What Types of Vulnerability Patterns Does SkillSpector Identify? A Technical Guide

SkillSpector identifies 10 distinct vulnerability pattern families—including privilege escalation, SSRF, prompt injection, supply chain risks, and rogue agent detection—using regex-based static analysis modules located in src/skillspector/nodes/analyzers/.

NVIDIA's SkillSpector is a security scanner built around a collection of static-pattern analyzers. Each analyzer scans source files for regular-expression signatures that map to a well-defined security issue class. Understanding the specific types of vulnerability patterns SkillSpector identifies allows security teams to tune scans for AI/ML pipelines and traditional codebases with precision.

Core Vulnerability Pattern Families

SkillSpector organizes its detection logic into specialized modules under src/skillspector/nodes/analyzers/. Each module defines a list of regular-expression patterns (with associated confidence scores) and helper logic to filter false positives, such as documentation examples.

Privilege Escalation (PE1–PE5)

The static_patterns_privilege_escalation.py module detects five classes of privilege-escalation risks (PE1–PE5). It flags over-permissive permission declarations, sudo/root execution, credential-file exposure, and dangerous Docker configurations including socket mounting or privileged container usage.

Server-Side Request Forgery (SSRF)

In static_patterns_ssrf.py, SkillSpector identifies URL construction patterns that can be abused to reach internal services. It detects hardcoded references to http://localhost, file:// protocols, cloud metadata endpoints (169.254.169.254), and other internal routes that could enable SSRF attacks.

Prompt Injection and Anti-Refusal

Two modules handle LLM-specific attacks. The static_patterns_prompt_injection.py analyzer finds constructs allowing attackers to inject malicious prompts into LLM-driven workflows. Complementing this, static_patterns_anti_refusal.py detects phrases or code structures designed to bypass LLM refusal mechanisms and coerce disallowed behavior.

System Prompt Leakage

The static_patterns_system_prompt_leakage.py module scans for accidental exposure of system-level prompts or configuration data that could be harvested by an LLM to reveal hidden instructions or security contexts.

Rogue Agent Detection

Through static_patterns_rogue_agent.py, SkillSpector identifies code that spawns or communicates with uncontrolled agents, hidden processes, or potential backdoors that could operate outside the intended security boundary.

Output Handling and Data Exfiltration

The static_patterns_output_handling.py analyzer flags patterns that write sensitive data to stdout, local files, or external services without proper sanitization, covering risks from information disclosure to active data exfiltration.

Supply Chain Risks

In static_patterns_supply_chain.py, the tool detects inclusion of untrusted dependencies, insecure imports, and hardcoded URLs pointing to external resources that could compromise the software supply chain.

Tool Misuse

The static_patterns_tool_misuse.py module identifies dangerous CLI flag combinations, unsafe subprocess calls, and misuse of system utilities that could lead to command injection or unintended system modifications.

YARA-Based Malware Detection

Finally, static_yara.py provides generic malicious-code detection using YARA rules to flag known malware signatures or suspicious code patterns that do not fit the specific categories above.

How SkillSpector Processes Patterns

SkillSpector aggregates findings through a centralized runner that orchestrates the individual analyzer modules and standardizes output.

The Static Runner Architecture

The static_runner.run_static_patterns function (defined in src/skillspector/nodes/analyzers/static_runner.py) loads each pattern module and executes regex scans across source files. Each analyzer applies its specific pattern set and produces AnalyzerFinding objects that are aggregated for report generation.

AnalyzerFinding Object Structure

Every match generates an AnalyzerFinding containing:

  • rule_id – Short identifier (e.g., PE2, SSRF)
  • message – Human-readable description
  • severity – Classification as LOW, MEDIUM, or HIGH
  • location – File name and exact line number
  • confidence – Numerical weight of the match likelihood
  • tags – Category tags (e.g., PRIVILEGE_ESCALATION, SSRF)

These objects are passed to the SARIF report generation pipeline defined in src/skillspector/sarif_models.py.

Practical Usage Examples

You can invoke SkillSpector via command line for full scans or programmatically to target specific vulnerability patterns.

CLI Scanning for All Patterns

Run a complete scan outputting SARIF format:

skillspector scan ./my-app --format sarif > results.sarif

The resulting SARIF entries include ruleId fields (e.g., PE2), severity levels, and physical location data with line numbers.

Direct Python API Integration

Import specific analyzers to run targeted checks without invoking the full static_runner:

from skillspector.nodes.analyzers import static_patterns_ssrf

findings = static_patterns_ssrf.analyze(
    content=open("client.py").read(),
    file_path="client.py",
    file_type="python"
)

for f in findings:
    print(f"[{f.severity}] {f.rule_id} – {f.message} (line {f.location.start_line})")

Selective Filtering by Category

Combine multiple analyzers and filter results programmatically:

from skillspector.nodes.analyzers import (
    static_patterns_privilege_escalation as pe,
    static_patterns_ssrf as ssrf,
)

all_findings = pe.analyze(src, "script.sh", "shell") + ssrf.analyze(src, "script.sh", "shell")
priv_esc = [f for f in all_findings if "PRIVILEGE_ESCALATION" in f.tags]

print(f"Found {len(priv_esc)} privilege-escalation issues")

Summary

  • SkillSpector identifies 10 vulnerability pattern families ranging from traditional security issues (SSRF, privilege escalation) to AI-specific risks (prompt injection, anti-refusal).
  • Each pattern module resides in src/skillspector/nodes/analyzers/ and implements regex-based detection with confidence scoring.
  • Findings are structured as AnalyzerFinding objects with standardized fields: rule_id, severity, location, confidence, and tags.
  • The static_runner.py orchestrates execution, while sarif_models.py handles report generation.
  • Both CLI and Python API support selective scanning, allowing developers to focus on specific threat categories like supply chain risks or rogue agent detection.

Frequently Asked Questions

What is the complete list of vulnerability patterns SkillSpector can detect?

SkillSpector detects privilege escalation (PE1–PE5), SSRF, prompt injection, system prompt leakage, rogue agents, output handling/data exfiltration, supply chain risks, tool misuse, anti-refusal patterns, and YARA-based malware signatures. Each category maps to a dedicated analyzer module in src/skillspector/nodes/analyzers/.

How does SkillSpector differ from traditional static application security testing (SAST) tools?

Unlike general-purpose SAST tools, SkillSpector includes specialized analyzers for AI-specific risks such as prompt injection, system prompt leakage, and anti-refusal bypasses. It also uses YARA rules for malware detection alongside regex-based pattern matching for code vulnerabilities.

Can I run a single vulnerability analyzer without executing the full scan?

Yes. You can import individual analyzer modules (e.g., static_patterns_ssrf) and call their analyze() method directly with file content and metadata. This approach bypasses the static_runner and returns AnalyzerFinding objects for programmatic processing.

What output formats does SkillSpector support for vulnerability findings?

SkillSpector primarily outputs findings in SARIF (Static Analysis Results Interchange Format) for integration with standard security dashboards. The sarif_models.py module handles the translation from internal AnalyzerFinding objects to SARIF-compliant JSON, including severity levels, line numbers, and confidence scores.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →