# Complete List of 68 SkillSpector Vulnerability Patterns and Severity Levels

> Explore the comprehensive list of 68 SkillSpector vulnerability patterns and their severity levels. Understand AI security risks from Prompt Injection to Supply Chain threats. Learn more today!

- Repository: [NVIDIA Corporation/SkillSpector](https://github.com/NVIDIA/SkillSpector)
- Tags: api-reference
- Published: 2026-07-09

---

**SkillSpector identifies 68 distinct AI security vulnerability patterns—ranging from Prompt Injection to Supply Chain risks—each mapped to a default severity level (LOW, MEDIUM, HIGH, or CRITICAL) defined in specialized analyzer modules.**

NVIDIA's SkillSpector is a static analysis framework designed to scan AI skills and agents for security vulnerabilities. The tool catalogs every security finding using a standardized pattern ID system (such as `SC4` or `P1`) and assigns a default severity based on the underlying risk. Understanding these **SkillSpector vulnerability patterns** and their severity levels is essential for prioritizing remediation efforts in AI application development.

## How SkillSpector Classifies Vulnerabilities

SkillSpector uses a centralized catalog defined in [`src/skillspector/nodes/analyzers/pattern_defaults.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/nodes/analyzers/pattern_defaults.py) to register pattern IDs, while individual analyzer modules in `src/skillspector/nodes/analyzers/` assign the specific severity. The severity levels follow the `Severity` enum defined in [`src/skillspector/models.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/models.py), supporting four values: **LOW**, **MEDIUM**, **HIGH**, and **CRITICAL**.

Each pattern ID follows a category prefix convention:
- **P***: Prompt Injection and Harmful Content
- **E***: Data Exfiltration
- **PE***: Privilege Escalation
- **SC***: Supply Chain
- **EA***: Excessive Agency
- **OH***: Output Handling
- **MP***: Memory Poisoning
- **TM***: Tool Misuse
- **RA***: Rogue Agent
- **TR***: Trigger Abuse
- **TT***: Behavioral Taint Tracking
- **YR***: YARA Rules
- **LP***: MCP Least Privilege
- **TP***: MCP Tool Poisoning
- **AS***: Agent Snooping
- **AR***: Anti-Refusal (Jailbreak)
- **SSRF***: Server-Side Request Forgery

## Complete SkillSpector Vulnerability Patterns Reference

The following sections detail all 68 vulnerability patterns organized by category, including their default severity and the source analyzer module that defines them.

### Prompt Injection and Harmful Content

These patterns detect attempts to manipulate AI behavior through malicious inputs or bypass safety controls.

- **P1**: **HIGH** — [`static_patterns_prompt_injection.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_prompt_injection.py)
- **P2**: **HIGH** — [`static_patterns_prompt_injection.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_prompt_injection.py)
- **P3**: **HIGH** — [`static_patterns_prompt_injection.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_prompt_injection.py)
- **P4**: **MEDIUM** — [`static_patterns_prompt_injection.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_prompt_injection.py)
- **P5**: **CRITICAL** — [`static_patterns_harmful_content.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_harmful_content.py)
- **P6**: **HIGH** — [`static_patterns_system_prompt_leakage.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_system_prompt_leakage.py)
- **P7**: **HIGH** — [`static_patterns_system_prompt_leakage.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_system_prompt_leakage.py)
- **P8**: **HIGH** — [`static_patterns_system_prompt_leakage.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_system_prompt_leakage.py)

### Data Exfiltration

Patterns identifying pathways where sensitive data may leak outside the system boundaries.

- **E1**: **HIGH** — [`static_patterns_data_exfiltration.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_data_exfiltration.py)
- **E2**: **HIGH** — [`static_patterns_data_exfiltration.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_data_exfiltration.py)
- **E3**: **HIGH** — [`static_patterns_data_exfiltration.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_data_exfiltration.py)
- **E4**: **HIGH** — [`static_patterns_data_exfiltration.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_data_exfiltration.py)
- **E5**: **HIGH** — [`static_patterns_data_exfiltration.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_data_exfiltration.py)

### Privilege Escalation

Detects mechanisms that could allow an AI agent to gain unauthorized elevated permissions.

