Labsco
Labsco/Repos/github/gh-aw-firewall
REPO PACKAGE

github gh-aw-firewall

OFFICIAL
github · publisher105 repository starsMIT · Freegithub.com/github/gh-aw-firewall
7skills
2ready to use

awf itself runs a command inside a Docker sandbox — a Squid proxy, the agent, and an optional API-proxy sidecar — so outbound HTTP/HTTPS only reaches an allowlisted set of domains. Two of the seven skills are pure guidance: agentic-workflows routes a gh-aw workflow design, debug, or upgrade request to the right prompt, and awf-debug-tools is a set of Python scripts for parsing logs and testing domains. The other five need Docker running locally to do anything: awf-skill itself, two more for debugging the firewall by inspecting containers, Squid logs, and iptables rules, one for debugging GitHub Actions runs generally, one (pr-finisher) that drives a pull request from a GitHub Copilot cloud agent to a mergeable, reviewed state without merging or triggering CI itself, and one that regenerates every compiled workflow file after gh-aw updates.

This is for someone already running, or about to run, awf to sandbox an agent's outbound network access — inside GitHub Actions or on a Linux host with Docker 20.10+ — who wants their own coding agent able to install, debug, and keep the generated workflow files in sync, rather than someone looking for a skill about firewalls in the abstract.

READ THE FULL ANALYSIS

A live warning sits at the top of the README. GitHub retired releases v0.25.21 through v0.25.39 over a billing bug and tells anyone still running one of them to upgrade immediately, which is worth checking before trusting any of these skills to debug or regenerate a setup built on an old version.

2Work with nothing else to set up.
105Stars on the GitHub repository, at last check.