SkillSpector Environment Variables: Complete Configuration Guide
SkillSpector requires environment variables to configure LLM providers (SKILLSPECTOR_PROVIDER), authenticate with services (OPENAI_API_KEY, NVIDIA_INFERENCE_KEY), and control runtime behavior like logging levels and model selection.
NVIDIA's SkillSpector is an open-source security analysis tool that uses large language models to inspect code. Before running SkillSpector, you must configure the necessary environment variables to specify which AI backend processes your requests and provide the required authentication credentials.
Core SkillSpector Configuration Variables
The SkillSpector codebase reads several SKILLSPECTOR_* prefixed variables to control provider selection, model configuration, and runtime behavior.
Provider Selection
Set SKILLSPECTOR_PROVIDER to choose the active LLM backend. Supported values include openai, anthropic, anthropic_proxy, bedrock, nv_build, and nv_inference. The system resolves this value in providers/__init__.py#L78 to instantiate the correct provider class.
export SKILLSPECTOR_PROVIDER=openai
Model Configuration
Control which models SkillSpector uses through several related variables:
SKILLSPECTOR_MODEL: Global model override that takes precedence over per-slot settings. Defined inconstants.py#L34.SKILLSPECTOR_MODEL_<SLOT>: Per-slot model overrides (e.g.,SKILLSPECTOR_MODEL_META_ANALYZER). The slot name must match entries in_MODEL_SLOTSfromconstants.py#L55.SKILLSPECTOR_MODEL_REGISTRY: Path to a YAML file defining custom model metadata including context length. Loaded inproviders/registry.py#L64.SKILLSPECTOR_STRICT_MODEL_VALIDATION: When set totrue, raises an error if any specified model is not present in the registry. Implemented inconstants.py#L93.
Logging and Runtime Options
Configure execution behavior and observability:
SKILLSPECTOR_LOG_LEVEL: Controls verbosity (DEBUG,INFO,WARNING,ERROR). Defaults toWARNING. Defined inconstants.py#L106.SKILLSPECTOR_OSV_TIMEOUT: Timeout in seconds for OSV vulnerability lookups. Set innodes/analyzers/osv_client.py#L41.SKILLSPECTOR_SSL_VERIFY: Set to"false"to disable SSL verification for the Anthropic-proxy provider. Checked inproviders/anthropic_proxy/provider.py#L148.LANGCHAIN_TAGS_EXTRA: Extra tags passed to LangChain for telemetry. Used incli.py#L341.ENV: General environment flag (dev,prod, etc.) used by the CLI. Referenced incli.py#L339.
Provider-Specific Credentials
Each LLM backend requires specific authentication variables. You only need to set the variables corresponding to your chosen provider.
OpenAI Configuration
When SKILLSPECTOR_PROVIDER is set to openai:
OPENAI_API_KEY: API key for OpenAI-compatible endpoints. Accessed inproviders/openai/provider.py#L54.OPENAI_BASE_URL: Base URL of the OpenAI-compatible API (e.g., for hosted endpoints). Used inproviders/openai/provider.py#L57.OPENAI_PROJECT_ID: Optional project identifier for OpenAI services. Referenced inproviders/openai/provider.py#L40.
Anthropic and Anthropic Proxy
For direct Anthropic access:
ANTHROPIC_API_KEY: API key for the Anthropic service. Read inproviders/anthropic/provider.py#L52.
For the Anthropic proxy wrapper:
ANTHROPIC_PROXY_API_KEY: API key for the proxy service. Read inproviders/anthropic_proxy/provider.py#L214.ANTHROPIC_PROXY_ENDPOINT_URL: Custom endpoint URL for the proxy. Used inproviders/anthropic_proxy/provider.py#L215.ANTHROPIC_PROXY_API_VERSION: API version string (defaults tov1). Defined inproviders/anthropic_proxy/provider.py#L65.
NVIDIA Inference Services
For NVIDIA Build or Inference endpoints:
NVIDIA_INFERENCE_KEY: Credential for NVIDIA's inference service. Required inproviders/nv_build/provider.py#L51.
AWS Bedrock
When using AWS Bedrock as the provider:
AWS_PROFILE: AWS credential profile name for authentication. Used inproviders/bedrock/provider.py#L102.AWS_REGION: AWS region for Bedrock access (defaults tous-east-1). Referenced inproviders/bedrock/provider.py#L103.
Configuration Examples
Configure SkillSpector to use OpenAI with specific logging:
export SKILLSPECTOR_PROVIDER=openai
export OPENAI_API_KEY=sk-your-key-here
export SKILLSPECTOR_LOG_LEVEL=DEBUG
export SKILLSPECTOR_MODEL=gpt-4
Configure for NVIDIA Inference with a custom model registry:
export SKILLSPECTOR_PROVIDER=nv_build
export NVIDIA_INFERENCE_KEY=nvapi-your-key
export SKILLSPECTOR_MODEL_REGISTRY=/path/to/models.yaml
export SKILLSPECTOR_STRICT_MODEL_VALIDATION=true
Configure for Bedrock with specific region:
export SKILLSPECTOR_PROVIDER=bedrock
export AWS_PROFILE=skillspector-profile
export AWS_REGION=us-west-2
Summary
- Provider selection requires
SKILLSPECTOR_PROVIDERand corresponding credentials (OPENAI_API_KEY,ANTHROPIC_API_KEY,NVIDIA_INFERENCE_KEY, orAWS_PROFILE). - Model configuration uses
SKILLSPECTOR_MODEL, per-slot overrides (SKILLSPECTOR_MODEL_<SLOT>), and optional registry validation viaSKILLSPECTOR_MODEL_REGISTRY. - Runtime control includes
SKILLSPECTOR_LOG_LEVEL,SKILLSPECTOR_OSV_TIMEOUT, andSKILLSPECTOR_SSL_VERIFYfor specific provider behaviors. - Telemetry can be customized with
LANGCHAIN_TAGS_EXTRAandENVvariables used in the CLI interface.
Frequently Asked Questions
What is the minimum set of environment variables required to run SkillSpector?
At minimum, you must set SKILLSPECTOR_PROVIDER to specify the LLM backend (e.g., openai, anthropic, or nv_build) and provide the corresponding API key for that provider, such as OPENAI_API_KEY or NVIDIA_INFERENCE_KEY. Without these authentication variables, the provider initialization will fail.
How do I configure different models for different analysis slots in SkillSpector?
Use the SKILLSPECTOR_MODEL_<SLOT> pattern, where the slot name corresponds to entries in _MODEL_SLOTS defined in constants.py#L55. For example, set SKILLSPECTOR_MODEL_META_ANALYZER to override the model specifically for the meta analyzer slot while using the global default for other components.
Can I disable SSL verification for the Anthropic proxy provider?
Yes, set SKILLSPECTOR_SSL_VERIFY to "false". This disables SSL verification specifically for the Anthropic-proxy provider as implemented in providers/anthropic_proxy/provider.py#L148. This is useful for testing against internal endpoints but should not be used in production environments.
Where does SkillSpector look for custom model registry definitions?
Set SKILLSPECTOR_MODEL_REGISTRY to the absolute file path of your YAML file containing custom model metadata. The system reads this registry in providers/registry.py#L64 to validate model context lengths and other parameters. When SKILLSPECTOR_STRICT_MODEL_VALIDATION is enabled, the system raises errors if specified models are not found in this registry.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →