# SkillSpector Environment Variables: Complete Configuration Guide

> Master SkillSpector environment variables. Configure LLM providers, API keys, and runtime settings for optimal performance. Essential guide for NVIDIA/SkillSpector users.

- Repository: [NVIDIA Corporation/SkillSpector](https://github.com/NVIDIA/SkillSpector)
- Tags: how-to-guide
- Published: 2026-07-12

---

**SkillSpector requires environment variables to configure LLM providers (`SKILLSPECTOR_PROVIDER`), authenticate with services (`OPENAI_API_KEY`, `NVIDIA_INFERENCE_KEY`), and control runtime behavior like logging levels and model selection.**

NVIDIA's SkillSpector is an open-source security analysis tool that uses large language models to inspect code. Before running SkillSpector, you must configure the necessary environment variables to specify which AI backend processes your requests and provide the required authentication credentials.

## Core SkillSpector Configuration Variables

The SkillSpector codebase reads several `SKILLSPECTOR_*` prefixed variables to control provider selection, model configuration, and runtime behavior.

### Provider Selection

Set **`SKILLSPECTOR_PROVIDER`** to choose the active LLM backend. Supported values include `openai`, `anthropic`, `anthropic_proxy`, `bedrock`, `nv_build`, and `nv_inference`. The system resolves this value in `providers/__init__.py#L78` to instantiate the correct provider class.

```bash
export SKILLSPECTOR_PROVIDER=openai

```

### Model Configuration

Control which models SkillSpector uses through several related variables:

- **`SKILLSPECTOR_MODEL`**: Global model override that takes precedence over per-slot settings. Defined in `constants.py#L34`.
- **`SKILLSPECTOR_MODEL_<SLOT>`**: Per-slot model overrides (e.g., `SKILLSPECTOR_MODEL_META_ANALYZER`). The slot name must match entries in `_MODEL_SLOTS` from `constants.py#L55`.
- **`SKILLSPECTOR_MODEL_REGISTRY`**: Path to a YAML file defining custom model metadata including context length. Loaded in `providers/registry.py#L64`.
- **`SKILLSPECTOR_STRICT_MODEL_VALIDATION`**: When set to `true`, raises an error if any specified model is not present in the registry. Implemented in `constants.py#L93`.

### Logging and Runtime Options

Configure execution behavior and observability:

- **`SKILLSPECTOR_LOG_LEVEL`**: Controls verbosity (`DEBUG`, `INFO`, `WARNING`, `ERROR`). Defaults to `WARNING`. Defined in `constants.py#L106`.
- **`SKILLSPECTOR_OSV_TIMEOUT`**: Timeout in seconds for OSV vulnerability lookups. Set in `nodes/analyzers/osv_client.py#L41`.
- **`SKILLSPECTOR_SSL_VERIFY`**: Set to `"false"` to disable SSL verification for the Anthropic-proxy provider. Checked in `providers/anthropic_proxy/provider.py#L148`.
- **`LANGCHAIN_TAGS_EXTRA`**: Extra tags passed to LangChain for telemetry. Used in `cli.py#L341`.
- **`ENV`**: General environment flag (`dev`, `prod`, etc.) used by the CLI. Referenced in `cli.py#L339`.

## Provider-Specific Credentials

Each LLM backend requires specific authentication variables. You only need to set the variables corresponding to your chosen provider.

### OpenAI Configuration

When `SKILLSPECTOR_PROVIDER` is set to `openai`:

- **`OPENAI_API_KEY`**: API key for OpenAI-compatible endpoints. Accessed in `providers/openai/provider.py#L54`.
- **`OPENAI_BASE_URL`**: Base URL of the OpenAI-compatible API (e.g., for hosted endpoints). Used in `providers/openai/provider.py#L57`.
- **`OPENAI_PROJECT_ID`**: Optional project identifier for OpenAI services. Referenced in `providers/openai/provider.py#L40`.

### Anthropic and Anthropic Proxy

For direct Anthropic access:
- **`ANTHROPIC_API_KEY`**: API key for the Anthropic service. Read in `providers/anthropic/provider.py#L52`.

