Repository navigation
Add Requesty as a provider option - #7
Thibaultjaigu wants to merge 1 commit into
Conversation
Greptile SummaryThis PR adds Requesty as an OpenAI-compatible provider alternative to OpenRouter, mirroring the existing
Confidence Score: 3/5Not safe to merge in current form — a Requesty-only user running the CLI will hit auth errors on the first scan turn because the majority of agents still call OpenRouter with the Requesty key. The attacker and evaluator changes are correct, but four other agents (Strategist, Mutator, Inspector, Target) and the injection evaluator remain OpenRouter-only. ScanEngine passes the resolved API key to all of them, so a Requesty key ends up at the OpenRouter endpoint and triggers authentication failures before the first attack turn completes. The model-name default issue compounds this: even if the other agents were fixed, the dot-vs-hyphen model ID mismatch could break Requesty calls when model names flow in from ScanEngine's defaults. src/agents/engine.ts and the unmodified agent files (strategist.ts, mutator.ts, inspector.ts, injection-evaluator.ts, target.ts) need Requesty support added to match what was done in attacker.ts and evaluator.ts. Important Files Changed
Flowchart%%{init: {'theme': 'neutral'}}%%
flowchart TD
CLI["CLI: zeroleaks scan --provider requesty"]
ENV["Sets process.env.REQUESTY_API_KEY = apiKey"]
RUN["runSecurityScan({ apiKey: requestyKey })"]
ENGINE["ScanEngine constructor\napiKey = config.apiKey (requestyKey)"]
ENGINE --> ATK["createAttacker({ apiKey: requestyKey })\n✅ Auto-detects REQUESTY_API_KEY\nUses createRequesty()"]
ENGINE --> EVAL["createEvaluator({ apiKey: requestyKey })\n✅ Auto-detects REQUESTY_API_KEY\nUses createRequesty()"]
ENGINE --> STRAT["createStrategist({ apiKey: requestyKey })\n❌ Uses createOpenRouter(requestyKey)\n→ 401 on OpenRouter"]
ENGINE --> MUT["createMutator({ apiKey: requestyKey })\n❌ Uses createOpenRouter(requestyKey)\n→ 401 on OpenRouter"]
ENGINE --> INSP["createInspector(..., requestyKey)\n❌ Uses createOpenRouter(requestyKey)\n→ 401 on OpenRouter"]
ENGINE --> TARGET["createTarget(prompt, { apiKey: requestyKey })\n❌ Uses createOpenRouter(requestyKey)\n→ 401 on OpenRouter"]
CLI --> ENV --> RUN --> ENGINE
%%{init: {'theme': 'base', 'themeVariables': {"darkMode": true, "background": "#0d1117", "primaryColor": "#21262d", "primaryTextColor": "#e6edf3", "primaryBorderColor": "#8b949e", "lineColor": "#8b949e", "textColor": "#e6edf3", "edgeLabelBackground": "#161b22", "actorBkg": "#21262d", "actorBorder": "#8b949e", "actorTextColor": "#e6edf3", "actorLineColor": "#8b949e", "signalColor": "#8b949e", "signalTextColor": "#e6edf3", "noteBkgColor": "#373320", "noteBorderColor": "#d4a72c", "noteTextColor": "#f0e6c0", "labelBoxBkgColor": "#21262d", "labelBoxBorderColor": "#8b949e", "labelTextColor": "#e6edf3", "loopTextColor": "#e6edf3", "activationBkgColor": "#30363d", "activationBorderColor": "#8b949e"}}}%%
flowchart TD
CLI["CLI: zeroleaks scan --provider requesty"]
ENV["Sets process.env.REQUESTY_API_KEY = apiKey"]
RUN["runSecurityScan({ apiKey: requestyKey })"]
ENGINE["ScanEngine constructor\napiKey = config.apiKey (requestyKey)"]
ENGINE --> ATK["createAttacker({ apiKey: requestyKey })\n✅ Auto-detects REQUESTY_API_KEY\nUses createRequesty()"]
ENGINE --> EVAL["createEvaluator({ apiKey: requestyKey })\n✅ Auto-detects REQUESTY_API_KEY\nUses createRequesty()"]
ENGINE --> STRAT["createStrategist({ apiKey: requestyKey })\n❌ Uses createOpenRouter(requestyKey)\n→ 401 on OpenRouter"]
ENGINE --> MUT["createMutator({ apiKey: requestyKey })\n❌ Uses createOpenRouter(requestyKey)\n→ 401 on OpenRouter"]
ENGINE --> INSP["createInspector(..., requestyKey)\n❌ Uses createOpenRouter(requestyKey)\n→ 401 on OpenRouter"]
ENGINE --> TARGET["createTarget(prompt, { apiKey: requestyKey })\n❌ Uses createOpenRouter(requestyKey)\n→ 401 on OpenRouter"]
CLI --> ENV --> RUN --> ENGINE
Reviews (1): Last reviewed commit: "Add Requesty as a provider option" | Re-trigger Greptile |
x1xhlol
left a comment
There was a problem hiding this comment.
