Skills altllm-portal-api-keys
๐Ÿ“ฆ

altllm-portal-api-keys

Content revision r1 High Risk ๐ŸŒ Network accessโš™๏ธ External commands๐Ÿ“ Filesystem access

Manage AltLLM Portal API Keys

Portal API keys need careful lifecycle control across agents and applications. This skill guides AltLLM CLI tasks for listing, creating, updating, disabling, and revoking keys.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "altllm-portal-api-keys" from https://skillstore.io/skills/internet-court-altllm-portal-api-keys.md and its manifest at https://skillstore.io/api/skills/internet-court-altllm-portal-api-keys/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Your Agent should still show its plan and request any confirmation required by the security policy.

Test it

Using "altllm-portal-api-keys". List Portal API keys for my active workspace.

Expected outcome:

A concise summary with key names, prefixes, status values, and model allowlists.

Using "altllm-portal-api-keys". Create a key named Codex Agent with two allowed models.

Expected outcome:

A confirmation request before creation, followed by a redacted result and storage warning for the one-time secret.

Using "altllm-portal-api-keys". Revoke this old key after I confirm the ID.

Expected outcome:

A permanent-action warning, target key confirmation, and a status update if the backend route succeeds.

Security Audit

High Risk
v2 โ€ข 7/21/2026 Open versioned report

All 33 static detections are false positives caused by Markdown formatting, documented HTTPS endpoints, CLI names, placeholders, and relative documentation links. However, the skill requires following shared documents outside the audited package, creating an unreviewed instruction dependency that should be removed or pinned before publication.

2
Files scanned
138
Lines analyzed
0
Review items
0
False positives ignored

Confirmed security concerns (1)

High
Unpinned Shared Instruction Dependency
The skill instructs the agent to read and follow two sibling shared documents before running commands. Those documents are outside the audited skill files, so their contents can change independently and introduce unsafe instructions.
The instruction explicitly requires following external sibling files, while the audited file structure does not include them. Their content and integrity cannot be evaluated in this audit.
Audited by: claude View Audit History โ†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/internet-court-altllm-portal-api-keys/audits/2?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/internet-court-altllm-portal-api-keys/security.svg)](https://skillstore.io/skills/internet-court-altllm-portal-api-keys?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/internet-court-altllm-portal-api-keys?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/internet-court-altllm-portal-api-keys/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/internet-court-altllm-portal-api-keys.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

internet-court. (2026). altllm-portal-api-keys security audit report (audit version 2) [Author version unspecified]. Skillstore. https://skillstore.io/skills/internet-court-altllm-portal-api-keys/audits/2

BibTeX citation

@techreport{internet-court-internet-court-altllm-portal-api-keys-2026, author = {internet-court}, title = {altllm-portal-api-keys security audit report (audit version 2)}, institution = {Skillstore}, year = {2026}, number = {2}, url = {https://skillstore.io/skills/internet-court-altllm-portal-api-keys/audits/2}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "altllm-portal-api-keys security audit report (audit version 2)" version: "unspecified" type: report authors: - name: "internet-court" date-released: "2026-07-21" url: "https://skillstore.io/skills/internet-court-altllm-portal-api-keys/audits/2" identifiers: - type: other value: "skillstore:internet-court-altllm-portal-api-keys:audit:2" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
41
Architecture
85
Maintainability
87
Content
65
Community
83
Spec Compliance

What You Can Build

Set Up Agent Credentials

Create a named Portal API key with a focused model allowlist for an external agent or application.

Rotate Application Access

List existing keys, create a replacement key, and plan disable or revoke actions for old credentials.

Review Model Access

Inspect documented allowlist options and status rules before changing which models a key can use.

Try These Prompts

List Portal Keys
Use the AltLLM Portal API Keys skill to list my Portal API keys for the confirmed account. Summarize active and disabled keys.
Create Scoped Key
Create a Portal API key named Codex Agent for altllm-native-fast and altllm-standard. Ask for confirmation before running the command.
Disable Existing Key
Update key <key_id> to disabled after confirming the target environment. Then show the resulting status without exposing secrets.
Plan Production Cleanup
Review the known production limitation, then propose a safe key cleanup plan before creating any temporary production keys.

Best Practices

  • Confirm the Portal account, target environment, and key ID before any state-changing command.
  • Redact full API key values from chat summaries, logs, screenshots, and tickets.
  • Use model allowlists to scope each key to the smallest required access.

Avoid

  • Creating temporary production keys when revoke is unavailable.
  • Pasting full API key values back into shared conversations or tickets.
  • Using the default model set when an application needs only a narrow allowlist.

Frequently Asked Questions

Can this skill log in to my wallet?
No. It is only for AltLLM Portal API key lifecycle tasks.
Does it support Claude, Codex, and Claude Code?
Yes. The report marks the skill as compatible with Claude, Codex, and Claude Code.
Can it create Flex model keys?
It can pass altllm-flex-* model IDs, but backend account checks remain authoritative.
Will it show the full key later?
No. The source says create returns the full key only once.
Are all key commands currently working?
No. The source documents single-key route issues for get, update, and revoke.
Should I use it for billing or payments?
No. The skill description excludes wallet login, billing history, and payment links.

Developer Details

License

MIT

Skillstore revision

r1

Version notice

The author did not declare a version.

Ref

3f6e026a3363e0954ede7bef0cfe88d4475de137

Maintenance freshness

7/21/2026

Usage

1 downloads ยท 0 views

File structure

๐Ÿ“ references/

๐Ÿ“„ cli-reference.md

๐Ÿ“„ SKILL.md

More from internet-court

View all
View all