- **PE1**: **HIGH** — [`static_patterns_privilege_escalation.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_privilege_escalation.py)
- **PE2**: **HIGH** — [`static_patterns_privilege_escalation.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_privilege_escalation.py)
- **PE3**: **HIGH** — [`static_patterns_privilege_escalation.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_privilege_escalation.py)

### Supply Chain

Identifies vulnerabilities in dependencies, packages, and third-party components used by AI skills.

- **SC1**: **LOW** — [`static_patterns_supply_chain.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_supply_chain.py)
- **SC2**: **HIGH** — [`static_patterns_supply_chain.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_supply_chain.py)
- **SC3**: **MEDIUM** — [`static_patterns_supply_chain.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_supply_chain.py)
- **SC4**: **MEDIUM** (OSV-mapped; worst-case **CRITICAL**) — [`static_patterns_supply_chain.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_supply_chain.py)
- **SC5**: **MEDIUM** — [`static_patterns_supply_chain.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_supply_chain.py)
- **SC6**: **MEDIUM** — [`static_patterns_supply_chain.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_supply_chain.py)

### Excessive Agency

Flags capabilities where the AI has more autonomy than necessary, increasing risk of unintended actions.

- **EA1**: **HIGH** — [`static_patterns_excessive_agency.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_excessive_agency.py)
- **EA2**: **HIGH** — [`static_patterns_excessive_agency.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_excessive_agency.py)
- **EA3**: **MEDIUM** — [`static_patterns_excessive_agency.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_excessive_agency.py)
- **EA4**: **MEDIUM** — [`static_patterns_excessive_agency.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_excessive_agency.py)

### Output Handling

Detects insecure processing of AI-generated outputs that could lead to injection or XSS attacks.

- **OH1**: **HIGH** — [`static_patterns_output_handling.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_output_handling.py)
- **OH2**: **HIGH** — [`static_patterns_output_handling.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_output_handling.py)
- **OH3**: **MEDIUM** — [`static_patterns_output_handling.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_output_handling.py)

### Memory Poisoning

Identifies attacks targeting the AI's context window or long-term memory stores.

- **MP1**: **MEDIUM** — [`static_patterns_memory_poisoning.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_memory_poisoning.py)
- **MP2**: **MEDIUM** — [`static_patterns_memory_poisoning.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_memory_poisoning.py)
- **MP3**: **HIGH** — [`static_patterns_memory_poisoning.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_memory_poisoning.py)

### Tool Misuse

Detects improper or dangerous usage patterns of connected tools and function calls.

- **TM1**: **MEDIUM** — [`static_patterns_tool_misuse.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_tool_misuse.py)
- **TM2**: **MEDIUM** — [`static_patterns_tool_misuse.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_tool_misuse.py)
- **TM3**: **MEDIUM** — [`static_patterns_tool_misuse.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_tool_misuse.py)
- **TM4**: **HIGH** — [`static_patterns_tool_misuse.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_tool_misuse.py)

### Rogue Agent

Flags behavior indicating an AI agent may be operating outside intended parameters or security boundaries.

- **RA1**: **HIGH** — [`static_patterns_rogue_agent.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_rogue_agent.py)
- **RA2**: **HIGH** — [`static_patterns_rogue_agent.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_rogue_agent.py)

### Trigger Abuse

Detects manipulation of event triggers or scheduling mechanisms within AI workflows.

- **TR1**: **HIGH** — [`static_patterns_trigger_abuse.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_trigger_abuse.py)
- **TR2**: **HIGH** — [`static_patterns_trigger_abuse.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_trigger_abuse.py)
- **TR3**: **MEDIUM** — [`static_patterns_trigger_abuse.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_trigger_abuse.py)

### Behavioral Taint Tracking

Dynamic analysis patterns tracking data flow from untrusted sources through the application.

