkillSpector? LLM-Driven Security Filtering Explained](/NVIDIA/SkillSpector/what-is-the-function-of-the-meta-analyzer-node-in-skill-spector)

Understand the meta_analyzer node in SkillSpector. This LLM-driven filter validates findings, assigns scores, and provides remediation advice for robust security analysis.

- Tags: internals
- Published: 2026-06-23

### [How SkillSpector Aggregates Findings from Different Analyzers: The LangGraph State Pattern](/NVIDIA/SkillSpector/how-are-findings-aggregated-from-different-analyzers-in-skill-spector)

Learn how SkillSpector aggregates findings from multiple analyzers using LangGraph's operator.add and shared state for efficient meta-analysis. Explore the state pattern in action.

- Tags: internals
- Published: 2026-06-23

### [What the build_context Node Gathers in NVIDIA SkillSpector](/NVIDIA/SkillSpector/what-information-is-gathered-by-the-build-context-node-in-skill-spector)

Discover what the build_context node in NVIDIA SkillSpector gathers. It collects file inventories and more to create a comprehensive ScanContext for your project analysis.

- Tags: internals
- Published: 2026-06-23

### [How the resolve_input Node Normalizes Input Sources in SkillSpector](/NVIDIA/SkillSpector/how-does-the-resolve-input-node-in-skill-spector-work)

Learn how SkillSpector resolve_input normalizes Git repos ZIPs URLs and local files into a standard directory while blocking SSRF and zip-slip attacks.

- Tags: internals
- Published: 2026-06-23

### [SkillSpector LangGraph Workflow: Core Nodes and Security Analyzers Explained](/NVIDIA/SkillSpector/what-are-the-key-nodes-in-the-skill-spector-langgraph-workflow)

Explore the SkillSpector LangGraph workflow and its core nodes like resolve_input, build_context, meta_analyzer, and report. Understand AI skill security scanning with dynamic analyzers.

- Tags: deep-dive
- Published: 2026-06-23

### [SkillSpector LangGraph Structure: How NVIDIA Built the Security Analysis Pipeline](/NVIDIA/SkillSpector/can-i-see-the-langgraph-structure-used-by-skill-spector)

Explore the LangGraph structure NVIDIA built for the SkillSpector security analysis pipeline. See the linear flow from input resolution to SARIF reporting in src/skillspector/graph.py.

- Tags: architecture
- Published: 2026-06-23

### [How SkillSpector Improves Precision with LLM Analysis: 7 Techniques from the NVIDIA Codebase](/NVIDIA/SkillSpector/how-does-skill-spector-improve-precision-with-llm-analysis)

Discover how SkillSpector enhances LLM analysis precision with 7 techniques from the NVIDIA codebase, including prompt engineering and Pydantic validation. Eliminate low-confidence results.

- Tags: deep-dive
- Published: 2026-06-23

### [What Is the LLM Semantic Analysis Stage in SkillSpector?](/NVIDIA/SkillSpector/what-is-the-purpose-of-the-llm-semantic-analysis-stage-in-skill-spector)

Discover the LLM Semantic Analysis stage in NVIDIA SkillSpector. Understand how it refines security findings, determines intent and impact, and generates AI-powered explanations and remedies.

- Tags: deep-dive
- Published: 2026-06-23

### [How SkillSpector Uses OSV.dev for Vulnerability Lookups in Python Dependencies](/NVIDIA/SkillSpector/how-does-skill-spector-use-osv-dev-for-vulnerability-lookups)

Discover how SkillSpector leverages OSV.dev for efficient Python dependency vulnerability lookups. Learn about batched API requests, caching, and offline fallback.

- Tags: how-to-guide
- Published: 2026-06-23

### [How Does SkillSpector Perform AST-Based Behavioral Analysis?](/NVIDIA/SkillSpector/how-does-skill-spector-perform-ast-based-behavioral-analysis)

Discover how SkillSpector uses AST-based behavioral analysis to scan Python code for dangerous execution patterns like eval and subprocess, providing structured security alerts with precise line numbers.

- Tags: internals
- Published: 2026-06-23

### [How Static Analysis Works in SkillSpector's Detection Process](/NVIDIA/SkillSpector/what-is-the-role-of-static-analysis-in-skill-spector-detection-process)

Discover how static analysis in NVIDIA SkillSpector rapidly detects insecure patterns by scanning code and configs through regex nodes in a LangGraph workflow.

- Tags: how-to-guide
- Published: 2026-06-23

### [How the SkillSpector Two-Stage Detection Pipeline Works: Static Analysis + LLM Meta-Analysis](/NVIDIA/SkillSpector/how-does-the-two-stage-detection-pipeline-in-skill-spector-function)

Discover how SkillSpector's two-stage detection pipeline enhances vulnerability analysis by merging static analysis with LLM meta-analysis for accurate results and actionable remediation.

- Tags: internals
- Published: 2026-06-23

### [SkillSpector Architecture: Inside NVIDIA's LangGraph Security Analysis Pipeline](/NVIDIA/SkillSpector/what-is-the-architecture-of-skill-spector)

Explore SkillSpector architecture, NVIDIA's LangGraph security pipeline. Discover its state-machine workflow for consistent, extensible skill analysis from input to reporting.

- Tags: architecture
- Published: 2026-06-23

### [What Programming Languages Are Used in SkillSpector? A Deep Dive into NVIDIA's Dual-Language Architecture](/NVIDIA/SkillSpector/what-programming-languages-are-used-in-skill-spector)

Discover the programming languages powering SkillSpector. NVIDIA's SkillSpector uses Python for its security engine and TypeScript for integrations.

- Tags: deep-dive
- Published: 2026-06-23

### [How SkillSpector Detects Privilege Escalation Attempts (sudo, credentials, SSH keys)](/NVIDIA/SkillSpector/detect-privilege-escalation-sudo-credentials-ssh-keys)

SkillSpector detects privilege escalation attempts by analyzing source code for risky sudo, credential, and SSH key usage. Secure your code effectively.

- Tags: deep-dive
- Published: 2026-06-22

### [How SkillSpector Detects Tool Poisoning Attacks in MCP Skill Definitions](/NVIDIA/SkillSpector/detect-tool-poisoning-attacks-mcp-skills)

Discover how SkillSpector powerfully detects tool poisoning attacks in MCP skill definitions. Learn its four specialized checks for hidden instructions, deception, injection, and mismatches.

- Tags: how-to-guide
- Published: 2026-06-22

### [What Input Formats Does SkillSpector Support? Git URLs, ZIP, and Local Directories Explained](/NVIDIA/SkillSpector/skillsepector-supported-input-formats)

SkillSpector supports Git URLs, ZIP archives, and local directories. Learn how SkillSpector normalizes these input formats for seamless project analysis and get started quickly.

- Tags: api-reference
- Published: 2026-06-22

### [How SkillSpector Performs OSV.dev Live Vulnerability Lookups for Supply Chain Security](/NVIDIA/SkillSpector/osv-dev-vulnerability-lookups-supply-chain)

SkillSpector secures your supply chain by performing live OSV.dev vulnerability lookups. It batches queries, calls the OSV.dev API, and normalizes findings with offline fallbacks. Learn how it works.

- Tags: how-to-guide
- Published: 2026-06-22

### [How to Integrate NVIDIA SkillSpector into CI/CD Pipelines Using SARIF Output](/NVIDIA/SkillSpector/integrate-skillsepector-ci-cd-sarif)

Integrate NVIDIA SkillSpector into CI CD pipelines with SARIF output. Automate code scanning and get security findings directly in your pull requests.

- Tags: how-to-guide
- Published: 2026-06-22

### [How to Interpret SkillSpector Risk Scores and Severity Levels on the 0-100 Scale](/NVIDIA/SkillSpector/interpret-skillsepector-risk-scores-severity)

Understand SkillSpector risk scores and severity levels from 0-100. Learn how findings, script multipliers, and severity bands define risk, from LOW to CRITICAL.

- Tags: tutorials
- Published: 2026-06-22

### [MCP Least Privilege Violations in SkillSpector: Underdeclared and Overdeclared Capabilities Explained](/NVIDIA/SkillSpector/mcp-least-privilege-violations-capabilities)

Understand MCP least privilege violations in NVIDIA SkillSpector. Learn how underdeclared and overdeclared capabilities are detected and how to ensure proper permission management for enhanced security.

- Tags: deep-dive
- Published: 2026-06-22

### [How Taint Tracking in SkillSpector Detects Credential Exfiltration Chains](/NVIDIA/SkillSpector/taint-tracking-credential-exfiltration)

SkillSpector's taint tracking analyzes Python ASTs to build data-flow graphs and detect credential exfiltration chains by tracing data from sources to sinks.

- Tags: deep-dive
- Published: 2026-06-22

### [How to Configure LLM Providers Like OpenAI, Anthropic, and NVIDIA for SkillSpector's Semantic Analysis](/NVIDIA/SkillSpector/configure-llm-providers-semantic-analysis)

Configure LLM providers OpenAI, Anthropic, and NVIDIA for SkillSpector semantic analysis. Set environment variables, export API keys, and run skillspector scan for powerful insights.

- Tags: how-to-guide
- Published: 2026-06-22

### [How NVIDIA SkillSpector Detects Prompt Injection Vulnerabilities in AI Agent Skills](/NVIDIA/SkillSpector/how-skillsepector-detect-prompt-injection-vulnerabilities)

Discover how NVIDIA SkillSpector uses static code analysis and regex pattern matching to detect prompt injection vulnerabilities in AI agent skills before execution.

- Tags: how-to-guide
- Published: 2026-06-22

### [How SkillSpector Assigns Severity Levels Based on Risk Scores](/NVIDIA/SkillSpector/how-are-severity-levels-assigned-based-on-skillspector-risk-scores)

Discover how SkillSpector assigns severity levels using risk scores. Learn how finding severities, executable scripts, and score bands determine installation recommendations.

- Tags: how-to-guide
- Published: 2026-06-21

### [What Is the TP Analyzer in SkillSpector? MCP Tool-Poisoning Detection Explained](/NVIDIA/SkillSpector/what-is-function-of-tp-analyzer-in-skillspector)

Discover the TP analyzer in SkillSpector, an NVIDIA security tool that detects four types of tool-poisoning attacks in skill manifests. Learn about hidden instructions, Unicode deception, parameter injection, and behavior misma...

- Tags: deep-dive
- Published: 2026-06-21

### [How SkillSpector Uses Abstract Syntax Trees (AST) for Python Security Analysis](/NVIDIA/SkillSpector/how-does-skillspector-use-abstract-syntax-tree)

Discover how SkillSpector leverages Python Abstract Syntax Trees AST for robust security analysis. Detect dangerous calls and track credential flows with precision.

- Tags: internals
- Published: 2026-06-21

### [What Dependency File Formats Does SkillSpector Parse? A Complete Guide to Supply Chain Analysis](/NVIDIA/SkillSpector/what-dependency-file-formats-does-skillspector-parse)

SkillSpector parses five dependency file formats requirements.txt, package.json, pyproject.toml, setup.py and Pipfile for Python and Node.js supply chain analysis. Identify vulnerable packages.

- Tags: how-to-guide
- Published: 2026-06-21

### [What Is the SC4 Analyzer in SkillSpector? Detecting Known Vulnerable Dependencies](/NVIDIA/SkillSpector/what-is-purpose-of-sc4-analyzer-in-skillspector)

Discover how the SkillSpector SC4 analyzer detects vulnerable dependencies by querying OSV.dev for real-time security insights. Keep your code secure.

- Tags: deep-dive
- Published: 2026-06-21

### [Static Analysis Analyzers in SkillSpector: Complete Security Scanning Guide](/NVIDIA/SkillSpector/what-are-static-analysis-analyzers-in-skillspector)

Discover SkillSpector's twelve static analysis analyzers for comprehensive security scanning. Detect threats like prompt injection without code execution.

- Tags: how-to-guide
- Published: 2026-06-21

### [How to Use SkillSpector with LangGraph: Integration Guide and API Reference](/NVIDIA/SkillSpector/how-to-use-skillspector-with-langgraph)

Integrate SkillSpector with LangGraph by invoking its compiled StateGraph for security scans. Learn how to use SkillSpector via API or as a subgraph in your workflows.

- Tags: integration-guide
- Published: 2026-06-21

### [Python API for SkillSpector: Architecture, Components, and Usage Guide](/NVIDIA/SkillSpector/what-is-python-api-for-skillspector)

Explore the Python API for SkillSpector, NVIDIA's tool for skill analysis. Learn about its architecture, components, and usage for programmatic LangGraph workflows.

- Tags: architecture
- Published: 2026-06-21

### [How SkillSpector Taint Tracking Identifies Data Exfiltration Paths](/NVIDIA/SkillSpector/how-does-skillspector-taint-tracking-identify-data-exfiltration-paths)

Learn how SkillSpector taint tracking pinpoints data exfiltration paths by analyzing Python ASTs to trace data flows from sensitive sources to dangerous sinks. Discover explicit and implicit data leaks.

- Tags: deep-dive
- Published: 2026-06-21

### [SkillSpector Dangerous Function Calls: AST Analyzer Detection Patterns](/NVIDIA/SkillSpector/which-dangerous-function-calls-does-skillspector-ast-analyzer-identify)

SkillSpector's AST analyzer detects dangerous function calls in Python code, including execution APIs, subprocess, OS spawners, and dynamic access. Secure your code now.

- Tags: internals
- Published: 2026-06-21

### [How AST-Based Behavioral Analysis Detects Dangerous Code in SkillSpector](/NVIDIA/SkillSpector/how-does-ast-based-behavioral-analysis-detect-dangerous-code-in-skillspector)

Discover how SkillSpector's AST-based behavioral analysis uncovers dangerous code by identifying risky Python function calls and complex execution patterns. Protect your projects today.

- Tags: deep-dive
- Published: 2026-06-21

### [MCP Tool Poisoning Detection: Analyzing the Four Attack Vectors in NVIDIA SkillSpector](/NVIDIA/SkillSpector/what-are-four-attack-vectors-for-mcp-tool-poisoning-detection)

Discover the four MCP tool poisoning attack vectors—Hidden Instructions, Unicode Deception, Parameter Description Injection, and LLM Description-Behavior Mismatch—analyzed by NVIDIA SkillSpector. Learn how it detects these thre...

- Tags: deep-dive
- Published: 2026-06-21

### [How SkillSpector Detects MCP Tool Poisoning: A Deep Dive into TP1-TP4 Analysis](/NVIDIA/SkillSpector/how-does-skillspector-detect-mcp-tool-poisoning)

SkillSpector detects MCP tool poisoning through TP1-TP4 analysis using regex, Unicode scanning, parameter injection, and LLM behavioral verification. Learn how SkillSpector secures your NVIDIA Skill Manifests.

- Tags: deep-dive
- Published: 2026-06-21

### [How SkillSpector Detects MCP Least Privilege Violations: A Deep Dive into the LP1-LP4 Rules](/NVIDIA/SkillSpector/how-does-skillspector-detect-mcp-least-privilege-violations)

SkillSpector detects MCP least privilege violations by analyzing skill source code against declared permissions. Learn about the LP1-LP4 rules that identify under-declared, over-declared, wildcard, and missing permissions.

- Tags: deep-dive
- Published: 2026-06-21

### [How SkillSpector Handles Offline or Air-Gapped Environments for Vulnerability Lookups](/NVIDIA/SkillSpector/how-does-skillspector-handle-offline-or-air-gapped-environments-for-vulnerability-lookups)

SkillSpector ensures continuous security scanning in offline or air-gapped environments by falling back to a built-in static database for vulnerability lookups. Keep your systems secure.

- Tags: how-to-guide
- Published: 2026-06-21

### [Does SkillSpector's OSV.dev Integration Require an API Key?](/NVIDIA/SkillSpector/does-skillspector-osv-dev-integration-require-api-key)

Learn if SkillSpector's OSV.dev integration needs an API key. SkillSpector directly queries public OSV.dev API endpoints, no authentication needed. Get the details now.

- Tags: api-reference
- Published: 2026-06-21

### [How SkillSpector's OSV.dev Integration Performs Live CVE Lookups](/NVIDIA/SkillSpector/how-does-skillspector-osv-dev-integration-perform-live-cve-lookups)

Discover how SkillSpector uses OSV.dev integration for live CVE lookups, detecting vulnerabilities in Python and JavaScript dependencies without external databases.

- Tags: how-to-guide
- Published: 2026-06-21

### [SkillSpector Executable Scripts Multiplier: How the 1.3× Risk Boost Works in NVIDIA/SkillSpector](/NVIDIA/SkillSpector/what-is-multiplier-for-skills-with-executable-scripts-in-skillspector-scoring)

Discover how SkillSpector's executable scripts add a 1.3x risk boost to your scores. Learn about the multiplier implemented in project report.py.

- Tags: deep-dive
- Published: 2026-06-21

### [How SkillSpector Calculates Its Risk Scoring Algorithm: A Deep Dive into NVIDIA’s Security Scanner](/NVIDIA/SkillSpector/how-is-risk-scoring-algorithm-calculated-in-skillspector)

Discover how SkillSpector calculates its risk scoring algorithm, aggregating findings, applying multipliers, and mapping results for clear security recommendations.

- Tags: deep-dive
- Published: 2026-06-21

### [Can SkillSpector Analyze Skills Without an API Key? Static-Only Security Scanning Explained](/NVIDIA/SkillSpector/can-skillspector-analyze-skills-without-api-key)

SkillSpector analyzes skills without an API key using static-only security scanning. Discover how to perform comprehensive local source code analysis with the --no-llm flag.

- Tags: how-to-guide
- Published: 2026-06-21

### [How to Enable LLM Semantic Analysis in SkillSpector: A Complete Configuration Guide](/NVIDIA/SkillSpector/how-to-enable-llm-semantic-analysis-in-skillspector)

Unlock LLM semantic analysis in SkillSpector. Follow our guide to configure OpenAI or Anthropic providers, export API keys, and map semantic analyzer IDs for enhanced insights.

- Tags: how-to-guide
- Published: 2026-06-21

### [How to Integrate SkillSpector into CI/CD Pipelines for Automated Security Scanning](/NVIDIA/SkillSpector/how-can-skillspector-be-integrated-into-existing-cicd-pipelines)

Seamlessly integrate SkillSpector into your CI/CD pipelines for automated security scanning. Run the CLI with SARIF output and upload results to your security dashboard for fast static-only scans on every commit.

- Tags: how-to-guide
- Published: 2026-06-20

### [Semantic Analysis vs Static Pattern Matching in NVIDIA SkillSpector: Key Differences Explained](/NVIDIA/SkillSpector/what-is-difference-between-semantic-analysis-and-static-pattern-matching)

Discover the key differences between semantic analysis and static pattern matching in NVIDIA SkillSpector. Understand how LLM interpretation and regex flagging uncover code vulnerabilities.

- Tags: deep-dive
- Published: 2026-06-20

### [Understanding SkillSpector's SC4 Supply Chain Security Scanning: Core Components Explained](/NVIDIA/SkillSpector/what-are-core-components-of-skillspector-supply-chain-security-scanning-sc4)

Explore SkillSpector's SC4 Supply Chain Security Scanning. Learn about its dual vulnerability detection: live OSV.dev API and static database for Python and npm.

- Tags: deep-dive
- Published: 2026-06-20

### [How to Configure SkillSpector to Use a Custom YARA Rules Directory](/NVIDIA/SkillSpector/how-to-configure-skillspector-to-use-custom-yara-rules-directory)

Learn how to configure SkillSpector using the yara rules dir flag to load your custom YARA rules for enhanced security scans. Speed up threat detection today.

- Tags: how-to-guide
- Published: 2026-06-20

### [How State Transitions Work Between LangGraph Nodes in SkillSpector](/NVIDIA/SkillSpector/how-does-state-transition-occur-between-langgraph-nodes-in-skillspector)

Understand how state transitions work between LangGraph nodes in SkillSpector. Discover how the shared SkillspectorState TypedDict enables immutable state passing and partial dictionary merging.

- Tags: internals
- Published: 2026-06-20

### [How to Run Tests and Add New Test Cases for SkillSpector Analyzers](/NVIDIA/SkillSpector/how-to-run-tests-and-add-new-test-cases-for-skillspector-analyzers)

Learn how to run tests and add new test cases for SkillSpector analyzers. Discover how pytest and Makefile orchestrate comprehensive testing for your analyzers.

- Tags: how-to-guide
- Published: 2026-06-20

### [NVIDIA SkillSpector 64 Vulnerability Patterns: Complete Catalog with Severity Levels](/NVIDIA/SkillSpector/what-are-64-vulnerability-patterns-and-their-associated-severity-levels)

Explore the NVIDIA SkillSpector 64 vulnerability patterns. Discover each pattern's mapped severity level: CRITICAL, HIGH, MEDIUM, or LOW. Master static analysis with this comprehensive catalog.

- Tags: api-reference
- Published: 2026-06-20

### [How SkillSpector Detects MCP Tool Poisoning: Four Static Analysis Methods Explained](/NVIDIA/SkillSpector/what-methods-does-skillspector-use-to-detect-mcp-tool-poisoning)

Discover how SkillSpector detects MCP tool poisoning using four static analysis methods: covert instruction extraction, Unicode deception, parameter injection scanning, and LLM semantic verification.

- Tags: deep-dive
- Published: 2026-06-20

### [How SkillSpector Detects Prompt Injection in SKILL.md Files: A Static Analysis Deep Dive](/NVIDIA/SkillSpector/how-does-skillspector-detect-prompt-injection-in-skill-md-files)

SkillSpector uses static pattern analysis and four regex families to detect prompt injection in SKILL.md files by identifying instruction overrides, data exfiltration, and more.

- Tags: deep-dive
- Published: 2026-06-20

### [SkillSpector Input Resolution Process: How Git URLs, ZIP Files, and Directories Are Normalized](/NVIDIA/SkillSpector/what-is-input-resolution-process-for-git-urls-zip-files-directories)

Learn how SkillSpector normalizes Git URLs, ZIP files, and directories into a single local path using its hierarchical detection system. Discover the InputHandler resolve process.

- Tags: internals
- Published: 2026-06-20

### [How the meta_analyzer Filters Static Findings in NVIDIA SkillSpector](/NVIDIA/SkillSpector/what-is-function-of-meta_analyzer-in-filtering-static-findings)

Discover how the meta_analyzer in NVIDIA SkillSpector filters static findings. It uses an LLM to reduce false positives, confirm vulnerabilities, and provide actionable remediation steps. Learn more!

- Tags: internals
- Published: 2026-06-20

### [How to Debug SkillSpector Using LangGraph Studio: A Step-by-Step Guide](/NVIDIA/SkillSpector/how-can-developers-debug-skillspector-using-langgraph-studio)

Debug SkillSpector efficiently with LangGraph Studio. Step through node-by-node, inspect SkillSpectorState, and pinpoint analyzer or LLM call bugs. Easy, actionable guide.

- Tags: how-to-guide
- Published: 2026-06-20

### [How Taint Tracking Enables Data Exfiltration Detection in NVIDIA SkillSpector](/NVIDIA/SkillSpector/how-does-taint-tracking-enable-detection-of-data-exfiltration)

Learn how SkillSpector's taint tracking detects data exfiltration by tracing sensitive data from sources to dangerous sinks, identifying direct and indirect tainted propagation.

- Tags: deep-dive
- Published: 2026-06-20

### [How to Extend YARA Rules in SkillSpector for Custom Malware Signatures](/NVIDIA/SkillSpector/how-to-extend-yara-rules-to-incorporate-custom-malware-signatures)

Learn to extend YARA rules in SkillSpector and create custom malware signatures. SkillSpector merges built-in and user rules for enhanced detection.

- Tags: how-to-guide
- Published: 2026-06-20

### [How the Behavioral AST Analyzer Identifies Dangerous Code Patterns in SkillSpector](/NVIDIA/SkillSpector/how-does-behavioral-ast-analyzer-identify-dangerous-code-patterns)

Discover how the SkillSpector Behavioral AST analyzer identifies dangerous code patterns by parsing Python and matching calls to high-risk functions like exec() and eval(). Enhance your code security today.

- Tags: internals
- Published: 2026-06-20

### [How to Interpret SARIF Output for CI/CD Integration with NVIDIA SkillSpector](/NVIDIA/SkillSpector/how-to-effectively-interpret-sarif-output-for-cicd-integration-purposes)

Effectively interpret SARIF output from NVIDIA SkillSpector for CI CD integration. Trigger automated build failures and security gates with standard JSON parsing.

- Tags: how-to-guide
- Published: 2026-06-20

### [How MCP Least Privilege Detection Works in NVIDIA SkillSpector](/NVIDIA/SkillSpector/what-is-mechanism-behind-mcp-least-privilege-detection)

Discover how MCP least privilege detection in NVIDIA SkillSpector works. It compares declared vs. actual permissions to find under-declared, over-declared, wildcard, or missing privileges.

- Tags: deep-dive
- Published: 2026-06-20

### [How to Use the SkillSpector Python API for Programmatic Security Scanning](/NVIDIA/SkillSpector/how-can-skillspector-be-utilized-programmatically-via-python-api)

Learn how to use the SkillSpector Python API programmatically. Invoke the LangGraph workflow with a state dictionary to get security findings, reports, and risk scores.

- Tags: how-to-guide
- Published: 2026-06-20

### [How to Configure Various LLM Providers Like OpenAI, Anthropic, and NVIDIA in SkillSpector](/NVIDIA/SkillSpector/how-to-configure-various-llm-providers-openai-anthropic-nvidia)

Learn to configure LLM providers like OpenAI, Anthropic, and NVIDIA in SkillSpector using the SKILLSPECTOR_PROVIDER environment variable for seamless integration.

- Tags: how-to-guide
- Published: 2026-06-20

### [How OSV.dev Vulnerability Lookup Works in SkillSpector: Live API with Offline Fallback Support](/NVIDIA/SkillSpector/how-does-osv-dev-vulnerability-lookup-operate-with-offline-fallback-support)

SkillSpector's SC4 performs live OSV.dev vulnerability lookup for dependencies, falling back to a static database for offline resilience. Enhance your supply chain security.

- Tags: internals
- Published: 2026-06-20

### [How SkillSpector Calculates Its Security Risk Score: Methodology and Implementation](/NVIDIA/SkillSpector/what-is-methodology-for-calculating-skillspector-risk-score)

Learn how SkillSpector calculates its security risk score by aggregating weighted findings, applying multipliers for scripts, and mapping to severity bands. Get installation recommendations.

- Tags: deep-dive
- Published: 2026-06-20

### [How to Integrate Custom Analyzer Nodes into NVIDIA SkillSpector’s LangGraph Workflow](/NVIDIA/SkillSpector/how-to-integrate-custom-analyzer-nodes-into-langgraph-workflow)

Seamlessly integrate custom analyzer nodes into NVIDIA SkillSpector's LangGraph workflow. Learn how to create, register, and wire your custom analyzers for enhanced analysis capabilities.

- Tags: how-to-guide
- Published: 2026-06-20

### [How SkillSpector's Two-Stage Detection Pipeline Works: Static Analysis to LLM Validation](/NVIDIA/SkillSpector/how-does-skillspector-two-stage-detection-pipeline-function)

Discover how SkillSpector's two-stage pipeline uses static analysis and LLM validation to detect vulnerabilities, filter false positives, and provide remediation steps. Learn more about NVIDIA/SkillSpector.

- Tags: internals
- Published: 2026-06-20

### [How `_estimate_extra_overhead` Calculates Token Overhead for LLM Prompts in SkillSpector](/NVIDIA/SkillSpector/estimate_extra_overhead-calculate-token-overhead-prompts)

Discover how _estimate_extra_overhead in NVIDIA SkillSpector calculates LLM prompt token overhead by estimating character-based token counts for supplementary prompt content. Learn more!

- Tags: internals
- Published: 2026-06-19

### [How SkillSpector Uses 4-Character-Per-Token Estimation for LLM Token Budgeting](/NVIDIA/SkillSpector/4-character-per-token-estimation-estimate_tokens)

Discover how SkillSpector uses 4-character-per-token estimation for fast LLM token budgeting. Learn about this efficient heuristic in the NVIDIA/SkillSpector repository.

- Tags: how-to-guide
- Published: 2026-06-19

### [How `get_batches` Splits Files Exceeding Token Budgets into Smaller Chunks in NVIDIA SkillSpector](/NVIDIA/SkillSpector/get_batches-split-files-token-budgets-chunks)

Discover how SkillSpector's get_batches method intelligently splits large files into smaller chunks, ensuring they fit within token budgets using line-based segmentation.

- Tags: internals
- Published: 2026-06-19

### [How SkillSpector Implements Async Batch Processing with arun_batches and max_concurrency](/NVIDIA/SkillSpector/skillspector-async-batch-processing-arun_batches-max_concurrency)

Discover how SkillSpector implements async batch processing with arun_batches and max_concurrency using asyncio semaphores for efficient parallel code analysis.

- Tags: internals
- Published: 2026-06-19

### [How to Run SkillSpector in Docker with Environment Variables](/NVIDIA/SkillSpector/how-to-run-skillspector-docker-environment-variables)

Learn how to run SkillSpector in Docker using environment variables. Easily configure API keys and model settings by mounting volumes and using -e flags or env files for seamless integration.

- Tags: how-to-guide
- Published: 2026-06-18

### [How SkillSpector's LLM Analyzer Implements Anti-Jailbreak Protections](/NVIDIA/SkillSpector/how-llm-analyzer-avoid-manipulation-anti-jailbreak-protections)

Discover how SkillSpector's LLM analyzer uses anti-jailbreak protections like static filtering, hardened prompts, and token budgeting to prevent manipulation. Learn about NVIDIA/SkillSpector's robust security.

- Tags: deep-dive
- Published: 2026-06-18

### [How the LangGraph StateGraph Workflow Orchestrates Analyzer Nodes in SkillSpector](/NVIDIA/SkillSpector/how-langgraph-stategraph-workflow-orchestrate-analyzer-nodes)

Learn how the LangGraph StateGraph workflow orchestrates analyzer nodes in NVIDIA SkillSpector. Discover its fan-out pattern and dynamic loading for efficient analysis.

- Tags: internals
- Published: 2026-06-18

### [How static_patterns_prompt_injection Detects Instruction Overrides in NVIDIA SkillSpector](/NVIDIA/SkillSpector/how-static-patterns-prompt-injection-detect-instruction-overrides)

Discover how static_patterns_prompt_injection detects instruction overrides in NVIDIA SkillSpector by scanning regex patterns. Learn about high-severity findings and confidence scores for each match.

- Tags: how-to-guide
- Published: 2026-06-18

### [How the semantic_developer_intent Analyzer Evaluates Skill Purpose with LLM in SkillSpector](/NVIDIA/SkillSpector/how-semantic-developer-intent-analyzer-evaluate-skill-purpose-llm)

Discover how the semantic_developer_intent analyzer uses LLM to pinpoint skill purpose mismatches by comparing manifest declarations against actual code behavior in SkillSpector.

- Tags: deep-dive
- Published: 2026-06-18

### [How SkillSpector Handles Offline Environments for OSV.dev: Resilient Vulnerability Scanning](/NVIDIA/SkillSpector/how-skillspector-handle-offline-environments-osv-dev)

Discover how SkillSpector ensures continuous OSV.dev scanning in offline environments by catching network errors, returning empty lists, and using its static vulnerability database.

- Tags: how-to-guide
- Published: 2026-06-18

### [How Behavioral Taint Tracking Works in SkillSpector: Detecting Source-to-Sink Data Flows](/NVIDIA/SkillSpector/how-taint-tracking-work-behavioral-taint-tracking-analyzer)

Discover how NVIDIA SkillSpector's behavioral taint tracking detects data flows from sources to sinks using AST-based analysis and rule-based classification. Learn to identify sensitive value propagation.

- Tags: deep-dive
- Published: 2026-06-18

### [How to Extend SkillSpector by Adding Custom Analyzers: A Step-by-Step Guide](/NVIDIA/SkillSpector/how-to-extend-skillspector-adding-custom-analyzers)

Learn to extend SkillSpector by adding custom analyzers. Follow this step-by-step guide to implement and register your custom analysis nodes in the NVIDIA SkillSpector pipeline for enhanced functionality.

- Tags: how-to-guide
- Published: 2026-06-18

### [What Dangerous Code Patterns Does the Behavioral AST Analyzer Detect?](/NVIDIA/SkillSpector/what-dangerous-code-patterns-behavioral-ast-analyzer-detect)

Discover dangerous code patterns like exec eval and process spawning detected by the behavioral AST analyzer in NVIDIA SkillSpector. Improve your code security today.

- Tags: deep-dive
- Published: 2026-06-18

### [What Are MCP Least Privilege Violations and How SkillSpector Detects Them](/NVIDIA/SkillSpector/what-are-mcp-least-privilege-violations-how-detected)

Discover MCP least privilege violations and how SkillSpector pinpoints them. Learn how SkillSpector analyzes declared vs. actual skill permissions to ensure security and prevent unauthorized access.

- Tags: deep-dive
- Published: 2026-06-18

### [How to Configure SkillSpector Provider Credentials for Anthropic, NVIDIA, and OpenAI](/NVIDIA/SkillSpector/how-to-configure-skillspector-provider-credentials)

Configure SkillSpector provider credentials for Anthropic, NVIDIA, and OpenAI using environment variables. Learn how to set API keys for seamless LLM integration.

- Tags: how-to-guide
- Published: 2026-06-18

### [Static Patterns Analyzers vs Semantic Security Discovery in NVIDIA SkillSpector](/NVIDIA/SkillSpector/difference-static-patterns-analyzers-semantic-security-discovery)

Understand the difference between static patterns analyzers and semantic security discovery in NVIDIA SkillSpector. Learn how LLM reasoning differs from rule-based scanning for security.

- Tags: deep-dive
- Published: 2026-06-18

### [How SkillSpector's Risk Scoring Algorithm Calculates Severity](/NVIDIA/SkillSpector/how-skillspector-risk-scoring-algorithm-calculate-severity)

Discover how SkillSpector's risk scoring algorithm calculates severity. Learn about point values, multipliers, and clamping for accurate risk assessment.

- Tags: internals
- Published: 2026-06-18

### [How to Add Custom YARA Rules to SkillSpector Scans: A Complete Guide](/NVIDIA/SkillSpector/how-to-add-custom-yara-rules-to-skillspector-scans)

Learn to add custom YARA rules to SkillSpector scans using the --yara-rules-dir flag. Enhance your security analysis with tailored detection capabilities.

- Tags: how-to-guide
- Published: 2026-06-18

### [How to Integrate SkillSpector into CI/CD Pipelines for SARIF Output](/NVIDIA/SkillSpector/how-to-integrate-skillspector-into-ci-cd-pipelines-sarif-output)

Integrate SkillSpector into CI/CD pipelines to generate SARIF output for automated security annotations on pull requests. Streamline your workflow with GitHub Actions Azure Pipelines & GitLab CI.

- Tags: how-to-guide
- Published: 2026-06-18

### [How SkillSpector's LangGraph Two-Stage Analysis Pipeline Works: Static Detection Meets LLM Validation](/NVIDIA/SkillSpector/how-skillspector-langgraph-two-stage-analysis-pipeline-work)

Discover how SkillSpector's LangGraph pipeline combines static analysis with LLM validation to detect vulnerabilities, filter false positives, and provide remediation guidance for enhanced code security.

- Tags: internals
- Published: 2026-06-18

### [How to Contribute New Vulnerability Patterns to SkillSpector: A Complete Developer Guide](/NVIDIA/SkillSpector/how-to-contribute-new-vulnerability-patterns-to-skillspector)

Learn to contribute new vulnerability patterns to SkillSpector. This guide details creating Python modules, registering analyzers, adding metadata, and writing tests for the NVIDIA SkillSpector tool.

- Tags: how-to-guide
- Published: 2026-06-17

### [How Semantic Security Discovery Evaluates Intent Beyond Pattern Matching in NVIDIA SkillSpector](/NVIDIA/SkillSpector/how-semantic-security-discovery-evaluates-intent-beyond-pattern-matching)

Discover how semantic security discovery in NVIDIA SkillSpector goes beyond pattern matching. Analyze skill file meaning and intent with LLMs to detect advanced attacks missed by static analysis.

- Tags: deep-dive
- Published: 2026-06-17

### [How to Scan Skills from Git URLs or Compressed Archives with NVIDIA SkillSpector](/NVIDIA/SkillSpector/how-to-scan-skills-from-git-urls-or-compressed-archives)

Easily scan skills from Git URLs or compressed archives with NVIDIA SkillSpector. Learn how to analyze code efficiently and gain insights into your project's capabilities.

- Tags: how-to-guide
- Published: 2026-06-17

### [How Taint Tracking Analyzes Data Flow from Sources to Sinks in NVIDIA SkillSpector](/NVIDIA/SkillSpector/how-taint-tracking-analyzes-data-flow-from-sources-to-sinks)

Discover how NVIDIA SkillSpector's taint tracking analyzes data flow. Learn how it traces tainted data from sources to sinks through Python AST parsing for security insights.

- Tags: deep-dive
- Published: 2026-06-17

### [How to Use Docker to Scan Skills Without Installing Python Dependencies](/NVIDIA/SkillSpector/how-to-use-docker-to-scan-skills-without-installing-python-dependencies)

Scan AI skill bundles easily with the NVIDIA SkillSpector Docker image. Avoid Python dependency headaches and get started quickly on your host machine.

- Tags: how-to-guide
- Published: 2026-06-17

### [Security Limitations of Static-Only Analysis vs Full LLM Analysis in SkillSpector](/NVIDIA/SkillSpector/what-are-the-security-limitations-of-static-only-analysis-vs-full-llm-analysis)

Explore SkillSpector's security limitations. Discover how full LLM analysis uncovers hidden intent and API misuse that static-only analysis misses, while understanding potential LLM risks.

- Tags: deep-dive
- Published: 2026-06-17

### [How to Reduce False Positives from Static Pattern Matching in SkillSpector](/NVIDIA/SkillSpector/how-to-reduce-false-positives-from-static-pattern-matching)

Reduce false positives in SkillSpector static pattern matching using built-in filters for safer code analysis. Improve accuracy and confidence.

- Tags: how-to-guide
- Published: 2026-06-17

### [How to Interpret SARIF Output Format from NVIDIA SkillSpector for Security Tool Integration](/NVIDIA/SkillSpector/how-to-interpret-sarif-output-format-for-integration-with-security-tooling)

Learn to interpret SARIF output from NVIDIA SkillSpector for seamless security tool integration. Leverage structured JSON for CI pipelines and vulnerability dashboards.

- Tags: how-to-guide
- Published: 2026-06-17

### [How MCP Least Privilege Analysis Detects Permission Mismatches in Skill Definitions](/NVIDIA/SkillSpector/how-mcp-least-privilege-analysis-detects-permission-mismatches-in-skill-definitions)

Learn how MCP least privilege analysis detects permission mismatches in SkillSpector skill definitions by comparing manifest declarations against executable capabilities for enhanced security.

- Tags: deep-dive
- Published: 2026-06-17

### [How the LangGraph Workflow Processes Skills Through the Analysis Pipeline in SkillSpector](/NVIDIA/SkillSpector/how-the-langgraph-workflow-processes-skills-through-the-analysis-pipeline)

Discover how SkillSpector's LangGraph workflow processes skills through its analysis pipeline. Learn about source resolution, static analysis, LLM enrichment, and report generation.

- Tags: internals
- Published: 2026-06-17

### [How to Configure Different LLM Providers (OpenAI, Anthropic, NVIDIA) for Semantic Analysis in SkillSpector](/NVIDIA/SkillSpector/how-to-configure-different-llm-providers-for-semantic-analysis)

Easily configure OpenAI, Anthropic, or NVIDIA LLM providers for semantic analysis in SkillSpector. Learn how to set the SKILLSPECTOR_PROVIDER environment variable for seamless integration.

- Tags: how-to-guide
- Published: 2026-06-17

### [How SkillSpector Batches Large Files for LLM Analysis: A Technical Deep Dive](/NVIDIA/SkillSpector/how-skillspector-handles-large-files-llm-analysis-batching)

Discover how SkillSpector batches large files for LLM analysis. Learn how it splits files into chunks, processes them in parallel, and maintains accurate line numbers for precise findings.

- Tags: deep-dive
- Published: 2026-06-16

### [How SkillSpector Detects Prompt Injection Vulnerabilities in SKILL.md Files](/NVIDIA/SkillSpector/how-skillspector-detects-prompt-injection-in-skill-md)

SkillSpector finds prompt injection vulnerabilities in SKILL.md files using a static-pattern analyzer. It identifies instruction overrides and hidden commands as high-severity findings.

- Tags: how-to-guide
- Published: 2026-06-16

### [SkillSpector Static Patterns Analyzers: Threat Categories and Architecture Explained](/NVIDIA/SkillSpector/difference-between-static-patterns-analyzers)

Explore SkillSpector static_patterns analyzers, understanding their distinct threat detection capabilities, shared architecture, and how they identify diverse security risks from prompt injection to supply chain threats.

- Tags: deep-dive
- Published: 2026-06-16

### [How to Use SkillSpector as a Python Library: Programmatic Security Analysis](/NVIDIA/SkillSpector/how-to-use-skillspector-as-python-library)

Learn to use SkillSpector as a Python library for programmatic security analysis. Import skillspector.graph and call invoke with your input path to run the security pipeline.

- Tags: how-to-guide
- Published: 2026-06-16

### [How SkillSpector Determines Confidence Scores for Security Findings](/NVIDIA/SkillSpector/how-skillspector-calculates-confidence-scores)

Learn how SkillSpector determines confidence scores for security findings. Explore LLM self-assessment and deterministic heuristics for accurate vulnerability identification.

- Tags: internals
- Published: 2026-06-16

### [Expected Structure of a Skill File Scanned by SkillSpector: Directory Layout and Manifest Guide](/NVIDIA/SkillSpector/what-is-the-structure-of-a-skill-file)

Discover the expected structure of a SkillSpector skill file. Learn about the mandatory SKILL.md and optional implementation files for NVIDIA's SkillSpector.

- Tags: guide
- Published: 2026-06-16

### [How to Extend the SkillSpector Analyzer Pipeline with Custom Analyzers](/NVIDIA/SkillSpector/how-to-extend-analyzer-pipeline-custom-analyzers)

Learn to extend the SkillSpector analyzer pipeline by creating custom analyzers. Follow our guide to add new analysis nodes and integrate them seamlessly into the SkillSpector workflow.

- Tags: how-to-guide
- Published: 2026-06-16

### [How to Run SkillSpector Using Docker: Complete Setup Guide](/NVIDIA/SkillSpector/how-to-run-skillspector-in-docker)

Easily run SkillSpector security scans with Docker. Mount your code and invoke the CLI for dependency-free analysis. Get the complete setup guide for NVIDIA/SkillSpector.

- Tags: how-to-guide
- Published: 2026-06-16

### [How the Meta Analyzer in SkillSpector Filters False Positives: A Technical Deep Dive](/NVIDIA/SkillSpector/how-meta-analyzer-filters-false-positives)

Learn how SkillSpector's meta analyzer leverages LLMs to filter false positives, ensuring accurate vulnerability detection and providing essential remediation details for developers.

- Tags: deep-dive
- Published: 2026-06-16

### [SkillSpector Input Formats: Handling Git, URLs, ZIP Archives, and Local Files](/NVIDIA/SkillSpector/what-input-formats-does-skillspector-handle)

Discover the input formats SkillSpector supports for code analysis. Effortlessly use Git URLs, ZIP archives, local files, and more to extract skills.

- Tags: how-to-guide
- Published: 2026-06-16

### [How Behavioral AST Analysis Detects Dangerous Code Patterns in SkillSpector](/NVIDIA/SkillSpector/how-behavioral-ast-analysis-finds-dangerous-code-patterns)

Discover how SkillSpector's behavioral AST analysis uncovers dangerous Python code patterns like exec() and eval() that traditional scans miss. Secure your code effectively.

- Tags: deep-dive
- Published: 2026-06-16

### [OSV.dev Integration for CVE Lookups in SkillSpector: Implementation Guide](/NVIDIA/SkillSpector/how-osv-dev-integration-works-for-cve-lookups)

Learn how to integrate OSV.dev for CVE lookups in NVIDIA SkillSpector. This guide details batch API queries, in-memory caching, and fallback strategies for vulnerability data.

- Tags: how-to-guide
- Published: 2026-06-16

### [How SkillSpector Identifies MCP Tool Poisoning Attacks: A Technical Deep Dive](/NVIDIA/SkillSpector/how-skillspector-detects-mcp-tool-poisoning-attacks)

Learn how SkillSpector identifies MCP tool poisoning attacks with its mcp_tool_poisoning analyzer. Discover four checks: hidden instructions, Unicode deception, parameter injection, and description code mismatches.

- Tags: deep-dive
- Published: 2026-06-16

### [How Taint Tracking Analysis Helps SkillSpector Detect Data Exfiltration](/NVIDIA/SkillSpector/how-taint-tracking-analysis-detects-data-exfiltration)

SkillSpector uses taint tracking analysis to detect data exfiltration by tracing sensitive data flow from sources to sinks in Python code, finding explicit and implicit leakage.

- Tags: deep-dive
- Published: 2026-06-16

### [How to Configure Different LLM Providers (OpenAI, Anthropic, NVIDIA) in SkillSpector](/NVIDIA/SkillSpector/how-to-configure-llm-providers-openai-anthropic-nvidia)

Effortlessly configure SkillSpector with OpenAI, Anthropic, or NVIDIA LLM providers by setting the SKILLSPECTOR_PROVIDER environment variable and API key. Switch backends easily without code changes.

- Tags: how-to-guide
- Published: 2026-06-16

### [How SkillSpector Calculates Its Security Risk Score: Algorithm and Implementation](/NVIDIA/SkillSpector/how-to-calculate-risk-score-in-skillspector)

Discover how SkillSpector calculates its security risk score using severity weighted points and an executable script multiplier. Learn the algorithm and implementation behind assessing skill bundle safety.

- Tags: internals
- Published: 2026-06-16

### [How the SkillSpector Input Resolver Handles Git URLs, Zip Files, and Directories](/NVIDIA/SkillSpector/skill-spector-input-resolver-handle-git-urls-zip-files-directories)

Learn how the SkillSpector input resolver unifies Git URLs, zip files, and directories into a single local path for seamless analysis. Understand the InputHandler class.

- Tags: how-to-guide
- Published: 2026-06-15

### [How AST-Based Behavioral Analysis Detects Exec and Eval Calls in SkillSpector](/NVIDIA/SkillSpector/ast-based-behavioral-analysis-detect-exec-eval-calls-skill-spector)

Discover how SkillSpector's AST behavioral analysis pinpoints exec and eval calls using taint tracking to secure your code. Learn about safe Python execution now.

- Tags: how-to-guide
- Published: 2026-06-15

### [How the LangGraph Workflow Orchestrates 20+ Analyzers in NVIDIA SkillSpector](/NVIDIA/SkillSpector/langgraph-workflow-orchestrate-20-analyzers-skill-spector)

Discover how the LangGraph workflow orchestrates 20+ analyzers in NVIDIA SkillSpector. Learn about dynamic node registration, concurrent execution, and state aggregation for efficient risk scoring and reporting.

