PR Babysitter
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
Decide and implement how to support a new LLM provider or agent engine in AWF - either as a proxied provider (api-proxy adapter) or a direct-API engine (domain allowlist only), e.g.
$ npx skills add github/gh-aw-firewall --skill add-llm-provider -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install github/gh-aw-firewall add-llm-provider --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/add-llm-provider .claude/skills/add-llm-provider && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "add-llm-provider" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.github/skills/add-llm-provider into .claude/skills/add-llm-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-llm-provider", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/github/gh-aw-firewall/tree/main/.github/skills/add-llm-providerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add github/gh-aw-firewall --skill add-llm-provider -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install github/gh-aw-firewall add-llm-provider --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/add-llm-provider .agents/skills/add-llm-provider && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "add-llm-provider" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.github/skills/add-llm-provider into .agents/skills/add-llm-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-llm-provider", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add github/gh-aw-firewall --skill add-llm-provider -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install github/gh-aw-firewall add-llm-provider --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/add-llm-provider .cursor/skills/add-llm-provider && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "add-llm-provider" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.github/skills/add-llm-provider into .cursor/skills/add-llm-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-llm-provider", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/github/gh-aw-firewall.git --path .github/skills/add-llm-provider--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add github/gh-aw-firewall --skill add-llm-provider -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install github/gh-aw-firewall add-llm-provider --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/add-llm-provider .gemini/skills/add-llm-provider && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "add-llm-provider" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.github/skills/add-llm-provider into .gemini/skills/add-llm-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-llm-provider", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install github/gh-aw-firewall add-llm-providerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add github/gh-aw-firewall --skill add-llm-provider -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/add-llm-provider .github/skills/add-llm-provider && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "add-llm-provider" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.github/skills/add-llm-provider into .github/skills/add-llm-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-llm-provider", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add github/gh-aw-firewall --skill add-llm-provider -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install github/gh-aw-firewall add-llm-provider --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/add-llm-provider .opencode/skills/add-llm-provider && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "add-llm-provider" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.github/skills/add-llm-provider into .opencode/skills/add-llm-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-llm-provider", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
add-llm-providerDecide and implement how to support a new LLM provider or agent engine in AWF - either as a proxied provider (api-proxy adapter) or a direct-API engine (domain allowlist only), e.g.
Add LLM Provider is an agent skill from github/gh-aw-firewall, published by the product's own GitHub organization. Decide and implement how to support a new LLM provider or agent engine in AWF - either as a proxied provider (api-proxy adapter) or a direct-API engine (domain allowlist only), e.g. Cursor, Aider, or any tool that calls its own endpoint.
Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It works with GitHub. The repository describes itself as: GitHub Agentic Workflows Firewall. The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit e51e3ce. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
dockernpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use docker and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Add LLM Provider loads about 1.4k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 653 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from github/gh-aw-firewall at commit e51e3ce, republished under its MIT licence (© github). 653 words, ~1,384 tokens.
.claude/skills/add-llm-provider/SKILL.md (or your agent's skills folder).Use this skill whenever a new agent engine or LLM provider needs to work behind AWF and it is unclear how to "set it up." AWF supports two fundamentally different integration paths — picking the wrong one is the most common source of confusion (e.g. "why is token-usage.jsonl empty for this engine?").
Ask: does the engine call the provider's API directly (its own base URL, its own auth), or can it be configured to route through AWF's API-proxy sidecar? The sidecar is always enabled; --enable-api-proxy is deprecated and ignored. Its provider ports are http://172.30.0.30:10000 (OpenAI), :10001 (Anthropic), :10002 (Copilot), :10003 (Gemini), and :10004 (Vertex AI).
OPENAI_BASE_URL, ANTHROPIC_BASE_URL rewritten to the sidecar) → Path A: Proxied provider.api2.cursor.sh / api3.cursor.sh directly), or manages its own credentials outside AWF → Path B: Direct-API engine.When unsure, run the engine once with --keep-containers and inspect docker exec awf-squid cat /var/log/squid/access.log (see docs/squid_log_filtering.md) to see which hosts it actually contacts and whether traffic reaches the api-proxy sidecar or goes straight out through Squid.
Choose this when you want AWF to hold the API key/OIDC token and inject it, keeping secrets out of the agent container.
