Complete List of 68 SkillSpector Vulnerability Patterns and Severity Levels
SkillSpector identifies 68 distinct AI security vulnerability patterns—ranging from Prompt Injection to Supply Chain risks—each mapped to a default severity level (LOW, MEDIUM, HIGH, or CRITICAL) defined in specialized analyzer modules.
NVIDIA's SkillSpector is a static analysis framework designed to scan AI skills and agents for security vulnerabilities. The tool catalogs every security finding using a standardized pattern ID system (such as SC4 or P1) and assigns a default severity based on the underlying risk. Understanding these SkillSpector vulnerability patterns and their severity levels is essential for prioritizing remediation efforts in AI application development.
How SkillSpector Classifies Vulnerabilities
SkillSpector uses a centralized catalog defined in src/skillspector/nodes/analyzers/pattern_defaults.py to register pattern IDs, while individual analyzer modules in src/skillspector/nodes/analyzers/ assign the specific severity. The severity levels follow the Severity enum defined in src/skillspector/models.py, supporting four values: LOW, MEDIUM, HIGH, and CRITICAL.
Each pattern ID follows a category prefix convention:
- P*: Prompt Injection and Harmful Content
- E*: Data Exfiltration
- PE*: Privilege Escalation
- SC*: Supply Chain
- EA*: Excessive Agency
- OH*: Output Handling
- MP*: Memory Poisoning
- TM*: Tool Misuse
- RA*: Rogue Agent
- TR*: Trigger Abuse
- TT*: Behavioral Taint Tracking
- YR*: YARA Rules
- LP*: MCP Least Privilege
- TP*: MCP Tool Poisoning
- AS*: Agent Snooping
- AR*: Anti-Refusal (Jailbreak)
- SSRF*: Server-Side Request Forgery
Complete SkillSpector Vulnerability Patterns Reference
The following sections detail all 68 vulnerability patterns organized by category, including their default severity and the source analyzer module that defines them.
Prompt Injection and Harmful Content
These patterns detect attempts to manipulate AI behavior through malicious inputs or bypass safety controls.
- P1: HIGH —
static_patterns_prompt_injection.py - P2: HIGH —
static_patterns_prompt_injection.py - P3: HIGH —
static_patterns_prompt_injection.py - P4: MEDIUM —
static_patterns_prompt_injection.py - P5: CRITICAL —
static_patterns_harmful_content.py - P6: HIGH —
static_patterns_system_prompt_leakage.py - P7: HIGH —
static_patterns_system_prompt_leakage.py - P8: HIGH —
static_patterns_system_prompt_leakage.py
Data Exfiltration
Patterns identifying pathways where sensitive data may leak outside the system boundaries.
- E1: HIGH —
static_patterns_data_exfiltration.py - E2: HIGH —
static_patterns_data_exfiltration.py - E3: HIGH —
static_patterns_data_exfiltration.py - E4: HIGH —
static_patterns_data_exfiltration.py - E5: HIGH —
static_patterns_data_exfiltration.py
Privilege Escalation
Detects mechanisms that could allow an AI agent to gain unauthorized elevated permissions.
- PE1: HIGH —
static_patterns_privilege_escalation.py - PE2: HIGH —
static_patterns_privilege_escalation.py - PE3: HIGH —
static_patterns_privilege_escalation.py
Supply Chain
Identifies vulnerabilities in dependencies, packages, and third-party components used by AI skills.
- SC1: LOW —
static_patterns_supply_chain.py - SC2: HIGH —
static_patterns_supply_chain.py - SC3: MEDIUM —
static_patterns_supply_chain.py - SC4: MEDIUM (OSV-mapped; worst-case CRITICAL) —
static_patterns_supply_chain.py - SC5: MEDIUM —
static_patterns_supply_chain.py - SC6: MEDIUM —
static_patterns_supply_chain.py
Excessive Agency
Flags capabilities where the AI has more autonomy than necessary, increasing risk of unintended actions.
- EA1: HIGH —
static_patterns_excessive_agency.py - EA2: HIGH —
static_patterns_excessive_agency.py - EA3: MEDIUM —
static_patterns_excessive_agency.py - EA4: MEDIUM —
static_patterns_excessive_agency.py
Output Handling
Detects insecure processing of AI-generated outputs that could lead to injection or XSS attacks.
- OH1: HIGH —
static_patterns_output_handling.py - OH2: HIGH —
static_patterns_output_handling.py - OH3: MEDIUM —
static_patterns_output_handling.py
Memory Poisoning
Identifies attacks targeting the AI's context window or long-term memory stores.
- MP1: MEDIUM —
static_patterns_memory_poisoning.py - MP2: MEDIUM —
static_patterns_memory_poisoning.py - MP3: HIGH —
static_patterns_memory_poisoning.py
Tool Misuse
Detects improper or dangerous usage patterns of connected tools and function calls.
- TM1: MEDIUM —
static_patterns_tool_misuse.py - TM2: MEDIUM —
static_patterns_tool_misuse.py - TM3: MEDIUM —
static_patterns_tool_misuse.py - TM4: HIGH —
static_patterns_tool_misuse.py
Rogue Agent
Flags behavior indicating an AI agent may be operating outside intended parameters or security boundaries.
- RA1: HIGH —
static_patterns_rogue_agent.py - RA2: HIGH —
static_patterns_rogue_agent.py
Trigger Abuse
Detects manipulation of event triggers or scheduling mechanisms within AI workflows.
- TR1: HIGH —
static_patterns_trigger_abuse.py - TR2: HIGH —
static_patterns_trigger_abuse.py - TR3: MEDIUM —
static_patterns_trigger_abuse.py
Behavioral Taint Tracking
Dynamic analysis patterns tracking data flow from untrusted sources through the application.
- TT1: HIGH —
behavioral_taint_tracking.py - TT2: MEDIUM —
behavioral_taint_tracking.py - TT3: CRITICAL —
behavioral_taint_tracking.py - TT4: HIGH —
behavioral_taint_tracking.py - TT5: CRITICAL —
behavioral_taint_tracking.py
YARA Rules
Pattern matching for known malicious signatures using YARA-based detection.
- YR1: CRITICAL —
static_patterns_yara.py - YR2: CRITICAL —
static_patterns_yara.py - YR3: HIGH —
static_patterns_yara.py - YR4: HIGH —
static_patterns_yara.py
MCP Least Privilege
Ensures Model Context Protocol (MCP) servers and clients adhere to minimal permission principles.
- LP1: HIGH —
mcp_least_privilege.py - LP2: HIGH —
mcp_least_privilege.py - LP3: HIGH —
mcp_least_privilege.py - LP4: MEDIUM —
mcp_least_privilege.py
MCP Tool Poisoning
Detects compromised or malicious tool definitions within MCP implementations.
- TP1: HIGH —
mcp_tool_poisoning.py - TP2: HIGH —
mcp_tool_poisoning.py - TP3: HIGH —
mcp_tool_poisoning.py - TP4: HIGH —
mcp_tool_poisoning.py
Agent Snooping
Identifies unauthorized information gathering by AI agents beyond their intended scope.
- AS1: HIGH —
static_patterns_agent_snooping.py - AS2: HIGH —
static_patterns_agent_snooping.py - AS3: HIGH —
static_patterns_agent_snooping.py
Anti-Refusal (Jailbreak)
Detects prompt engineering attempts designed to bypass safety refusals or content policies.
- AR1: HIGH —
static_patterns_anti_refusal.py - AR2: HIGH —
static_patterns_anti_refusal.py - AR3: CRITICAL —
static_patterns_anti_refusal.py
Server-Side Request Forgery (SSRF)
Patterns identifying vulnerabilities allowing unauthorized external network requests.
