github gh-aw-firewall
OFFICIALLABSCO SUMMARY
awf itself runs a command inside a Docker sandbox — a Squid proxy, the agent, and an optional API-proxy sidecar — so outbound HTTP/HTTPS only reaches an allowlisted set of domains. Two of the seven skills are pure guidance: agentic-workflows routes a gh-aw workflow design, debug, or upgrade request to the right prompt, and awf-debug-tools is a set of Python scripts for parsing logs and testing domains. The other five need Docker running locally to do anything: awf-skill itself, two more for debugging the firewall by inspecting containers, Squid logs, and iptables rules, one for debugging GitHub Actions runs generally, one (pr-finisher) that drives a pull request from a GitHub Copilot cloud agent to a mergeable, reviewed state without merging or triggering CI itself, and one that regenerates every compiled workflow file after gh-aw updates.
This is for someone already running, or about to run, awf to sandbox an agent's outbound network access — inside GitHub Actions or on a Linux host with Docker 20.10+ — who wants their own coding agent able to install, debug, and keep the generated workflow files in sync, rather than someone looking for a skill about firewalls in the abstract.
READ THE FULL ANALYSIS
A live warning sits at the top of the README. GitHub retired releases v0.25.21 through v0.25.39 over a billing bug and tells anyone still running one of them to upgrade immediately, which is worth checking before trusting any of these skills to debug or regenerate a setup built on an old version.
ALSO IN THIS PACKAGE
Agentic Workflows
GitHub Agentic Workflows (gh-aw) - Create, debug, and upgrade AI-powered workflows with intelligent prompt routing.
Interactive Workflow Designer
Interactive wizard that guides users through creating and optimizing agentic workflows for the AWF (Agentic Workflow Firewall) repository
Self-Hosted Runner Doctor
Portable agent for diagnosing AWF (Agentic Workflow Firewall) failures on self-hosted, ARC/DinD, GHEC, and GHES runners. Load this single file into any coding agent and paste your failing workflow log.
technical-doc-writer
AI technical documentation writer for awf library using Astro Starlight
WHAT'S INSIDE
7 showing · 7 totalNothing else to set up — install it and go.
agentic-workflows
Whatever you're trying to do with a GitHub Actions workflow that runs an AI agent — design it, build it, debug it, or update it — this points you to the exact instructions for that job, pulled from GitHub's own workflow documentation set.
awf-debug-tools
Four small scripts that answer the questions you would otherwise chase through pages of container logs when this project's firewall blocks something: which addresses were refused, how often, and whether the firewall itself is healthy.
awf-skill
Give a command, a script or an AI agent a list of the websites it is allowed to reach, and everything else is refused — a way to run code you do not fully trust without it quietly calling somewhere you never approved.
debug-firewall
The by-hand version of firewall troubleshooting: ready-made commands for looking inside the two containers the firewall runs in, reading which traffic they let through and which they refused, and checking the rules on the machine underneath.
debugging-workflows
A build failed on GitHub and the answer is buried somewhere in its log. This pulls down that log and the run's summary, and lists the handful of causes — a missing permission, a timeout, a blocked address — behind most failures.
pr-finisher
Takes an open pull request through the chores left before anyone can merge it — every review comment answered and closed out, the tests passing, conflicts cleared — then stops and tells a person what is still theirs to do.
recompile-workflows
The AI-agent workflows here are written in one file and actually run from a second one generated from it. This regenerates all of them, and applies the follow-up step that is easy to forget — the one that makes the project's tests run against the code in the repository rather than a downloaded copy.
HOW TO GET IT
npx skills add github/gh-aw-firewallnpx skills add github/gh-aw-firewall --skill <name> --full-depthPick the skill name from the Skills tab — each entry there installs independently.