# SkillSpector Trust Model and Data Egress: A Complete Security Analysis

> Analyze SkillSpector's trust model and data egress. Learn how SkillSpector ensures security through static analysis, controlled LLM data transmission, and OSV.dev integration.

- Repository: [NVIDIA Corporation/SkillSpector](https://github.com/NVIDIA/SkillSpector)
- Tags: deep-dive
- Published: 2026-06-24

---

**SkillSpector validates AI-agent skills through defense-in-depth static analysis without executing code, transmitting file contents only to configured LLM endpoints when semantic analysis is enabled, while dependency vulnerabilities are checked against OSV.dev.**

NVIDIA's SkillSpector is an open-source security scanner that evaluates AI-agent "skills" through static analysis rather than sandboxed execution. Understanding SkillSpector's trust model and data egress is critical for organizations deploying AI agents in secure environments, as the tool offers configurable privacy controls that determine whether sensitive code leaves the host machine. The project implements a zero-trust architecture where scanned skills are treated as potentially malicious, with clear boundaries between local analysis and external network requests.

## Understanding SkillSpector's Zero-Execution Trust Model

SkillSpector assumes **zero trust** for any skill under examination. The tool never executes, imports, or dynamically evaluates the code being scanned, eliminating remote code execution risks during analysis.

### Defense-in-Depth Static Analysis

The core security layer relies entirely on static inspection implemented across multiple modules. The static analyzers located in `src/skillspector/nodes/analyzers/static_patterns_*.py` perform regex-based pattern matching and Python AST inspection without spawning processes or importing modules. Additional semantic discovery occurs in [`src/skillspector/nodes/analyzers/semantic_security_discovery.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/nodes/analyzers/semantic_security_discovery.py), which reads file text but never interprets or executes it.

This static-only approach ensures that malicious payloads, import hooks, or runtime exploits within the target skill cannot compromise the scanning host.

### Optional LLM Semantic Validation

When enabled, SkillSpector performs deep semantic analysis by transmitting file contents to a configured Large Language Model provider. The request logic resides in [`src/skillspector/llm_utils.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/llm_utils.py), with provider-specific adapters under `src/skillspector/providers/` (including OpenAI, Anthropic, and NVIDIA internal models). This layer detects sophisticated attack vectors like prompt injection and jailbreak attempts that pure static analysis might miss.

Because the LLM receives the raw UTF-8 text of the skill, this represents the primary data egress path in the default configuration.

## Data Egress Paths and Network Requests

SkillSpector makes outbound network requests only under specific conditions, with two distinct egress channels:

| Component | Data Transmitted | Destination | Trigger |
|-----------|------------------|-------------|---------|
| **LLM Provider** | Full file contents (UTF-8 text) | Configured endpoint via `SKILLSPECTOR_PROVIDER` | Enabled by default; disabled with `--no-llm` |
| **OSV.dev Client** | Package names and version strings | `https://api.osv.dev` | Always active for SC4 (Supply Chain Check) |

### LLM Provider Communication

When semantic analysis is active, [`src/skillspector/llm_utils.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/llm_utils.py) constructs POST requests containing the complete text of each source file. For example, when using OpenAI, the tool sends the file content within the message payload to `https://api.openai.com/v1/chat/completions`. This transmission occurs once per file analyzed and requires explicit API credentials via environment variables.

### OSV.dev Dependency Lookups

The Supply Chain Check (SC4) implemented in [`src/skillspector/nodes/analyzers/osv_client.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/nodes/analyzers/osv_client.py) queries OSV.dev for known CVEs affecting the skill's declared dependencies. This request transmits only package coordinates (e.g., `requests==2.28.2`) rather than source code. If the OSV.dev service is unreachable, SkillSpector automatically falls back to an embedded vulnerability list, ensuring continuous operation in air-gapped environments without additional egress.

## How to Control and Minimize Data Egress

Organizations can operate SkillSpector in three distinct privacy modes depending on their security requirements.

### Static-Only Mode (--no-llm)

Run the scanner without LLM analysis to prevent any file content transmission:

```bash
skillspector scan ./my-skill/ --no-llm

```

In this mode, only static analysis and OSV.dev queries occur. To eliminate the OSV.dev request as well, configure network restrictions to block `api.osv.dev`, forcing the scanner to use its internal static vulnerability database.

### Air-Gapped Environments

For complete network isolation, combine the static-only flag with absent API credentials:

```python
from skillspector import graph

result = graph.invoke({
    "input_path": "./my-skill/",
    "output_format": "json",
    "use_llm": False,  # Disables file-content transmission

    "provider": "none",  # Ensures no LLM path is taken

})

print(result["risk_assessment"]["recommendation"])

```

Setting `SKILLSPECTOR_PROVIDER=none` or omitting the variable guarantees that even if `use_llm` is accidentally enabled, the LLM path cannot execute without credentials.

### Full Analysis with External Providers

When comprehensive security vetting outweighs data egress concerns, enable full LLM analysis:

```bash
export SKILLSPECTOR_PROVIDER=openai
export OPENAI_API_KEY=sk-...
skillspector scan ./my-skill/

```

This configuration sends all file contents to the specified endpoint while maintaining the OSV.dev dependency checks.

## Key Implementation Files

The following source files define SkillSpector's trust boundaries and data handling:

- **[`src/skillspector/llm_utils.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/llm_utils.py)** – Handles LLM request construction, response parsing, and content transmission to external providers.
- **[`src/skillspector/providers/openai/provider.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/openai/provider.py)** – OpenAI-specific adapter; similar adapters exist for Anthropic and NVIDIA models under `src/skillspector/providers/`.
- **[`src/skillspector/nodes/analyzers/osv_client.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/nodes/analyzers/osv_client.py)** – Performs batch queries to OSV.dev for supply chain vulnerability detection.
- **[`src/skillspector/nodes/analyzers/semantic_security_discovery.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/nodes/analyzers/semantic_security_discovery.py)** – Static semantic analysis that reads but never executes file contents.
- **[`src/skillspector/graph.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/graph.py)** – Orchestrates the analysis pipeline, managing the transition between static analysis and optional LLM validation.

## Summary

- SkillSpector operates on a **zero-execution trust model**, analyzing skills through static inspection rather than sandboxed execution.
- **Data egress** occurs via two channels: LLM providers receive full file contents (when enabled), and OSV.dev receives dependency coordinates (always active for SC4).
- **Static-only mode** (`--no-llm` or `use_llm=False`) eliminates file content transmission while maintaining security analysis.
- **Air-gapped operation** is supported through OSV.dev fallback mechanisms and the absence of LLM credentials.
- All network transmission is configurable, with clear separation between local analysis in `static_patterns_*.py` and external communication in [`llm_utils.py`](https://github.com/NVIDIA/SkillSpector/blob/main/llm_utils.py).

## Frequently Asked Questions

### Does SkillSpector execute the code it scans?

No. SkillSpector never executes, imports, or dynamically evaluates the skill being analyzed. According to the NVIDIA/SkillSpector source code, the tool relies solely on static analysis techniques including regex pattern matching, Python AST inspection, and YARA signatures implemented in `src/skillspector/nodes/analyzers/`. This design prevents malicious code from compromising the scanning host through runtime exploits.

### What data does SkillSpector send to external services?

SkillSpector transmits two categories of data: full file contents (UTF-8 text) to configured LLM endpoints when semantic analysis is enabled, and package name/version strings to OSV.dev for vulnerability lookups. The tool does not transmit telemetry, system information, or execution traces. File contents are only sent when the LLM analysis layer is active; disable this with `--no-llm` to keep all source code on-premise.

### Can SkillSpector run completely offline?

Yes. SkillSpector supports air-gapped operation by running with `--no-llm` to disable LLM communication and blocking access to `api.osv.dev`. When the OSV.dev service is unreachable, the scanner automatically falls back to an embedded vulnerability list in [`src/skillspector/nodes/analyzers/osv_client.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/nodes/analyzers/osv_client.py), ensuring supply chain checks continue without network connectivity. No other external dependencies are required for operation.

### How do I verify that no data is leaving my network?

Configure your firewall to block outbound connections to `api.osv.dev` and ensure the `SKILLSPECTOR_PROVIDER` environment variable is unset or set to `none`. Run the scanner with `--no-llm` and monitor network traffic during execution. The absence of API credentials and the static-only flag guarantees that [`src/skillspector/llm_utils.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/llm_utils.py) will never construct outbound requests, while the OSV.dev fallback mechanism ensures analysis continues using local data.