Official agent skill

Add LLM Provider

by github in github/gh-aw-firewall

Decide and implement how to support a new LLM provider or agent engine in AWF - either as a proxied provider (api-proxy adapter) or a direct-API engine (domain allowlist only), e.g.

OfficialMITAuto-check passed

Install Add LLM Provider

skills CLI
$ npx skills add github/gh-aw-firewall --skill add-llm-provider -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install github/gh-aw-firewall add-llm-provider --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/add-llm-provider .claude/skills/add-llm-provider && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
add-llm-provider
GitHub stars
148
Token cost
~1.4k tokens
SKILL.md length
653 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Decide and implement how to support a new LLM provider or agent engine in AWF - either as a proxied provider (api-proxy adapter) or a direct-API engine (domain allowlist only), e.g.

  • Works in 7 steps: Create… → Register it in… → Add its port to… → …
  • SKILL.md covers Step 1 — Determine how the…, Path A — Proxied provider…, Path B — Direct-API engine (no… and Checklist
  • Calls docker and npm

What it does

Add LLM Provider is an agent skill from github/gh-aw-firewall, published by the product's own GitHub organization. Decide and implement how to support a new LLM provider or agent engine in AWF - either as a proxied provider (api-proxy adapter) or a direct-API engine (domain allowlist only), e.g. Cursor, Aider, or any tool that calls its own endpoint.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with GitHub. The repository describes itself as: GitHub Agentic Workflows Firewall. The licence is MIT.

Example prompts

  • “/add-llm-provider”

Requirements

  • Docker

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Create containers/api-proxy/providers/.js implementing the ProviderAdapter interface.
  2. Register it in containers/api-proxy/providers/index.js.
  3. Add its port to src/config/sandbox-network-policy.json, then extend the closed NetworkPolicy shape and validation in…
  4. Add each credential to the API-proxy environment pipeline in src/services/api-proxy-env-config.ts and explicitly exclude it from agent…
  5. Add the upstream domain(s) to the allowlist wherever the caller configures --allow-domains (AWF itself does not hardcode per-provider…
  6. Document auth details in docs/auth-matrix.md if it's a net-new auth pattern.
  7. Write adapter unit tests (providers/.test.js) and run cd containers/api-proxy && npm test -- providers/.test.js.

What it can do on your machine

Read from SKILL.md and the folder at commit e51e3ce. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Add LLM Provider loads about 1.4k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 653 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from github/gh-aw-firewall at commit e51e3ce, republished under its MIT licence (© github). 653 words, ~1,384 tokens.

Download SKILL.mdSave it as .claude/skills/add-llm-provider/SKILL.md (or your agent's skills folder).
name
add-llm-provider
description
Decide and implement how to support a new LLM provider or agent engine in AWF - either as a proxied provider (api-proxy adapter) or a direct-API engine (domain allowlist only), e.g. Cursor, Aider, or any tool that calls its own endpoint.

Add LLM Provider

Use this skill whenever a new agent engine or LLM provider needs to work behind AWF and it is unclear how to "set it up." AWF supports two fundamentally different integration paths — picking the wrong one is the most common source of confusion (e.g. "why is token-usage.jsonl empty for this engine?").

Step 1 — Determine how the engine talks to its LLM backend

Ask: does the engine call the provider's API directly (its own base URL, its own auth), or can it be configured to route through AWF's API-proxy sidecar? The sidecar is always enabled; --enable-api-proxy is deprecated and ignored. Its provider ports are http://172.30.0.30:10000 (OpenAI), :10001 (Anthropic), :10002 (Copilot), :10003 (Gemini), and :10004 (Vertex AI).

  • If the engine has built-in support for pointing at AWF's api-proxy ports (env vars like OPENAI_BASE_URL, ANTHROPIC_BASE_URL rewritten to the sidecar) → Path A: Proxied provider.
  • If the engine always calls its own hardcoded/native endpoint regardless of proxy env vars (e.g. Cursor CLI calling api2.cursor.sh / api3.cursor.sh directly), or manages its own credentials outside AWF → Path B: Direct-API engine.

When unsure, run the engine once with --keep-containers and inspect docker exec awf-squid cat /var/log/squid/access.log (see docs/squid_log_filtering.md) to see which hosts it actually contacts and whether traffic reaches the api-proxy sidecar or goes straight out through Squid.

Path A — Proxied provider (credentials injected by api-proxy)

Choose this when you want AWF to hold the API key/OIDC token and inject it, keeping secrets out of the agent container.

Use containers/api-proxy/providers/ADDING-A-PROVIDER.md for the adapter interface, then:

  1. Create containers/api-proxy/providers/<name>.js implementing the ProviderAdapter interface.
  2. Register it in containers/api-proxy/providers/index.js.
  3. Add its port to src/config/sandbox-network-policy.json, then extend the closed NetworkPolicy shape and validation in src/config/network-policy.ts and the compatibility mapping in src/types/ports.ts. Add it to the Dockerfile EXPOSE list; the whole providers/ directory is already copied. src/host-iptables-rules.ts consumes Object.values(API_PROXY_PORTS), so it normally needs no change.
  4. Add each credential to the API-proxy environment pipeline in src/services/api-proxy-env-config.ts and explicitly exclude it from agent passthrough in src/services/agent-environment/excluded-vars.ts; never forward a provider credential generically or from src/docker-manager.ts.
  5. Add the upstream domain(s) to the allowlist wherever the caller configures --allow-domains (AWF itself does not hardcode per-provider domains).
  6. Document auth details in docs/auth-matrix.md if it's a net-new auth pattern.
  7. Write adapter unit tests (providers/<name>.test.js) and run cd containers/api-proxy && npm test -- providers/<name>.test.js.
Show full SKILL.md (278 more words)Show less

Path B — Direct-API engine (no proxy adapter needed)

Choose this when the engine calls its own API directly and either manages its own credentials, or credential injection isn't feasible/needed through AWF.

  1. No API-proxy adapter is required. The API proxy remains enabled, but do not try to force an engine through it when it cannot use the sidecar.
  2. Just allowlist the domain(s) the engine needs, either via the CLI flag or config file:
    bash
    awf --allow-domains api2.cursor.sh,api3.cursor.sh -- cursor-agent ...
    or in the AWF config file under network.allowDomains (see docs/awf-config-spec.md and docs/awf-config.schema.json).
  3. If the engine requires its API key in the agent environment, it cannot receive API-proxy credential isolation. Pass only a minimally scoped credential by an intentional mechanism appropriate to the caller, and do not use sensitiveAllowedDomains for the key: that setting only redacts secret-derived endpoint hostnames in logs and audit artifacts.
  4. Telemetry caveat: because traffic never passes through the API-proxy sidecar, AWF's token-usage.jsonl / token-tracking metrics will stay empty for this engine. Any downstream check that assumes all engines produce proxy telemetry (e.g. a "token usage present" CI gate) must exclude direct-API engines instead of trying to make them populate it.
  5. Confirm the domains are correct by testing with --keep-containers and checking Squid's access log for TCP_DENIED entries, then iterating on the allowlist (see docs/quickstart.md "Test Domain Blocking" section).

Checklist

  • Identified whether the engine is proxied (Path A) or direct-API (Path B)
  • Path A: adapter created and registered; network policy, credential isolation, image port, and tests updated
  • Path B: domain(s) allowlisted, telemetry-dependent checks updated to exclude this engine
  • Verified with --keep-containers + Squid access log that the engine's real traffic is allowed and nothing extraneous is

© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/add-llm-provider of github/gh-aw-firewall.

Open the folder on GitHubat commit e51e3ce

Compare with similar skills

Add LLM Provider next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Add LLM Provider compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Add LLM Provider this skillgithub/gh-aw-firewall148—~1.4kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Diagnosing Superpowers Sessionsobra/superpowers296k3 repos~1.7kAutomated safety check: PassMIT
GitHub Deep Researchbytedance/deer-flow83k5 repos~1.3kAutomated safety check: PassMIT
Greplooponyx-dot-app/onyx32k4 repos~3.3kAutomated safety check: PassMIT
Update V8 Versionopeninterpreter/openinterpreter69k2 repos~845Automated safety check: PassApache-2.0

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Investigates a session where Superpowers went wrong, reads the transcripts on disk and produces an evidence-cited report, optionally prepared as a bug report for the maintainers.

    296k GitHub starsUsed in 3 repos~1.7k tokens
    Agent WorkflowsAuto-check passed
  • GitHub Deep Research

    bytedance/deer-flow

    Researches a GitHub repository over four rounds using the GitHub API and web search, then writes a structured markdown report with timeline, metrics and Mermaid diagrams.

    83k GitHub starsUsed in 5 repos~1.3k tokens
    Research & ScienceAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed
  • Update V8 Version

    openinterpreter/openinterpreter

    Bumps the pinned v8 and rusty_v8 versions in Codex, validates the release-candidate path with the v8-canary check, and traces failures to upstream build changes.

    69k GitHub starsUsed in 2 repos~845 tokens
    DevOps & CloudAuto-check passed
  • Last30days

    mvanhorn/last30days-skill

    Research what people actually say about any topic in the last 30 days.

    64k GitHub stars~7.8k tokensUpdated today
    Research & ScienceAuto-check: notes

More from github/gh-aw-firewall

  • Awf Debug Tools

    github/gh-aw-firewall

    Official

    Practical Python scripts for debugging awf - parse logs, diagnose issues, inspect containers, test domains

    148 GitHub stars~2.6k tokensUpdated today
    Auto-check: notes
  • Recompile Workflows

    github/gh-aw-firewall

    Official

    Regenerate and post-process all agentic workflows. An agent skill from github/gh-aw-firewall.

    148 GitHub stars~568 tokensUpdated today
    Auto-check passed
  • Debug Firewall

    github/gh-aw-firewall

    Official

    Debug the AWF firewall by inspecting Docker containers (awf-squid, awf-agent), analyzing Squid access logs, checking iptables rules, and troubleshooting blocked domains or network issues.

    148 GitHub stars~1.2k tokensUpdated today
    Auto-check: notes
  • Debugging Workflows

    github/gh-aw-firewall

    Official

    Debug GitHub Actions workflows by downloading logs, analyzing summaries, and understanding how agentic workflows and the AWF firewall work together.

    148 GitHub stars~2.7k tokensUpdated today
    Auto-check: notes
  • Diagnose Awf

    github/gh-aw-firewall

    Official

    Diagnose an AWF (Agentic Workflow Firewall) failure from an error, workflow run URL, or symptom.

    148 GitHub stars~829 tokensUpdated today
    Auto-check passed

Works with

Questions about Add LLM Provider

What does Add LLM Provider do?

Decide and implement how to support a new LLM provider or agent engine in AWF - either as a proxied provider (api-proxy adapter) or a direct-API engine (domain allowlist only), e.g. Add LLM Provider is an agent skill from github/gh-aw-firewall, published by the product's own GitHub organization.g.

How do I install Add LLM Provider in Claude Code?

Run `npx skills add github/gh-aw-firewall --skill add-llm-provider -a claude-code`. Or copy the skill folder (.github/skills/add-llm-provider in github/gh-aw-firewall) into .claude/skills/add-llm-provider in your project. Claude Code loads it when a task matches its description.

How do I install Add LLM Provider in Codex?

Run `npx skills add github/gh-aw-firewall --skill add-llm-provider -a codex`. Or copy the skill folder (.github/skills/add-llm-provider in github/gh-aw-firewall) into .agents/skills/add-llm-provider in your project. Codex loads it when a task matches its description.

Can I use Add LLM Provider in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/gh-aw-firewall --skill add-llm-provider -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/add-llm-provider, .gemini/skills/add-llm-provider, .github/skills/add-llm-provider and .opencode/skills/add-llm-provider in your project.

What does Add LLM Provider need to run?

Going by SKILL.md and its folder, Add LLM Provider needs the command-line tools its instructions call (docker and npm). Our summary lists: Docker.

Does Add LLM Provider access the network?

SKILL.md contains no URLs. Its commands use docker and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Add LLM Provider safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Add LLM Provider use?

Add LLM Provider is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Add LLM Provider use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Add LLM Provider?

Skills that share tags, products or a category with Add LLM Provider: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Diagnosing Superpowers Sessions (obra/superpowers, 296k stars), GitHub Deep Research (bytedance/deer-flow, 83k stars) and Greploop (onyx-dot-app/onyx, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Add LLM Provider?

github (a GitHub organization, an official publisher) maintains it in github/gh-aw-firewall, which has 148 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 8, 2026.

Source: github/gh-aw-firewall on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.