For the Anthropic proxy wrapper:
- **`ANTHROPIC_PROXY_API_KEY`**: API key for the proxy service. Read in `providers/anthropic_proxy/provider.py#L214`.
- **`ANTHROPIC_PROXY_ENDPOINT_URL`**: Custom endpoint URL for the proxy. Used in `providers/anthropic_proxy/provider.py#L215`.
- **`ANTHROPIC_PROXY_API_VERSION`**: API version string (defaults to `v1`). Defined in `providers/anthropic_proxy/provider.py#L65`.

### NVIDIA Inference Services

For NVIDIA Build or Inference endpoints:
- **`NVIDIA_INFERENCE_KEY`**: Credential for NVIDIA's inference service. Required in `providers/nv_build/provider.py#L51`.

### AWS Bedrock

When using AWS Bedrock as the provider:
- **`AWS_PROFILE`**: AWS credential profile name for authentication. Used in `providers/bedrock/provider.py#L102`.
- **`AWS_REGION`**: AWS region for Bedrock access (defaults to `us-east-1`). Referenced in `providers/bedrock/provider.py#L103`.

## Configuration Examples

Configure SkillSpector to use OpenAI with specific logging:

```bash
export SKILLSPECTOR_PROVIDER=openai
export OPENAI_API_KEY=sk-your-key-here
export SKILLSPECTOR_LOG_LEVEL=DEBUG
export SKILLSPECTOR_MODEL=gpt-4

```

Configure for NVIDIA Inference with a custom model registry:

```bash
export SKILLSPECTOR_PROVIDER=nv_build
export NVIDIA_INFERENCE_KEY=nvapi-your-key
export SKILLSPECTOR_MODEL_REGISTRY=/path/to/models.yaml
export SKILLSPECTOR_STRICT_MODEL_VALIDATION=true

```

Configure for Bedrock with specific region:

```bash
export SKILLSPECTOR_PROVIDER=bedrock
export AWS_PROFILE=skillspector-profile
export AWS_REGION=us-west-2

```

## Summary

- **Provider selection** requires `SKILLSPECTOR_PROVIDER` and corresponding credentials (`OPENAI_API_KEY`, `ANTHROPIC_API_KEY`, `NVIDIA_INFERENCE_KEY`, or `AWS_PROFILE`).
- **Model configuration** uses `SKILLSPECTOR_MODEL`, per-slot overrides (`SKILLSPECTOR_MODEL_<SLOT>`), and optional registry validation via `SKILLSPECTOR_MODEL_REGISTRY`.
- **Runtime control** includes `SKILLSPECTOR_LOG_LEVEL`, `SKILLSPECTOR_OSV_TIMEOUT`, and `SKILLSPECTOR_SSL_VERIFY` for specific provider behaviors.
- **Telemetry** can be customized with `LANGCHAIN_TAGS_EXTRA` and `ENV` variables used in the CLI interface.

## Frequently Asked Questions

### What is the minimum set of environment variables required to run SkillSpector?

At minimum, you must set `SKILLSPECTOR_PROVIDER` to specify the LLM backend (e.g., `openai`, `anthropic`, or `nv_build`) and provide the corresponding API key for that provider, such as `OPENAI_API_KEY` or `NVIDIA_INFERENCE_KEY`. Without these authentication variables, the provider initialization will fail.

### How do I configure different models for different analysis slots in SkillSpector?

Use the `SKILLSPECTOR_MODEL_<SLOT>` pattern, where the slot name corresponds to entries in `_MODEL_SLOTS` defined in `constants.py#L55`. For example, set `SKILLSPECTOR_MODEL_META_ANALYZER` to override the model specifically for the meta analyzer slot while using the global default for other components.

### Can I disable SSL verification for the Anthropic proxy provider?

Yes, set `SKILLSPECTOR_SSL_VERIFY` to `"false"`. This disables SSL verification specifically for the Anthropic-proxy provider as implemented in `providers/anthropic_proxy/provider.py#L148`. This is useful for testing against internal endpoints but should not be used in production environments.

### Where does SkillSpector look for custom model registry definitions?

Set `SKILLSPECTOR_MODEL_REGISTRY` to the absolute file path of your YAML file containing custom model metadata. The system reads this registry in `providers/registry.py#L64` to validate model context lengths and other parameters. When `SKILLSPECTOR_STRICT_MODEL_VALIDATION` is enabled, the system raises errors if specified models are not found in this registry.