How to Run SkillSpector in Docker with LLM API Keys

You can run NVIDIA SkillSpector inside a Docker container by mounting your code to /scan and passing LLM credentials via environment variables or an .env file, using the image built from the repository's Dockerfile.

NVIDIA SkillSpector is an open-source security scanner for AI skills that analyzes code for vulnerabilities using static analysis and LLM-based semantic validation. To run SkillSpector in Docker with LLM API keys, you build the container from the project's Dockerfile and supply provider credentials through environment variables. This approach eliminates the need for a local Python environment while ensuring secure handling of sensitive API keys.

Build the SkillSpector Docker Image

The repository provides a multi-stage Dockerfile that creates a lightweight runtime image. The build process uses a builder stage to install dependencies into a virtual environment, then copies that environment into the final image.

Build the image from the repository root using Make:

make docker-build

Alternatively, build directly with Docker:

docker build -t skillspector .

The container is configured with ENTRYPOINT ["skillspector"], which means any arguments passed after the image name are forwarded directly to the SkillSpector CLI as implemented in src/skillspector/cli.py.

Configure LLM API Credentials

SkillSpector requires API keys for the LLM provider you intend to use. The CLI reads these from environment variables, parsing them in src/skillspector/cli.py (lines 92-106), and supports OpenAI, Anthropic, and NVIDIA inference endpoints.

Create an .env file following the template provided in .env.example:

SKILLSPECTOR_PROVIDER=anthropic
ANTHROPIC_API_KEY=sk-ant-...

# OPENAI_API_KEY=sk-...

# NVIDIA_INFERENCE_KEY=nvapi-...

Supported environment variables include:

  • OPENAI_API_KEY – for OpenAI GPT models
  • ANTHROPIC_API_KEY – for Claude models
  • NVIDIA_INFERENCE_KEY – for NVIDIA build provider
  • SKILLSPECTOR_PROVIDER – specifies which provider to use (openai, anthropic, or nv_build)
  • SKILLSPECTOR_MODEL – overrides the default model selection

Run the Container with Mounted Volumes

Execute scans by mounting your local skill directory to /scan in the container. The container uses /scan as its working directory.

To run a static analysis without LLM validation:

docker run --rm -v "$PWD:/scan" skillspector scan ./my-skill/ --no-llm

To run with LLM analysis using an .env file:

docker run --rm \
  -v "$PWD:/scan" \
  --env-file .env \
  skillspector scan ./my-skill/

To pass credentials directly via command line:

docker run --rm \
  -v "$PWD:/scan" \
  -e SKILLSPECTOR_PROVIDER=anthropic \
  -e ANTHROPIC_API_KEY="$ANTHROPIC_API_KEY" \
  skillspector scan ./my-skill/

Connect to Local LLM Endpoints

You can route SkillSpector to local OpenAI-compatible servers, such as Ollama, by setting additional environment variables.

docker run --rm \
  -v "$PWD:/scan" \
  -e SKILLSPECTOR_PROVIDER=openai \
  -e OPENAI_API_KEY=ollama \
  -e OPENAI_BASE_URL=http://localhost:11434/v1 \
  -e SKILLSPECTOR_MODEL=llama3.1:8b \
  skillspector scan ./my-skill/

This configuration sets SKILLSPECTOR_MODEL to force a specific model and uses OPENAI_BASE_URL to redirect requests to your local inference server.

Summary

  • Build the image from the Dockerfile using make docker-build or docker build -t skillspector .
  • Supply credentials via an .env file or -e flags for OPENAI_API_KEY, ANTHROPIC_API_KEY, or NVIDIA_INFERENCE_KEY
  • Mount your code to /scan when running the container to allow SkillSpector to access your skill files
  • Override the provider and model using SKILLSPECTOR_PROVIDER and SKILLSPECTOR_MODEL environment variables
  • Disable LLM analysis with --no-llm for faster static-only scans

Frequently Asked Questions

Do I need Python installed on my host machine to run SkillSpector?

No. When you run SkillSpector in Docker, the container includes its own Python runtime and dependencies. You only need Docker installed on your host system. The Dockerfile creates a self-contained image that executes the skillspector command without requiring a local Python environment.

Which environment variables are required for LLM analysis?

You must provide the API key corresponding to your chosen provider: OPENAI_API_KEY for OpenAI, ANTHROPIC_API_KEY for Anthropic, or NVIDIA_INFERENCE_KEY for NVIDIA inference endpoints. Additionally, set SKILLSPECTOR_PROVIDER to specify which backend to use (openai, anthropic, or nv_build). These variables are parsed by src/skillspector/cli.py and forwarded to the scan logic.

How do I run SkillSpector against a local Ollama instance?

Set SKILLSPECTOR_PROVIDER=openai, configure OPENAI_BASE_URL to point to your Ollama endpoint (e.g., http://localhost:11434/v1), and provide a dummy value for OPENAI_API_KEY. You can also specify the model using SKILLSPECTOR_MODEL, such as llama3.1:8b, to ensure SkillSpector uses the correct local model for semantic analysis.

Can I disable LLM analysis when running in Docker?

Yes. Append the --no-llm flag to your scan command to perform static analysis only. This skips the semantic vulnerability checks and runs faster, which is useful when you do not have API keys configured or want to perform quick static scans without network calls to external providers.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →