Repository navigation
Expand file tree
/
Copy path.env.example
More file actions
132 lines (109 loc) · 5.13 KB
/
Copy path.env.example
File metadata and controls
132 lines (109 loc) · 5.13 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
# Bawbel Scanner — Environment Variables
# Copy this file to .env and fill in your values.
# All variables are optional — the scanner works without any of them.
#
# Usage:
# cp .env.example .env
# # edit .env with your values
# source .env && bawbel scan ./my-skill.md
#
# Or pass inline:
# ANTHROPIC_API_KEY=sk-ant-... bawbel scan ./my-skill.md
# ── Logging ──────────────────────────────────────────────────────────────────
# Log verbosity: DEBUG | INFO | WARNING | ERROR
# Default: WARNING (silent in normal use)
BAWBEL_LOG_LEVEL=WARNING
# ── Scanner limits ────────────────────────────────────────────────────────────
# Skip files larger than N megabytes
# Default: 10
BAWBEL_MAX_FILE_SIZE_MB=10
# Subprocess timeout for YARA and Semgrep engines (seconds)
# Default: 30
BAWBEL_SCAN_TIMEOUT_SEC=30
# Minimum confidence score for a finding to pass FP-3 threshold check.
# The effective threshold depends on file profile (skill=0.60, mcp_manifest=0.55,
# documentation=0.85, unknown=0.60). This var overrides only the fallback threshold
# for files that don't match any named profile.
# Default: 0.80
# BAWBEL_CONFIDENCE_THRESHOLD=0.80
# ── Stage 2: LLM Semantic Analysis ───────────────────────────────────────────
# Requires: pip install "bawbel-scanner[llm]"
# At least one provider key must be set for Stage 2 to activate.
#
# Provider keys — set whichever you use:
# Key Auto-selected model
# ─────────────────── ────────────────────────────────
# ANTHROPIC_API_KEY → claude-haiku-4-5-20251001
# OPENAI_API_KEY → gpt-4o-mini
# GEMINI_API_KEY → gemini/gemini-1.5-flash
# MISTRAL_API_KEY → mistral/mistral-small
# GROQ_API_KEY → groq/llama3-8b-8192
# Uncomment and fill in your key:
# ANTHROPIC_API_KEY=sk-ant-...
# OPENAI_API_KEY=sk-...
# GEMINI_API_KEY=...
# MISTRAL_API_KEY=...
# GROQ_API_KEY=...
# Override the auto-selected model (any LiteLLM model string)
# Examples:
# claude-haiku-4-5-20251001
# gpt-4o-mini
# gemini/gemini-1.5-flash
# ollama/mistral ← local, no API key needed
# ollama/llama3
# BAWBEL_LLM_MODEL=claude-haiku-4-5-20251001
# Max content characters sent to LLM per scan (large files are truncated)
# Default: 8000
# BAWBEL_LLM_MAX_CHARS=8000
# LLM call timeout in seconds
# Default: 30
# BAWBEL_LLM_TIMEOUT=30
# Set to "false" to disable Stage 2 entirely even if a key is set
# Default: true
# BAWBEL_LLM_ENABLED=true
# ── FP-4: Meta-Analyzer ───────────────────────────────────────────────────────
# Requires: pip install "bawbel-scanner[llm]" (same dependency as Stage 2)
# Reviews medium-confidence findings (one LLM call per file) and reclassifies
# each as real (+0.15 confidence), needs_review (-0.05), or false_positive (suppressed).
# Skips automatically when no provider key is configured.
# Set to "false" to disable the LLM FP filter entirely
# Default: true
# BAWBEL_META_ANALYZER_ENABLED=true
# Confidence window — only findings within [MIN, MAX] are sent to the LLM.
# Findings above MAX are trusted as-is; findings below MIN are already suppressed.
# Default: 0.35 (min), 0.80 (max)
# BAWBEL_META_MIN_CONFIDENCE=0.35
# BAWBEL_META_MAX_CONFIDENCE=0.80
# ── Stage 3: Behavioral Sandbox ──────────────────────────────────────────────
# Requires: Docker Desktop or Docker Engine running
# Disabled by default — set BAWBEL_SANDBOX_ENABLED=true to enable.
#
# Image resolution (hybrid strategy):
# 1. Check local Docker cache → run immediately if found
# 2. Pull from Docker Hub → cache + run
# 3. Build from bundled Dockerfile → offline / air-gapped fallback
#
# BAWBEL_SANDBOX_IMAGE controls which image to use:
# "default" → hybrid strategy above (recommended)
# "local" → skip Hub, always build from bundled Dockerfile
# "<image>" → use custom image (enterprise registry, dev/test)
#
# Examples:
# BAWBEL_SANDBOX_IMAGE=default
# BAWBEL_SANDBOX_IMAGE=local
# BAWBEL_SANDBOX_IMAGE=registry.company.com/bawbel/sandbox@sha256:abc123
# BAWBEL_SANDBOX_IMAGE=my-custom-sandbox:dev
# Enable Stage 3 behavioral sandbox
# Default: false
# BAWBEL_SANDBOX_ENABLED=true
# Sandbox Docker image
# Default: default (hybrid — Hub pull with local build fallback)
# BAWBEL_SANDBOX_IMAGE=default
# Container execution timeout in seconds
# Default: 30
# BAWBEL_SANDBOX_TIMEOUT=30
# Container network mode
# none → fully isolated, no internet (recommended for security)
# bridge → container has internet access (needed for network egress testing)
# Default: none
# BAWBEL_SANDBOX_NETWORK=none