Agent skill

Project Settings Cascade

by samugit83 in samugit83/redamon

Changing or adding a project setting / default value in RedAmon.

MITAuto-check passedSecurity

Install Project Settings Cascade

skills CLI
$ npx skills add samugit83/redamon --skill project-settings-cascade -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install samugit83/redamon project-settings-cascade --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/project-settings-cascade .claude/skills/project-settings-cascade && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
project-settings-cascade
GitHub stars
3k
Token cost
~2.4k tokens
SKILL.md length
978 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

Changing or adding a project setting / default value in RedAmon.

  • Tasks that involve Penetration testing
  • SKILL.md covers When to Use, Critical Rules, The layers (recon example:… and The registry reaches three…, plus 2 more sections
  • Calls docker, python3 and npm
  • Tasks that involve ORMs and data access

What it does

Project Settings Cascade is an agent skill from samugit83/redamon. Changing or adding a project setting / default value in RedAmon. A single setting is duplicated across Prisma, two separate Python settings modules, the orchestrator defaults endpoint, and the frontend fallback; miss a layer and the UI shows one value while the backend uses another, and existing projects keep the old value forever. Trigger: editing a @default in webapp/prisma/schema.prisma; editing DEFAULTAGENTSETTINGS or fetchagentsettings in agentic/projectsettings.py, or DEFAULTSETTINGS or fetchprojectsettings…

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Penetration testing, ORMs and data access and Bug bounty. It works with Prisma, Python and Model Context Protocol. The repository describes itself as: Open-source, self-hosted AI penetration testing framework: maps your attack surface into a graph, autonomously exploits it from a Kali sandbox with human approval gates, and… The licence is MIT.

When your agent uses it

  • Tasks that involve Penetration testing
  • Tasks that involve ORMs and data access
  • Tasks that involve Bug bounty

Example prompts

  • “/project-settings-cascade”

Requirements

  • Python 3
  • Node.js
  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit d90c940. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker
    • python3
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Project Settings Cascade loads about 2.4k tokens when it runs. Until then it costs about 182 tokens; SKILL.md has 978 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~182
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from samugit83/redamon at commit d90c940, republished under its MIT licence (© samugit83). 978 words, ~2,394 tokens.

Download SKILL.mdSave it as .claude/skills/project-settings-cascade/SKILL.md (or your agent's skills folder).
name
project-settings-cascade
description
Changing or adding a project setting / default value in RedAmon. A single setting is duplicated across Prisma, two separate Python settings modules, the orchestrator defaults endpoint, and the frontend fallback; miss a layer and the UI shows one value while the backend uses another, and existing projects keep the old value forever. Trigger: editing a @default in webapp/prisma/schema.prisma; editing DEFAULT_AGENT_SETTINGS or fetch_agent_settings in agentic/project_settings.py, or DEFAULT_SETTINGS or fetch_project_settings in recon/project_settings.py; editing the /defaults endpoint or RUNTIME_ONLY_KEYS in recon_orchestrator/api.py; changing a default toggle/number/string in a ProjectForm section.
license
MIT
metadata.author
redamon
metadata.version
1.0.0
metadata.scope
webapp, agentic, recon
metadata.auto_invoke
Changing or adding a project setting or default value, Editing a Prisma @default, a Python settings default, or the /defaults endpoint

When to Use

  • Adding a new project setting, or changing the default value of an existing one.

This skill is the settings sub-pattern the tool/skill skills depend on; they link here rather than restating it. For the surrounding tool wiring, see agentic-tool-integration, recon-tool-integration, or builtin-agent-skill.


Critical Rules

  • NEVER change a default in one layer only. A setting is synchronized across every layer in the table below. Update them in one commit or the UI and backend drift silently.
  • NEVER assume existing projects pick up a new/changed default. A Prisma @default applies to new projects only. Existing rows keep their stored value; changing behaviour for them needs an explicit SQL UPDATE (ask before running it - it mutates every project).
  • NEVER share settings code between agent and recon. agentic/project_settings.py and recon/project_settings.py are separate modules with their own default dicts (DEFAULT_AGENT_SETTINGS vs DEFAULT_SETTINGS). A setting used by both is declared in both.
  • NEVER use prisma migrate. This project is push-based: docker compose exec webapp npx prisma db push.
  • ALWAYS keep the name triad aligned: DB column snake_case (via @map()), Prisma field + frontend + API camelCase, Python key SCREAMING_SNAKE_CASE. A mismatch means fetch_*_settings reads None and silently falls back to the default.
  • ALWAYS give the frontend onChange a fallback equal to the Python/Prisma default, so a project saved before the field existed does not write undefined.
  • A new column FAILS THE BUILD until it has a registry entry. Every parameter is described once, in recon_settings/registry.yaml, with its unit, phase, traffic class, engagement-cap flag, MCP disposition, meaning, and either a bound or a named validator. Add the column, run python3 tooling/scripts/extract_recon_registry.py to draft the entry, EDIT IT, then python3 recon_settings/build.py. The draft is a starting point: no extraction can tell whether a meaning is true or a bound is right.
  • NEVER hand-edit registry.json. It is a build artifact, written to two places (recon_settings/ for Python, webapp/src/lib/reconSettings/ for TypeScript) by one build, and build.py --check fails the gate when either is stale. Edit the YAML.
  • NEVER add a rate field without roe_capped: true. An rps field with traffic: active and no cap fails the build, because that gap is how three rate limits shipped reachable over MCP and outside the engagement ceiling.
  • mcp: settable is the normal answer, and a REAL bound is the control. The form input and the MCP validator are both generated from the registry, so a bound of 0..10000000 is a fake control on both doors at once. bounds.test.ts fails any count or threads maximum above 100000; the only way past it is a field whose SHIPPED default is already higher, named individually in ABOVE_THE_FLAT_CEILING with its own maximum, and the test refuses an entry whose default would fit under the ceiling anyway.
  • A field with a closed vocabulary gets values:, not validator: free_text. That is what makes the form render a <select> and the write refuse an unknown value instead of accepting it and having the runtime replace it silently. bounds.test.ts also fails a bespoke control that renders a closed-value field as anything but a <select>, because a text box over a closed set means the form accepts what the save rejects.
  • mcp: never needs a deny_reason the schema defines - identity, internal, escalation, secret, upload-managed, engagement-record, not-tuning or derived. There is no ALLOW/DENY table and no unbounded reason; denying a tuning field "to be safe" makes the API the weaker of two doors and fails parity.test.ts.
  • A settable field needs a form input, and an input needs a classification. form_section is joined from the tool's entry unless the field names its own, and an explicit null means "no input anywhere" - which the parity test reads to tell a deliberate omission from a forgotten one.
  • State what 0 means on any field that defaults to it. Several rates treat 0 as UNLIMITED, which makes it the FASTEST value rather than the safest. A numeric defaulting to 0 without zero_means fails the build, and the meaning has to repeat it in words.

Show full SKILL.md (320 more words)Show less

The layers (recon example: katanaTimeout)

LayerFileForm
DB / schemawebapp/prisma/schema.prismakatanaTimeout Int @default(3600) @map("katana_timeout")
Python defaultrecon/project_settings.py:21 DEFAULT_SETTINGS (or agentic/project_settings.py DEFAULT_AGENT_SETTINGS)'KATANA_TIMEOUT': 3600
Fetch mappingrecon/project_settings.py:863 fetch_project_settings (or fetch_agent_settings in the agent module)settings['KATANA_TIMEOUT'] = project.get('katanaTimeout', DEFAULT_SETTINGS['KATANA_TIMEOUT'])
Registryrecon_settings/registry.yamlkatanaTimeout: { tool: katana, runtime_key: KATANA_TIMEOUT, unit: seconds, phase: resource_enum, traffic: active, roe_capped: false, mcp: settable, bounds: {...}, meaning: ... }
Served defaultsrecon_orchestrator/api.py /defaultsnothing to do: the payload and its exclusions are REGISTRY QUERIES now. A key with no column is excluded by source: internal, and the column name comes from the registry rather than a snake-to-camel guess (which could not recover an intercap, so nine settings never reached the form).
Frontendthe tool's ProjectForm section componentcontrol with an onChange fallback equal to the default. Its min/max must not be WIDER than the registry bounds, or the form accepts a value the save refuses.

