# How to Run SkillSpector in Docker with API Keys: A Complete Setup Guide

> Learn to run SkillSpector in Docker with API keys. This guide details building the image, mounting directories, and setting LLM credentials for a seamless setup of NVIDIA SkillSpector.

- Repository: [NVIDIA Corporation/SkillSpector](https://github.com/NVIDIA/SkillSpector)
- Tags: how-to-guide
- Published: 2026-06-25

---

**You can run NVIDIA SkillSpector in a Docker container by building the image from the repository's `Dockerfile`, mounting your skill directory to `/scan`, and supplying LLM provider credentials via environment variables or an `.env` file.**

SkillSpector is an open-source security scanning tool from NVIDIA that analyzes AI skill implementations for vulnerabilities. Running SkillSpector in Docker eliminates the need to install Python dependencies on your host system while keeping sensitive API keys secure through environment variable injection. This guide walks through the exact steps to configure and execute containerized scans using the official `Dockerfile` and credential handling implemented in [`src/skillspector/cli.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/cli.py).

## Building the SkillSpector Docker Image

The NVIDIA/SkillSpector repository provides a multi-stage `Dockerfile` at the repository root that creates a self-contained runtime environment. The build process uses a builder stage to install the package into a virtual environment, then copies that environment into the final runtime image.

Use the provided Makefile target or build directly:

```bash

# Option 1: Using Make

make docker-build

# Option 2: Direct Docker build

docker build -t skillspector .

```

The container's `ENTRYPOINT` is configured as `["skillspector"]`, meaning any arguments you pass after the image name are forwarded directly to the SkillSpector CLI.

## Configuring API Keys for Containerized Execution

SkillSpector requires credentials for your chosen LLM provider to perform semantic analysis. According to the source code in [`src/skillspector/cli.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/cli.py) (lines 92-106), the application reads environment variables for **OpenAI**, **Anthropic**, and **NVIDIA** providers.

The repository includes an `.env.example` file demonstrating the required variable names:

- `OPENAI_API_KEY`
- `ANTHROPIC_API_KEY` 
- `NVIDIA_INFERENCE_KEY`
- `SKILLSPECTOR_PROVIDER` (set to `openai`, `anthropic`, or `nv_build`)
- `SKILLSPECTOR_MODEL` (optional model override)

### Creating an Environment File

Create an `.env` file in your working directory to avoid exposing keys in shell history:

```bash
cat > .env <<'EOF'
SKILLSPECTOR_PROVIDER=anthropic
ANTHROPIC_API_KEY=sk-ant-api03-...
EOF

```

For OpenAI:

```bash
cat > .env <<'EOF'
SKILLSPECTOR_PROVIDER=openai
OPENAI_API_KEY=sk-...
EOF

```

### Passing Credentials via Command Line

Alternatively, pass variables directly using the `-e` flag:

```bash
docker run --rm \
  -e SKILLSPECTOR_PROVIDER=openai \
  -e OPENAI_API_KEY="$OPENAI_API_KEY" \
  skillspector --help

```

## Executing Scans in Docker

The container expects your target skill directory mounted at `/scan`, which serves as the working directory inside the container.

### Running Static Analysis Without LLM

For pure static analysis that requires no API keys:

```bash
docker run --rm \
  -v "$PWD:/scan" \
  skillspector scan ./my-skill/ --no-llm

```

The `--no-llm` flag skips semantic analysis and runs only the vulnerability pattern matching.

### Running LLM-Enabled Analysis

To run a full scan with LLM analysis, mount your `.env` file:

```bash
docker run --rm \
  -v "$PWD:/scan" \
  --env-file .env \
  skillspector scan ./my-skill/

```

Or pass the environment variables explicitly:

```bash
docker run --rm \
  -v "$PWD:/scan" \
  -e SKILLSPECTOR_PROVIDER=anthropic \
  -e ANTHROPIC_API_KEY="$ANTHROPIC_API_KEY" \
  skillspector scan ./my-skill/

```

## Connecting to Local LLM Endpoints

You can route SkillSpector to a local OpenAI-compatible server (such as Ollama) by overriding the base URL. This configuration requires setting `OPENAI_API_KEY` to a dummy value (like "ollama") and specifying `OPENAI_BASE_URL`:

```bash
docker run --rm \
  -v "$PWD:/scan" \
  -e SKILLSPECTOR_PROVIDER=openai \
  -e OPENAI_API_KEY=ollama \
  -e OPENAI_BASE_URL=http://localhost:11434/v1 \
  -e SKILLSPECTOR_MODEL=llama3.1:8b \
  skillspector scan ./my-skill/

```

Note that when connecting to localhost from within Docker, you may need to use `host.docker.internal` instead of `localhost` depending on your Docker version and host OS.

## Summary

- **Build** the image using `make docker-build` or `docker build -t skillspector .` from the repository root
- **Configure** credentials via `.env` file or `-e` flags using variables defined in `.env.example`
- **Mount** your target directory to `/scan` when running the container
- **Use** `--no-llm` to run static analysis without requiring API keys
- **Override** the provider and model with `SKILLSPECTOR_PROVIDER` and `SKILLSPECTOR_MODEL` environment variables

## Frequently Asked Questions

### Do I need Python installed on my host to run SkillSpector in Docker?

No. The Docker image contains all Python dependencies and the SkillSpector runtime. You only need Docker installed on your system. The container encapsulates the entire execution environment as defined in the repository's `Dockerfile`.

### Where does SkillSpector read API keys from when running in a container?

SkillSpector reads API keys from environment variables, as implemented in [`src/skillspector/cli.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/cli.py) lines 92-106. When running in Docker, you can inject these variables using the `--env-file` flag to load an `.env` file, or pass individual variables with the `-e` flag.

### Can I use a local LLM like Ollama with SkillSpector in Docker?

Yes. Set `SKILLSPECTOR_PROVIDER` to `openai`, configure `OPENAI_BASE_URL` to point to your local endpoint (e.g., `http://host.docker.internal:11434/v1`), and provide a dummy value for `OPENAI_API_KEY`. You can also specify the model using `SKILLSPECTOR_MODEL`.

### What is the default entrypoint of the SkillSpector Docker image?

The `ENTRYPOINT` is set to `["skillspector"]` in the `Dockerfile`. This means any arguments you provide after the image name in your `docker run` command are passed directly to the SkillSpector CLI, exactly as they would be if running the tool natively.