Agent skill

LLM Provider Integration

by samugit83 in samugit83/redamon

Adding an LLM provider to RedAmon: the credential boundary (keys must never reach scan containers), prefix-routed model ids, and the provider registry.

MITAuto-check passedSecurity

Install LLM Provider Integration

skills CLI
$ npx skills add samugit83/redamon --skill llm-provider-integration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install samugit83/redamon llm-provider-integration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/llm-provider-integration .claude/skills/llm-provider-integration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
llm-provider-integration
GitHub stars
3k
Token cost
~1.1k tokens
SKILL.md length
391 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

Adding an LLM provider to RedAmon: the credential boundary (keys must never reach scan containers), prefix-routed model ids, and the provider registry.

  • Tasks that involve Penetration testing
  • SKILL.md covers When to Use, Critical Rules, The two invariants and Commands, plus 1 more section
  • Calls docker

What it does

LLM Provider Integration is an agent skill from samugit83/redamon. Adding an LLM provider to RedAmon: the credential boundary (keys must never reach scan containers), prefix-routed model ids, and the provider registry. A misrouted model id or a leaked key are the two failures this guards. Trigger: adding or editing an LLM provider; editing parsemodelprovider in agentic/orchestratorhelpers/llmsetup.py, the webapp provider-type registry, the userllmproviders model, or an LLM call site that passes an API key; a non-chat provider type (TypeSafe Jev) or a path that picks "any…

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Penetration testing. It works with Model Context Protocol and OpenAI. The repository describes itself as: Open-source, self-hosted AI penetration testing framework: maps your attack surface into a graph, autonomously exploits it from a Kali sandbox with human approval gates, and… The licence is MIT.

When your agent uses it

  • Tasks that involve Penetration testing

Example prompts

  • “any provider row”
  • “/llm-provider-integration”

Requirements

  • Node.js
  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit d90c940. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

LLM Provider Integration loads about 1.1k tokens when it runs. Until then it costs about 139 tokens; SKILL.md has 391 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~139
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from samugit83/redamon at commit d90c940, republished under its MIT licence (© samugit83). 391 words, ~1,073 tokens.

Download SKILL.mdSave it as .claude/skills/llm-provider-integration/SKILL.md (or your agent's skills folder).
name
llm-provider-integration
description
Adding an LLM provider to RedAmon: the credential boundary (keys must never reach scan containers), prefix-routed model ids, and the provider registry. A misrouted model id or a leaked key are the two failures this guards. Trigger: adding or editing an LLM provider; editing parse_model_provider in agentic/orchestrator_helpers/llm_setup.py, the webapp provider-type registry, the user_llm_providers model, or an LLM call site that passes an API key; a non-chat provider type (TypeSafe Jev) or a path that picks "any provider row".
license
MIT
metadata.author
redamon
metadata.version
1.0.0
metadata.scope
agentic, webapp
metadata.auto_invoke
Adding or integrating an LLM provider, Editing model-id routing or provider credential handling, Adding a non-chat provider type, or a path that picks any…

When to Use

  • Adding a new LLM provider (OpenAI-compatible or otherwise) the agent can use.

For a non-LLM external API tool, use agentic-tool-integration.


Critical Rules

  • NEVER let a provider API key reach a scan container. Keys live in exactly two places: Postgres user_llm_providers rows and, in transit, on the wire between webapp and agent. The recon / scan / MCP containers must never see them. Do not thread a provider key through recon settings or container env.
  • NEVER add a model id that is not prefix-routed. Anything other than claude-* and bare OpenAI ids MUST carry a provider/<model> prefix, resolved by parse_model_provider() at agentic/orchestrator_helpers/llm_setup.py:67. An unprefixed id routes to the wrong provider silently.
  • NEVER treat every user_llm_providers row as a chat LLM. A non-chat type (today jev, the TypeSafe decision API) must be skipped by every path that builds a chat model, or its token is sent to the wrong host: setup_llm's custom branch builds ChatOpenAI(api_key=<row key>) with no base URL, which is api.openai.com. Add the type to NON_CHAT_PROVIDER_TYPES in BOTH twins (agentic/llm_builder.py, webapp/src/lib/llmProviderKinds.ts); use chat_providers() / isChatProvider wherever rows are listed, counted, gated or forwarded (the /api/models forward, the project LLM gate, the triage preflight, the feature-model grid); and never let a stale custom/<id> fall back to "the first provider" (custom_provider_or_fallback falls back only to custom-capable types). setup_llm also refuses a non-chat type outright.
  • A non-chat provider's endpoint is a constant, and its type is locked. agentic/jev_client.py is the only code that talks to api.typesafe.ai: a fixed base URL, no redirects, fixed error texts. On the webapp, POST forces model, URL and headers and allows one row per user; PUT and the test route refuse a type change in either direction and ignore a body-supplied URL/headers for a stored row, so a stored token can never be re-pointed at another host.
  • ALWAYS register the provider in the webapp provider-type registry and propagate the key kwarg into every LLM call site. A provider registered but not propagated builds a client with no credentials. The guide enumerates all 11 integration points; touch each.
Show full SKILL.md (52 more words)Show less

The two invariants

InvariantWhereFailure if broken
Keys only in Postgres + webapp<->agent transitwebapp/prisma/schema.prisma user_llm_providers; agent settings fetchkey leaks into scan/MCP containers
Model id prefix routingparse_model_provider() llm_setup.py:67model routes to the wrong provider

Commands

bash
docker compose build agent && docker compose up -d agent   # agentic/ is baked
docker compose exec webapp npx prisma db push              # provider schema changes (NEVER prisma migrate)

Resources

© samugit83, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/llm-provider-integration of samugit83/redamon.

Open the folder on GitHubat commit d90c940

Compare with similar skills

LLM Provider Integration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

LLM Provider Integration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
LLM Provider Integration this skillsamugit83/redamon3k—~1.1kAutomated safety check: PassMIT
Burp Scansix2dez/burp-ai-agent1.5k—~6.4kAutomated safety check: WarnMIT
China AI Compliance AuditjnMetaCode/shellward140—~1.1kAutomated safety check: PassApache-2.0
Burp MCP Vuln Checklangbyyi/CyberStrikeAI-SRC134—~3.1kAutomated safety check: PassApache-2.0
Dast Automationhardw00t/ai-security-arsenal104—~2.2kAutomated safety check: PassNone
Screenshot BurpEncod3d-Sec/TORCH3291 repos~1.9kAutomated safety check: NotesMIT

Similar skills

  • Burp Scan

    six2dez/burp-ai-agent

    Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs.

    1.5k GitHub stars~6.4k tokensUpdated 1 mo ago
    SecurityAuto-check: warnings
  • China AI Compliance Audit

    jnMetaCode/shellward

    按中国法规(网安法 / PIPL / 等保2.0 / 数据出境 / AI生成内容标识)审计一个 AI 项目的代码仓库,产出每条都带 文件:行 取证、经独立复核、经脚本校验的合规报告。当用户问「这个项目上线合不合规」「调用了 OpenAI/Claude 算不算数据出境」「要不要做 AI 标识」「帮我做合规自查/等保/PIPL 检查」时使用。Audit an AI project's…

    140 GitHub stars~1.1k tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Burp MCP Vuln Check

    langbyyi/CyberStrikeAI-SRC

    Automate low-impact web vulnerability verification through Burp MCP.

    134 GitHub stars~3.1k tokensUpdated yesterday
    SecurityAuto-check passed
  • Dast Automation

    hardw00t/ai-security-arsenal

    Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling.

    104 GitHub stars~2.2k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Screenshot Burp

    Encod3d-Sec/TORCH

    Capture a Burp Suite Repeater request/response as a PoC image (targets/<eng/poc/) by driving the Burp MCP + the Kali GUI.

    329 GitHub starsUsed in 1 repo~1.9k tokens
    SecurityAuto-check: notes
  • Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

    329 GitHub stars~1.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from samugit83/redamon

All 15 skills in this repo
  • Add Community Skill

    samugit83/redamon

    Adding a Community Agent Skill: a Markdown attack-workflow file that users import from the catalog, which then competes in the Intent Router and is injected into the agent's system prompt.

    3k GitHub stars~775 tokensUpdated yesterday
    Auto-check passed
  • Add Partial Recon

    samugit83/redamon

    Adding partial-recon support for a tool: running a single pipeline phase on demand from the workflow graph, reading its inputs from the existing Neo4j graph and merging results back.

    3k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Agentic Tool Integration

    samugit83/redamon

    Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in…

    3k GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Builtin Agent Skill

    samugit83/redamon

    Adding a built-in Agent Skill (an attack technique like ssrf, xxe, rce) that ships hardcoded in RedAmon: classified by the Intent Router, injected into the agent prompt, toggled per project, badged…

    3k GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Graph DB Writes

    samugit83/redamon

    Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must…

    3k GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • MCP Server Tools

    samugit83/redamon

    Adding, removing or changing a tool on RedAmon's INBOUND MCP server, where external agents connect in with a personal access token.

    3k GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about LLM Provider Integration

What does LLM Provider Integration do?

Adding an LLM provider to RedAmon: the credential boundary (keys must never reach scan containers), prefix-routed model ids, and the provider registry. LLM Provider Integration is an agent skill from samugit83/redamon. Adding an LLM provider to RedAmon: the credential boundary (keys must never reach scan containers), prefix-routed model ids, and the provider registry.

When should I use LLM Provider Integration?

LLM Provider Integration fits situations like: tasks that involve Penetration testing.

How do I install LLM Provider Integration in Claude Code?

Run `npx skills add samugit83/redamon --skill llm-provider-integration -a claude-code`. Or copy the skill folder (skills/llm-provider-integration in samugit83/redamon) into .claude/skills/llm-provider-integration in your project. Claude Code loads it when a task matches its description.

How do I install LLM Provider Integration in Codex?

Run `npx skills add samugit83/redamon --skill llm-provider-integration -a codex`. Or copy the skill folder (skills/llm-provider-integration in samugit83/redamon) into .agents/skills/llm-provider-integration in your project. Codex loads it when a task matches its description.

Can I use LLM Provider Integration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add samugit83/redamon --skill llm-provider-integration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/llm-provider-integration, .gemini/skills/llm-provider-integration, .github/skills/llm-provider-integration and .opencode/skills/llm-provider-integration in your project.

What does LLM Provider Integration need to run?

Going by SKILL.md and its folder, LLM Provider Integration needs the command-line tools its instructions call (docker). Our summary lists: Node.js; Docker.

Does LLM Provider Integration access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is LLM Provider Integration safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does LLM Provider Integration use?

LLM Provider Integration is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does LLM Provider Integration use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to LLM Provider Integration?

Skills that share tags, products or a category with LLM Provider Integration: Burp Scan (six2dez/burp-ai-agent, 1.5k stars), China AI Compliance Audit (jnMetaCode/shellward, 140 stars), Burp MCP Vuln Check (langbyyi/CyberStrikeAI-SRC, 134 stars) and Dast Automation (hardw00t/ai-security-arsenal, 104 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains LLM Provider Integration?

samugit83 (a GitHub user) maintains it in samugit83/redamon, which has 2,961 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 7, 2026.

Source: samugit83/redamon on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.