4 min read

LLM: Prompt Any Model From Your Terminal (GitHub, Scanned)

Simon Willison's CLI for prompting hundreds of models, with every exchange logged to SQLite.

LLM logo
✅
Scan: safe. Nothing to warn about. A small Python codebase with no hits, no install hooks and no known advisories; the trust decision is the plugins you choose to install. Scanned Sep 22, 2026; the full report is below.

LLM is a command-line tool and Python library for talking to language models. Install it, save an API key, and llm "Ten fun names for a pet pelican" sends a prompt to OpenAI; pipe a file into it with a system prompt and it explains code, summarises a log or pulls the text out of a scanned image. Plugins add everything else: Anthropic's Claude, Google's Gemini, Mistral, models served by Ollama and dozens more, all behind the same command and the same flags.

What sets it apart is that it remembers. Every prompt and response is logged to a local SQLite database you can search, open in Datasette or query directly, which turns a pile of one-off experiments into a record you can return to. It also does embeddings, structured extraction against a JSON schema, multi-turn chat and tool calling, so it scales from a quick question to a shell script that works through a folder of documents.

It is written by Simon Willison, co-creator of the Django web framework and author of Datasette, who writes up nearly every release on his blog. The project is Apache-2.0 licensed, has about 12,600 stars, and reached version 0.36 in September 2026.

  • Repository: github.com/simonw/llm
  • Licence: Apache-2.0 (Apache License 2.0)
  • Language: Python. Stars: 12.6K. Forks: 1,012. Last push: Sep 22, 2026.
  • Scan: safe, Sep 22, 2026, commit 764dc38

Who it is for

Developers and power users who live in a terminal and want one tool for every model provider, people who want a searchable history of what they asked and what came back, and anyone scripting model calls into shell pipelines.

Getting started

1. Install with pip (Homebrew, pipx and uv tool install also work)

pip install llm

2. Save an OpenAI key and run a prompt

llm keys set openai && llm "Ten fun names for a pet pelican"

3. Add Claude through its plugin

llm install llm-anthropic && llm keys set anthropic

4. Or prompt a local model served by Ollama

llm install llm-ollama && llm -m llama3.2:latest 'What is the capital of France?'

LLM is free, but hosted models are not: prompts to OpenAI, Anthropic or Google are billed to your own API key. The docs carry a warning about the Homebrew build and plugins that need PyTorch, so pip, pipx or uv is the safer install if you plan to run models locally through plugins.

Safety scan

We cloned simonw/llm at commit 764dc38 on Sep 22, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No secrets, no suspicious patterns, no bare-IP URLs and no committed binaries across 118 files and about 52,000 lines, roughly 37,000 of them Python. The many example.test hosts in the host list are fixtures for the test suite's mocked HTTP calls; the only real API host in the code is api.openai.com, for the built-in OpenAI models.
  • No npm hooks, setup.py command classes, build scripts or installer scripts. The package is plain Python, installed from PyPI or Homebrew.
  • The only pinned lockfile is docs/requirements.txt (3 packages, for building the documentation), with no known advisories. Runtime dependencies are declared as version ranges in the package metadata, so the scan could not check exact versions; pip resolves current releases when you install.
  • Plugins are where the trust sits. llm install runs pip for whatever package name you give it, and a plugin gets the same access to your machine and your saved keys as LLM itself, so stick to plugins from the project's directory or ones you have read. Keys saved with llm keys set are kept as plain text in a keys.json file in LLM's user directory.
  • Four workflows, none using pull_request_target; the one third-party action is pinned to a tag rather than a commit. Dependabot and a licence are present; no security policy, CodeQL or contributing guide.

What the scanner counted

CheckResult
SecretsNone found.
Suspicious codeNone found.
Install-time codeNone: nothing runs at install beyond the package manager itself.
Committed binariesNone.
CI workflows4 workflows. None use pull_request_target. 1 of 1 third-party action pinned to a tag rather than a commit.
Network hosts27 distinct hosts referenced from source; most often api.openai.com, github.com, llm.datasette.io, images.example.test. No URLs to bare IP addresses.
Known vulnerabilities0 advisories across 3 pinned packages: 0 critical, 0 high, 0 moderate, 0 low. docs/requirements.txt: 3 packages, 0 advisories.
Project hygieneHas automated dependency updates, licence file. Missing security policy, CodeQL, contributing guide.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

By the numbers

Stars12.6K
Forks1,012
Contributors79
Commits1,300
Open issues433
Open pull requests288
Releases72
Latest release0.36
LicenceApache-2.0
Main languagePython
Project age3 years
Last pushSep 22, 2026
Tracked files118
Lines of code52.2K
Checkout size2 MB

Lines by language: Python 37.1K, Markdown 11.7K, YAML 3,285, TOML 100, Shell 30, HTML 17.

Questions

Is LLM free?

Yes. LLM is Apache-2.0 licensed and free to install and use. What costs money is the model behind it: prompts to OpenAI, Anthropic, Google and other hosted providers are billed to your own API key at their normal rates, while local models reached through plugins such as llm-ollama cost nothing beyond your hardware.

Where does LLM store my prompts?

In a SQLite database in LLM's own directory on your machine. llm logs shows recent entries, llm logs path prints where the file is, and llm logs off turns logging off. Nothing is sent anywhere except the request to the model you chose.

How is LLM different from Ollama?

Ollama runs models; LLM talks to them. LLM has no inference engine of its own, so it calls hosted APIs directly and reaches local models through plugins, including one for Ollama. Many people use both: Ollama to serve a model, and LLM as the front end that logs every exchange and works the same way across providers.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.