Understanding Severity Levels for Risks Detected by SkillSpector
SkillSpector classifies every security risk using four distinct severity levels—LOW, MEDIUM, HIGH, and CRITICAL—defined as a StrEnum in src/skillspector/models.py and assigned to each AnalyzerFinding throughout the analysis pipeline.
NVIDIA/SkillSpector is an open-source security analysis framework that inspects code for vulnerabilities and malicious patterns. The severity levels for risks detected by SkillSpector provide a standardized classification system that enables development teams to prioritize remediation efforts based on potential impact.
The Four Canonical Severity Levels
SkillSpector defines risk severity through a Severity enum located in src/skillspector/models.py. This StrEnum subclass contains four distinct values that every analyzer uses to classify findings.
LOW
LOW severity indicates minor risks unlikely to cause real damage. These findings appear in green when rendered in the final report and typically represent informational or cosmetic issues.
MEDIUM
MEDIUM severity represents noticeable risks that should be addressed but are not urgent. The report renders these in yellow, signaling moderate concern that warrants scheduled maintenance.
HIGH
HIGH severity flags serious risks that could lead to significant impact if left unchecked. These appear in orange in the formatted output and require prioritized attention.
CRITICAL
CRITICAL severity marks extremely severe risks demanding immediate remediation. These appear in red and typically include malware detections, cryptominers, or harmful content patterns that pose active threats.
How Severity Levels for Risks Detected by SkillSpector Are Assigned
All analyzer implementations import the severity enum using from skillspector.models import Severity and assign a level to each AnalyzerFinding they produce. The classification logic varies by analyzer type based on detection confidence and threat category.
Static Analysis Mapping
The YARA static analyzer (src/skillspector/nodes/analyzers/static_yara.py) demonstrates typical mapping logic. It converts raw YARA categories into severity levels—for example, mapping "malware" to Severity.CRITICAL and "cryptominer" to Severity.HIGH.
from skillspector.models import AnalyzerFinding, Location, Severity
def analyze_yara_match(match):
category, rule_id, default_sev = _CATEGORY_MAP[match.namespace]
sev = Severity[match.meta.get("severity", default_sev.name)]
return AnalyzerFinding(
rule_id=rule_id,
message=f"YARA match: {category}",
severity=sev,
location=Location(file=match.file, start_line=match.line),
)
Other static pattern analyzers, such as src/skillspector/nodes/analyzers/static_patterns_harmful_content.py, assign severities directly based on pattern matches without intermediate mapping.
Working with Severity in Practice
When constructing findings programmatically, you instantiate AnalyzerFinding with a specific Severity enum value.
Creating a Finding with Specific Severity
from skillspector.models import AnalyzerFinding, Location, Severity
finding = AnalyzerFinding(
rule_id="YR1",
message="Detected known malware signature",
severity=Severity.CRITICAL,
location=Location(file="app.py", start_line=42, end_line=45),
confidence=0.92,
tags=["malware", "yara"],
)
Serializing to SARIF
Because Severity extends StrEnum, the values serialize naturally to strings for SARIF or JSON output compliance without explicit conversion logic.
from skillspector.models import Severity
def format_severity(sev: Severity) -> str:
# SARIF expects string values
return sev.value
Rendering Severity Levels for Risks Detected by SkillSpector in Reports
The Report node in src/skillspector/nodes/report.py formats severity with color-coding for terminal output. It maps enum values to visual indicators: green for LOW, yellow for MEDIUM, orange for HIGH, and red for CRITICAL. This visual hierarchy helps security teams immediately triage findings when reviewing scan results.
Summary
- SkillSpector uses four severity levels (
LOW,MEDIUM,HIGH,CRITICAL) defined as aStrEnuminsrc/skillspector/models.py. - Every
AnalyzerFindingrequires a severity assignment populated by analyzers likestatic_yara.pybased on detection categories. - The
StrEnumimplementation enables direct string serialization for SARIF compliance via thevalueattribute. - Final reports render severity with color-coding to facilitate immediate risk triage.
Frequently Asked Questions
What are the four severity levels in SkillSpector?
The four severity levels are LOW, MEDIUM, HIGH, and CRITICAL, defined in the Severity enum within src/skillspector/models.py. LOW indicates minor risks unlikely to cause damage, while CRITICAL represents immediate threats such as malware that demand urgent remediation.
How does SkillSpector determine which severity level to assign?
Analyzers assign severity based on predefined mapping rules specific to their detection mechanism. The YARA analyzer maps categories like "malware" to CRITICAL and "cryptominer" to HIGH, while pattern-based analyzers assign levels directly in implementation files such as static_patterns_harmful_content.py.
Can severity levels be customized or extended?
The severity levels are fixed as a StrEnum in the core models file. While you cannot add new levels without modifying src/skillspector/models.py, analyzers can dynamically select from the existing four levels based on rule metadata or confidence scores when instantiating AnalyzerFinding objects.
How are severity levels displayed in SkillSpector output?
The Report node renders severity with color-coded formatting: green for LOW, yellow for MEDIUM, orange for HIGH, and red for CRITICAL. When exporting to SARIF or JSON formats, the StrEnum provides string values directly through the value property for standard compliance.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →