# SkillSpector Severity Levels and Risk Score Ranges Explained

> Understand SkillSpector severity levels and risk score ranges including LOW MEDIUM HIGH and CRITICAL with clear thresholds for pass fail statuses.

- Repository: [NVIDIA Corporation/SkillSpector](https://github.com/NVIDIA/SkillSpector)
- Tags: api-reference
- Published: 2026-07-11

---

**SkillSpector defines four severity levels—LOW (0–24), MEDIUM (25–49), HIGH (50–74), and CRITICAL (75–100)—that map directly to numeric risk score ranges, with a hard-coded threshold of 50 determining whether a scan passes or fails.**

NVIDIA SkillSpector classifies security findings using a severity-based system that drives automated risk scoring. Understanding these severity levels and their corresponding risk score ranges is essential for configuring CI/CD pipelines and interpreting scan outputs correctly.

## The Four Severity Levels and Their Risk Score Ranges

SkillSpector implements severity as string literals (treated as an enum-like construct) mapped to hard-coded numeric ranges in the analysis pipeline. Each finding receives a risk score based on its assigned severity level.

### LOW Severity (0–24)

**LOW** severity findings cover the range of 0 to 24. These represent minor issues with minimal security impact, often benign configuration problems or style violations that pose little risk in realistic threat models.

### MEDIUM Severity (25–49)

**MEDIUM** severity spans 25 to 49. These findings indicate moderate concerns that may affect application performance, stability, or introduce low-impact security weaknesses. While they require review, they typically fall below the failure threshold.

### HIGH Severity (50–74)

**HIGH** severity covers 50 to 74. These are significant vulnerabilities that could be exploited in realistic attack scenarios. According to the source code in [`src/skillspector/constants.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/constants.py), the `RISK_THRESHOLD` constant is set to `50`, meaning any finding in this range or above automatically triggers a scan failure by default.

### CRITICAL Severity (75–100)

**CRITICAL** severity encompasses 75 to 100. These represent severe flaws such as remote code execution vectors or privilege escalation vulnerabilities that demand immediate remediation and will always cause the scan to fail.

## How the Risk Threshold Works

The `RISK_THRESHOLD = 50` definition in [`src/skillspector/constants.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/constants.py) serves as the gate between acceptable and unacceptable risk. The analysis pipeline treats any finding whose computed risk score meets or exceeds this threshold as "unsafe," causing the scan to fail unless specifically configured otherwise.

## Implementation in sarif_models.py

The core mapping logic resides in [`src/skillspector/sarif_models.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/sarif_models.py), specifically within the `Finding` model. When the scanner creates a finding, it stores the severity label (e.g., `"HIGH"`) in the `severity` field, which the pipeline later translates to the corresponding numeric range for threshold comparison.

## Validating Severity Mappings

The repository verifies these severity assignments through targeted unit tests:

- **[`tests/unit/test_patterns_new.py`](https://github.com/NVIDIA/SkillSpector/blob/main/tests/unit/test_patterns_new.py)** asserts that rule **EA1** produces `Severity.MEDIUM` while rule **EA3** produces `Severity.LOW`, confirming the mapping logic works correctly for specific detection patterns.
- **[`tests/unit/test_cli.py`](https://github.com/NVIDIA/SkillSpector/blob/main/tests/unit/test_cli.py)** validates that the CLI output includes `"risk_severity": "LOW"` for low-risk scans, ensuring the severity labels propagate correctly to user-facing reports.

## Practical Code Examples

The following example demonstrates how to convert severity labels to their range midpoints and evaluate them against the risk threshold:

```python
from skillspector.constants import RISK_THRESHOLD

def severity_to_score(severity: str) -> int:
    """Map a severity label to the midpoint of its risk-score range."""
    mapping = {
        "LOW": 12,      # midpoint of 0-24

        "MEDIUM": 37,   # midpoint of 25-49

        "HIGH": 62,     # midpoint of 50-74

        "CRITICAL": 87, # midpoint of 75-100

    }
    return mapping[severity.upper()]

# Example usage

severity = "HIGH"
score = severity_to_score(severity)
print(f"Severity {severity} maps to risk score {score}")

# Determine if a scan is unsafe

if score >= RISK_THRESHOLD:
    print("⛔ Scan is unsafe – treat as failure")
else:
    print("✅ Scan is safe")

```

When creating findings programmatically using the SARIF models, you explicitly set the severity label:

```python
from skillspector.sarif_models import Finding

finding = Finding(
    rule_id="OH1",
    message="Potential command injection",
    severity="HIGH",          # severity label from the defined ranges

    level="error",
    locations=[...],
)

print(f"Finding severity: {finding.severity}")   # → HIGH

print(f"Risk score: {severity_to_score(finding.severity)}")

```

## Summary

- **LOW** severity corresponds to risk scores **0–24**, covering minor configuration issues.
- **MEDIUM** severity corresponds to risk scores **25–49**, addressing moderate concerns.
- **HIGH** severity corresponds to risk scores **50–74**, representing significant vulnerabilities.
- **CRITICAL** severity corresponds to risk scores **75–100**, indicating severe security flaws.
- The **RISK_THRESHOLD** constant in [`src/skillspector/constants.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/constants.py) is set to **50**, making HIGH and CRITICAL findings fail the scan by default.
- Severity mappings are validated in [`tests/unit/test_patterns_new.py`](https://github.com/NVIDIA/SkillSpector/blob/main/tests/unit/test_patterns_new.py) and [`tests/unit/test_cli.py`](https://github.com/NVIDIA/SkillSpector/blob/main/tests/unit/test_cli.py).

## Frequently Asked Questions

### What is the risk threshold in SkillSpector?

The risk threshold is defined as `RISK_THRESHOLD = 50` in [`src/skillspector/constants.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/constants.py). Any finding with a risk score of 50 or above—encompassing HIGH (50–74) and CRITICAL (75–100) severities—causes the scan to fail by default, while LOW and MEDIUM findings allow the scan to pass.

### How does SkillSpector map severity labels to numeric scores?

SkillSpector uses hard-coded ranges defined in the analysis pipeline where **LOW** maps to 0–24, **MEDIUM** to 25–49, **HIGH** to 50–74, and **CRITICAL** to 75–100. These mappings are enforced when the `Finding` model in [`src/skillspector/sarif_models.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/sarif_models.py) processes raw detection results.

### Where are severity levels defined in the SkillSpector codebase?

Severity levels are implemented as string literals in the core analysis logic. The threshold constant resides in [`src/skillspector/constants.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/constants.py), while the storage and translation logic lives in [`src/skillspector/sarif_models.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/sarif_models.py). Unit tests in [`tests/unit/test_patterns_new.py`](https://github.com/NVIDIA/SkillSpector/blob/main/tests/unit/test_patterns_new.py) verify that specific rule IDs like EA1 and EA3 map to the correct severity labels.

### Can I customize the risk score ranges in SkillSpector?

The risk score ranges (0–24, 25–49, 50–74, 75–100) are hard-coded in the analysis pipeline and cannot be changed via configuration. However, you can modify the `RISK_THRESHOLD` value in [`constants.py`](https://github.com/NVIDIA/SkillSpector/blob/main/constants.py) to adjust which minimum score triggers a scan failure, effectively changing which severity levels block your pipeline.