OpenROAD Issue Triage
The-OpenROAD-Project/OpenROAD
Reproduces an OpenROAD GitHub bug from an attached tarball and shrinks the failing design with whittle.py so maintainers get a minimal test case.
Practical Python scripts for debugging awf - parse logs, diagnose issues, inspect containers, test domains
$ npx skills add github/gh-aw-firewall --skill awf-debug-tools -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install github/gh-aw-firewall awf-debug-tools --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/awf-debug-tools .claude/skills/awf-debug-tools && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "awf-debug-tools" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.claude/skills/awf-debug-tools into .claude/skills/awf-debug-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "awf-debug-tools", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/github/gh-aw-firewall/tree/main/.claude/skills/awf-debug-toolsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add github/gh-aw-firewall --skill awf-debug-tools -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install github/gh-aw-firewall awf-debug-tools --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/awf-debug-tools .agents/skills/awf-debug-tools && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "awf-debug-tools" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.claude/skills/awf-debug-tools into .agents/skills/awf-debug-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "awf-debug-tools", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add github/gh-aw-firewall --skill awf-debug-tools -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install github/gh-aw-firewall awf-debug-tools --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/awf-debug-tools .cursor/skills/awf-debug-tools && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "awf-debug-tools" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.claude/skills/awf-debug-tools into .cursor/skills/awf-debug-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "awf-debug-tools", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/github/gh-aw-firewall.git --path .claude/skills/awf-debug-tools--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add github/gh-aw-firewall --skill awf-debug-tools -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install github/gh-aw-firewall awf-debug-tools --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/awf-debug-tools .gemini/skills/awf-debug-tools && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "awf-debug-tools" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.claude/skills/awf-debug-tools into .gemini/skills/awf-debug-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "awf-debug-tools", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install github/gh-aw-firewall awf-debug-toolsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add github/gh-aw-firewall --skill awf-debug-tools -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/awf-debug-tools .github/skills/awf-debug-tools && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "awf-debug-tools" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.claude/skills/awf-debug-tools into .github/skills/awf-debug-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "awf-debug-tools", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add github/gh-aw-firewall --skill awf-debug-tools -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install github/gh-aw-firewall awf-debug-tools --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/awf-debug-tools .opencode/skills/awf-debug-tools && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "awf-debug-tools" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.claude/skills/awf-debug-tools into .opencode/skills/awf-debug-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "awf-debug-tools", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
awf-debug-toolsPractical Python scripts for debugging awf - parse logs, diagnose issues, inspect containers, test domains
Awf Debug Tools is an agent skill from github/gh-aw-firewall, published by the product's own GitHub organization. Practical Python scripts for debugging awf - parse logs, diagnose issues, inspect containers, test domains
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts (for example `scripts/common.py`, `scripts/diagnose-awf.py` and `scripts/inspect-containers.py`).
It sits in Development, covering Debugging. It works with Python, GitHub and Docker. The repository describes itself as: GitHub Agentic Workflows Firewall. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 681e932. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
Bash(python:*)Bash(docker:*)Bash(sudo:*)ReadFrom allowed-tools in the SKILL.md frontmatter.
Ships 6 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
pythonjqpipFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Awf Debug Tools loads about 2.6k tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 696 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
sudo awf --allow-domains github.com,npmjs.org 'your-command'# Squid logs require sudo to readsudo python .claude/skills/awf-debug-tools/scripts/parse-squid-logs.py --log-file /tmp/squid-logs-*/access.logsudo awf --allow-domains github.com 'curl https://api.github.com'Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from github/gh-aw-firewall at commit 681e932, republished under its MIT licence (© github). 696 words, ~2,590 tokens.
.claude/skills/awf-debug-tools/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.A collection of practical Python scripts that help agents efficiently debug and operate the awf firewall. These scripts reduce verbose Docker/log output by 80%+ and provide actionable insights instead of raw data dumps.
Problem: Docker commands and log files are verbose and hard for agents to parse. Diagnosing issues requires 10+ manual commands and produces noisy output that wastes tokens.
Solution: One script replaces 5-10 manual commands with clean, filtered output optimized for agent consumption. All scripts support JSON format for easy parsing.
All scripts are located in .claude/skills/awf-debug-tools/scripts/:
# Auto-discover logs and show all domains
python .claude/skills/awf-debug-tools/scripts/parse-squid-logs.py
# Show only blocked domains
python .claude/skills/awf-debug-tools/scripts/parse-squid-logs.py --blocked-only
# Filter by domain
python .claude/skills/awf-debug-tools/scripts/parse-squid-logs.py --domain github.com
# Show top 10, JSON output
python .claude/skills/awf-debug-tools/scripts/parse-squid-logs.py --top 10 --format json# Quick health check
python .claude/skills/awf-debug-tools/scripts/diagnose-awf.py
# Detailed output
python .claude/skills/awf-debug-tools/scripts/diagnose-awf.py --verbose
# JSON output for agent parsing
python .claude/skills/awf-debug-tools/scripts/diagnose-awf.py --format json# Inspect all containers
python .claude/skills/awf-debug-tools/scripts/inspect-containers.py
# Specific container only
python .claude/skills/awf-debug-tools/scripts/inspect-containers.py --container awf-squid
# Show only logs
python .claude/skills/awf-debug-tools/scripts/inspect-containers.py --logs-only
# JSON output
python .claude/skills/awf-debug-tools/scripts/inspect-containers.py --format json# Test if domain is allowed
python .claude/skills/awf-debug-tools/scripts/test-domain.py github.com
# Test blocked domain with fix suggestion
python .claude/skills/awf-debug-tools/scripts/test-domain.py npmjs.org --suggest-fix
# Check allowlist only (no log lookup)
python .claude/skills/awf-debug-tools/scripts/test-domain.py api.github.com --check-allowlist
# JSON output
python .claude/skills/awf-debug-tools/scripts/test-domain.py github.com --format jsonWhen a command fails due to blocked domain:
# 1. Run diagnostics to check overall health
python .claude/skills/awf-debug-tools/scripts/diagnose-awf.py
# 2. Parse logs to find which domains were blocked
python .claude/skills/awf-debug-tools/scripts/parse-squid-logs.py --blocked-only
# 3. Test specific domain and get fix suggestion
python .claude/skills/awf-debug-tools/scripts/test-domain.py npmjs.org --suggest-fix
# 4. Apply the suggested fix
sudo awf --allow-domains github.com,npmjs.org 'your-command'When containers aren't starting or behaving unexpectedly:
# 1. Check container status and recent logs
python .claude/skills/awf-debug-tools/scripts/inspect-containers.py
# 2. Run full diagnostics
python .claude/skills/awf-debug-tools/scripts/diagnose-awf.py --verbose
# 3. If issues found, check Squid logs for errors
python .claude/skills/awf-debug-tools/scripts/parse-squid-logs.pyFor agents to diagnose issues without human intervention:
# Run all checks with JSON output
python .claude/skills/awf-debug-tools/scripts/diagnose-awf.py --format json | jq .
# Parse blocked domains
python .claude/skills/awf-debug-tools/scripts/parse-squid-logs.py --blocked-only --format json | jq .
# Test each blocked domain
python .claude/skills/awf-debug-tools/scripts/test-domain.py npmjs.org --format json | jq .All scripts support two output formats:
Use --format json to get structured output that's easy to parse programmatically.
All scripts use consistent exit codes:
All scripts use Python 3.8+ stdlib only. No pip install required. They work out of the box on any system with Python 3.8+.
Purpose: Extract blocked domains from Squid logs with counts and statistics.
Key Options:
--blocked-only - Show only blocked domains--domain DOMAIN - Filter by specific domain--top N - Show top N domains by request count--format {table,json} - Output formatAuto-discovers logs from running containers, preserved logs, or work directories.
Purpose: Run automated diagnostic checks and report issues with fixes.
