# What Types of Vulnerability Patterns Does SkillSpector Identify? A Technical Guide

> SkillSpector identifies 10 vulnerability patterns like privilege escalation, SSRF, prompt injection, and supply chain risks using regex-based static analysis. Learn more.

- Repository: [NVIDIA Corporation/SkillSpector](https://github.com/NVIDIA/SkillSpector)
- Tags: deep-dive
- Published: 2026-07-11

---

**SkillSpector identifies 10 distinct vulnerability pattern families—including privilege escalation, SSRF, prompt injection, supply chain risks, and rogue agent detection—using regex-based static analysis modules located in `src/skillspector/nodes/analyzers/`.**

NVIDIA's SkillSpector is a security scanner built around a collection of static-pattern analyzers. Each analyzer scans source files for regular-expression signatures that map to a well-defined security issue class. Understanding the specific types of vulnerability patterns SkillSpector identifies allows security teams to tune scans for AI/ML pipelines and traditional codebases with precision.

## Core Vulnerability Pattern Families

SkillSpector organizes its detection logic into specialized modules under `src/skillspector/nodes/analyzers/`. Each module defines a list of regular-expression patterns (with associated confidence scores) and helper logic to filter false positives, such as documentation examples.

### Privilege Escalation (PE1–PE5)

The [`static_patterns_privilege_escalation.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_privilege_escalation.py) module detects five classes of privilege-escalation risks (PE1–PE5). It flags over-permissive permission declarations, **sudo/root execution**, credential-file exposure, and dangerous Docker configurations including socket mounting or privileged container usage.

### Server-Side Request Forgery (SSRF)

In [`static_patterns_ssrf.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_ssrf.py), SkillSpector identifies URL construction patterns that can be abused to reach internal services. It detects hardcoded references to `http://localhost`, `file://` protocols, cloud metadata endpoints (`169.254.169.254`), and other internal routes that could enable SSRF attacks.

### Prompt Injection and Anti-Refusal

Two modules handle LLM-specific attacks. The [`static_patterns_prompt_injection.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_prompt_injection.py) analyzer finds constructs allowing attackers to inject malicious prompts into LLM-driven workflows. Complementing this, [`static_patterns_anti_refusal.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_anti_refusal.py) detects phrases or code structures designed to **bypass LLM refusal mechanisms** and coerce disallowed behavior.

### System Prompt Leakage

The [`static_patterns_system_prompt_leakage.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_system_prompt_leakage.py) module scans for accidental exposure of system-level prompts or configuration data that could be harvested by an LLM to reveal hidden instructions or security contexts.

### Rogue Agent Detection

Through [`static_patterns_rogue_agent.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_rogue_agent.py), SkillSpector identifies code that spawns or communicates with **uncontrolled agents**, hidden processes, or potential backdoors that could operate outside the intended security boundary.

### Output Handling and Data Exfiltration

The [`static_patterns_output_handling.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_output_handling.py) analyzer flags patterns that write sensitive data to **stdout**, local files, or external services without proper sanitization, covering risks from information disclosure to active data exfiltration.

### Supply Chain Risks

In [`static_patterns_supply_chain.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_supply_chain.py), the tool detects inclusion of **untrusted dependencies**, insecure imports, and hardcoded URLs pointing to external resources that could compromise the software supply chain.

### Tool Misuse

The [`static_patterns_tool_misuse.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_patterns_tool_misuse.py) module identifies dangerous CLI flag combinations, **unsafe subprocess calls**, and misuse of system utilities that could lead to command injection or unintended system modifications.

### YARA-Based Malware Detection

Finally, [`static_yara.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_yara.py) provides generic malicious-code detection using **YARA rules** to flag known malware signatures or suspicious code patterns that do not fit the specific categories above.

## How SkillSpector Processes Patterns

SkillSpector aggregates findings through a centralized runner that orchestrates the individual analyzer modules and standardizes output.

### The Static Runner Architecture

The `static_runner.run_static_patterns` function (defined in [`src/skillspector/nodes/analyzers/static_runner.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/nodes/analyzers/static_runner.py)) loads each pattern module and executes regex scans across source files. Each analyzer applies its specific pattern set and produces `AnalyzerFinding` objects that are aggregated for report generation.

### AnalyzerFinding Object Structure

Every match generates an `AnalyzerFinding` containing:

- **rule_id** – Short identifier (e.g., `PE2`, `SSRF`)
- **message** – Human-readable description
- **severity** – Classification as `LOW`, `MEDIUM`, or `HIGH`
- **location** – File name and exact line number
- **confidence** – Numerical weight of the match likelihood
- **tags** – Category tags (e.g., `PRIVILEGE_ESCALATION`, `SSRF`)

These objects are passed to the SARIF report generation pipeline defined in [`src/skillspector/sarif_models.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/sarif_models.py).

## Practical Usage Examples

You can invoke SkillSpector via command line for full scans or programmatically to target specific vulnerability patterns.

### CLI Scanning for All Patterns

Run a complete scan outputting SARIF format:

```bash
skillspector scan ./my-app --format sarif > results.sarif

```

The resulting SARIF entries include `ruleId` fields (e.g., `PE2`), severity levels, and physical location data with line numbers.

### Direct Python API Integration

Import specific analyzers to run targeted checks without invoking the full `static_runner`:

```python
from skillspector.nodes.analyzers import static_patterns_ssrf

findings = static_patterns_ssrf.analyze(
    content=open("client.py").read(),
    file_path="client.py",
    file_type="python"
)

for f in findings:
    print(f"[{f.severity}] {f.rule_id} – {f.message} (line {f.location.start_line})")

```

### Selective Filtering by Category

Combine multiple analyzers and filter results programmatically:

```python
from skillspector.nodes.analyzers import (
    static_patterns_privilege_escalation as pe,
    static_patterns_ssrf as ssrf,
)

all_findings = pe.analyze(src, "script.sh", "shell") + ssrf.analyze(src, "script.sh", "shell")
priv_esc = [f for f in all_findings if "PRIVILEGE_ESCALATION" in f.tags]

print(f"Found {len(priv_esc)} privilege-escalation issues")

```

## Summary

- SkillSpector identifies **10 vulnerability pattern families** ranging from traditional security issues (SSRF, privilege escalation) to AI-specific risks (prompt injection, anti-refusal).
- Each pattern module resides in `src/skillspector/nodes/analyzers/` and implements regex-based detection with confidence scoring.
- Findings are structured as `AnalyzerFinding` objects with standardized fields: `rule_id`, `severity`, `location`, `confidence`, and `tags`.
- The [`static_runner.py`](https://github.com/NVIDIA/SkillSpector/blob/main/static_runner.py) orchestrates execution, while [`sarif_models.py`](https://github.com/NVIDIA/SkillSpector/blob/main/sarif_models.py) handles report generation.
- Both CLI and Python API support selective scanning, allowing developers to focus on specific threat categories like supply chain risks or rogue agent detection.

## Frequently Asked Questions

### What is the complete list of vulnerability patterns SkillSpector can detect?

SkillSpector detects privilege escalation (PE1–PE5), SSRF, prompt injection, system prompt leakage, rogue agents, output handling/data exfiltration, supply chain risks, tool misuse, anti-refusal patterns, and YARA-based malware signatures. Each category maps to a dedicated analyzer module in `src/skillspector/nodes/analyzers/`.

### How does SkillSpector differ from traditional static application security testing (SAST) tools?

Unlike general-purpose SAST tools, SkillSpector includes specialized analyzers for AI-specific risks such as prompt injection, system prompt leakage, and anti-refusal bypasses. It also uses YARA rules for malware detection alongside regex-based pattern matching for code vulnerabilities.

### Can I run a single vulnerability analyzer without executing the full scan?

Yes. You can import individual analyzer modules (e.g., `static_patterns_ssrf`) and call their `analyze()` method directly with file content and metadata. This approach bypasses the `static_runner` and returns `AnalyzerFinding` objects for programmatic processing.

### What output formats does SkillSpector support for vulnerability findings?

SkillSpector primarily outputs findings in SARIF (Static Analysis Results Interchange Format) for integration with standard security dashboards. The [`sarif_models.py`](https://github.com/NVIDIA/SkillSpector/blob/main/sarif_models.py) module handles the translation from internal `AnalyzerFinding` objects to SARIF-compliant JSON, including severity levels, line numbers, and confidence scores.