Security
telagod/code-abyss
Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries…
Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must…
$ npx skills add samugit83/redamon --skill graph-db-writes -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install samugit83/redamon graph-db-writes --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/graph-db-writes .claude/skills/graph-db-writes && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "graph-db-writes" agent skill from https://github.com/samugit83/redamon/tree/master/skills/graph-db-writes into .claude/skills/graph-db-writes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "graph-db-writes", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/samugit83/redamon/tree/master/skills/graph-db-writesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add samugit83/redamon --skill graph-db-writes -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install samugit83/redamon graph-db-writes --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/graph-db-writes .agents/skills/graph-db-writes && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "graph-db-writes" agent skill from https://github.com/samugit83/redamon/tree/master/skills/graph-db-writes into .agents/skills/graph-db-writes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "graph-db-writes", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add samugit83/redamon --skill graph-db-writes -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install samugit83/redamon graph-db-writes --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/graph-db-writes .cursor/skills/graph-db-writes && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "graph-db-writes" agent skill from https://github.com/samugit83/redamon/tree/master/skills/graph-db-writes into .cursor/skills/graph-db-writes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "graph-db-writes", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/samugit83/redamon.git --path skills/graph-db-writes--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add samugit83/redamon --skill graph-db-writes -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install samugit83/redamon graph-db-writes --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/graph-db-writes .gemini/skills/graph-db-writes && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "graph-db-writes" agent skill from https://github.com/samugit83/redamon/tree/master/skills/graph-db-writes into .gemini/skills/graph-db-writes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "graph-db-writes", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install samugit83/redamon graph-db-writesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add samugit83/redamon --skill graph-db-writes -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/graph-db-writes .github/skills/graph-db-writes && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "graph-db-writes" agent skill from https://github.com/samugit83/redamon/tree/master/skills/graph-db-writes into .github/skills/graph-db-writes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "graph-db-writes", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add samugit83/redamon --skill graph-db-writes -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install samugit83/redamon graph-db-writes --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/graph-db-writes .opencode/skills/graph-db-writes && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "graph-db-writes" agent skill from https://github.com/samugit83/redamon/tree/master/skills/graph-db-writes into .opencode/skills/graph-db-writes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "graph-db-writes", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
graph-db-writesWriting to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must…
Graph DB Writes is an agent skill from samugit83/redamon. Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must be updated together. A MERGE missing the tenant key silently merges one project's data into another's. Trigger: editing anything under graphdb/mixins/; adding or changing an updategraphfrom method; writing a Cypher MERGE/CREATE that adds a node, relationship or property; adding a new node label to the graph.
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Penetration testing, Threat modeling and Multi-tenancy. It works with Neo4j. The repository describes itself as: Open-source, self-hosted AI penetration testing framework: maps your attack surface into a graph, autonomously exploits it from a Kali sandbox with human approval gates, and… The licence is MIT.
Read from SKILL.md and the folder at commit 5dd993c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
python3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Graph DB Writes loads about 2.2k tokens when it runs. Until then it costs about 132 tokens; SKILL.md has 873 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from samugit83/redamon at commit 5dd993c, republished under its MIT licence (© samugit83). 873 words, ~2,207 tokens.
.claude/skills/graph-db-writes/SKILL.md (or your agent's skills folder).graph_db mixin or a scan tool that persists to the graph.For placing a whole new recon tool (which includes its graph write), use
recon-tool-integration; this skill is the
graph-write rules it depends on.
{<natural_key>, user_id, project_id} - the tenant-isolation triple. A MERGE
missing user_id/project_id merges one project's data into another's,
silently. Global reference nodes (e.g. CVE) key on their natural id only
(MERGE (c:CVE {id: $cve_id})); adding tenant keys there fragments shared data.SET a field another tool owns. Use ON CREATE SET
for provenance/first-writer fields (e.g. source) so a later tool merging the
same node does not clobber them; use plain SET only for this tool's own
enrichment fields. Reference: graph_db/mixins/graphql_mixin.py:189.SET v += $props fails the whole node write and the mixin's per-finding
except turns that into a silently dropped finding. Flatten first: nuclei's
cves arrive as {id,cvss,url} maps and are stored as id strings via
nuclei_cve_ids in graph_db/mixins/recon/vuln_mixin.py.updated_at) and
afterwards prunes the ones it did not touch - ingest-then-prune, never
clear-then-ingest. A half-failed scan that reported nothing would otherwise
empty the project, so the CALLER decides whether to prune and only does so
after an ingest that actually produced findings. Nodes an operator muted and
ones carrying triage_source = 'human' are never deleted, only stamped
stale_since: they hold an operator's mute, verdict and the fix items written
against them. A mute a node-filter RULE applied (muted_by starting rule:)
is not a person's decision and is pruned like any stale finding.
Reference: prune_unseen_findings in
graph_db/mixins/base_mixin.py, and the
four clears that spare them. A delete that spares muted findings takes the
node's write lock (SET n._prune_lock = true REMOVE n._prune_lock) BEFORE it
reads n:Muted, or a mute committing in between is deleted with the node.
An external agent's MCP mute keeps the owner's id in muted_by, so it is kept
like a person's; its muted_channel/muted_token stamp must be REMOVEd by
every unmute and cleared by every other mute, or a later mute inherits it.keep_hosts (anchored regexes, matched
against _KEEP_HOST_FIELDS with toStringOrNull, passed as a Cypher parameter)
to prune_unseen_findings, and skips the prune entirely for a degraded source.
What was cut is recorded on the Domain coverage record — recon_coverage_at,
recon_coverage_gaps, recon_skipped_hosts, recon_nuclei_truncated (written
by update_graph_coverage in
graph_db/mixins/recon/domain_mixin.py).
Those four are in the webapp's VOLATILE_PROPERTIES, so they never make a
Domain read as "changed" in the Recon Delta.MATCH for an entity node. Uniqueness is the
(id, user_id, project_id) triple, so a natural id is NOT unique across the
database and MATCH (n {id: $id}) can read or write another project's node.
Every read and write carries user_id/project_id; agent-facing queries go
through scope_query, never inject_tenant_filter alone.Subdomain, not a new label. Check
graph_db/schema_sections.md first - that
is the single declaration of every label, property and relationship.python3 tooling/scripts/seed_schema_catalog.py. A uniqueness key also
goes in graph_db/schema_keys.py, from which
schema.py renders its CREATE CONSTRAINT statements.
Do NOT copy the schema into the prompt or into GRAPH.SCHEMA.md: the prompt
splices the catalog in at __GRAPH_SCHEMA__, and GRAPH.SCHEMA.md deliberately
no longer lists labels at all. Three copies is what drifted, and four tests
now fail if you make a fourth.
Editing or removing a line there fails
test_the_composed_document_still_contains_the_baseline in
recon/tests/test_schema_catalog.py
(additions pass: it is a CONTAINS check, so a stale golden file can sit
unnoticed). Refresh the fixture in the same commit with the command in that
test's docstring, then read the fixture diff.
Still update NODE_COLORS in
webapp/src/app/graph/config/colors.ts,
which is presentation, not schema.// entity node - tenant-scoped: the {natural key, user_id, project_id} triple is mandatory
MERGE (bu:BaseURL {url: $baseurl, user_id: $user_id, project_id: $project_id})
ON CREATE SET bu.source = 'graphql_scan', bu.updated_at = datetime() // provenance: first writer only
MERGE (e:Endpoint {path: $path, method: 'POST', baseurl: $baseurl, user_id: $user_id, project_id: $project_id})
ON CREATE SET e.source = 'graphql_scan'
SET e += $props // this tool's own enrichment fields
MERGE (bu)-[:HAS_ENDPOINT]->(e)
// reference node - global: natural id only, NO tenant key
MERGE (c:CVE {id: $cve_id})Copied from graph_db/mixins/graphql_mixin.py.
| Writing | Mixin |
|---|---|
| core recon phases (subdomains, IPs, ports, HTTP, endpoints) | recon_mixin.py |
| passive OSINT enrichment | osint_mixin.py |
| secrets / credentials | secret_mixin.py |
| vuln scan (GVM) | gvm_mixin.py |
| GraphQL probes | graphql_mixin.py |
| supply-chain packages | supply_chain_mixin.py |
recon-tool-integration© samugit83, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/graph-db-writes of samugit83/redamon.
