What Is the meta_analyzer Node in SkillSpector? LLM-Driven Security Filtering Explained
The meta_analyzer node is the final LLM-powered validation and enrichment step that filters static analysis findings, assigns confidence scores, and generates remediation advice before report generation.
The meta_analyzer node serves as the critical quality gate in NVIDIA's SkillSpector security analysis pipeline. Located in src/skillspector/nodes/meta_analyzer.py, this component evaluates raw findings from parallel static analyzers using configurable large language models (LLMs) to eliminate false positives and produce high-confidence security assessments.
Where the meta_analyzer Node Lives in the Architecture
The node occupies a central position in SkillSpector’s directed analysis graph, positioned between parallel static analyzers and the final report generator.
Source Code Locations
src/skillspector/nodes/meta_analyzer.py— Contains theLLMMetaAnalyzerclass and the publicmeta_analyzer(state)entry point that implements filtering logic, prompt construction, and fallback handling.src/skillspector/graph.py— Defines the LangGraph workflow topology where analyzer nodes fan-out, then fan-in tometa_analyzer, which subsequently feeds thereportnode.src/skillspector/state.py— Defines theSkillspectorStatedictionary that carriesfindings,use_llm,model_config, and other parameters consumed by the node.src/skillspector/llm_analyzer_base.py— Provides theLLMAnalyzerBaseparent class that handles token budgeting, batching, and asynchronous LLM execution for the meta-analyzer.
What the meta_analyzer Node Does
The node executes a six-stage pipeline to refine raw security findings into actionable intelligence:
- Collects per-file findings — Aggregates outputs from preceding static analyzers (YARA, pattern matchers) contained in
state["findings"]. - Conditional LLM invocation — When
state["use_llm"]isTrue, sends each file with findings to the LLM configured instate["model_config"]["meta_analyzer"]using thePER_FILE_ANALYSIS_PROMPT. - Structured response parsing — Validates LLM output against the Pydantic
MetaAnalyzerResultschema to extract structured data. - Confidence-based filtering — Retains only findings where the LLM marks
is_vulnerability=Trueand assigns a confidence score ≥ 0.6. - Finding enrichment — Appends LLM-generated fields including
explanation,remediation, and refinedconfidencescores to retained findings. - Safe fallback execution — Applies heuristic filtering (
_fallback_filtered) when--no-llmmode is active, or passes findings through with default remediations (_passthrough_with_defaults) when LLM calls fail.
According to the SkillSpector source code, this architecture allows the meta-analyzer to act as a "human-in-the-loop" substitute, converting noisy static analysis output into concise, validated security reports.
Integration in the SkillSpector Pipeline
The node serves as the crucial bridge between raw analysis and final reporting in the directed acyclic graph:
resolve_input → build_context → [parallel static analyzers] → meta_analyzer → report
As implemented in src/skillspector/graph.py, all static analyzer nodes produce raw Finding objects that flow into the meta_analyzer node. After processing, the node emits filtered_findings to the report node, which serializes results into SARIF or human-readable formats.
Implementation Details and Fallback Mechanisms
The LLMMetaAnalyzer class extends LLMAnalyzerBase to inherit sophisticated LLM management capabilities while implementing domain-specific security logic.
Key Classes and Methods
meta_analyzer(state)— The public entry point function that orchestrates filtering logic based onSkillspectorStateconfiguration.LLMMetaAnalyzer— The analyzer class that constructs per-file prompts and parsesMetaAnalyzerResultobjects._fallback_filtered— Heuristic filtering method applied whenuse_llm=False, dropping low-confidence non-critical findings based on static severity rules._passthrough_with_defaults— Failure-recovery method that returns all original findings with default remediations drawn fromsrc/skillspector/nodes/analyzers/pattern_defaults.pywhen LLM calls error out.
Configuration Requirements
The node respects the model_config["meta_analyzer"] key for LLM selection (e.g., deepseek-ai/deepseek-v4-pro) and requires raw file content in state["file_cache"] to populate analysis prompts with source context.
Practical Usage Examples
Programmatic Invocation via Python API
To call the meta_analyzer node directly in custom scripts:
from skillspector.state import SkillspectorState
from skillspector.nodes.meta_analyzer import meta_analyzer
state = SkillspectorState(
findings=[
{
"rule_id": "E2",
"message": "Hard-coded credential",
"severity": "HIGH",
"confidence": 0.9,
"file": "skill.py",
"start_line": 12,
"end_line": 12,
"remediation": None,
}
],
use_llm=True,
model_config={"meta_analyzer": "deepseek-ai/deepseek-v4-pro"},
manifest={"name": "example-skill"},
file_cache={"skill.py": "def foo(): pass"},
)
filtered = meta_analyzer(state)
print(filtered["filtered_findings"])
This returns a list containing only LLM-validated findings, each enriched with explanation, remediation, and updated confidence scores.
Standard CLI Execution
Run the complete analysis pipeline including the meta-analyzer:
skill-spector scan ./my-skill \
--model-config meta_analyzer=deepseek-ai/deepseek-v4-pro \
--output-format sarif
The CLI automatically wires the node into the graph as defined in graph.py, executing it after all static analyzers complete.
Disabling LLM Processing (Heuristic Mode)
To bypass LLM calls and rely on static heuristics:
skill-spector scan ./my-skill --no-llm
With use_llm=False, the node invokes _fallback_filtered, applying confidence-based heuristics without external API calls.
Summary
- The
meta_analyzernode in SkillSpector functions as the final LLM-powered validation gate in the security analysis pipeline. - Located in
src/skillspector/nodes/meta_analyzer.py, it filters findings using a confidence threshold of 0.6 and theis_vulnerabilityboolean from parsedMetaAnalyzerResultobjects. - The node enriches retained findings with AI-generated explanations and remediations while providing safe fallbacks for offline or failure scenarios.
- It integrates between parallel static analyzers and the report generator in the LangGraph workflow defined in
src/skillspector/graph.py.
Frequently Asked Questions
What triggers the meta_analyzer node to run in SkillSpector?
The meta_analyzer node executes automatically after all parallel static analyzer nodes complete their execution, as defined by the graph edges in src/skillspector/graph.py. The node consumes the aggregated findings list from SkillspectorState and triggers regardless of whether LLM processing is enabled, though its internal logic selects between LLM-based or heuristic filtering based on the use_llm flag.
How does the meta_analyzer node filter false positives?
The node sends static findings to an LLM using the PER_FILE_ANALYSIS_PROMPT, which instructs the model to re-evaluate each finding and return a structured MetaAnalyzerResult. Only findings where the LLM returns is_vulnerability=True and assigns a confidence score of at least 0.6 are retained. Findings failing either criterion are discarded from the final output.
What happens if the LLM service is unavailable?
When LLM calls fail or timeout, the meta_analyzer node executes _passthrough_with_defaults, which returns all original findings with default remediations sourced from src/skillspector/nodes/analyzers/pattern_defaults.py. This ensures the pipeline completes successfully even during API outages, though without AI-generated enrichment.
Can I use SkillSpector without an LLM for the meta-analysis step?
Yes, by passing the --no-llm flag or setting use_llm=False in the state, the node bypasses LLM calls and executes _fallback_filtered instead. This mode applies static heuristics to drop low-confidence non-critical findings, providing a lightweight analysis option that requires no external API keys or network connectivity.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →