SkillSpector Environment Variables: Complete Configuration Guide

SkillSpector requires environment variables to configure LLM providers (SKILLSPECTOR_PROVIDER), authenticate with services (OPENAI_API_KEY, NVIDIA_INFERENCE_KEY), and control runtime behavior like logging levels and model selection.

NVIDIA's SkillSpector is an open-source security analysis tool that uses large language models to inspect code. Before running SkillSpector, you must configure the necessary environment variables to specify which AI backend processes your requests and provide the required authentication credentials.

Core SkillSpector Configuration Variables

The SkillSpector codebase reads several SKILLSPECTOR_* prefixed variables to control provider selection, model configuration, and runtime behavior.

Provider Selection

Set SKILLSPECTOR_PROVIDER to choose the active LLM backend. Supported values include openai, anthropic, anthropic_proxy, bedrock, nv_build, and nv_inference. The system resolves this value in providers/__init__.py#L78 to instantiate the correct provider class.

export SKILLSPECTOR_PROVIDER=openai

Model Configuration

Control which models SkillSpector uses through several related variables:

  • SKILLSPECTOR_MODEL: Global model override that takes precedence over per-slot settings. Defined in constants.py#L34.
  • SKILLSPECTOR_MODEL_<SLOT>: Per-slot model overrides (e.g., SKILLSPECTOR_MODEL_META_ANALYZER). The slot name must match entries in _MODEL_SLOTS from constants.py#L55.
  • SKILLSPECTOR_MODEL_REGISTRY: Path to a YAML file defining custom model metadata including context length. Loaded in providers/registry.py#L64.
  • SKILLSPECTOR_STRICT_MODEL_VALIDATION: When set to true, raises an error if any specified model is not present in the registry. Implemented in constants.py#L93.

Logging and Runtime Options

Configure execution behavior and observability:

  • SKILLSPECTOR_LOG_LEVEL: Controls verbosity (DEBUG, INFO, WARNING, ERROR). Defaults to WARNING. Defined in constants.py#L106.
  • SKILLSPECTOR_OSV_TIMEOUT: Timeout in seconds for OSV vulnerability lookups. Set in nodes/analyzers/osv_client.py#L41.
  • SKILLSPECTOR_SSL_VERIFY: Set to "false" to disable SSL verification for the Anthropic-proxy provider. Checked in providers/anthropic_proxy/provider.py#L148.
  • LANGCHAIN_TAGS_EXTRA: Extra tags passed to LangChain for telemetry. Used in cli.py#L341.
  • ENV: General environment flag (dev, prod, etc.) used by the CLI. Referenced in cli.py#L339.

Provider-Specific Credentials

Each LLM backend requires specific authentication variables. You only need to set the variables corresponding to your chosen provider.

OpenAI Configuration

When SKILLSPECTOR_PROVIDER is set to openai:

  • OPENAI_API_KEY: API key for OpenAI-compatible endpoints. Accessed in providers/openai/provider.py#L54.
  • OPENAI_BASE_URL: Base URL of the OpenAI-compatible API (e.g., for hosted endpoints). Used in providers/openai/provider.py#L57.
  • OPENAI_PROJECT_ID: Optional project identifier for OpenAI services. Referenced in providers/openai/provider.py#L40.

Anthropic and Anthropic Proxy

For direct Anthropic access:

  • ANTHROPIC_API_KEY: API key for the Anthropic service. Read in providers/anthropic/provider.py#L52.

For the Anthropic proxy wrapper:

  • ANTHROPIC_PROXY_API_KEY: API key for the proxy service. Read in providers/anthropic_proxy/provider.py#L214.
  • ANTHROPIC_PROXY_ENDPOINT_URL: Custom endpoint URL for the proxy. Used in providers/anthropic_proxy/provider.py#L215.
  • ANTHROPIC_PROXY_API_VERSION: API version string (defaults to v1). Defined in providers/anthropic_proxy/provider.py#L65.

NVIDIA Inference Services

For NVIDIA Build or Inference endpoints:

  • NVIDIA_INFERENCE_KEY: Credential for NVIDIA's inference service. Required in providers/nv_build/provider.py#L51.

AWS Bedrock

When using AWS Bedrock as the provider:

  • AWS_PROFILE: AWS credential profile name for authentication. Used in providers/bedrock/provider.py#L102.
  • AWS_REGION: AWS region for Bedrock access (defaults to us-east-1). Referenced in providers/bedrock/provider.py#L103.

Configuration Examples

Configure SkillSpector to use OpenAI with specific logging:

export SKILLSPECTOR_PROVIDER=openai
export OPENAI_API_KEY=sk-your-key-here
export SKILLSPECTOR_LOG_LEVEL=DEBUG
export SKILLSPECTOR_MODEL=gpt-4

Configure for NVIDIA Inference with a custom model registry:

export SKILLSPECTOR_PROVIDER=nv_build
export NVIDIA_INFERENCE_KEY=nvapi-your-key
export SKILLSPECTOR_MODEL_REGISTRY=/path/to/models.yaml
export SKILLSPECTOR_STRICT_MODEL_VALIDATION=true

Configure for Bedrock with specific region:

export SKILLSPECTOR_PROVIDER=bedrock
export AWS_PROFILE=skillspector-profile
export AWS_REGION=us-west-2

Summary

  • Provider selection requires SKILLSPECTOR_PROVIDER and corresponding credentials (OPENAI_API_KEY, ANTHROPIC_API_KEY, NVIDIA_INFERENCE_KEY, or AWS_PROFILE).
  • Model configuration uses SKILLSPECTOR_MODEL, per-slot overrides (SKILLSPECTOR_MODEL_<SLOT>), and optional registry validation via SKILLSPECTOR_MODEL_REGISTRY.
  • Runtime control includes SKILLSPECTOR_LOG_LEVEL, SKILLSPECTOR_OSV_TIMEOUT, and SKILLSPECTOR_SSL_VERIFY for specific provider behaviors.
  • Telemetry can be customized with LANGCHAIN_TAGS_EXTRA and ENV variables used in the CLI interface.

Frequently Asked Questions

What is the minimum set of environment variables required to run SkillSpector?

At minimum, you must set SKILLSPECTOR_PROVIDER to specify the LLM backend (e.g., openai, anthropic, or nv_build) and provide the corresponding API key for that provider, such as OPENAI_API_KEY or NVIDIA_INFERENCE_KEY. Without these authentication variables, the provider initialization will fail.

How do I configure different models for different analysis slots in SkillSpector?

Use the SKILLSPECTOR_MODEL_<SLOT> pattern, where the slot name corresponds to entries in _MODEL_SLOTS defined in constants.py#L55. For example, set SKILLSPECTOR_MODEL_META_ANALYZER to override the model specifically for the meta analyzer slot while using the global default for other components.

Can I disable SSL verification for the Anthropic proxy provider?

Yes, set SKILLSPECTOR_SSL_VERIFY to "false". This disables SSL verification specifically for the Anthropic-proxy provider as implemented in providers/anthropic_proxy/provider.py#L148. This is useful for testing against internal endpoints but should not be used in production environments.

Where does SkillSpector look for custom model registry definitions?

Set SKILLSPECTOR_MODEL_REGISTRY to the absolute file path of your YAML file containing custom model metadata. The system reads this registry in providers/registry.py#L64 to validate model context lengths and other parameters. When SKILLSPECTOR_STRICT_MODEL_VALIDATION is enabled, the system raises errors if specified models are not found in this registry.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →