LLM is a command-line tool and Python library for talking to language models. Install it, save an API key, and llm "Ten fun names for a pet pelican" sends a prompt to OpenAI; pipe a file into it with a system prompt and it explains code, summarises a log or pulls the text out of a scanned image. Plugins add everything else: Anthropic's Claude, Google's Gemini, Mistral, models served by Ollama and dozens more, all behind the same command and the same flags.
What sets it apart is that it remembers. Every prompt and response is logged to a local SQLite database you can search, open in Datasette or query directly, which turns a pile of one-off experiments into a record you can return to. It also does embeddings, structured extraction against a JSON schema, multi-turn chat and tool calling, so it scales from a quick question to a shell script that works through a folder of documents.
It is written by Simon Willison, co-creator of the Django web framework and author of Datasette, who writes up nearly every release on his blog. The project is Apache-2.0 licensed, has about 12,600 stars, and reached version 0.36 in September 2026.
- Repository: github.com/simonw/llm
- Licence: Apache-2.0 (Apache License 2.0)
- Language: Python. Stars: 12.6K. Forks: 1,012. Last push: Sep 22, 2026.
- Scan: safe, Sep 22, 2026, commit 764dc38
Who it is for
Developers and power users who live in a terminal and want one tool for every model provider, people who want a searchable history of what they asked and what came back, and anyone scripting model calls into shell pipelines.
Getting started
1. Install with pip (Homebrew, pipx and uv tool install also work)
pip install llm2. Save an OpenAI key and run a prompt
llm keys set openai && llm "Ten fun names for a pet pelican"3. Add Claude through its plugin
llm install llm-anthropic && llm keys set anthropic4. Or prompt a local model served by Ollama
llm install llm-ollama && llm -m llama3.2:latest 'What is the capital of France?'LLM is free, but hosted models are not: prompts to OpenAI, Anthropic or Google are billed to your own API key. The docs carry a warning about the Homebrew build and plugins that need PyTorch, so pip, pipx or uv is the safer install if you plan to run models locally through plugins.
Safety scan
We cloned simonw/llm at commit 764dc38 on Sep 22, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- No secrets, no suspicious patterns, no bare-IP URLs and no committed binaries across 118 files and about 52,000 lines, roughly 37,000 of them Python. The many example.test hosts in the host list are fixtures for the test suite's mocked HTTP calls; the only real API host in the code is api.openai.com, for the built-in OpenAI models.
- No npm hooks, setup.py command classes, build scripts or installer scripts. The package is plain Python, installed from PyPI or Homebrew.
- The only pinned lockfile is docs/requirements.txt (3 packages, for building the documentation), with no known advisories. Runtime dependencies are declared as version ranges in the package metadata, so the scan could not check exact versions; pip resolves current releases when you install.
- Plugins are where the trust sits. llm install runs pip for whatever package name you give it, and a plugin gets the same access to your machine and your saved keys as LLM itself, so stick to plugins from the project's directory or ones you have read. Keys saved with llm keys set are kept as plain text in a keys.json file in LLM's user directory.
- Four workflows, none using pull_request_target; the one third-party action is pinned to a tag rather than a commit. Dependabot and a licence are present; no security policy, CodeQL or contributing guide.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | None found. |
| Suspicious code | None found. |
| Install-time code | None: nothing runs at install beyond the package manager itself. |
| Committed binaries | None. |
| CI workflows | 4 workflows. None use pull_request_target. 1 of 1 third-party action pinned to a tag rather than a commit. |
| Network hosts | 27 distinct hosts referenced from source; most often api.openai.com, github.com, llm.datasette.io, images.example.test. No URLs to bare IP addresses. |
| Known vulnerabilities | 0 advisories across 3 pinned packages: 0 critical, 0 high, 0 moderate, 0 low. docs/requirements.txt: 3 packages, 0 advisories. |
| Project hygiene | Has automated dependency updates, licence file. Missing security policy, CodeQL, contributing guide. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
By the numbers
| Stars | 12.6K |
|---|---|
| Forks | 1,012 |
| Contributors | 79 |
| Commits | 1,300 |
| Open issues | 433 |
| Open pull requests | 288 |
| Releases | 72 |
| Latest release | 0.36 |
| Licence | Apache-2.0 |
| Main language | Python |
| Project age | 3 years |
| Last push | Sep 22, 2026 |
| Tracked files | 118 |
| Lines of code | 52.2K |
| Checkout size | 2 MB |
Lines by language: Python 37.1K, Markdown 11.7K, YAML 3,285, TOML 100, Shell 30, HTML 17.
Questions
Is LLM free?
Yes. LLM is Apache-2.0 licensed and free to install and use. What costs money is the model behind it: prompts to OpenAI, Anthropic, Google and other hosted providers are billed to your own API key at their normal rates, while local models reached through plugins such as llm-ollama cost nothing beyond your hardware.
Where does LLM store my prompts?
In a SQLite database in LLM's own directory on your machine. llm logs shows recent entries, llm logs path prints where the file is, and llm logs off turns logging off. Nothing is sent anywhere except the request to the model you chose.
How is LLM different from Ollama?
Ollama runs models; LLM talks to them. LLM has no inference engine of its own, so it calls hosted APIs directly and reaches local models through plugins, including one for Ollama. Many people use both: Ollama to serve a model, and LLM as the front end that logs every exchange and works the same way across providers.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