Open the folder on GitHubat commit 5dd993c
Graph DB Writes next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Graph DB Writes this skillsamugit83/redamon | 3k | — | ~2.2k | Automated safety check: Pass | MIT | |
| Securitytelagod/code-abyss | 244 | — | ~907 | Automated safety check: Pass | MIT | |
| Csono-session/pstack | 136 | — | ~12k | Automated safety check: Notes | MIT | |
| Senior Securitydavila7/claude-code-templates | 33k | 2 repos | ~1.1k | Automated safety check: Notes | MIT | |
| Openfdd Mt Securitybbartling/open-fdd | 173 | — | ~2.2k | Automated safety check: Pass | Custom licence | |
| Threat Model Disciplinehypnguyen1209/offensive-claude | 388 | — | ~660 | Automated safety check: Pass | MIT |
telagod/code-abyss
Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries…
no-session/pstack
Chief Security Officer mode. An agent skill from no-session/pstack.
davila7/claude-code-templates
Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing.
bbartling/open-fdd
Multi-tenant authz, pre-auth disclosure hardening, and Kali disposition.
hypnguyen1209/offensive-claude
A skill your agent uses when starting an engagement, before exploitation, or whenever the attack surface changes — build/validate the threat model and detect drift (new unreviewed surface) before…
ooiyeefei/ccc
Run an enterprise security review of a system design or existing code before it ships.
samugit83/redamon
Adding a Community Agent Skill: a Markdown attack-workflow file that users import from the catalog, which then competes in the Intent Router and is injected into the agent's system prompt.
samugit83/redamon
Adding partial-recon support for a tool: running a single pipeline phase on demand from the workflow graph, reading its inputs from the existing Neo4j graph and merging results back.
samugit83/redamon
Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in…
samugit83/redamon
Adding a built-in Agent Skill (an attack technique like ssrf, xxe, rce) that ships hardcoded in RedAmon: classified by the Intent Router, injected into the agent prompt, toggled per project, badged…
samugit83/redamon
Adding an LLM provider to RedAmon: the credential boundary (keys must never reach scan containers), prefix-routed model ids, and the provider registry.
samugit83/redamon
Adding, removing or changing a tool on RedAmon's INBOUND MCP server, where external agents connect in with a personal access token.
Works with
Categories
Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must…. Graph DB Writes is an agent skill from samugit83/redamon. Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must be updated together.
Graph DB Writes fits situations like: tasks that involve Penetration testing; tasks that involve Threat modeling; tasks that involve Multi-tenancy.
Run `npx skills add samugit83/redamon --skill graph-db-writes -a claude-code`. Or copy the skill folder (skills/graph-db-writes in samugit83/redamon) into .claude/skills/graph-db-writes in your project. Claude Code loads it when a task matches its description.
Run `npx skills add samugit83/redamon --skill graph-db-writes -a codex`. Or copy the skill folder (skills/graph-db-writes in samugit83/redamon) into .agents/skills/graph-db-writes in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add samugit83/redamon --skill graph-db-writes -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/graph-db-writes, .gemini/skills/graph-db-writes, .github/skills/graph-db-writes and .opencode/skills/graph-db-writes in your project.
Going by SKILL.md and its folder, Graph DB Writes needs the command-line tools its instructions call (python3). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Graph DB Writes is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Graph DB Writes: Security (telagod/code-abyss, 244 stars), Cso (no-session/pstack, 136 stars), Senior Security (davila7/claude-code-templates, 33k stars) and Openfdd Mt Security (bbartling/open-fdd, 173 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
samugit83 (a GitHub user) maintains it in samugit83/redamon, which has 2,982 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 8, 2026.
Source: samugit83/redamon on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.