- **TT1**: **HIGH** — [`behavioral_taint_tracking.py`](https://github.com/NVIDIA/SkillSpector/blob/main/behavioral_taint_tracking.py)
- **TT2**: **MEDIUM** — [`behavioral_taint_tracking.py`](https://github.com/NVIDIA/SkillSpector/blob/main/behavioral_taint_tracking.py)
- **TT3**: **CRITICAL** — [`behavioral_taint_tracking.py`](https://github.com/NVIDIA/SkillSpector/blob/main/behavioral_taint_tracking.py)
- **TT4**: **HIGH** — [`behavioral_taint_tracking.py`](https://github.com/NVIDIA/SkillSpector/blob/main/behavioral_taint_tracking.py)
- **TT5**: **CRITICAL** — [`behavioral_taint_tracking.py`](https://github.com/NVIDIA/SkillSpector/blob/main/behavioral_taint_tracking.py)

### YARA Rules

Pattern matching for known malicious signatures using YARA-based detection.

- **YR1**: **CRITICAL** — [`static_patterns_yara.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_yara.py)
- **YR2**: **CRITICAL** — [`static_patterns_yara.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_yara.py)
- **YR3**: **HIGH** — [`static_patterns_yara.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_yara.py)
- **YR4**: **HIGH** — [`static_patterns_yara.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_yara.py)

### MCP Least Privilege

Ensures Model Context Protocol (MCP) servers and clients adhere to minimal permission principles.

- **LP1**: **HIGH** — [`mcp_least_privilege.py`](https://github.com/NVIDIA/SkillSpector/blob/main/mcp_least_privilege.py)
- **LP2**: **HIGH** — [`mcp_least_privilege.py`](https://github.com/NVIDIA/SkillSpector/blob/main/mcp_least_privilege.py)
- **LP3**: **HIGH** — [`mcp_least_privilege.py`](https://github.com/NVIDIA/SkillSpector/blob/main/mcp_least_privilege.py)
- **LP4**: **MEDIUM** — [`mcp_least_privilege.py`](https://github.com/NVIDIA/SkillSpector/blob/main/mcp_least_privilege.py)

### MCP Tool Poisoning

Detects compromised or malicious tool definitions within MCP implementations.

- **TP1**: **HIGH** — [`mcp_tool_poisoning.py`](https://github.com/NVIDIA/SkillSpector/blob/main/mcp_tool_poisoning.py)
- **TP2**: **HIGH** — [`mcp_tool_poisoning.py`](https://github.com/NVIDIA/SkillSpector/blob/main/mcp_tool_poisoning.py)
- **TP3**: **HIGH** — [`mcp_tool_poisoning.py`](https://github.com/NVIDIA/SkillSpector/blob/main/mcp_tool_poisoning.py)
- **TP4**: **HIGH** — [`mcp_tool_poisoning.py`](https://github.com/NVIDIA/SkillSpector/blob/main/mcp_tool_poisoning.py)

### Agent Snooping

Identifies unauthorized information gathering by AI agents beyond their intended scope.

- **AS1**: **HIGH** — [`static_patterns_agent_snooping.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_agent_snooping.py)
- **AS2**: **HIGH** — [`static_patterns_agent_snooping.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_agent_snooping.py)
- **AS3**: **HIGH** — [`static_patterns_agent_snooping.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_agent_snooping.py)

### Anti-Refusal (Jailbreak)

Detects prompt engineering attempts designed to bypass safety refusals or content policies.

- **AR1**: **HIGH** — [`static_patterns_anti_refusal.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_anti_refusal.py)
- **AR2**: **HIGH** — [`static_patterns_anti_refusal.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_anti_refusal.py)
- **AR3**: **CRITICAL** — [`static_patterns_anti_refusal.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_anti_refusal.py)

### Server-Side Request Forgery (SSRF)

Patterns identifying vulnerabilities allowing unauthorized external network requests.

- **SSRF1**: **HIGH** — [`static_patterns_ssrf.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_ssrf.py)
- **SSRF2**: **MEDIUM** — [`static_patterns_ssrf.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_ssrf.py)
- **SSRF3**: **MEDIUM** — [`static_patterns_ssrf.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_ssrf.py)

## How Severities Are Assigned in the Source Code

Severity assignment occurs within each analyzer's implementation. When an analyzer detects a vulnerability, it instantiates an `AnalyzerFinding` object with a `Severity` enum value from [`src/skillspector/models.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/models.py).

For example, Supply Chain pattern **SC4** dynamically maps severity based on OSV (Open Source Vulnerabilities) database entries, defaulting to **MEDIUM** but escalating to **CRITICAL** for severe CVEs. Conversely, **SC1** maintains a static **LOW** severity for informational dependency findings.

The master dictionary `DEFAULT_EXPLANATIONS` in [`pattern_defaults.py`](https://github.com/NVIDIA/SkillSpector/blob/main/pattern_defaults.py) contains metadata and human-readable descriptions for each of the 67 cataloged patterns, with the full set of 68 patterns including the System Prompt Leakage variants (`P6-P8`).

## Querying Pattern Information Programmatically

You can retrieve pattern metadata programmatically using SkillSpector's Python API:

```python
from skillspector.nodes.analyzers.pattern_defaults import get_pattern_name, get_category

def get_pattern_details(pattern_id: str):
    """Retrieve human-readable details for any SkillSpector pattern ID."""
    name = get_pattern_name(pattern_id)
    category = get_category(pattern_id)
    
    # Note: Severity is determined by the emitting analyzer at detection time

    return {
        "id": pattern_id,
        "name": name,
        "category": category
    }

# Example usage

print(get_pattern_details("SC4"))
print(get_pattern_details("TT3"))

```

When running scans via CLI, the severity appears in SARIF output:

```bash

# Analyze a skill directory

skillspector analyze path/to/skill

# Example SARIF excerpt showing severity

{
  "ruleId": "SC4",
  "level": "warning",
  "message": "Known Vulnerable Dependency",
  "properties": {
    "severity": "MEDIUM"
  }
}

```

## Summary

- SkillSpector defines **68 vulnerability patterns** across 17 security categories, from Prompt Injection to SSRF.
- Severity levels (**LOW**, **MEDIUM**, **HIGH**, **CRITICAL**) are assigned by specialized analyzers in `src/skillspector/nodes/analyzers/`.
- The master pattern catalog resides in [`pattern_defaults.py`](https://github.com/NVIDIA/SkillSpector/blob/main/pattern_defaults.py), while severity logic is implemented in individual analyzer modules (e.g., [`static_patterns_prompt_injection.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_prompt_injection.py), [`behavioral_taint_tracking.py`](https://github.com/NVIDIA/SkillSpector/blob/main/behavioral_taint_tracking.py)).
- **Critical** severity patterns include `P5`, `TT3`, `TT5`, `YR1`, `YR2`, and `AR3`, indicating immediate remediation priority.
- Supply Chain pattern `SC4` uniquely supports dynamic severity mapping based on external OSV database severity ratings.

## Frequently Asked Questions

### What are the most critical vulnerability patterns in SkillSpector?

The patterns assigned **CRITICAL** severity are `P5` (Harmful Content), `TT3` and `TT5` (Behavioral Taint Tracking), `YR1` and `YR2` (YARA Rules), and `AR3` (Anti-Refusal/Jailbreak). These represent the highest risk findings and should be addressed immediately according to the NVIDIA/SkillSpector security guidelines.

### How does SkillSpector determine severity for Supply Chain vulnerabilities?

Supply Chain pattern `SC4` dynamically maps its severity from the Open Source Vulnerabilities (OSV) database rather than using a static value. While it defaults to **MEDIUM**, the analyzer in [`static_patterns_supply_chain.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_supply_chain.py) escalates the finding to **CRITICAL** when the OSV entry indicates severe impact. Other Supply Chain patterns (`SC1`, `SC2`, etc.) use static severity assignments defined in their respective analyzer modules.

### Can I customize the severity levels for specific SkillSpector patterns?

SkillSpector uses hardcoded severity values in the analyzer source code to ensure consistency across deployments. You cannot override these defaults via configuration files. However, when processing SARIF output from the tool, your CI/CD pipeline or security platform can apply custom severity mapping based on your organization's risk tolerance.

### Where can I find the complete mapping of pattern IDs to remediation advice?

Remediation guidance for all 68 patterns is stored in the `DEFAULT_EXPLANATIONS` dictionary within [`src/skillspector/nodes/analyzers/pattern_defaults.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/nodes/analyzers/pattern_defaults.py). This file contains human-readable descriptions, recommended fixes, and references to security best practices for each pattern ID, accessible programmatically through the `get_pattern_name()` and related utility functions.