Checks:
Key Options:
--verbose - Show detailed check output--format {text,json} - Output formatPurpose: Show concise container status without verbose docker output.
Shows:
Key Options:
--container NAME - Inspect specific container only--logs-only - Show only recent logs--tail N - Number of log lines (default: 5)--format {text,json} - Output formatPurpose: Test if domain is reachable through the firewall.
Checks:
Key Options:
--check-allowlist - Only check allowlist, don't check logs--suggest-fix - Show suggested --allow-domains flag--format {text,json} - Output formatdebug-firewall skillawf-mcp-gateway skilldocs/troubleshooting.mdAll scripts are designed for fast execution:
parse-squid-logs.py: <2 seconds for typical log filesdiagnose-awf.py: <3 seconds for all checksinspect-containers.py: <2 seconds for both containerstest-domain.py: <1 second for domain check$ python .claude/skills/awf-debug-tools/scripts/parse-squid-logs.py --blocked-only
Blocked Domains (sorted by count):
Domain Blocked Allowed Total
=================================================
registry.npmjs.org 45 0 45
example.com 12 0 12
Total requests: 1234
Blocked: 57 (4.6%)
Allowed: 1177 (95.4%)$ python .claude/skills/awf-debug-tools/scripts/diagnose-awf.py
AWF Diagnostic Report
========================================
[✓] Containers: awf-squid (running), awf-agent (exited:0)
[✓] Health: Squid healthy
[✓] Network: awf-net exists ([{Subnet:172.30.0.0/24 Gateway:172.30.0.1}])
[✓] Connectivity: Squid reachable on 172.30.0.10:3128
[✓] DNS: DNS servers: 127.0.0.11, 8.8.8.8, 8.8.4.4
[✓] Config: 3 domains in allowlist (github.com, .github.com, api.github.com)
Summary: All checks passed ✓$ python .claude/skills/awf-debug-tools/scripts/test-domain.py npmjs.org --suggest-fix
Testing: npmjs.org
[✗] Allowlist check: Not in allowlist
[✗] Reachability: Blocked (403 TCP_DENIED:HIER_NONE)
[✗] Status: BLOCKED
Suggested fix:
awf --allow-domains github.com,npmjs.org 'your-command'--format json | jq .Script not found:
# Use absolute path
python /home/mossaka/developer/gh-aw-repos/gh-aw-firewall/.claude/skills/awf-debug-tools/scripts/parse-squid-logs.pyPermission denied on logs:
# Squid logs require sudo to read
sudo python .claude/skills/awf-debug-tools/scripts/parse-squid-logs.py --log-file /tmp/squid-logs-*/access.logNo logs found:
# Run awf first to generate logs
sudo awf --allow-domains github.com 'curl https://api.github.com'
# Then parse
python .claude/skills/awf-debug-tools/scripts/parse-squid-logs.pyPlanned scripts for future versions:
analyze-traffic.py - Analyze traffic patterns over timegenerate-allowlist.py - Auto-generate allowlist from logscleanup-awf.py - Clean up orphaned resourcesbenchmark-awf.py - Performance testing utilitiesIf you are diagnosing a failure rather than exploring, enter through the
diagnose-awf skill and the canonical diagnosis registry in
docs/diagnostics/README.md. This skill is one of the
specialist references it routes to.
© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (scripts) in .claude/skills/awf-debug-tools of github/gh-aw-firewall.
Open the folder on GitHubat commit 681e932
Awf Debug Tools next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Awf Debug Tools this skillgithub/gh-aw-firewall | 148 | — | ~2.6k | Automated safety check: Notes | MIT | |
| OpenROAD Issue TriageThe-OpenROAD-Project/OpenROAD | 3.2k | — | ~842 | Automated safety check: Pass | BSD-3-Clause | |
| Burla Parallel Dev ClustersBurla-Cloud/burla | 263 | — | ~1.6k | Automated safety check: Pass | Custom licence | |
| Zizkadb Dev SetupZIZKA-AI-SL/ZizkaDB | 124 | — | ~535 | Automated safety check: Notes | Custom licence | |
| Debug Sessionai-dynamo/dynamo | 8.2k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Burla Internals Deep DiveBurla-Cloud/burla | 263 | — | ~2.4k | Automated safety check: Pass | Custom licence |
The-OpenROAD-Project/OpenROAD
Reproduces an OpenROAD GitHub bug from an attached tarball and shrinks the failing design with whittle.py so maintainers get a minimal test case.
