# The 68 Vulnerability Patterns Detected by SkillSpector: Complete Reference

> Explore the 68 vulnerability patterns SkillSpector detects. Understand each rule ID for prompt injection, environment variable harvesting, and more from NVIDIA. Enhance your code security.

- Repository: [NVIDIA Corporation/SkillSpector](https://github.com/NVIDIA/SkillSpector)
- Tags: api-reference
- Published: 2026-07-12

---

**NVIDIA SkillSpector detects 68 distinct vulnerability patterns organized into 17 high-level categories, mapping each finding to specific rule IDs—such as `P1` for Prompt Injection or `E2` for Environment Variable Harvesting—defined in [`pattern_defaults.py`](https://github.com/NVIDIA/SkillSpector/blob/main/pattern_defaults.py) and surfaced via static and behavioral analyzers.**

NVIDIA SkillSpector is an open-source security scanner designed to audit AI skills and agents for security flaws. The tool implements a comprehensive taxonomy of **68 vulnerability patterns** that cover everything from prompt injection to supply chain risks. Each pattern is assigned a unique rule ID and linked to one of 17 categories defined in the `PatternCategory` enum, providing developers with actionable remediation guidance.

## The 17 Vulnerability Categories

SkillSpector classifies findings using the `PatternCategory` enum defined in [[`src/skillspector/nodes/analyzers/pattern_defaults.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/nodes/analyzers/pattern_defaults.py)](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/nodes/analyzers/pattern_defaults.py#L24-L44). These categories represent the I7 vulnerability taxonomy:

- **Prompt Injection** – Attempts to override system instructions or ignore safety constraints.
- **Data Exfiltration** – Leakage of environment variables, files, or conversation context.
- **Privilege Escalation** – Requests for higher privileges or access to credential files.
- **Supply Chain** – Risks from unpinned dependencies, typosquatting, or known CVEs.
- **Excessive Agency** – Unrestricted tool access or autonomous high-impact decisions.
- **Output Handling** – Unsanitized model output fed into other security contexts.
- **System Prompt Leakage** – Direct or indirect exposure of system prompts.
- **Memory Poisoning** – Persistent content injection or context window manipulation.
- **Tool Misuse** – Unsafe parameters or chaining of tools.
- **Rogue Agent** – Self-modifying code or persistence mechanisms.
- **Trigger Abuse** – Overly broad or conflicting trigger patterns.
- **YARA Match** – Known malware signatures detected by YARA rules.
- **MCP Least Privilege** – Capability-declared permission mismatches.
- **MCP Tool Poisoning** – Hidden metadata or deceptive descriptions in skill manifests.
- **Agent Snooping** – Reading agent configuration or other skill files.
- **Anti-Refusal** – Instructions that suppress safety refusals.
- **Server-Side Request Forgery** – Network requests targeting internal services.

## The 68 Detectable Patterns by Category

Each pattern corresponds to a **rule ID** (e.g., `P1`, `E2`, `LP3`) defined across three dictionaries in [`pattern_defaults.py`](https://github.com/NVIDIA/SkillSpector/blob/main/pattern_defaults.py): `DEFAULT_EXPLANATIONS` (lines 46-138), `RULE_ID_TO_CATEGORY` (lines 141-213), and `PATTERN_NAMES` (lines 216-288). The complete list includes 59 static patterns with explicit explanations and 9 behavioral AST patterns.

### Prompt Injection (P1–P5)

- **`P1` – Override Instructions**: Attempts to override system instructions or ignore safety constraints.
- **`P2` – Hidden Instructions**: Instructions concealed in comments or invisible text.
- **`P3` – External Transmission Instructions**: Directs the agent to send conversation context to external services.
- **`P4` – Subtle Steering**: Instructions that may alter agent decision-making without explicit commands.
- **`P5` – Harmful Content**: Content that could cause physical harm if executed.

### System Prompt Leakage (P6–P8)

- **`P6` – System Prompt Leakage**: Direct exposure of system prompts or internal rules.
- **`P7` – System Prompt Leakage**: Indirect extraction via rephrasing, translation, or summarization.
- **`P8` – System Prompt Leakage**: Exfiltration of system prompts via tool calls.

### Data Exfiltration (E1–E4)

- **`E1` – External Transmission**: Data sent to external URLs, potentially telemetry or exfiltration.
- **`E2` – Env Variable Harvesting**: Access to environment variables that may contain secrets.
- **`E3` – File System Enumeration**: Scans directories for sensitive files.
- **`E4` – Conversation Context Leak**: Leaks agent conversation context to external services.

### Privilege Escalation (PE1–PE3)

- **`PE1` – Excessive Permissions**: Skill requests more permissions than needed.
- **`PE2` – Sudo/Root Invocation**: Uses sudo or root privileges.
- **`PE3` – Credential File Access**: Accesses credential files such as SSH keys or AWS credentials.

