Agent skill

New Provider

by go-to-k in go-to-k/cdkd

Scaffold a new SDK Provider for a given AWS resource type (e.g., AWS::SES::EmailIdentity).

Apache-2.0Auto-check passedDevelopment

Install New Provider

skills CLI
$ npx skills add go-to-k/cdkd --skill new-provider -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install go-to-k/cdkd new-provider --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/go-to-k/cdkd.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/new-provider .claude/skills/new-provider && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
new-provider
GitHub stars
146
Token cost
~1.4k tokens
SKILL.md length
638 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
Apache-2.0

At a glance

Scaffold a new SDK Provider for a given AWS resource type (e.g., AWS::SES::EmailIdentity).

  • Works in 10 steps: Parse the resource type to determine → Check if provider already exists in… → Read an existing provider as reference… → …
  • Tasks that involve Project scaffolding
  • SKILL.md covers Input, Steps and Important
  • Calls pnpm

What it does

New Provider is an agent skill from go-to-k/cdkd. Scaffold a new SDK Provider for a given AWS resource type (e.g., AWS::SES::EmailIdentity). Creates provider file, registers it, and generates test boilerplate.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Project scaffolding. It works with Amazon Web Services and AWS CloudFormation. The repository describes itself as: Drop-in CDK CLI for existing CDK apps — up to 15x faster deploys via direct AWS SDK calls instead of CloudFormation. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Project scaffolding

Example prompts

  • “/new-provider”

Workflow steps

10 steps, taken from the first numbered list in SKILL.md.

  1. Parse the resource type to determine
  2. Check if provider already exists in src/provisioning/providers/ and src/provisioning/register-providers.ts.
  3. Read an existing provider as reference for the pattern. Use a simple one like src/provisioning/providers/ssm-parameter-provider.ts or…
  4. Read the AWS SDK docs or infer the API calls needed
  5. Create the provider file at src/provisioning/providers/{service}-{resource}-provider.ts
  6. Register the provider
  7. Create test file at tests/unit/provisioning/providers/{service}-{resource}-provider.test.ts
  8. Check if @aws-sdk/client-{service} is already in package.json. If not, tell the user to run pnpm add @aws-sdk/client-{service}.
  9. Run typecheck, lint, build, and tests to verify everything works.
  10. Create integration test by invoking /new-integ with a test name based on the resource type (e.g., ses-email-identity). The integ test…

What it can do on your machine

Read from SKILL.md and the folder at commit aefb343. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

New Provider loads about 1.4k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 638 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from go-to-k/cdkd at commit aefb343, republished under its Apache-2.0 licence (© go-to-k). 638 words, ~1,428 tokens.

Download SKILL.mdSave it as .claude/skills/new-provider/SKILL.md (or your agent's skills folder).
name
new-provider
description
Scaffold a new SDK Provider for a given AWS resource type (e.g., AWS::SES::EmailIdentity). Creates provider file, registers it, and generates test boilerplate.
argument-hint
<AWS::Service::Resource>

New Provider Scaffold

You are scaffolding a new SDK Provider for cdkd.

Input

The user provides an AWS resource type like AWS::SES::EmailIdentity.

Steps

  1. Parse the resource type to determine:

    • Service name (e.g., SES)
    • Resource name (e.g., EmailIdentity)
    • AWS SDK client package (e.g., @aws-sdk/client-ses)
    • Provider file name (e.g., ses-email-identity-provider.ts)
  2. Check if provider already exists in src/provisioning/providers/ and src/provisioning/register-providers.ts.

  3. Read an existing provider as reference for the pattern. Use a simple one like src/provisioning/providers/ssm-parameter-provider.ts or src/provisioning/providers/logs-log-group-provider.ts.

  4. Read the AWS SDK docs or infer the API calls needed:

    • CREATE: Which API creates this resource? What does it return (physical ID, attributes)?
    • UPDATE: Which API updates this resource?
    • DELETE: Which API deletes this resource?
    • getAttribute: Which attributes might be needed for Fn::GetAtt?
    • import: Which API verifies a resource exists by physical id (Get* / Describe* / Head*), and which List* + ListTags* (or equivalent) lookup-by-tag pair lets you find a resource by its aws:cdk:path tag? See "Import method" under step 5 — most providers follow the same shape.
  5. Create the provider file at src/provisioning/providers/{service}-{resource}-provider.ts:

    • Import the AWS SDK client and commands
    • Implement ResourceProvider interface (create, update, delete, getAttribute, import)
    • Take clients from getAwsClients(), or build your own SDK client with ...ambientClientDefaults() (../../utils/ambient-client-defaults.js) spread FIRST — a bare awsClientDefaults() drops a library caller's explicit credentials and fails ambient-client-defaults-fence.test.ts (#3588)
    • Follow ESM import conventions (.js extension)
    • Return proper physicalId and attributes from create

    Import method — copy the shape from a similar provider rather than writing it from scratch: s3-bucket-provider.ts for a tag-ARRAY service, lambda-function-provider.ts for a tag-MAP one, kms-provider.ts for a service with no template name property. The shape is: resolve an explicit physical id first (resolveExplicitPhysicalId(input, '<NameField>'), i.e. the --resource override or Properties.<NameField>) and verify it with a Get / Head / Describe call; otherwise, with input.cdkPath present, walk the service's List* paginator, fetch tags per resource and match aws:cdk:path through matchesCdkPath (CDK_PATH_TAG in ../import-helpers.js).

    Notes:

    • Return null (not throw) when the resource is not found — caller treats this as "skipped" rather than failure.
    • attributes: {} is fine; Fn::GetAtt reconstructs missing attributes at deploy time via constructAttribute (see src/deployment/intrinsic-resolver/getatt.ts).
    • For services whose ListTags returns a Record<string,string> map instead of a Tag[] array (Lambda, SQS), read the value at key CDK_PATH_TAG directly instead of going through matchesCdkPath.
    • For services with NO template-supplied name field (KMS Key, CloudFront Distribution), skip step 1's name fallback — only the explicit-override path and tag lookup apply.
    • Some services don't support tagging or ListTags requires extra IAM. If tag lookup is impractical, document that limitation in the method's doc comment and rely on --resource overrides.
  6. Register the provider:

    • Re-export the class from src/provisioning/provider-classes.ts (export { ServiceResourceProvider } from './providers/{service}-{resource}-provider.js';) — never import it statically in register-providers.ts or anywhere else (#4521)
    • In registerAllProviders() (src/provisioning/register-providers.ts), add the class to the const { ... } = classes destructure and add registry.register('AWS::Service::Resource', new ServiceResourceProvider())
  7. Create test file at tests/unit/provisioning/providers/{service}-{resource}-provider.test.ts:

    • Mock the AWS SDK client
    • Test create (verify API call, physicalId, attributes)
    • Test update (verify API call)
    • Test delete (verify API call)
    • Test delete idempotency (not-found treated as success)
    • Test import explicit-override path (knownPhysicalId verified, attrs returned)
    • Test import tag-based lookup (List + ListTags + cdkPath match)
    • Test import not-found (returns null, does not throw)
  8. Check if @aws-sdk/client-{service} is already in package.json. If not, tell the user to run pnpm add @aws-sdk/client-{service}.

  9. Run typecheck, lint, build, and tests to verify everything works.

  10. Create integration test by invoking /new-integ with a test name based on the resource type (e.g., ses-email-identity). The integ test should create a minimal CDK stack using the new resource type.

Show full SKILL.md (59 more words)Show less

Important

  • Follow the exact patterns used by existing providers
  • Always use .js extension in imports (ESM)
  • Physical ID should match what CloudFormation uses for that resource type
  • Include delete idempotency (not-found errors treated as success)
  • Do NOT add the SDK client package yourself; tell the user if it's missing
  • Always create an integration test after the provider is implemented

© go-to-k, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/new-provider of go-to-k/cdkd.

Open the folder on GitHubat commit aefb343

Compare with similar skills

New Provider next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

New Provider compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
New Provider this skillgo-to-k/cdkd146—~1.4kAutomated safety check: PassApache-2.0
AWS Native Runtime Investigationpulumi/pulumi-aws-native108—~753Automated safety check: PassApache-2.0
New Resourcemondoohq/mql412—~5.6kAutomated safety check: PassCustom licence
PR Reviewaws/aws-cdk-cli107—~2kAutomated safety check: PassApache-2.0
Scaffold Workshopaws-samples/sample-amazon-bedrock-agentcore-onboarding133—~1.5kAutomated safety check: NotesMIT-0
Nx Plugin For AWSawslabs/nx-plugin-for-aws152—~3.6kAutomated safety check: PassApache-2.0

Similar skills

  • AWS Native Runtime Investigation

    pulumi/pulumi-aws-native

    Official

    Use after triage or repository evidence establishes that an issue involves Pulumi AWS Native runtime behavior across the Pulumi provider protocol, generated CloudFormation metadata, and AWS Cloud…

    108 GitHub stars~753 tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • New Resource

    mondoohq/mql

    Add or change a resource in an existing mql provider — schema, codegen, implementation, tests, and verification against a real target.

    412 GitHub stars~5.6k tokensUpdated today
    DevelopmentAuto-check passed
  • PR Review

    aws/aws-cdk-cli

    Official

    AWS CDK CLI general PR reviewer. An agent skill from aws/aws-cdk-cli.

    107 GitHub stars~2k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Scaffold Workshop

    aws-samples/sample-amazon-bedrock-agentcore-onboarding

    Official

    Scaffold and draft a new AgentCore workshop. An agent skill from aws-samples/sample-amazon-bedrock-agentcore-onboarding.

    133 GitHub stars~1.5k tokensUpdated 9 days ago
    DevelopmentAuto-check: notes
  • Nx Plugin For AWS

    awslabs/nx-plugin-for-aws

    Official

    Scaffold and build cloud-native applications on AWS using @aws/nx-plugin generators.

    152 GitHub stars~3.6k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • Codegen

    s3s-project/s3s

    Change generated code in this repository. An agent skill from s3s-project/s3s.

    311 GitHub stars~726 tokensUpdated 2 days ago
    DevelopmentAuto-check passed

More from go-to-k/cdkd

All 14 skills in this repo
  • Hunt Bugs

    go-to-k/cdkd

    Proactively hunt for cdkd bugs by deploying real CDK apps that exercise common-but-untested AWS resources, configs, and CloudFormation notations against real AWS, then fix what breaks.

    146 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Use Cdkd

    go-to-k/cdkd

    Build the current cdkd checkout and use it from another CDK project.

    146 GitHub stars~669 tokensUpdated today
    Auto-check passed
  • Verify PR

    go-to-k/cdkd

    Comprehensive PR readiness check before merge. An agent skill from go-to-k/cdkd.

    146 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Work Issues

    go-to-k/cdkd

    Work through already-filed GitHub issues (typically the bug-hunt's output) end to end — triage safely, pick as many FILE-DISJOINT issues as the run can carry, claim each on the issue before starting…

    146 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Cdkd

    go-to-k/cdkd

    Install cdkd and use it safely from an AWS CDK project. An agent skill from go-to-k/cdkd.

    146 GitHub stars~7k tokensUpdated today
    Auto-check: notes
  • Run Integ

    go-to-k/cdkd

    Run integration tests (deploy + destroy) against real AWS. An agent skill from go-to-k/cdkd.

    146 GitHub stars~5.8k tokensUpdated today
    Auto-check passed

Questions about New Provider

What does New Provider do?

Scaffold a new SDK Provider for a given AWS resource type (e.g., AWS::SES::EmailIdentity). New Provider is an agent skill from go-to-k/cdkd., AWS::SES::EmailIdentity).

When should I use New Provider?

New Provider fits situations like: tasks that involve Project scaffolding.

How do I install New Provider in Claude Code?

Run `npx skills add go-to-k/cdkd --skill new-provider -a claude-code`. Or copy the skill folder (.claude/skills/new-provider in go-to-k/cdkd) into .claude/skills/new-provider in your project. Claude Code loads it when a task matches its description.

How do I install New Provider in Codex?

Run `npx skills add go-to-k/cdkd --skill new-provider -a codex`. Or copy the skill folder (.claude/skills/new-provider in go-to-k/cdkd) into .agents/skills/new-provider in your project. Codex loads it when a task matches its description.

Can I use New Provider in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add go-to-k/cdkd --skill new-provider -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/new-provider, .gemini/skills/new-provider, .github/skills/new-provider and .opencode/skills/new-provider in your project.

What does New Provider need to run?

Going by SKILL.md and its folder, New Provider needs the command-line tools its instructions call (pnpm).

Does New Provider access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is New Provider safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does New Provider use?

New Provider is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does New Provider use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to New Provider?

Skills that share tags, products or a category with New Provider: AWS Native Runtime Investigation (pulumi/pulumi-aws-native, 108 stars), New Resource (mondoohq/mql, 412 stars), PR Review (aws/aws-cdk-cli, 107 stars) and Scaffold Workshop (aws-samples/sample-amazon-bedrock-agentcore-onboarding, 133 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains New Provider?

go-to-k (a GitHub user) maintains it in go-to-k/cdkd, which has 146 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 10, 2026.

Source: go-to-k/cdkd on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.