- Tags: architecture
- Published: 2026-06-15

### [How to Configure OpenAI, Anthropic, and NVIDIA LLM Providers in SkillSpector](/NVIDIA/SkillSpector/how-to-configure-llm-providers-openai-anthropic-nvidia-skill-spector)

Learn how to configure OpenAI, Anthropic, and NVIDIA LLM providers in SkillSpector. Easily integrate language models using environment variables and provider plugins for seamless AI development.

- Tags: how-to-guide
- Published: 2026-06-15

### [How SkillSpector's Taint Tracking Detects Credential Exfiltration Chains](/NVIDIA/SkillSpector/skill-spector-taint-tracking-credential-exfiltration-chains)

SkillSpector's taint tracking analyzes Python ASTs to detect credential exfiltration chains. It traces data from sources to network sinks, mapping exfiltration paths with severity-based rules.

- Tags: deep-dive
- Published: 2026-06-15

### [How the LLM Analyzer Base Class Implements Anti-Jailbreak Protections in NVIDIA SkillSpector](/NVIDIA/SkillSpector/llm-analyzer-base-class-anti-jailbreak-protections)

Discover how the LLM Analyzer Base class in NVIDIA SkillSpector uses structured outputs, prompt templates, token budgeting, and pre-filtering for robust anti-jailbreak protections. Secure your LLM analyses.

- Tags: internals
- Published: 2026-06-15

### [How to Run SkillSpector in Docker with API Keys Configured](/NVIDIA/SkillSpector/how-to-run-skill-spector-docker-api-keys)

Run SkillSpector in Docker easily. Configure API keys via environment variables or an env file for seamless LLM scanning. Get started now!

- Tags: how-to-guide
- Published: 2026-06-15

### [How to Integrate SkillSpector into CI/CD Pipelines Using SARIF Output](/NVIDIA/SkillSpector/how-to-integrate-skill-spector-into-ci-cd-pipelines-sarif-output)

Integrate SkillSpector into CI/CD pipelines with SARIF output. Automate security scanning and annotations in GitHub Actions, Azure DevOps, and GitLab CI for enhanced code quality.

- Tags: how-to-guide
- Published: 2026-06-15

### [How SkillSpector Performs AST-Based Behavioral Analysis: A Deep Dive into the Detection Engine](/NVIDIA/SkillSpector/how-does-skillspector-ast-based-behavioral-analysis-work)

Discover how SkillSpector uses AST-based behavioral analysis to identify dangerous Python code patterns like exec eval and subprocess calls by parsing code and matching nodes against rules.

- Tags: deep-dive
- Published: 2026-06-14

### [What Are the Main Categories of Security Issues SkillSpector Scans For?](/NVIDIA/SkillSpector/what-are-main-categories-of-security-issues-skillspector-scans-for)

Discover the main security issues SkillSpector scans for, including static pattern-based vulnerabilities and semantic LLM-based risks in AI agent skill bundles.

- Tags: deep-dive
- Published: 2026-06-14

### [Types of Analysis Custom Analyzers Can Perform in NVIDIA SkillSpector](/NVIDIA/SkillSpector/what-types-of-analysis-can-custom-analyzers-perform-in-skillspector)

Discover the five analysis types custom analyzers perform in NVIDIA SkillSpector including static code matching YARA rule evaluation behavioral AST taint tracking MCP enforcement and LLM reasoning

- Tags: how-to-guide
- Published: 2026-06-14

### [How Findings Are Added to State in SkillSpector Analysis: A Complete Guide](/NVIDIA/SkillSpector/how-are-findings-added-to-state-in-skillspector-analysis)

Learn how findings are added to the SkillSpector state using LangGraph's operator add annotation for efficient analysis. Understand the process in this complete guide.

- Tags: how-to-guide
- Published: 2026-06-14

### [Expected Signature for a Custom SkillSpector Analyzer: Implementation Guide](/NVIDIA/SkillSpector/what-is-expected-signature-for-custom-skillspector-analyzer)

Learn the expected signature for a custom SkillSpector analyzer inheriting from LLMAnalyzerBase. Implement the __init__ method to initialize the LLM backend and token budget for efficient analysis.

- Tags: how-to-guide
- Published: 2026-06-14

### [How to Extend SkillSpector with Custom Analyzers: A Complete Guide](/NVIDIA/SkillSpector/how-can-i-extend-skillspector-with-custom-analyzers)

Extend SkillSpector with custom analyzers by creating Python modules and registering them. This guide simplifies adding new analysis capabilities to your SkillSpector workflow.

- Tags: how-to-guide
- Published: 2026-06-14

### [How to Configure SkillSpector to Use Local LLMs Like Ollama: A Complete Guide](/NVIDIA/SkillSpector/how-to-configure-skillspector-to-use-local-llms-like-ollama)

Configure SkillSpector to use local LLMs with Ollama. Follow this guide to set up your local server endpoint and API key for seamless integration with NVIDIA/SkillSpector.

- Tags: how-to-guide
- Published: 2026-06-14

### [Which LLM Providers Are Supported by SkillSpector? OpenAI, Anthropic, and NVIDIA Build](/NVIDIA/SkillSpector/which-llm-providers-are-supported-by-skillspector)

SkillSpector integrates with major LLM providers including OpenAI, Anthropic, and NVIDIA Build. Discover seamless credential resolution and uniform model access. Explore supported LLMs now.

- Tags: getting-started
- Published: 2026-06-14

### [How SkillSpector Handles Offline and Air-Gapped Vulnerability Scanning](/NVIDIA/SkillSpector/how-does-skillspector-handle-offline-or-air-gapped-environments-for-vulnerability-scanning)

SkillSpector ensures continuous vulnerability scanning in air-gapped environments by automatically falling back to a built-in database when the OSV.dev API is unreachable.

- Tags: how-to-guide
- Published: 2026-06-14

### [OSV.dev Analyzer Dependency Sources in NVIDIA SkillSpector: PyPI and npm Support](/NVIDIA/SkillSpector/what-dependency-sources-does-osv-dev-analyzer-support)

NVIDIA SkillSpector's OSV.dev analyzer scans PyPI and npm dependencies for vulnerabilities. Secure your Python and JavaScript projects today.

- Tags: api-reference
- Published: 2026-06-14

### [How SkillSpector Integrates with OSV.dev for Vulnerability Lookups](/NVIDIA/SkillSpector/how-does-skillspector-integrate-with-osv-dev-for-vulnerability-lookups)

Learn how SkillSpector integrates with OSV.dev for fast vulnerability lookups of Python and JavaScript dependencies. Discover security risks efficiently.

- Tags: how-to-guide
- Published: 2026-06-14

### [How Executable Scripts Affect SkillSpector's Risk Score: The 1.3× Multiplier Explained](/NVIDIA/SkillSpector/what-is-effect-of-executable-scripts-on-skillspector-risk-score)

Discover how executable scripts increase SkillSpector's risk score by 1.3x. Learn how this multiplier impacts skill severity for NVIDIA/SkillSpector.

- Tags: deep-dive
- Published: 2026-06-14

### [How SkillSpector Determines the Severity of Findings: A Complete Technical Guide](/NVIDIA/SkillSpector/how-does-skillspector-determine-severity-of-findings)

Learn how SkillSpector determines finding severity using a priority-based extraction system. Understand LOW, MEDIUM, HIGH, and CRITICAL levels for each analyzer type.

- Tags: deep-dive
- Published: 2026-06-14

### [How the SkillSpector Risk Scoring Algorithm Evaluates Skill Security](/NVIDIA/SkillSpector/what-is-skillspector-risk-scoring-algorithm)

Learn how the SkillSpector risk scoring algorithm elevates security findings, applies multipliers for executable scripts, and maps results to severity bands for installation recommendations.

- Tags: deep-dive
- Published: 2026-06-14

### [How to Use Custom YARA Rules with SkillSpector: A Complete Guide](/NVIDIA/SkillSpector/how-do-i-use-custom-yara-rules-with-skillspector)

Learn to use custom YARA rules with SkillSpector. Guide shows how to pass your rules directory to the CLI for enhanced analysis. Improve security scans.

- Tags: how-to-guide
- Published: 2026-06-14

### [How to Run SkillSpector Using Docker: A Complete Setup Guide](/NVIDIA/SkillSpector/how-to-run-skillspector-using-docker)

Learn to run SkillSpector using Docker. This guide shows you how to build a multi-stage image for easy scanning without local Python installation.

- Tags: how-to-guide
- Published: 2026-06-14

### [How to Use SkillSpector in GitLab CI: Automated Security Scanning for AI Agents](/NVIDIA/SkillSpector/how-can-skillspector-be-used-in-gitlab-ci)

Learn to integrate SkillSpector into GitLab CI for automated AI agent security scanning. Generate SARIF reports and set risk score thresholds to ensure code quality.

- Tags: how-to-guide
- Published: 2026-06-14

### [How to Configure SkillSpector for GitHub Actions: Complete CI/CD Integration Guide](/NVIDIA/SkillSpector/how-do-i-configure-skillspector-for-github-actions)

Integrate SkillSpector into your GitHub Actions CI/CD pipeline using the official nvidia skillspector action. Generate SARIF reports for the GitHub Security Dashboard seamlessly.

- Tags: how-to-guide
- Published: 2026-06-14

### [How to Integrate SkillSpector into Your CI/CD Pipeline for Automated AI Security Scanning](/NVIDIA/SkillSpector/how-can-i-integrate-skillspector-into-my-ci-cd-pipeline)

Integrate SkillSpector into your CI/CD pipeline for automated AI security scanning. Run the scan command and upload the SARIF report to detect vulnerabilities in every code change.

- Tags: how-to-guide
- Published: 2026-06-14

### [LangGraph in SkillSpector: Orchestrating AI Security Scanning Workflows](/NVIDIA/SkillSpector/what-is-role-of-langgraph-in-skillspector-architecture)

Discover how LangGraph orchestrates AI security scanning workflows in NVIDIA SkillSpector. Learn about its state-driven pipeline for deterministic analysis and reporting.

- Tags: architecture
- Published: 2026-06-14

### [How SkillSpector Uses LLM Semantic Analysis in Its Second Stage](/NVIDIA/SkillSpector/how-does-skillspector-use-llm-semantic-analysis-in-second-stage)

Discover how SkillSpector's second stage leverages LLM semantic analysis to filter, enrich, and validate vulnerabilities with high confidence, ensuring accurate security findings.

- Tags: internals
- Published: 2026-06-14

### [What Security Issues Does SkillSpector’s First Stage Detect?](/NVIDIA/SkillSpector/what-types-of-security-issues-does-skillspector-first-stage-detect)

SkillSpector's first stage statically detects 64 risky constructs in 16 categories like prompt injection and data exfiltration without running code.

- Tags: internals
- Published: 2026-06-14

### [How SkillSpector's Two-Stage Analysis Pipeline Works](/NVIDIA/SkillSpector/how-does-skillspector-two-stage-analysis-pipeline-work)

Discover how SkillSpector's two-stage analysis pipeline works for AI agent skills. It uses fast static analysis and optional LLM semantic analysis for accurate findings and risk context.

- Tags: internals
- Published: 2026-06-14

### [AST-Based Behavioral Analysis Patterns in SkillSpector: The 8 Detection Rules Explained](/NVIDIA/SkillSpector/what-ast-based-behavioral-analysis-patterns-skillspector-looks-for)

Discover the 8 AST-based behavioral analysis patterns SkillSpector detects in Python. Understand exec calls, eval, and dangerous execution chains reported in SARIF.

- Tags: deep-dive
- Published: 2026-06-12

### [How SkillSpector's Python API Handles LLM Analysis: A Deep Dive into the Two-Stage Pipeline](/NVIDIA/SkillSpector/how-skillspector-python-api-handles-llm-analysis)

Explore SkillSpector's Python API and its two stage pipeline for LLM analysis. Discover how it batches code, crafts prompts, and generates security findings.

- Tags: deep-dive
- Published: 2026-06-12

### [How to Get JSON Output from SkillSpector](/NVIDIA/SkillSpector/how-to-get-json-output-from-skillspector-scan)

Learn how to get JSON output from SkillSpector scans. Use the --format json flag and optionally specify an output file path for seamless integration.

- Tags: how-to-guide
- Published: 2026-06-12

### [SkillSpector Scan Commands: CLI Reference for Analyzing AI Skill Bundles](/NVIDIA/SkillSpector/what-are-typical-commands-to-scan-with-skillspector)

Master SkillSpector scan commands with this CLI reference. Analyze AI skill bundles from local dirs, Git URLs, or zip files. Get output in terminal, JSON, Markdown, or SARIF.

- Tags: api-reference
- Published: 2026-06-12

### [How OSV.dev Lookup Results Are Cached in SkillSpector: In-Memory TTL Strategy](/NVIDIA/SkillSpector/how-are-results-cached-during-osv-dev-lookups)

Discover how SkillSpector caches OSV.dev lookup results using an in-memory TTL strategy for faster batch analysis and reduced network requests.

- Tags: internals
- Published: 2026-06-12

### [How SkillSpector Handles Unreachable OSV.dev in Offline Environments](/NVIDIA/SkillSpector/how-skillspector-handles-offline-osv-dev-environments)

SkillSpector ensures continuous scanning in air-gapped environments by handling unreachable OSV.dev with network exception catching and fallback to static patterns.

- Tags: how-to-guide
- Published: 2026-06-12

### [How SkillSpector Performs OSV.dev Vulnerability Lookups for Dependencies](/NVIDIA/SkillSpector/how-skillspector-performs-osv-dev-vulnerability-lookups)

Discover how SkillSpector secures dependencies with efficient OSV.dev vulnerability lookups batching API requests caching results and using static fallback lists.

- Tags: how-to-guide
- Published: 2026-06-12

### [How SkillSpector Uses SARIF Output for Security Dashboards: Architecture and Integration](/NVIDIA/SkillSpector/how-skillspector-uses-sarif-output-for-security-dashboards)

Learn how SkillSpector uses SARIF output to power security dashboards. Integrate findings with GitHub Advanced Security and Azure DevOps for robust security insights.

- Tags: architecture
- Published: 2026-06-12

### [How to Disable LLM Analysis in SkillSpector for Faster Scans](/NVIDIA/SkillSpector/how-to-disable-llm-analysis-in-skillspector)

Speed up SkillSpector scans by disabling LLM analysis. Learn how to use the --no-llm flag for faster static-only checks and eliminate network overhead.

- Tags: how-to-guide
- Published: 2026-06-12

### [How the First Stage of SkillSpector's Analysis Works: Input Resolution Explained](/NVIDIA/SkillSpector/how-does-the-first-stage-of-skillspector-analysis-work)

Discover how SkillSpector's resolve input stage transforms diverse references like Git URLs and local directories into a standardized path for effective scanning. Learn more.

- Tags: internals
- Published: 2026-06-12

### [How NVIDIA SkillSpector Uses a Two-Stage Analysis Pipeline to Scan AI Agent Skills](/NVIDIA/SkillSpector/what-is-the-two-stage-analysis-pipeline-in-skillspector)

Explore SkillSpector's two-stage analysis pipeline. Discover how this NVIDIA tool uses static scan and LLM semantic review to find AI agent vulnerabilities and provide remediation guidance.

- Tags: deep-dive
- Published: 2026-06-12

### [How SkillSpector Merges Custom YARA Rules with Built-In Rules](/NVIDIA/SkillSpector/how-skillspector-merges-custom-yara-rules)

Discover how SkillSpector merges custom and built-in YARA rules for enhanced threat detection. Learn about namespace collision safety and performance caching in NVIDIA/SkillSpector.

- Tags: how-to-guide
- Published: 2026-06-12

### [The 4 Prompt Injection Patterns Detected by NVIDIA SkillSpector](/NVIDIA/SkillSpector/what-are-the-5-prompt-injection-patterns-skillspector-identifies)

NVIDIA SkillSpector detects 4 prompt injection patterns like Instruction Override and Exfiltration Commands. Learn to identify and prevent attacks with this powerful tool.

- Tags: deep-dive
- Published: 2026-06-12