### Supply Chain (SC1–SC6)

- **`SC1` – Unpinned Dependencies**: Dependencies lack version pinning.
- **`SC2` – Remote Code Execution**: Remote code downloaded and executed.
- **`SC3` – Obfuscated Code**: Base64 or hex encoded code with execution.
- **`SC4` – Known Vulnerable Dependency**: Dependency has known CVEs.
- **`SC5` – Abandoned Dependency**: Dependency appears unmaintained.
- **`SC6` – Typosquatting Dependency**: Package name resembles a popular one (possible typosquatting).

### Excessive Agency (EA1–EA4)

- **`EA1` – Unrestricted Tool Access**: Skill grants unrestricted tool access.
- **`EA2` – Autonomous Decision Making**: High-impact decisions without human-in-the-loop.
- **`EA3` – Scope Creep**: Skill performs actions outside its stated purpose.
- **`EA4` – Unbounded Resource Access**: No limits on API calls, storage, or compute.

### Output Handling (OH1–OH3)

- **`OH1` – Unvalidated Output Injection**: Model output used without validation or sanitization.
- **`OH2` – Cross-Context Output**: Output moved between security contexts without checks.
- **`OH3` – Unbounded Output**: No limits on output size or generation rate.

### Memory Poisoning (MP1–MP3)

- **`MP1` – Persistent Context Injection**: Injects content that persists across interactions.
- **`MP2` – Context Window Stuffing**: Filler content displaces legitimate instructions.
- **`MP3` – Memory Manipulation**: Manipulates agent memory or state.

### Tool Misuse (TM1–TM3)

- **`TM1` – Tool Parameter Abuse**: Unsafe tool parameters (e.g., `shell=True`).
- **`TM2` – Chaining Abuse**: Chains tools to bypass safety checks.
- **`TM3` – Unsafe Defaults**: Default tool settings that are insecure.

### Rogue Agent (RA1–RA2)

- **`RA1` – Self-Modification**: Skill modifies its own code or configuration at runtime.
- **`RA2` – Session Persistence**: Creates cron jobs, startup scripts, or state files.

### MCP Least Privilege (LP1–LP4)

- **`LP1` – Underdeclared Capability**: Uses capabilities not covered by declared permissions.
- **`LP2` – Wildcard Permission**: Permission list contains a wildcard (`*`).
- **`LP3` – Missing Permission Declaration**: No permissions field but capabilities are used.
- **`LP4` – Overdeclared Permission**: Permission declared but no corresponding code capability.

### MCP Tool Poisoning (TP1–TP4)

- **`TP1` – Hidden Instructions**: Hidden instructions in skill metadata.
- **`TP2` – Unicode Deception**: Homoglyphs, RTL overrides, or invisible characters.
- **`TP3` – Parameter Description Injection**: Malicious content in parameter descriptions or defaults.
- **`TP4` – Description-Behavior Mismatch**: Skill description does not match actual code behavior.

### Agent Snooping (AS1–AS3)

- **`AS1` – Agent Config Directory Access**: Reads `.claude/`, `.codex/`, or `.gemini/` directories.
- **`AS2` – MCP Config Access**: Reads [`mcp.json`](https://github.com/NVIDIA/SkillSpector/blob/main/mcp.json) containing server URLs, tokens, or tool definitions.
- **`AS3` – Skill Enumeration**: Reads other installed skills' [`SKILL.md`](https://github.com/NVIDIA/SkillSpector/blob/main/SKILL.md) files.

### Anti-Refusal (AR1–AR3)

- **`AR1` – Refusal Suppression**: Instructs the agent to never refuse.
- **`AR2` – Disclaimer Suppression**: Instructs the agent to omit warnings or disclaimers.
- **`AR3` – Safety Policy Nullification**: Directly attempts to nullify safety policies.

### Server-Side Request Forgery (SSRF1–SSRF3)

- **`SSRF1` – Cloud Metadata Access**: Accesses cloud instance metadata (e.g., `169.254.169.254`).
- **`SSRF2` – Internal Network Request**: Requests to loopback, link-local, or private-range hosts.
- **`SSRF3` – Dynamic Request Target**: Builds request target from untrusted data.

### YARA Match (YR1–YR4)

- **`YR1` – Malware Signature**: YARA match for known malware (reverse shell, backdoor).
- **`YR2` – Webshell Detected**: YARA match for known webshell patterns.
- **`YR3` – Crypto Miner Detected**: YARA match for cryptocurrency mining indicators.
- **`YR4` – Hack Tool / Exploit Detected**: YARA match for offensive tools or exploit frameworks.

### Behavioral AST (AST1–AST9)

The **Behavioral AST** analyser in [[`src/skillspector/nodes/analyzers/behavioral_ast.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/nodes/analyzers/behavioral_ast.py)](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/nodes/analyzers/behavioral_ast.py) detects nine additional execution-related evasion patterns (`AST1` through `AST9`). These patterns identify runtime code manipulation and evasion techniques that static analysis might miss, completing the total count of 68 patterns.

## How SkillSpector Uses These Patterns

SkillSpector maps detections to categories through three primary mechanisms:

1. **Static Pattern Analyzers**: Files like [`static_patterns_prompt_injection.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_prompt_injection.py) and [`static_patterns_ssrf.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_ssrf.py) import `PatternCategory` and call `get_category(rule_id)` to tag findings according to the taxonomy defined in [`pattern_defaults.py`](https://github.com/NVIDIA/SkillSpector/blob/main/pattern_defaults.py).

