# How to Run SkillSpector in Docker with LLM API Keys

> Easily run SkillSpector in Docker with LLM API keys. Mount your code and configure credentials via environment variables for seamless integration. Get started today.

- Repository: [NVIDIA Corporation/SkillSpector](https://github.com/NVIDIA/SkillSpector)
- Tags: how-to-guide
- Published: 2026-06-24

---

**You can run NVIDIA SkillSpector inside a Docker container by mounting your code to `/scan` and passing LLM credentials via environment variables or an `.env` file, using the image built from the repository's Dockerfile.**

NVIDIA SkillSpector is an open-source security scanner for AI skills that analyzes code for vulnerabilities using static analysis and LLM-based semantic validation. To run SkillSpector in Docker with LLM API keys, you build the container from the project's `Dockerfile` and supply provider credentials through environment variables. This approach eliminates the need for a local Python environment while ensuring secure handling of sensitive API keys.

## Build the SkillSpector Docker Image

The repository provides a multi-stage `Dockerfile` that creates a lightweight runtime image. The build process uses a builder stage to install dependencies into a virtual environment, then copies that environment into the final image.

Build the image from the repository root using Make:

```bash
make docker-build

```

Alternatively, build directly with Docker:

```bash
docker build -t skillspector .

```

The container is configured with `ENTRYPOINT ["skillspector"]`, which means any arguments passed after the image name are forwarded directly to the SkillSpector CLI as implemented in [`src/skillspector/cli.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/cli.py).

## Configure LLM API Credentials

SkillSpector requires API keys for the LLM provider you intend to use. The CLI reads these from environment variables, parsing them in [`src/skillspector/cli.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/cli.py) (lines 92-106), and supports OpenAI, Anthropic, and NVIDIA inference endpoints.

Create an `.env` file following the template provided in `.env.example`:

```text
SKILLSPECTOR_PROVIDER=anthropic
ANTHROPIC_API_KEY=sk-ant-...

# OPENAI_API_KEY=sk-...

# NVIDIA_INFERENCE_KEY=nvapi-...

```

Supported environment variables include:

- `OPENAI_API_KEY` – for OpenAI GPT models
- `ANTHROPIC_API_KEY` – for Claude models
- `NVIDIA_INFERENCE_KEY` – for NVIDIA build provider
- `SKILLSPECTOR_PROVIDER` – specifies which provider to use (`openai`, `anthropic`, or `nv_build`)
- `SKILLSPECTOR_MODEL` – overrides the default model selection

## Run the Container with Mounted Volumes

Execute scans by mounting your local skill directory to `/scan` in the container. The container uses `/scan` as its working directory.

To run a static analysis without LLM validation:

```bash
docker run --rm -v "$PWD:/scan" skillspector scan ./my-skill/ --no-llm

```

To run with LLM analysis using an `.env` file:

```bash
docker run --rm \
  -v "$PWD:/scan" \
  --env-file .env \
  skillspector scan ./my-skill/

```

To pass credentials directly via command line:

```bash
docker run --rm \
  -v "$PWD:/scan" \
  -e SKILLSPECTOR_PROVIDER=anthropic \
  -e ANTHROPIC_API_KEY="$ANTHROPIC_API_KEY" \
  skillspector scan ./my-skill/

```

## Connect to Local LLM Endpoints

You can route SkillSpector to local OpenAI-compatible servers, such as Ollama, by setting additional environment variables.

```bash
docker run --rm \
  -v "$PWD:/scan" \
  -e SKILLSPECTOR_PROVIDER=openai \
  -e OPENAI_API_KEY=ollama \
  -e OPENAI_BASE_URL=http://localhost:11434/v1 \
  -e SKILLSPECTOR_MODEL=llama3.1:8b \
  skillspector scan ./my-skill/

```

This configuration sets `SKILLSPECTOR_MODEL` to force a specific model and uses `OPENAI_BASE_URL` to redirect requests to your local inference server.

## Summary

- **Build the image** from the `Dockerfile` using `make docker-build` or `docker build -t skillspector .`
- **Supply credentials** via an `.env` file or `-e` flags for `OPENAI_API_KEY`, `ANTHROPIC_API_KEY`, or `NVIDIA_INFERENCE_KEY`
- **Mount your code** to `/scan` when running the container to allow SkillSpector to access your skill files
- **Override the provider** and model using `SKILLSPECTOR_PROVIDER` and `SKILLSPECTOR_MODEL` environment variables
- **Disable LLM analysis** with `--no-llm` for faster static-only scans

## Frequently Asked Questions

### Do I need Python installed on my host machine to run SkillSpector?

No. When you run SkillSpector in Docker, the container includes its own Python runtime and dependencies. You only need Docker installed on your host system. The `Dockerfile` creates a self-contained image that executes the `skillspector` command without requiring a local Python environment.

### Which environment variables are required for LLM analysis?

You must provide the API key corresponding to your chosen provider: `OPENAI_API_KEY` for OpenAI, `ANTHROPIC_API_KEY` for Anthropic, or `NVIDIA_INFERENCE_KEY` for NVIDIA inference endpoints. Additionally, set `SKILLSPECTOR_PROVIDER` to specify which backend to use (`openai`, `anthropic`, or `nv_build`). These variables are parsed by [`src/skillspector/cli.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/cli.py) and forwarded to the scan logic.

### How do I run SkillSpector against a local Ollama instance?

Set `SKILLSPECTOR_PROVIDER=openai`, configure `OPENAI_BASE_URL` to point to your Ollama endpoint (e.g., `http://localhost:11434/v1`), and provide a dummy value for `OPENAI_API_KEY`. You can also specify the model using `SKILLSPECTOR_MODEL`, such as `llama3.1:8b`, to ensure SkillSpector uses the correct local model for semantic analysis.

### Can I disable LLM analysis when running in Docker?

Yes. Append the `--no-llm` flag to your scan command to perform static analysis only. This skips the semantic vulnerability checks and runs faster, which is useful when you do not have API keys configured or want to perform quick static scans without network calls to external providers.