Use containers/api-proxy/providers/ADDING-A-PROVIDER.md for the adapter interface, then:
containers/api-proxy/providers/<name>.js implementing the ProviderAdapter interface.containers/api-proxy/providers/index.js.src/config/sandbox-network-policy.json, then extend the closed NetworkPolicy shape and validation in src/config/network-policy.ts and the compatibility mapping in src/types/ports.ts. Add it to the Dockerfile EXPOSE list; the whole providers/ directory is already copied. src/host-iptables-rules.ts consumes Object.values(API_PROXY_PORTS), so it normally needs no change.src/services/api-proxy-env-config.ts and explicitly exclude it from agent passthrough in src/services/agent-environment/excluded-vars.ts; never forward a provider credential generically or from src/docker-manager.ts.--allow-domains (AWF itself does not hardcode per-provider domains).providers/<name>.test.js) and run cd containers/api-proxy && npm test -- providers/<name>.test.js.Choose this when the engine calls its own API directly and either manages its own credentials, or credential injection isn't feasible/needed through AWF.
awf --allow-domains api2.cursor.sh,api3.cursor.sh -- cursor-agent ...network.allowDomains (see docs/awf-config-spec.md and docs/awf-config.schema.json).sensitiveAllowedDomains for the key: that setting only redacts secret-derived endpoint hostnames in logs and audit artifacts.token-usage.jsonl / token-tracking metrics will stay empty for this engine. Any downstream check that assumes all engines produce proxy telemetry (e.g. a "token usage present" CI gate) must exclude direct-API engines instead of trying to make them populate it.--keep-containers and checking Squid's access log for TCP_DENIED entries, then iterating on the allowlist (see docs/quickstart.md "Test Domain Blocking" section).--keep-containers + Squid access log that the engine's real traffic is allowed and nothing extraneous is© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/add-llm-provider of github/gh-aw-firewall.
Open the folder on GitHubat commit e51e3ce
Add LLM Provider next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Add LLM Provider this skillgithub/gh-aw-firewall | 148 | — | ~1.4k | Automated safety check: Pass | MIT | |
| PR Babysitteropeninterpreter/openinterpreter | 69k | 3 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Diagnosing Superpowers Sessionsobra/superpowers | 296k | 3 repos | ~1.7k | Automated safety check: Pass | MIT | |
| GitHub Deep Researchbytedance/deer-flow | 83k | 5 repos | ~1.3k | Automated safety check: Pass | MIT | |
| Greplooponyx-dot-app/onyx | 32k | 4 repos | ~3.3k | Automated safety check: Pass | MIT | |
| Update V8 Versionopeninterpreter/openinterpreter | 69k | 2 repos | ~845 | Automated safety check: Pass | Apache-2.0 |
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
obra/superpowers
Investigates a session where Superpowers went wrong, reads the transcripts on disk and produces an evidence-cited report, optionally prepared as a bug report for the maintainers.
bytedance/deer-flow
Researches a GitHub repository over four rounds using the GitHub API and web search, then writes a structured markdown report with timeline, metrics and Mermaid diagrams.
onyx-dot-app/onyx
Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.
openinterpreter/openinterpreter
Bumps the pinned v8 and rusty_v8 versions in Codex, validates the release-candidate path with the v8-canary check, and traces failures to upstream build changes.
mvanhorn/last30days-skill
Research what people actually say about any topic in the last 30 days.
github/gh-aw-firewall
Practical Python scripts for debugging awf - parse logs, diagnose issues, inspect containers, test domains
github/gh-aw-firewall
Regenerate and post-process all agentic workflows. An agent skill from github/gh-aw-firewall.
github/gh-aw-firewall
Debug the AWF firewall by inspecting Docker containers (awf-squid, awf-agent), analyzing Squid access logs, checking iptables rules, and troubleshooting blocked domains or network issues.
github/gh-aw-firewall
Debug GitHub Actions workflows by downloading logs, analyzing summaries, and understanding how agentic workflows and the AWF firewall work together.
github/gh-aw-firewall
Diagnose an AWF (Agentic Workflow Firewall) failure from an error, workflow run URL, or symptom.
Works with
Decide and implement how to support a new LLM provider or agent engine in AWF - either as a proxied provider (api-proxy adapter) or a direct-API engine (domain allowlist only), e.g. Add LLM Provider is an agent skill from github/gh-aw-firewall, published by the product's own GitHub organization.g.
Run `npx skills add github/gh-aw-firewall --skill add-llm-provider -a claude-code`. Or copy the skill folder (.github/skills/add-llm-provider in github/gh-aw-firewall) into .claude/skills/add-llm-provider in your project. Claude Code loads it when a task matches its description.
Run `npx skills add github/gh-aw-firewall --skill add-llm-provider -a codex`. Or copy the skill folder (.github/skills/add-llm-provider in github/gh-aw-firewall) into .agents/skills/add-llm-provider in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/gh-aw-firewall --skill add-llm-provider -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/add-llm-provider, .gemini/skills/add-llm-provider, .github/skills/add-llm-provider and .opencode/skills/add-llm-provider in your project.
Going by SKILL.md and its folder, Add LLM Provider needs the command-line tools its instructions call (docker and npm). Our summary lists: Docker.
SKILL.md contains no URLs. Its commands use docker and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Add LLM Provider is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Add LLM Provider: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Diagnosing Superpowers Sessions (obra/superpowers, 296k stars), GitHub Deep Research (bytedance/deer-flow, 83k stars) and Greploop (onyx-dot-app/onyx, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
github (a GitHub organization, an official publisher) maintains it in github/gh-aw-firewall, which has 148 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 8, 2026.
Source: github/gh-aw-firewall on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.