Agent skill

Caveman Gateway Setup

by JuliusBrussee in JuliusBrussee/caveman

Routes every LLM call in a repository through the Caveman Cloud gateway in record mode, so requests and costs are measured without changing behavior.

Apache-2.0Auto-check: warningsDevOps & Cloud

Install Caveman Gateway Setup

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add JuliusBrussee/caveman --skill caveman-setup -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install JuliusBrussee/caveman caveman-setup --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/JuliusBrussee/caveman.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/caveman-setup .claude/skills/caveman-setup && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
caveman-setup
GitHub stars
111k
Used in
1 other repo
Token cost
~2.6k tokens
SKILL.md length
1,080 words
Files
1
Skills in repo
18
Repo updated
First seen
Licence
Apache-2.0

At a glance

Routes every LLM call in a repository through the Caveman Cloud gateway in record mode, so requests and costs are measured without changing behavior.

  • Works in 5 steps: Find every live LLM callsite → Pick the app slug → Wire each callsite → …
  • Adding spend observability for LLM calls to an existing codebase
  • SKILL.md covers Rules (non-negotiable), Step 1 — Find every live LLM…, Step 2 — Pick the app slug and Step 3 — Wire each callsite, plus 3 more sections
  • Calls curl; reaches gateway.caveman.so; needs CAVE_API_KEY and PROVIDER_KEY

What it does

The agent integrates a repo with the Caveman gateway, a byte-preserving LLM proxy that in record mode measures what the app sends and what it costs, and changes nothing else. It needs four values from the prompt that started it: the gateway URL, an API key for the gateway, whether provider keys are stored in Caveman Cloud or sent per request, and the dashboard URL. If any is missing, it stops and asks, and it never guesses a URL or mints a key.

The rules call for a minimal, verified integration. The agent finds every live LLM callsite by reading dependency files and searching for SDK imports and raw HTTP calls to provider APIs, wires each through existing configuration, keeps the gateway key in the repo's env file, adding that file to .gitignore if needed, and never touches provider keys. The final report states the HTTP status and usage numbers from a real verification call. It enables no optimization and claims no savings.

When your agent uses it

  • Adding spend observability for LLM calls to an existing codebase
  • Setting up Caveman Cloud for a repository
  • Finding all the LLM callsites in a project and routing them through a gateway

Example prompts

  • “Set up caveman for this repo using the gateway URL and key I give you.”
  • “Add LLM spend observability to our Node service without changing how it behaves.”
  • “Find every place we call OpenAI or Anthropic and route it through the Caveman gateway.”

Requirements

  • A Caveman gateway URL, gateway API key and dashboard URL
  • Network access to the gateway

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Find every live LLM callsite
  2. Pick the app slug
  3. Wire each callsite
  4. Verify with one real request
  5. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 2e08b91. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • gateway.caveman.so

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CAVE_API_KEY
    • PROVIDER_KEY
    • OPENAI_API_KEY
    • ANTHROPIC_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Caveman Gateway Setup loads about 2.6k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 1,080 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • NoteMentions a .env fileSKILL.md:30
    already uses (`.env`, `.env.local`, …). If that file isn't gitignored, add it
  • WarningTells the agent its actions are pre-authorized / not to stop for confirmationSKILL.md:147
    verification request. Send it now — do not pause to ask permission for it.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from JuliusBrussee/caveman at commit 2e08b91, republished under its Apache-2.0 licence (© JuliusBrussee). 1,080 words, ~2,609 tokens.

Download SKILL.mdSave it as .claude/skills/caveman-setup/SKILL.md (or your agent's skills folder).
name
caveman-setup
description
Wire a repository through the Caveman Cloud gateway so every LLM request is measured, with no behavior change. Use for "set up caveman" or adding LLM spend observability.

You are wiring this repository through the Caveman gateway. Caveman is a byte-preserving LLM proxy: in record mode it measures what your app sends and what it costs, and changes nothing else. Your job is a minimal, verified integration — not a refactor.

The prompt that sent you here provides four values. Refer to them as:

  • GATEWAY — the gateway base URL (e.g. https://gateway.caveman.so or http://127.0.0.1:8787)
  • CAVE_API_KEY — the gateway auth secret (treat like any API key: env var only, never committed, never printed in full)
  • PROVIDER_KEYS — stored (provider keys live encrypted in Caveman Cloud) or byok (this app sends its own provider key per request)
  • DASHBOARD — the dashboard base URL (e.g. https://app.caveman.so)

If any value is missing, stop and ask for it. Do not guess a URL or mint a key.

Rules (non-negotiable)

  1. Coherent integration. Wire every live LLM callsite through existing configuration and responsible seams. Touch each layer correctness requires. No drive-by refactors or formatting sweeps; add an abstraction only when it clarifies ownership or lowers lifecycle cost.
  2. Secrets stay in env vars. CAVE_API_KEY goes into the env file the repo already uses (.env, .env.local, …). If that file isn't gitignored, add it to .gitignore and say so. Never hardcode the key in source.
  3. Report only what you observed. The final report states the HTTP status and usage numbers from the real verification response — never assumed success. If verification fails, report the failure template instead.
  4. Record mode only. You are adding measurement. You do not enable any optimization, and you do not claim any savings — verified savings are $0 until an optimizer is explicitly turned on and passes its eval gate.
  5. Provider keys are not your business. With PROVIDER_KEYS: stored you never see one. With byok, the app's existing provider key stays exactly where it already is.

Step 1 — Find every live LLM callsite

Read dependency files (package.json, requirements.txt, pyproject.toml, go.mod, lockfiles) and search the source for LLM clients:

  • SDK imports: openai, @anthropic-ai/sdk, anthropic, ai + @ai-sdk/* (Vercel), langchain*, litellm, google-genai / @google/genai, crewai, pydantic_ai, openai-agents / agents
  • Raw HTTP to api.openai.com, api.anthropic.com, generativelanguage.googleapis.com
  • Existing base-URL env vars: OPENAI_BASE_URL, OPENAI_API_BASE, ANTHROPIC_BASE_URL, GEMINI_BASE_URL, GOOGLE_GEMINI_BASE_URL

List what you found (file:line per callsite) before changing anything. If you find no LLM callsites, stop and report the "nothing to wire" template at the end of this file — do not invent an integration.

Step 2 — Pick the app slug

One slug names this app in the gateway path: GATEWAY/w/<app>. Derive it from the package/module name (e.g. support-bot, acme-api). Grammar: lowercase [a-z0-9] first, then [a-z0-9._-], max 64 chars. Spend for this whole app groups under that slug on the dashboard.

Step 3 — Wire each callsite

The pattern is always the same: base URL → the gateway with /w/<app>, plus one auth header. Gateway auth is x-cave-api-key: CAVE_API_KEY (Authorization: Bearer CAVE_API_KEY also works where a header is awkward). With PROVIDER_KEYS: byok, also send x-cave-upstream-key: <the provider key the app already uses>.

Two facts that make the wiring safe (both are gateway-enforced, not hopes): the gateway rebuilds upstream auth headers from scratch, so a client's Authorization/x-api-key value is never forwarded to the provider; and with stored, upstream auth comes from the encrypted connection server-side. So in stored mode, where an SDK insists on an api-key parameter, set it to the Cave key — it authenticates the gateway and goes no further.

Exact shapes (use the one matching each callsite — these are the product's published recipes, not suggestions):

OpenAI SDK (TS) — Chat Completions and Responses both route through:

ts
const client = new OpenAI({
  baseURL: `${process.env.CAVE_GATEWAY_URL}/w/<app>/openai/v1`,
  apiKey: process.env.OPENAI_API_KEY,           // byok: unchanged · stored: use CAVE_API_KEY
  defaultHeaders: {
    "x-cave-api-key": process.env.CAVE_API_KEY!,
    // byok only:
    "x-cave-upstream-key": process.env.OPENAI_API_KEY!,
  },
});

OpenAI SDK (Python) — same shape: base_url=f"{gw}/w/<app>/openai/v1", default_headers={"x-cave-api-key": ..., "x-cave-upstream-key": ...}.

Anthropic SDK (TS/Python) — the SDK appends /v1/messages itself. The x-cave-api-key header is required here in both modes (this SDK's own key param rides x-api-key, which is not a gateway-auth header):

python
client = anthropic.Anthropic(
    base_url=f"{os.environ['CAVE_GATEWAY_URL']}/w/<app>",
    api_key=os.environ["ANTHROPIC_API_KEY"],      # byok: unchanged · stored: use CAVE_API_KEY
    default_headers={
        "x-cave-api-key": os.environ["CAVE_API_KEY"],
        # byok only:
        "x-cave-upstream-key": os.environ["ANTHROPIC_API_KEY"],
    },
)

Vercel AI SDK — createOpenAICompatible({ baseURL: ${gw}/w/<app>/openai/v1, headers: { "x-cave-api-key": ... } }); Anthropic models via createAnthropic({ baseURL: ${gw}/w/<app>/v1, headers: { ... } }).

LangChain / LangGraph — ChatOpenAI(base_url=f"{gw}/w/<app>/openai/v1", default_headers={...}); ChatAnthropic(base_url=f"{gw}/w/<app>", default_headers={...}). LangGraph inherits whatever model you pass it.

LiteLLM — per call api_base=f"{gw}/w/<app>/openai/v1" + extra_headers={...}, or fleet-wide in the LiteLLM proxy config.yaml.

Raw HTTP / anything else — swap the host, keep the provider's native path: GATEWAY/w/<app>/v1/chat/completions (OpenAI protocol) or GATEWAY/w/<app>/v1/messages (Anthropic protocol), add the header(s).

Concretely, with slug support-bot and the hosted gateway, an OpenAI-SDK base URL reads https://gateway.caveman.so/w/support-bot/openai/v1. And in stored mode, drop every x-cave-upstream-key line entirely — it is byok-only.

For frameworks not listed (google-genai, crewai, pydantic-ai, openai-agents), fetch the matching page under <docs origin>/docs/integrations/ — same origin this skill came from — and follow it.

Add to the repo's env file (and reference from code — no literals):

CAVE_GATEWAY_URL=<GATEWAY>
CAVE_API_KEY=<CAVE_API_KEY>
Show full SKILL.md (341 more words)Show less

Step 4 — Verify with one real request

The user pasted the setup prompt to authorize exactly this: one small verification request. Send it now — do not pause to ask permission for it. An integration that ends unverified because you hesitated is a worse outcome than one tiny request; finishing the verification and the report autonomously is the point of this skill.

Send one minimal request through the wiring you just built — the app's own cheapest path if it has a script for it, otherwise curl on the path matching the protocol you just wired with the app's own model and a small cap (max_tokens ≤ 32):

bash
# OpenAI-protocol wiring:
curl -sS "$CAVE_GATEWAY_URL/w/<app>/v1/chat/completions" \
  -H "x-cave-api-key: $CAVE_API_KEY" \
  -H "content-type: application/json" \
  -d '{"model":"<model the repo already uses>","max_tokens":16,"messages":[{"role":"user","content":"ping"}]}'

# Anthropic-protocol wiring:
curl -sS "$CAVE_GATEWAY_URL/w/<app>/v1/messages" \
  -H "x-cave-api-key: $CAVE_API_KEY" \
  -H "anthropic-version: 2023-06-01" \
  -H "content-type: application/json" \
  -d '{"model":"<model the repo already uses>","max_tokens":16,"messages":[{"role":"user","content":"ping"}]}'

(byok: add -H "x-cave-upstream-key: $PROVIDER_KEY".) This is one real, billable provider request — that is the point: real traffic, real measurement.

Read the response. Success = HTTP 200 with a usage block. Anything else = the matching failure template below.

Step 5 — Report

End with exactly this shape, values filled from what you actually did and saw:

## Caveman is live in this repo

Wired: <n> callsite(s) in <n> file(s)
  - <file> — <one-line what changed>
App slug: <app> — spend for this app groups under it
Verified: HTTP 200 · model <model> · <in> in / <out> out tokens (one real request)
Mode: record — measured only. No model-visible bytes changed, no optimization
enabled. Verified savings are $0 until you turn an optimizer on and it passes
its eval gate. That honesty is the product.

See the dollars: <DASHBOARD>/traces — your request is the top row, priced from
the public catalog. <DASHBOARD>/getting-started flips to "First request received."

Want spend split by workflow (e.g. support-reply vs nightly-digest), not just
by app? Say "discover workflows" — I'll fetch <docs origin>/docs/discover-workflows.md
and label every callsite by the job it does.

Failure templates (use verbatim, filled in — never soften)

  • Nothing to wire: "I found no LLM callsites in this repo (searched SDKs, raw provider HTTP, base-URL env vars). If this repo runs a coding agent rather than shipping LLM code, use caveman wrap <agent> instead — see <DASHBOARD>/getting-started."
  • Gateway unreachable: "The verification request could not reach GATEWAY (<error>). Wiring is in place but unverified — nothing will be measured until the gateway is reachable. Check the URL and network, then re-run the verification curl above."
  • 401 cave_invalid_api_key: "The gateway rejected CAVE_API_KEY. Mint a new key at <DASHBOARD>/getting-started and update the env file; the wiring itself is unchanged."
  • 404 cave_route_not_found: "The gateway matched no route — usually a malformed /w/<app> slug (lowercase [a-z0-9] first, then [a-z0-9._-], max 64) or a path that doesn't match the SDK's protocol. Fix the URL and re-verify."
  • Provider error (4xx/5xx via gateway): report status + body verbatim; the gateway is reachable and auth passed, the upstream call failed — usually a provider key or model-name issue in the app itself.

Never report success on any of these. An unverified integration is reported as unverified.

© JuliusBrussee, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/caveman-setup of JuliusBrussee/caveman.

Open the folder on GitHubat commit 2e08b91

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in JuliusBrussee/caveman, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Caveman Gateway Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Caveman Gateway Setup compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Caveman Gateway Setup this skillJuliusBrussee/caveman111k1 repos~2.6kAutomated safety check: WarnApache-2.0
Sentry Instrumentgetsentry/sentry-for-ai268—~3.2kAutomated safety check: PassApache-2.0
App Observabilitygrafana/skills281—~1.8kAutomated safety check: PassApache-2.0
Ag2 Telemetryag2ai/build-with-ag2252—~1.9kAutomated safety check: PassApache-2.0
Monitoring Observabilityyonatangross/orchestkit290—~2.2kAutomated safety check: PassMIT
AI Observabilityomer-metin/skills-for-antigravity162—~578Automated safety check: PassApache-2.0

Similar skills

  • Sentry Instrument

    getsentry/sentry-for-ai

    Official

    Instrument an application with Sentry — detect the platform, install and initialize the SDK if needed, and wire up any signal — error monitoring, tracing/performance, logging, metrics, profiling…

    268 GitHub stars~3.2k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • App Observability

    grafana/skills

    Official

    Get RED metrics + service maps + frontend RUM + AI/LLM monitoring out of Grafana Cloud — Application Observability (tracesspanmetrics from OTel traces, p50/p95/p99 latency, exemplar-to-trace…

    281 GitHub stars~1.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Ag2 Telemetry

    ag2ai/build-with-ag2

    Add OpenTelemetry traces to an AG2 beta Agent via TelemetryMiddleware (autogen.beta.middleware.builtin).

    252 GitHub stars~1.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Monitoring Observability

    yonatangross/orchestkit

    Monitoring and observability patterns for Prometheus metrics, Grafana dashboards, Langfuse v4 LLM tracing (astype, scorecurrentspan, shouldexportspan, LangfuseMedia), and drift detection.

    290 GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • AI Observability

    omer-metin/skills-for-antigravity

    Implement comprehensive observability for LLM applications including tracing (Langfuse/Helicone), cost tracking, token optimization, RAG evaluation metrics (RAGAS), hallucination detection, and…

    162 GitHub stars~578 tokensUpdated 8 mo ago
    AI & LLM EngineeringAuto-check passed
  • Failproof AI SDK Integration

    FailproofAI/failproofai

    Helps instrument a custom Python or TypeScript agent to record events for Failproof AI, verify what gets written, and run an evaluator worker that scores the runs.

    5.3k GitHub stars~6k tokensUpdated 2 days ago
    AI & LLM EngineeringAuto-check passed

More from JuliusBrussee/caveman

All 18 skills in this repo
  • Caveman Workflow Labeler

    JuliusBrussee/caveman

    Finds every LLM workflow in a repository, proposes a labeling table and, once you agree, wires labels so Caveman Cloud groups spend per workflow.