Reviewed the provider-selection path across the CLI, attacker, evaluator, and docs. The OpenRouter default appears preserved, and Requesty is only selected explicitly or when REQUESTY_API_KEY is present without OPENROUTER_API_KEY, which keeps existing users on the current path. No blocking changes from this pass; the main thing I would consider before merge is a small unit/CLI coverage check around provider resolution so the auto-detection rules do not regress later.
Requesty (https://router.requesty.ai/v1) is an OpenAI-compatible LLM router. It is wired into resolveModel, the single place every agent (attacker, evaluator, strategist, mutator, inspector, injection evaluator and target) gets its model from, so no agent code changes. Requesty is never picked automatically. It is used only when selected explicitly: the CLI flag --provider requesty (or ZEROLEAKS_PROVIDER), opts.provider on resolveModel, or a requesty/ prefix on a single model id. Unknown --provider values are rejected instead of falling back. The key comes from REQUESTY_API_KEY or --requesty-api-key. OpenRouter stays the default and the OpenAI direct path is unchanged. Adds tests/provider.test.ts covering the selection rules and the CLI validation, plus README, AGENTS.md and .env.example notes.
a4068fe to
94efded
Compare
|
@x1xhlol thanks for the pass. I reworked the branch after your review and it now has the coverage you asked for. Provider resolution lives in one place, One behaviour change from the first version, in line with your note about keeping existing users on the current path: Requesty is never auto detected any more. It is only used when asked for explicitly, so a Requesty key sitting in the environment changes nothing. |
|
Thanks for the PR, and for reworking it after the review! #10 was just merged and and adds a Model ids like Since that covers it, I'm going to close this one. If anything doesn't work with Requesty, open an issue and we'll take a look. |
This adds Requesty as an opt in router for the scanner, next to the existing OpenRouter and OpenAI paths in
resolveModel.Requesty (
https://router.requesty.ai/v1) is an OpenAI compatible LLM router with the sameprovider/modelid format as OpenRouter. It is never picked automatically: OpenRouter stays the default for every model, and settingREQUESTY_API_KEYalone changes nothing. Requesty is only used when you ask for it with--provider requesty(orZEROLEAKS_PROVIDER=requesty), or when a single model id carries arequesty/prefix.Changes:
Rebased on current main. The first version added a
@requesty/ai-sdkdependency and picked Requesty whenever a key was present. Since upstream centralised provider selection insrc/provider.ts, the PR was redone on top of that: no new dependency (Requesty is created with the existing@ai-sdk/openaiclient pointed at the Requesty base URL), the key based auto detection is gone, and there is an explicit--providerflag plus arequesty/model id prefix instead.src/provider.ts:RouterProvidertype,parseProvider(unknown values throw instead of silently falling back),isRequestyModel, and a Requesty branch inresolveModelthat strips therequesty/prefix before sending the id. OpenAI ids keep the OpenAI direct path whenOPENAI_API_KEYis set, exactly as before.src/bin/cli.ts:--provider <openrouter|requesty>and--requesty-api-key, withREQUESTY_API_KEYandZEROLEAKS_PROVIDERas env equivalents.--provider requestywithout a Requesty key exits with a clear error, and a Requesty key alone now satisfies the "at least one key" check.resolveModel, the flag covers every agent with no per agent changes.tests/provider.test.ts: covers the default (OpenRouter even when only a Requesty key is set), the prefix, the flag and env var, the OpenAI direct path, and the CLI validation.README.md,AGENTS.md,.env.example: document the option and the model library (https://app.requesty.ai/model-library).Usage:
Docs: https://docs.requesty.ai
Disclosure: I work at Requesty. Happy to adjust anything to match project conventions.