How Many Vulnerability Patterns Does SkillSpector Detect? A Complete Breakdown of NVIDIA's LLM Security Rules

SkillSpector detects exactly 59 distinct vulnerability patterns, defined in the DEFAULT_EXPLANATIONS dictionary of the pattern_defaults.py module.

NVIDIA's SkillSpector is an open-source security analysis tool designed to identify vulnerabilities in LLM-generated code and skills. If you are evaluating this static analyzer, you need to know exactly how many vulnerability patterns SkillSpector detects and where they are defined. This article examines the complete catalog of 59 security rules implemented in the repository, their source code organization, and programmatic access methods.

The Complete Catalog of 59 Vulnerability Patterns

SkillSpector organizes its security rules into 59 unique pattern identifiers stored in src/skillspector/nodes/analyzers/pattern_defaults.py. The DEFAULT_EXPLANATIONS dictionary maps each identifier to a human-readable explanation, remediation strategy, and category classification.

The patterns use alphabetical prefixes to denote logical groupings:

  • P series (P1–P8): 8 patterns
  • E series (E1–E4): 4 patterns
  • PE series (PE1–PE3): 3 patterns
  • SC series (SC1–SC6): 6 patterns
  • EA series (EA1–EA4): 4 patterns
  • OH series (OH1–OH3): 3 patterns
  • MP series (MP1–MP3): 3 patterns
  • TM series (TM1–TM3): 3 patterns
  • RA series (RA1–RA2): 2 patterns
  • TR series (TR1–TR3): 3 patterns
  • TT series (TT1–TT5): 5 patterns
  • YR series (YR1–YR4): 4 patterns
  • LP series (LP1–LP4): 4 patterns
  • TP series (TP1–TP4): 4 patterns
  • AS series (AS1–AS3): 3 patterns

Each identifier corresponds to a specific security antipattern ranging from prompt injection vulnerabilities to unsafe code execution paths.

Where Patterns Are Defined in the Source Code

The canonical definition of all 59 patterns resides in src/skillspector/nodes/analyzers/pattern_defaults.py. This module exports the DEFAULT_EXPLANATIONS dictionary, which serves as the central registry for pattern metadata.

Key files in the pattern detection pipeline include:

How to Query the Pattern Count Programmatically

You can verify the total count of vulnerability patterns dynamically by inspecting the DEFAULT_EXPLANATIONS dictionary at runtime. This approach ensures you are working with the exact rule set loaded in your SkillSpector installation.

from skillspector.nodes.analyzers import pattern_defaults

# Count entries in the central pattern registry

num_patterns = len(pattern_defaults.DEFAULT_EXPLANATIONS)

print(f"SkillSpector detects {num_patterns} vulnerability patterns.")

# Output: SkillSpector detects 59 vulnerability patterns.

This snippet imports the analyzer module and counts the dictionary entries, returning the current total of defined security patterns. Each entry includes the pattern ID, default explanation, remediation guidance, category classification, and display name.

Summary

  • SkillSpector defines 59 distinct vulnerability patterns across 15 categorical prefixes.
  • Patterns are centrally registered in src/skillspector/nodes/analyzers/pattern_defaults.py within the DEFAULT_EXPLANATIONS dictionary.
  • The detection engine in meta_analyzer.py references these definitions to flag security issues in LLM outputs.
  • You can programmatically verify the pattern count by checking the length of DEFAULT_EXPLANATIONS.

Frequently Asked Questions

How many vulnerability patterns does SkillSpector detect?

SkillSpector detects exactly 59 vulnerability patterns. These are enumerated in the DEFAULT_EXPLANATIONS dictionary in the pattern_defaults.py module, with identifiers ranging from P1 to AS3 across multiple security categories.

What categories do the SkillSpector vulnerability patterns cover?

The 59 patterns are organized into 15 alphabetical prefixes (P, E, PE, SC, EA, OH, MP, TM, RA, TR, TT, YR, LP, TP, AS). Each prefix groups related security antipatterns, with full metadata including descriptions and remediations stored in the central pattern registry.

Where are the pattern definitions stored in the SkillSpector repository?

All pattern definitions reside in src/skillspector/nodes/analyzers/pattern_defaults.py. This file contains the DEFAULT_EXPLANATIONS dictionary that maps each pattern ID to its metadata, while src/skillspector/nodes/analyzers/__init__.py exposes helper functions for accessing specific pattern details.

How can I access the explanation for a specific vulnerability pattern?

Import the pattern_defaults module and query the DEFAULT_EXPLANATIONS dictionary directly, or use the helper functions exposed in the analyzers package. Each entry provides the human-readable explanation, remediation steps, and category classification for the corresponding pattern ID.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →