Agent skill

Agentic Tool Integration

by samugit83 in samugit83/redamon

Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in…

MITAuto-check passedAgent Workflows

Install Agentic Tool Integration

skills CLI
$ npx skills add samugit83/redamon --skill agentic-tool-integration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install samugit83/redamon agentic-tool-integration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/agentic-tool-integration .claude/skills/agentic-tool-integration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
agentic-tool-integration
GitHub stars
2.9k
Token cost
~1.3k tokens
SKILL.md length
419 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in…

  • Tasks that involve MCP servers
  • SKILL.md covers When to Use, Critical Rules, Pick the integration type… and Commands, plus 1 more section
  • Calls docker
  • Tasks that involve Penetration testing

What it does

Agentic Tool Integration is an agent skill from samugit83/redamon. Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in single mode but silently break in parallel plans. Trigger: adding or editing a tool the agent invokes; editing agentic/prompts/toolregistry.py, PhaseAwareToolExecutor in agentic/tools.py, agentic/orchestratorhelpers/nodes/executetoolnode.py or executeplannode.py, TOOLPHASEMAP / DANGEROUSTOOLS in…

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering MCP servers, Penetration testing and Planning. It works with Model Context Protocol. The repository describes itself as: Open-source, self-hosted AI penetration testing framework: maps your attack surface into a graph, autonomously exploits it from a Kali sandbox with human approval gates, and… The licence is MIT.

When your agent uses it

  • Tasks that involve MCP servers
  • Tasks that involve Penetration testing
  • Tasks that involve Planning

Example prompts

  • “/agentic-tool-integration”

Requirements

  • Python 3
  • Node.js
  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit 34ab441. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Agentic Tool Integration loads about 1.3k tokens when it runs. Until then it costs about 148 tokens; SKILL.md has 419 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~148
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from samugit83/redamon at commit 34ab441, republished under its MIT licence (© samugit83). 419 words, ~1,344 tokens.

Download SKILL.mdSave it as .claude/skills/agentic-tool-integration/SKILL.md (or your agent's skills folder).
name
agentic-tool-integration
description
Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in single mode but silently break in parallel plans. Trigger: adding or editing a tool the agent invokes; editing agentic/prompts/tool_registry.py, PhaseAwareToolExecutor in agentic/tools.py, agentic/orchestrator_helpers/nodes/execute_tool_node.py or execute_plan_node.py, TOOL_PHASE_MAP / DANGEROUS_TOOLS in agentic/project_settings.py, or a new MCP server in mcp/servers/.
license
MIT
metadata.author
redamon
metadata.version
1.0.0
metadata.scope
agentic
metadata.auto_invoke
Adding a tool the agent can call, Editing the agent tool registry, phase map, or PhaseAwareToolExecutor dispatch, Adding or editing an MCP server the agent uses

When to Use

  • Adding any tool the agent uses during a chat session (CLI wrapper, MCP tool, or API tool).

For a recon-pipeline tool (runs during a scan, writes the graph), use recon-tool-integration instead. For the per-setting/default multi-layer wiring, use project-settings-cascade. For a whole new attack skill (not a tool), use builtin-agent-skill.


Critical Rules

  • NEVER import a package not already in the agent image. agentic/ is baked into the redamon-agent image; a missing import crash-loops the container. Confirm it is in agentic/requirements.txt or the Dockerfile first.
  • NEVER add a tool without a TOOL_REGISTRY entry in agentic/prompts/tool_registry.py. The registry is the single source of truth the LLM reads; an unregistered tool is invisible to the agent. All four fields (purpose, when_to_use, args_format, description) are required, and the description must clear the 100-char minimum in agentic/tests/test_tool_registry_completeness.py, which fails on any unregistered or stub entry.
  • NEVER forget the dispatch branch for a non-MCP / API tool. PhaseAwareToolExecutor.execute() at agentic/tools.py:2070 has hardcoded if/elif dispatch. A Type D (API) tool or an MCP tool needing key injection MUST add an elif; without it the tool is registered but never dispatched. MCP tools with no key injection go through the else branch automatically.
  • NEVER edit execute_tool_node.py without mirroring it in execute_plan_node.py. execute_tool_node.py (single tool) and execute_plan_node.py (parallel plans) duplicate long-running detection and session/listener handlers. Update one only and the tool works interactively but silently misbehaves in parallel plan execution.
  • NEVER rely on the Prisma default to reach existing projects. The agentToolPhaseMap default applies to NEW projects only. Existing projects need a jsonb UPDATE or the agent never sees the tool there. See project-settings-cascade.
  • ALWAYS add the tool to TOOL_PHASE_MAP in agentic/project_settings.py. If it sends attack traffic: also add it to DANGEROUS_TOOLS (frozenset, project_settings.py:22), a per-tool section in agentic/prompts/stealth_rules.py, and the right list in CATEGORY_TOOL_MAP (_check_roe_blocked, execute_plan_node.py:47).

Show full SKILL.md (120 more words)Show less

Pick the integration type (simplest that fits)

TypeUse whenCore files beyond the registry
A kali_shelltool is in Kali, 300s timeout OK, no parsingDockerfile + kali_shell description only (no registry entry)
B MCP tool on existing serverCLI tool, custom timeout/parsing, fire-and-forget@mcp.tool() in an existing mcp/servers/*.py (auto-discovered)
C new MCP serverstateful/interactive, own portnew mcp/servers/*_server.py + SERVERS in run_servers.py + URL in MCPToolsManager
D API/HTTP toolexternal API, key-gatedToolManager class + elif dispatch in tools.py + orchestrator key hot-reload

Naming is uniform across every layer: MCP fn / registry key / phase-map key = execute_<tool>; Prisma field camelCase; Python setting SCREAMING_SNAKE; DB column snake_case via @map().

Commands

bash
docker compose build agent && docker compose up -d agent   # mandatory: agentic/ is baked
docker compose exec webapp npx prisma db push              # if you added a Prisma field (NEVER prisma migrate)
./agentic/run_tests.sh                                     # gate; includes the registry completeness test

Resources

© samugit83, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/agentic-tool-integration of samugit83/redamon.

Open the folder on GitHubat commit 34ab441

Compare with similar skills

Agentic Tool Integration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Agentic Tool Integration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Agentic Tool Integration this skillsamugit83/redamon2.9k—~1.3kAutomated safety check: PassMIT
Codex with ChatGPT Planning LoopXiaoDuoYa/codex-with-chatgpt7.1k—~11kAutomated safety check: NotesMIT
Burp Scansix2dez/burp-ai-agent1.5k—~6.4kAutomated safety check: WarnMIT
Burp MCP Vuln Checklangbyyi/CyberStrikeAI-SRC133—~3.1kAutomated safety check: PassApache-2.0
Quick Startjpicklyk/task-orchestrator207—~4kAutomated safety check: PassMIT
Upload Artifactclosedloop-ai/claude-plugins122—~1.4kAutomated safety check: NotesApache-2.0

Similar skills

  • Codex with ChatGPT Planning Loop

    XiaoDuoYa/codex-with-chatgpt

    Uses ChatGPT in the browser as the planning and review brain for a Codex session, with Codex keeping all execution and ChatGPT reading the workspace through a bridge.

    7.1k GitHub stars~11k tokensUpdated 6 days ago
    Agent WorkflowsAuto-check: notes
  • Burp Scan

    six2dez/burp-ai-agent

    Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs.

    1.5k GitHub stars~6.4k tokensUpdated 1 mo ago
    SecurityAuto-check: warnings
  • Burp MCP Vuln Check

    langbyyi/CyberStrikeAI-SRC

    Automate low-impact web vulnerability verification through Burp MCP.

    133 GitHub stars~3.1k tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Quick Start

    jpicklyk/task-orchestrator

    Interactive onboarding for the MCP Task Orchestrator. An agent skill from jpicklyk/task-orchestrator.

    207 GitHub stars~4k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Upload Artifact

    closedloop-ai/claude-plugins

    Upload a file as a ClosedLoop document (PRD, implementation plan, feature, or template).

    122 GitHub stars~1.4k tokensUpdated today
    Agent WorkflowsAuto-check: notes
  • Hunt Burp

    Encod3d-Sec/TORCH

    Drive Burp Suite over its MCP server as an AI triage + attack layer - review proxy history for signals, replay via Repeater/send, OOB-gate blind bugs with Collaborator, fuzz via Intruder (RoE-safe)…

    329 GitHub stars~3.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from samugit83/redamon

All 15 skills in this repo
  • Add Community Skill

    samugit83/redamon

    Adding a Community Agent Skill: a Markdown attack-workflow file that users import from the catalog, which then competes in the Intent Router and is injected into the agent's system prompt.

    2.9k GitHub stars~775 tokensUpdated 2 days ago
    Auto-check passed
  • Add Partial Recon

    samugit83/redamon

    Adding partial-recon support for a tool: running a single pipeline phase on demand from the workflow graph, reading its inputs from the existing Neo4j graph and merging results back.

    2.9k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Builtin Agent Skill

    samugit83/redamon

    Adding a built-in Agent Skill (an attack technique like ssrf, xxe, rce) that ships hardcoded in RedAmon: classified by the Intent Router, injected into the agent prompt, toggled per project, badged…

    2.9k GitHub stars~1.4k tokensUpdated 2 days ago
    Auto-check passed
  • Graph DB Writes

    samugit83/redamon

    Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must…

    2.9k GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed
  • LLM Provider Integration

    samugit83/redamon

    Adding an LLM provider to RedAmon: the credential boundary (keys must never reach scan containers), prefix-routed model ids, and the provider registry.

    2.9k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • MCP Server Tools

    samugit83/redamon

    Adding, removing or changing a tool on RedAmon's INBOUND MCP server, where external agents connect in with a personal access token.

    2.9k GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check passed

Questions about Agentic Tool Integration

What does Agentic Tool Integration do?

Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in…. Agentic Tool Integration is an agent skill from samugit83/redamon. Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in single mode but silently break in parallel plans.

When should I use Agentic Tool Integration?

Agentic Tool Integration fits situations like: tasks that involve MCP servers; tasks that involve Penetration testing; tasks that involve Planning.

How do I install Agentic Tool Integration in Claude Code?

Run `npx skills add samugit83/redamon --skill agentic-tool-integration -a claude-code`. Or copy the skill folder (skills/agentic-tool-integration in samugit83/redamon) into .claude/skills/agentic-tool-integration in your project. Claude Code loads it when a task matches its description.

How do I install Agentic Tool Integration in Codex?

Run `npx skills add samugit83/redamon --skill agentic-tool-integration -a codex`. Or copy the skill folder (skills/agentic-tool-integration in samugit83/redamon) into .agents/skills/agentic-tool-integration in your project. Codex loads it when a task matches its description.

Can I use Agentic Tool Integration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add samugit83/redamon --skill agentic-tool-integration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/agentic-tool-integration, .gemini/skills/agentic-tool-integration, .github/skills/agentic-tool-integration and .opencode/skills/agentic-tool-integration in your project.

What does Agentic Tool Integration need to run?

Going by SKILL.md and its folder, Agentic Tool Integration needs the command-line tools its instructions call (docker). Our summary lists: Python 3; Node.js; Docker.

Does Agentic Tool Integration access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Agentic Tool Integration safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Agentic Tool Integration use?

Agentic Tool Integration is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Agentic Tool Integration use?

About 1.3k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Agentic Tool Integration?

Skills that share tags, products or a category with Agentic Tool Integration: Codex with ChatGPT Planning Loop (XiaoDuoYa/codex-with-chatgpt, 7.1k stars), Burp Scan (six2dez/burp-ai-agent, 1.5k stars), Burp MCP Vuln Check (langbyyi/CyberStrikeAI-SRC, 133 stars) and Quick Start (jpicklyk/task-orchestrator, 207 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Agentic Tool Integration?

samugit83 (a GitHub user) maintains it in samugit83/redamon, which has 2,948 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 5, 2026.

Source: samugit83/redamon on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.