Burla-Cloud/burla
Sets up an isolated Burla dev cluster per git worktree so several agents can work in parallel, and explains when to use local-dev or remote-dev.
ZIZKA-AI-SL/ZizkaDB
Set up and start the local ZizkaDB development stack. An agent skill from ZIZKA-AI-SL/ZizkaDB.
ai-dynamo/dynamo
Sets up a structured debugging session for a Dynamo bug — pull the report from a Linear ticket, GitHub issue, or pasted text, capture the environment, create a persistent worklog markdown file, and…
Burla-Cloud/burla
Reference for Burla internals: how a remote_parallel_map job flows between services, how clusters and nodes are managed, and where the head keeps its state.
Edwardvaneechoud/Flowfile
Catalog of Flowfile's environment variables and runtime flags: what each does, where the code reads it, its default, and where the docs disagree with the code.
github/gh-aw-firewall
Regenerate and post-process all agentic workflows. An agent skill from github/gh-aw-firewall.
github/gh-aw-firewall
Decide and implement how to support a new LLM provider or agent engine in AWF - either as a proxied provider (api-proxy adapter) or a direct-API engine (domain allowlist only), e.g.
github/gh-aw-firewall
Debug the AWF firewall by inspecting Docker containers (awf-squid, awf-agent), analyzing Squid access logs, checking iptables rules, and troubleshooting blocked domains or network issues.
github/gh-aw-firewall
Debug GitHub Actions workflows by downloading logs, analyzing summaries, and understanding how agentic workflows and the AWF firewall work together.
github/gh-aw-firewall
Diagnose an AWF (Agentic Workflow Firewall) failure from an error, workflow run URL, or symptom.
Categories
Practical Python scripts for debugging awf - parse logs, diagnose issues, inspect containers, test domains. Awf Debug Tools is an agent skill from github/gh-aw-firewall, published by the product's own GitHub organization.
Awf Debug Tools fits situations like: tasks that involve Debugging.
Run `npx skills add github/gh-aw-firewall --skill awf-debug-tools -a claude-code`. Or copy the skill folder (.claude/skills/awf-debug-tools in github/gh-aw-firewall) into .claude/skills/awf-debug-tools in your project. Claude Code loads it when a task matches its description.
Run `npx skills add github/gh-aw-firewall --skill awf-debug-tools -a codex`. Or copy the skill folder (.claude/skills/awf-debug-tools in github/gh-aw-firewall) into .agents/skills/awf-debug-tools in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/gh-aw-firewall --skill awf-debug-tools -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/awf-debug-tools, .gemini/skills/awf-debug-tools, .github/skills/awf-debug-tools and .opencode/skills/awf-debug-tools in your project.
Going by SKILL.md and its folder, Awf Debug Tools needs Python for the scripts in its folder and the command-line tools its instructions call (python, jq and pip). Our summary lists: Python 3; Docker. Its frontmatter pre-approves these tools: Bash(python:*), Bash(docker:*), Bash(sudo:*), Read.
SKILL.md names 1 domain. In commands or code: api.github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Awf Debug Tools is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Awf Debug Tools: OpenROAD Issue Triage (The-OpenROAD-Project/OpenROAD, 3.2k stars), Burla Parallel Dev Clusters (Burla-Cloud/burla, 263 stars), Zizkadb Dev Setup (ZIZKA-AI-SL/ZizkaDB, 124 stars) and Debug Session (ai-dynamo/dynamo, 8.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
github (a GitHub organization, an official publisher) maintains it in github/gh-aw-firewall, which has 148 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 7, 2026.
Source: github/gh-aw-firewall on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.