Agent-only settings use DEFAULT_AGENT_SETTINGS + fetch_agent_settings; recon-only use DEFAULT_SETTINGS + fetch_project_settings. There is no shared module.

The registry reaches three services on three schedules

This is the part that bites, because two of the three pick a change up on their own and the third does not:

ServiceHow it gets the registryAfter a registry change
reconvolume-mounted, spawned per scannothing
recon-orchestratorread-only mountdocker compose restart recon-orchestrator
agentCOPY-baked (agentic/Dockerfile)docker compose build agent && docker compose up -d agent

Rebuilding the agent is not optional after a registry change. build.py also writes recon_settings/roe_parse_prompt.py, which embeds the SHA-256 of registry.json, and /roe/parse compares that digest against the registry it actually loaded. A stale agent image therefore returns 503 on every RoE document upload, naming both digests, rather than parsing a document against a field list that no longer matches what will validate the answer.

It fails closed on purpose: a stale prompt does not produce an error, it produces a confidently wrong configuration.

Commands

bash
python3 tooling/scripts/extract_recon_registry.py             # draft the registry entry for a new column
python3 recon_settings/build.py                               # rebuild the THREE artifacts (--check in the gate)
cd webapp && npm run docs:settings                            # regenerate the wiki settings registry
docker compose exec webapp npx prisma db push                 # apply schema; NEVER prisma migrate
docker compose build agent && docker compose up -d agent      # REQUIRED after ANY registry change (see below)
docker compose restart recon-orchestrator                     # picks the registry up from its mount
# existing projects (ask first - mutates every row):
docker compose exec postgres psql -U redamon -d redamon -c "UPDATE projects SET katana_timeout = 3600 WHERE katana_timeout IS NULL;"

Resources

© samugit83, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/project-settings-cascade of samugit83/redamon.

Open the folder on GitHubat commit d90c940

Compare with similar skills

Project Settings Cascade next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Project Settings Cascade compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Project Settings Cascade this skillsamugit83/redamon3k—~2.4kAutomated safety check: PassMIT
Context7 Efficientaiskillstore/marketplace430—~1.5kAutomated safety check: PassNone
Bug Bounty Campaign DriverEncod3d-Sec/TORCH3291 repos~1.8kAutomated safety check: PassMIT
Prisma CLIcurvenote/curvenote169—~1.6kAutomated safety check: PassMIT
Context7 MCPrtadewald/skills180—~681Automated safety check: PassNone
Documentation Lookupaffaan-m/ECC275k1 repos~670Automated safety check: PassMIT

Similar skills

  • Context7 Efficient

    aiskillstore/marketplace

    Token-efficient library documentation fetcher using Context7 MCP with 86.8% token savings through intelligent shell pipeline filtering.

    430 GitHub stars~1.5k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub starsUsed in 1 repo~1.8k tokens
    SecurityAuto-check passed
  • Prisma CLI

    curvenote/curvenote

    Prisma CLI commands reference covering all available commands, options, and usage patterns.

    169 GitHub stars~1.6k tokensUpdated 10 days ago
    DatabasesAuto-check passed
  • Context7 MCP

    rtadewald/skills

    This skill should be used when the user asks about libraries, frameworks, API references, or needs code examples.

    180 GitHub stars~681 tokensUpdated 10 days ago
    DatabasesAuto-check passed
  • 通过 Context7 MCP 使用最新的库和框架文档,而非训练数据。当用户提出设置问题、API参考、代码示例或命名框架(例如 React、Next.js、Prisma)时激活。

    275k GitHub starsUsed in 1 repo~670 tokens
    DatabasesAuto-check passed
  • Context7 MCP

    danielvm-git/bigpowers

    Fetch current library docs via Context7 MCP instead of training data.

    257 GitHub stars~603 tokensUpdated 17 days ago
    DatabasesAuto-check passed

More from samugit83/redamon

All 15 skills in this repo
  • Add Community Skill

    samugit83/redamon

    Adding a Community Agent Skill: a Markdown attack-workflow file that users import from the catalog, which then competes in the Intent Router and is injected into the agent's system prompt.

    3k GitHub stars~775 tokensUpdated yesterday
    Auto-check passed
  • Add Partial Recon

    samugit83/redamon

    Adding partial-recon support for a tool: running a single pipeline phase on demand from the workflow graph, reading its inputs from the existing Neo4j graph and merging results back.

    3k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Agentic Tool Integration

    samugit83/redamon

    Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in…

    3k GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Builtin Agent Skill

    samugit83/redamon

    Adding a built-in Agent Skill (an attack technique like ssrf, xxe, rce) that ships hardcoded in RedAmon: classified by the Intent Router, injected into the agent prompt, toggled per project, badged…

    3k GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Graph DB Writes

    samugit83/redamon

    Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must…

    3k GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • LLM Provider Integration

    samugit83/redamon

    Adding an LLM provider to RedAmon: the credential boundary (keys must never reach scan containers), prefix-routed model ids, and the provider registry.

    3k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed

Questions about Project Settings Cascade

What does Project Settings Cascade do?

Changing or adding a project setting / default value in RedAmon. Project Settings Cascade is an agent skill from samugit83/redamon. Changing or adding a project setting / default value in RedAmon.

When should I use Project Settings Cascade?

Project Settings Cascade fits situations like: tasks that involve Penetration testing; tasks that involve ORMs and data access; tasks that involve Bug bounty.

How do I install Project Settings Cascade in Claude Code?

Run `npx skills add samugit83/redamon --skill project-settings-cascade -a claude-code`. Or copy the skill folder (skills/project-settings-cascade in samugit83/redamon) into .claude/skills/project-settings-cascade in your project. Claude Code loads it when a task matches its description.

How do I install Project Settings Cascade in Codex?

Run `npx skills add samugit83/redamon --skill project-settings-cascade -a codex`. Or copy the skill folder (skills/project-settings-cascade in samugit83/redamon) into .agents/skills/project-settings-cascade in your project. Codex loads it when a task matches its description.

Can I use Project Settings Cascade in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add samugit83/redamon --skill project-settings-cascade -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/project-settings-cascade, .gemini/skills/project-settings-cascade, .github/skills/project-settings-cascade and .opencode/skills/project-settings-cascade in your project.

What does Project Settings Cascade need to run?

Going by SKILL.md and its folder, Project Settings Cascade needs the command-line tools its instructions call (docker, python3 and npm). Our summary lists: Python 3; Node.js; Docker.

Does Project Settings Cascade access the network?

SKILL.md contains no URLs. Its commands use docker and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Project Settings Cascade safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Project Settings Cascade use?

Project Settings Cascade is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Project Settings Cascade use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Project Settings Cascade?

Skills that share tags, products or a category with Project Settings Cascade: Context7 Efficient (aiskillstore/marketplace, 430 stars), Bug Bounty Campaign Driver (Encod3d-Sec/TORCH, 329 stars), Prisma CLI (curvenote/curvenote, 169 stars) and Context7 MCP (rtadewald/skills, 180 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Project Settings Cascade?

samugit83 (a GitHub user) maintains it in samugit83/redamon, which has 2,961 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 7, 2026.

Source: samugit83/redamon on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.