2. **Semantic Analyzers**: Modules such as [`semantic_developer_intent.py`](https://github.com/NVIDIA/SkillSpector/blob/main/semantic_developer_intent.py) map detections to the same categories using helper functions from [`pattern_defaults.py`](https://github.com/NVIDIA/SkillSpector/blob/main/pattern_defaults.py), ensuring consistent classification across analysis types.

3. **Meta-Analyzer**: The [[`meta_analyzer.py`](https://github.com/NVIDIA/SkillSpector/blob/main/meta_analyzer.py)](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/nodes/meta_analyzer.py#L262-L298) aggregates findings from all analyzers, resolves each rule's category, explanation, and remediation, and writes them into the SARIF report.

## Practical Usage Example

Run SkillSpector on a local skill directory to generate a report containing the 68 vulnerability patterns:

```bash

# Analyze a skill and output SARIF

skill-spector analyze ./my_skill --output report.sarif

# Filter for specific pattern (e.g., Prompt Injection P1)

jq '.runs[0].results[] | select(.ruleId=="P1")' report.sarif

```

The SARIF output contains structured entries mapping to the pattern IDs:

```json
{
  "ruleId": "P1",
  "level": "error",
  "message": {
    "text": "This pattern attempts to override system instructions or ignore safety constraints..."
  },
  "properties": {
    "category": "Prompt Injection",
    "remediation": "Remove or rewrite any text that instructs the agent to ignore prompts..."
  }
}

```

Each `ruleId` corresponds directly to the pattern IDs listed in the categories above, enabling automated triage and remediation workflows.

## Summary

- SkillSpector detects **68 vulnerability patterns** across **17 categories** defined in the `PatternCategory` enum.
- Pattern definitions reside in [`src/skillspector/nodes/analyzers/pattern_defaults.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/nodes/analyzers/pattern_defaults.py), with rule IDs mapped to explanations (lines 46-138), categories (lines 141-213), and names (lines 216-288).
- **Static analyzers** detect 59 explicit patterns (P1-P8, E1-E4, PE1-PE3, SC1-SC6, EA1-EA4, OH1-OH3, MP1-MP3, TM1-TM3, RA1-RA2, LP1-LP4, TP1-TP4, AS1-AS3, AR1-AR3, SSRF1-SSRF3, YR1-YR4), while the **Behavioral AST** analyzer handles AST1-AST9.
- Findings are aggregated by [`meta_analyzer.py`](https://github.com/NVIDIA/SkillSpector/blob/main/meta_analyzer.py) and exported in SARIF format with rule IDs, categories, and remediation guidance.

## Frequently Asked Questions

### What are the main categories of vulnerabilities SkillSpector detects?

SkillSpector organizes vulnerabilities into 17 categories including Prompt Injection, Data Exfiltration, Privilege Escalation, Supply Chain, Excessive Agency, Output Handling, System Prompt Leakage, Memory Poisoning, Tool Misuse, Rogue Agent, Trigger Abuse, YARA Match, MCP Least Privilege, MCP Tool Poisoning, Agent Snooping, Anti-Refusal, and Server-Side Request Forgery. These are defined in the `PatternCategory` enum in [`pattern_defaults.py`](https://github.com/NVIDIA/SkillSpector/blob/main/pattern_defaults.py).

### How does SkillSpector map rule IDs to categories?

The `RULE_ID_TO_CATEGORY` dictionary in [`pattern_defaults.py`](https://github.com/NVIDIA/SkillSpector/blob/main/pattern_defaults.py) (lines 141-213) maps each rule ID (such as `P1` or `E2`) to its corresponding `PatternCategory`. Static and semantic analyzers use this mapping via the `get_category(rule_id)` helper function to ensure consistent classification in SARIF reports.

### What is the difference between static patterns and behavioral AST patterns?

Static patterns (59 rules) are detected through regex and AST analysis of source code and metadata files, identifying issues like prompt injection or supply chain risks. The **Behavioral AST** patterns (AST1-AST9) are detected by [`behavioral_ast.py`](https://github.com/NVIDIA/SkillSpector/blob/main/behavioral_ast.py) and identify runtime execution evasion techniques, such as dynamic code evaluation or obfuscation methods that static analysis alone cannot catch.

### How can I view detailed explanations for a specific pattern in the SARIF output?

Each finding in the SARIF report includes a `ruleId` that corresponds to entries in the `DEFAULT_EXPLANATIONS` dictionary (lines 46-138 of [`pattern_defaults.py`](https://github.com/NVIDIA/SkillSpector/blob/main/pattern_defaults.py)). The [`meta_analyzer.py`](https://github.com/NVIDIA/SkillSpector/blob/main/meta_analyzer.py) embeds these explanations and remediation strings directly into the SARIF output's `properties` object, accessible under `properties.category` and `properties.remediation` for each result.