Understanding Severity Levels for Risks Detected by SkillSpector

SkillSpector classifies every security risk using four distinct severity levels—LOW, MEDIUM, HIGH, and CRITICAL—defined as a StrEnum in src/skillspector/models.py and assigned to each AnalyzerFinding throughout the analysis pipeline.

NVIDIA/SkillSpector is an open-source security analysis framework that inspects code for vulnerabilities and malicious patterns. The severity levels for risks detected by SkillSpector provide a standardized classification system that enables development teams to prioritize remediation efforts based on potential impact.

The Four Canonical Severity Levels

SkillSpector defines risk severity through a Severity enum located in src/skillspector/models.py. This StrEnum subclass contains four distinct values that every analyzer uses to classify findings.

LOW

LOW severity indicates minor risks unlikely to cause real damage. These findings appear in green when rendered in the final report and typically represent informational or cosmetic issues.

MEDIUM

MEDIUM severity represents noticeable risks that should be addressed but are not urgent. The report renders these in yellow, signaling moderate concern that warrants scheduled maintenance.

HIGH

HIGH severity flags serious risks that could lead to significant impact if left unchecked. These appear in orange in the formatted output and require prioritized attention.

CRITICAL

CRITICAL severity marks extremely severe risks demanding immediate remediation. These appear in red and typically include malware detections, cryptominers, or harmful content patterns that pose active threats.

How Severity Levels for Risks Detected by SkillSpector Are Assigned

All analyzer implementations import the severity enum using from skillspector.models import Severity and assign a level to each AnalyzerFinding they produce. The classification logic varies by analyzer type based on detection confidence and threat category.

Static Analysis Mapping

The YARA static analyzer (src/skillspector/nodes/analyzers/static_yara.py) demonstrates typical mapping logic. It converts raw YARA categories into severity levels—for example, mapping "malware" to Severity.CRITICAL and "cryptominer" to Severity.HIGH.

from skillspector.models import AnalyzerFinding, Location, Severity

def analyze_yara_match(match):
    category, rule_id, default_sev = _CATEGORY_MAP[match.namespace]
    sev = Severity[match.meta.get("severity", default_sev.name)]
    return AnalyzerFinding(
        rule_id=rule_id,
        message=f"YARA match: {category}",
        severity=sev,
        location=Location(file=match.file, start_line=match.line),
    )

Other static pattern analyzers, such as src/skillspector/nodes/analyzers/static_patterns_harmful_content.py, assign severities directly based on pattern matches without intermediate mapping.

Working with Severity in Practice

When constructing findings programmatically, you instantiate AnalyzerFinding with a specific Severity enum value.

Creating a Finding with Specific Severity

from skillspector.models import AnalyzerFinding, Location, Severity

finding = AnalyzerFinding(
    rule_id="YR1",
    message="Detected known malware signature",
    severity=Severity.CRITICAL,
    location=Location(file="app.py", start_line=42, end_line=45),
    confidence=0.92,
    tags=["malware", "yara"],
)

Serializing to SARIF

Because Severity extends StrEnum, the values serialize naturally to strings for SARIF or JSON output compliance without explicit conversion logic.

from skillspector.models import Severity

def format_severity(sev: Severity) -> str:
    # SARIF expects string values

    return sev.value

Rendering Severity Levels for Risks Detected by SkillSpector in Reports

The Report node in src/skillspector/nodes/report.py formats severity with color-coding for terminal output. It maps enum values to visual indicators: green for LOW, yellow for MEDIUM, orange for HIGH, and red for CRITICAL. This visual hierarchy helps security teams immediately triage findings when reviewing scan results.

Summary

  • SkillSpector uses four severity levels (LOW, MEDIUM, HIGH, CRITICAL) defined as a StrEnum in src/skillspector/models.py.
  • Every AnalyzerFinding requires a severity assignment populated by analyzers like static_yara.py based on detection categories.
  • The StrEnum implementation enables direct string serialization for SARIF compliance via the value attribute.
  • Final reports render severity with color-coding to facilitate immediate risk triage.

Frequently Asked Questions

What are the four severity levels in SkillSpector?

The four severity levels are LOW, MEDIUM, HIGH, and CRITICAL, defined in the Severity enum within src/skillspector/models.py. LOW indicates minor risks unlikely to cause damage, while CRITICAL represents immediate threats such as malware that demand urgent remediation.

How does SkillSpector determine which severity level to assign?

Analyzers assign severity based on predefined mapping rules specific to their detection mechanism. The YARA analyzer maps categories like "malware" to CRITICAL and "cryptominer" to HIGH, while pattern-based analyzers assign levels directly in implementation files such as static_patterns_harmful_content.py.

Can severity levels be customized or extended?

The severity levels are fixed as a StrEnum in the core models file. While you cannot add new levels without modifying src/skillspector/models.py, analyzers can dynamically select from the existing four levels based on rule metadata or confidence scores when instantiating AnalyzerFinding objects.

How are severity levels displayed in SkillSpector output?

The Report node renders severity with color-coded formatting: green for LOW, yellow for MEDIUM, orange for HIGH, and red for CRITICAL. When exporting to SARIF or JSON formats, the StrEnum provides string values directly through the value property for standard compliance.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →