# Understanding Severity Levels for Risks Detected by SkillSpector

> Discover SkillSpector's four severity levels LOW MEDIUM HIGH CRITICAL used to classify security risks. Understand how these levels help prioritize analysis findings.

- Repository: [NVIDIA Corporation/SkillSpector](https://github.com/NVIDIA/SkillSpector)
- Tags: getting-started
- Published: 2026-06-23

---

**SkillSpector classifies every security risk using four distinct severity levels—LOW, MEDIUM, HIGH, and CRITICAL—defined as a `StrEnum` in [`src/skillspector/models.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/models.py) and assigned to each `AnalyzerFinding` throughout the analysis pipeline.**

NVIDIA/SkillSpector is an open-source security analysis framework that inspects code for vulnerabilities and malicious patterns. The **severity levels for risks detected by SkillSpector** provide a standardized classification system that enables development teams to prioritize remediation efforts based on potential impact.

## The Four Canonical Severity Levels

SkillSpector defines risk severity through a **`Severity`** enum located in [`src/skillspector/models.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/models.py). This `StrEnum` subclass contains four distinct values that every analyzer uses to classify findings.

### LOW

**LOW** severity indicates minor risks unlikely to cause real damage. These findings appear in **green** when rendered in the final report and typically represent informational or cosmetic issues.

### MEDIUM

**MEDIUM** severity represents noticeable risks that should be addressed but are not urgent. The report renders these in **yellow**, signaling moderate concern that warrants scheduled maintenance.

### HIGH

**HIGH** severity flags serious risks that could lead to significant impact if left unchecked. These appear in **orange** in the formatted output and require prioritized attention.

### CRITICAL

**CRITICAL** severity marks extremely severe risks demanding immediate remediation. These appear in **red** and typically include malware detections, cryptominers, or harmful content patterns that pose active threats.

## How Severity Levels for Risks Detected by SkillSpector Are Assigned

All analyzer implementations import the severity enum using `from skillspector.models import Severity` and assign a level to each `AnalyzerFinding` they produce. The classification logic varies by analyzer type based on detection confidence and threat category.

### Static Analysis Mapping

The YARA static analyzer ([`src/skillspector/nodes/analyzers/static_yara.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/nodes/analyzers/static_yara.py)) demonstrates typical mapping logic. It converts raw YARA categories into severity levels—for example, mapping `"malware"` to `Severity.CRITICAL` and `"cryptominer"` to `Severity.HIGH`.

```python
from skillspector.models import AnalyzerFinding, Location, Severity

def analyze_yara_match(match):
    category, rule_id, default_sev = _CATEGORY_MAP[match.namespace]
    sev = Severity[match.meta.get("severity", default_sev.name)]
    return AnalyzerFinding(
        rule_id=rule_id,
        message=f"YARA match: {category}",
        severity=sev,
        location=Location(file=match.file, start_line=match.line),
    )

```

Other static pattern analyzers, such as [`src/skillspector/nodes/analyzers/static_patterns_harmful_content.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/nodes/analyzers/static_patterns_harmful_content.py), assign severities directly based on pattern matches without intermediate mapping.

## Working with Severity in Practice

When constructing findings programmatically, you instantiate `AnalyzerFinding` with a specific `Severity` enum value.

### Creating a Finding with Specific Severity

```python
from skillspector.models import AnalyzerFinding, Location, Severity

finding = AnalyzerFinding(
    rule_id="YR1",
    message="Detected known malware signature",
    severity=Severity.CRITICAL,
    location=Location(file="app.py", start_line=42, end_line=45),
    confidence=0.92,
    tags=["malware", "yara"],
)

```

### Serializing to SARIF

Because `Severity` extends `StrEnum`, the values serialize naturally to strings for SARIF or JSON output compliance without explicit conversion logic.

```python
from skillspector.models import Severity

def format_severity(sev: Severity) -> str:
    # SARIF expects string values

    return sev.value

```

## Rendering Severity Levels for Risks Detected by SkillSpector in Reports

The `Report` node in [`src/skillspector/nodes/report.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/nodes/report.py) formats severity with color-coding for terminal output. It maps enum values to visual indicators: **green** for LOW, **yellow** for MEDIUM, **orange** for HIGH, and **red** for CRITICAL. This visual hierarchy helps security teams immediately triage findings when reviewing scan results.

## Summary

- SkillSpector uses four **severity levels** (`LOW`, `MEDIUM`, `HIGH`, `CRITICAL`) defined as a `StrEnum` in [`src/skillspector/models.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/models.py).
- Every `AnalyzerFinding` requires a severity assignment populated by analyzers like [`static_yara.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_yara.py) based on detection categories.
- The `StrEnum` implementation enables direct string serialization for SARIF compliance via the `value` attribute.
- Final reports render severity with color-coding to facilitate immediate risk triage.

## Frequently Asked Questions

### What are the four severity levels in SkillSpector?

The four severity levels are **LOW**, **MEDIUM**, **HIGH**, and **CRITICAL**, defined in the `Severity` enum within [`src/skillspector/models.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/models.py). LOW indicates minor risks unlikely to cause damage, while CRITICAL represents immediate threats such as malware that demand urgent remediation.

### How does SkillSpector determine which severity level to assign?

Analyzers assign severity based on predefined mapping rules specific to their detection mechanism. The YARA analyzer maps categories like `"malware"` to `CRITICAL` and `"cryptominer"` to `HIGH`, while pattern-based analyzers assign levels directly in implementation files such as [`static_patterns_harmful_content.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_harmful_content.py).

### Can severity levels be customized or extended?

The severity levels are fixed as a `StrEnum` in the core models file. While you cannot add new levels without modifying [`src/skillspector/models.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/models.py), analyzers can dynamically select from the existing four levels based on rule metadata or confidence scores when instantiating `AnalyzerFinding` objects.

### How are severity levels displayed in SkillSpector output?

The `Report` node renders severity with color-coded formatting: green for LOW, yellow for MEDIUM, orange for HIGH, and red for CRITICAL. When exporting to SARIF or JSON formats, the `StrEnum` provides string values directly through the `value` property for standard compliance.