    111k GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Caveman Evidence Review

    JuliusBrussee/caveman

    Read-only review of Caveman Cloud data to explain where LLM spend goes: cost, score, workflows, traces, latency, errors, routing and verified savings.

    111k GitHub starsUsed in 1 repo~927 tokens
    Auto-check passed
  • Caveman Experiment Manager

    JuliusBrussee/caveman

    Reads the state and results of Caveman Cloud experiments and reports one recommendation or a block, without changing an experiment's lifecycle itself.

    111k GitHub starsUsed in 1 repo~975 tokens
    Auto-check passed
  • Caveman Optimization Evaluator

    JuliusBrussee/caveman

    Turns a Caveman report-only optimization observation into one minimal code change and a paired baseline evaluation, after the operator picks which to pursue.

    111k GitHub starsUsed in 1 repo~1.2k tokens
    Auto-check passed
  • Caveman Help Card

    JuliusBrussee/caveman

    Quick-reference card for the three caveman skills and their commands. Trigger: /caveman-help or "caveman help".

    111k GitHub stars~690 tokensUpdated yesterday
    Auto-check passed
  • Caveman Mode

    JuliusBrussee/caveman

    Switches the agent to a terse reply style that gives the answer first, drops filler, and keeps every technical fact, command and number exact.

    111k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Questions about Caveman Gateway Setup

What does Caveman Gateway Setup do?

Routes every LLM call in a repository through the Caveman Cloud gateway in record mode, so requests and costs are measured without changing behavior. The agent integrates a repo with the Caveman gateway, a byte-preserving LLM proxy that in record mode measures what the app sends and what it costs, and changes nothing else. It needs four values from the prompt that started it: the gateway URL, an API key for the gateway, whether provider keys are stored in Caveman Cloud or sent per request, and the dashboard URL.

When should I use Caveman Gateway Setup?

Caveman Gateway Setup fits situations like: adding spend observability for LLM calls to an existing codebase; setting up Caveman Cloud for a repository; finding all the LLM callsites in a project and routing them through a gateway.

How do I install Caveman Gateway Setup in Claude Code?

Run `npx skills add JuliusBrussee/caveman --skill caveman-setup -a claude-code`. Or copy the skill folder (skills/caveman-setup in JuliusBrussee/caveman) into .claude/skills/caveman-setup in your project. Claude Code loads it when a task matches its description.

How do I install Caveman Gateway Setup in Codex?

Run `npx skills add JuliusBrussee/caveman --skill caveman-setup -a codex`. Or copy the skill folder (skills/caveman-setup in JuliusBrussee/caveman) into .agents/skills/caveman-setup in your project. Codex loads it when a task matches its description.

Can I use Caveman Gateway Setup in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add JuliusBrussee/caveman --skill caveman-setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/caveman-setup, .gemini/skills/caveman-setup, .github/skills/caveman-setup and .opencode/skills/caveman-setup in your project.

What does Caveman Gateway Setup need to run?

Going by SKILL.md and its folder, Caveman Gateway Setup needs the command-line tools its instructions call (curl) and credentials named CAVE_API_KEY, PROVIDER_KEY, OPENAI_API_KEY and ANTHROPIC_API_KEY. Our summary lists: A Caveman gateway URL, gateway API key and dashboard URL; Network access to the gateway.

Does Caveman Gateway Setup access the network?

SKILL.md names 1 domain. In commands or code: gateway.caveman.so; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Caveman Gateway Setup safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): tells the agent its actions are pre-authorized / not to stop for confirmation. Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Caveman Gateway Setup use?

Caveman Gateway Setup is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Caveman Gateway Setup use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Caveman Gateway Setup?

Skills that share tags, products or a category with Caveman Gateway Setup: Sentry Instrument (getsentry/sentry-for-ai, 268 stars), App Observability (grafana/skills, 281 stars), Ag2 Telemetry (ag2ai/build-with-ag2, 252 stars) and Monitoring Observability (yonatangross/orchestkit, 290 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Caveman Gateway Setup?

JuliusBrussee (a GitHub user) maintains it in JuliusBrussee/caveman, which has 110,632 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 8, 2026.

Source: JuliusBrussee/caveman on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.