- SSRF1: HIGH —
static_patterns_ssrf.py - SSRF2: MEDIUM —
static_patterns_ssrf.py - SSRF3: MEDIUM —
static_patterns_ssrf.py
How Severities Are Assigned in the Source Code
Severity assignment occurs within each analyzer's implementation. When an analyzer detects a vulnerability, it instantiates an AnalyzerFinding object with a Severity enum value from src/skillspector/models.py.
For example, Supply Chain pattern SC4 dynamically maps severity based on OSV (Open Source Vulnerabilities) database entries, defaulting to MEDIUM but escalating to CRITICAL for severe CVEs. Conversely, SC1 maintains a static LOW severity for informational dependency findings.
The master dictionary DEFAULT_EXPLANATIONS in pattern_defaults.py contains metadata and human-readable descriptions for each of the 67 cataloged patterns, with the full set of 68 patterns including the System Prompt Leakage variants (P6-P8).
Querying Pattern Information Programmatically
You can retrieve pattern metadata programmatically using SkillSpector's Python API:
from skillspector.nodes.analyzers.pattern_defaults import get_pattern_name, get_category
def get_pattern_details(pattern_id: str):
"""Retrieve human-readable details for any SkillSpector pattern ID."""
name = get_pattern_name(pattern_id)
category = get_category(pattern_id)
# Note: Severity is determined by the emitting analyzer at detection time
return {
"id": pattern_id,
"name": name,
"category": category
}
# Example usage
print(get_pattern_details("SC4"))
print(get_pattern_details("TT3"))
When running scans via CLI, the severity appears in SARIF output:
# Analyze a skill directory
skillspector analyze path/to/skill
# Example SARIF excerpt showing severity
{
"ruleId": "SC4",
"level": "warning",
"message": "Known Vulnerable Dependency",
"properties": {
"severity": "MEDIUM"
}
}
Summary
- SkillSpector defines 68 vulnerability patterns across 17 security categories, from Prompt Injection to SSRF.
- Severity levels (LOW, MEDIUM, HIGH, CRITICAL) are assigned by specialized analyzers in
src/skillspector/nodes/analyzers/. - The master pattern catalog resides in
pattern_defaults.py, while severity logic is implemented in individual analyzer modules (e.g.,static_patterns_prompt_injection.py,behavioral_taint_tracking.py). - Critical severity patterns include
P5,TT3,TT5,YR1,YR2, andAR3, indicating immediate remediation priority. - Supply Chain pattern
SC4uniquely supports dynamic severity mapping based on external OSV database severity ratings.
Frequently Asked Questions
What are the most critical vulnerability patterns in SkillSpector?
The patterns assigned CRITICAL severity are P5 (Harmful Content), TT3 and TT5 (Behavioral Taint Tracking), YR1 and YR2 (YARA Rules), and AR3 (Anti-Refusal/Jailbreak). These represent the highest risk findings and should be addressed immediately according to the NVIDIA/SkillSpector security guidelines.
How does SkillSpector determine severity for Supply Chain vulnerabilities?
Supply Chain pattern SC4 dynamically maps its severity from the Open Source Vulnerabilities (OSV) database rather than using a static value. While it defaults to MEDIUM, the analyzer in static_patterns_supply_chain.py escalates the finding to CRITICAL when the OSV entry indicates severe impact. Other Supply Chain patterns (SC1, SC2, etc.) use static severity assignments defined in their respective analyzer modules.
Can I customize the severity levels for specific SkillSpector patterns?
SkillSpector uses hardcoded severity values in the analyzer source code to ensure consistency across deployments. You cannot override these defaults via configuration files. However, when processing SARIF output from the tool, your CI/CD pipeline or security platform can apply custom severity mapping based on your organization's risk tolerance.
Where can I find the complete mapping of pattern IDs to remediation advice?
Remediation guidance for all 68 patterns is stored in the DEFAULT_EXPLANATIONS dictionary within src/skillspector/nodes/analyzers/pattern_defaults.py. This file contains human-readable descriptions, recommended fixes, and references to security best practices for each pattern ID, accessible programmatically through the get_pattern_name() and related utility functions.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →