SkillSpector Severity Levels and Risk Score Ranges Explained

SkillSpector defines four severity levels—LOW (0–24), MEDIUM (25–49), HIGH (50–74), and CRITICAL (75–100)—that map directly to numeric risk score ranges, with a hard-coded threshold of 50 determining whether a scan passes or fails.

NVIDIA SkillSpector classifies security findings using a severity-based system that drives automated risk scoring. Understanding these severity levels and their corresponding risk score ranges is essential for configuring CI/CD pipelines and interpreting scan outputs correctly.

The Four Severity Levels and Their Risk Score Ranges

SkillSpector implements severity as string literals (treated as an enum-like construct) mapped to hard-coded numeric ranges in the analysis pipeline. Each finding receives a risk score based on its assigned severity level.

LOW Severity (0–24)

LOW severity findings cover the range of 0 to 24. These represent minor issues with minimal security impact, often benign configuration problems or style violations that pose little risk in realistic threat models.

MEDIUM Severity (25–49)

MEDIUM severity spans 25 to 49. These findings indicate moderate concerns that may affect application performance, stability, or introduce low-impact security weaknesses. While they require review, they typically fall below the failure threshold.

HIGH Severity (50–74)

HIGH severity covers 50 to 74. These are significant vulnerabilities that could be exploited in realistic attack scenarios. According to the source code in src/skillspector/constants.py, the RISK_THRESHOLD constant is set to 50, meaning any finding in this range or above automatically triggers a scan failure by default.

CRITICAL Severity (75–100)

CRITICAL severity encompasses 75 to 100. These represent severe flaws such as remote code execution vectors or privilege escalation vulnerabilities that demand immediate remediation and will always cause the scan to fail.

How the Risk Threshold Works

The RISK_THRESHOLD = 50 definition in src/skillspector/constants.py serves as the gate between acceptable and unacceptable risk. The analysis pipeline treats any finding whose computed risk score meets or exceeds this threshold as "unsafe," causing the scan to fail unless specifically configured otherwise.

Implementation in sarif_models.py

The core mapping logic resides in src/skillspector/sarif_models.py, specifically within the Finding model. When the scanner creates a finding, it stores the severity label (e.g., "HIGH") in the severity field, which the pipeline later translates to the corresponding numeric range for threshold comparison.

Validating Severity Mappings

The repository verifies these severity assignments through targeted unit tests:

  • tests/unit/test_patterns_new.py asserts that rule EA1 produces Severity.MEDIUM while rule EA3 produces Severity.LOW, confirming the mapping logic works correctly for specific detection patterns.
  • tests/unit/test_cli.py validates that the CLI output includes "risk_severity": "LOW" for low-risk scans, ensuring the severity labels propagate correctly to user-facing reports.

Practical Code Examples

The following example demonstrates how to convert severity labels to their range midpoints and evaluate them against the risk threshold:

from skillspector.constants import RISK_THRESHOLD

def severity_to_score(severity: str) -> int:
    """Map a severity label to the midpoint of its risk-score range."""
    mapping = {
        "LOW": 12,      # midpoint of 0-24

        "MEDIUM": 37,   # midpoint of 25-49

        "HIGH": 62,     # midpoint of 50-74

        "CRITICAL": 87, # midpoint of 75-100

    }
    return mapping[severity.upper()]

# Example usage

severity = "HIGH"
score = severity_to_score(severity)
print(f"Severity {severity} maps to risk score {score}")

# Determine if a scan is unsafe

if score >= RISK_THRESHOLD:
    print("⛔ Scan is unsafe – treat as failure")
else:
    print("✅ Scan is safe")

When creating findings programmatically using the SARIF models, you explicitly set the severity label:

from skillspector.sarif_models import Finding

finding = Finding(
    rule_id="OH1",
    message="Potential command injection",
    severity="HIGH",          # severity label from the defined ranges

    level="error",
    locations=[...],
)

print(f"Finding severity: {finding.severity}")   # → HIGH

print(f"Risk score: {severity_to_score(finding.severity)}")

Summary

  • LOW severity corresponds to risk scores 0–24, covering minor configuration issues.
  • MEDIUM severity corresponds to risk scores 25–49, addressing moderate concerns.
  • HIGH severity corresponds to risk scores 50–74, representing significant vulnerabilities.
  • CRITICAL severity corresponds to risk scores 75–100, indicating severe security flaws.
  • The RISK_THRESHOLD constant in src/skillspector/constants.py is set to 50, making HIGH and CRITICAL findings fail the scan by default.
  • Severity mappings are validated in tests/unit/test_patterns_new.py and tests/unit/test_cli.py.

Frequently Asked Questions

What is the risk threshold in SkillSpector?

The risk threshold is defined as RISK_THRESHOLD = 50 in src/skillspector/constants.py. Any finding with a risk score of 50 or above—encompassing HIGH (50–74) and CRITICAL (75–100) severities—causes the scan to fail by default, while LOW and MEDIUM findings allow the scan to pass.

How does SkillSpector map severity labels to numeric scores?

SkillSpector uses hard-coded ranges defined in the analysis pipeline where LOW maps to 0–24, MEDIUM to 25–49, HIGH to 50–74, and CRITICAL to 75–100. These mappings are enforced when the Finding model in src/skillspector/sarif_models.py processes raw detection results.

Where are severity levels defined in the SkillSpector codebase?

Severity levels are implemented as string literals in the core analysis logic. The threshold constant resides in src/skillspector/constants.py, while the storage and translation logic lives in src/skillspector/sarif_models.py. Unit tests in tests/unit/test_patterns_new.py verify that specific rule IDs like EA1 and EA3 map to the correct severity labels.

Can I customize the risk score ranges in SkillSpector?

The risk score ranges (0–24, 25–49, 50–74, 75–100) are hard-coded in the analysis pipeline and cannot be changed via configuration. However, you can modify the RISK_THRESHOLD value in constants.py to adjust which minimum score triggers a scan failure, effectively changing which severity levels block your pipeline.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →