Debugging Local Task Agent Runs
PostHog/posthog
Debug the output of local PostHog task runs — the wizard cloud-run path that executes inside a Docker sandbox under the local Temporal process-task workflow (the wizard that integrates PostHog, then…
Debug the AWF firewall by inspecting Docker containers (awf-squid, awf-agent), analyzing Squid access logs, checking iptables rules, and troubleshooting blocked domains or network issues.
$ npx skills add github/gh-aw-firewall --skill debug-firewall -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install github/gh-aw-firewall debug-firewall --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/debug-firewall .claude/skills/debug-firewall && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "debug-firewall" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.claude/skills/debug-firewall into .claude/skills/debug-firewall/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "debug-firewall", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/github/gh-aw-firewall/tree/main/.claude/skills/debug-firewallType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add github/gh-aw-firewall --skill debug-firewall -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install github/gh-aw-firewall debug-firewall --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/debug-firewall .agents/skills/debug-firewall && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "debug-firewall" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.claude/skills/debug-firewall into .agents/skills/debug-firewall/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "debug-firewall", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add github/gh-aw-firewall --skill debug-firewall -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install github/gh-aw-firewall debug-firewall --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/debug-firewall .cursor/skills/debug-firewall && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "debug-firewall" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.claude/skills/debug-firewall into .cursor/skills/debug-firewall/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "debug-firewall", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/github/gh-aw-firewall.git --path .claude/skills/debug-firewall--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add github/gh-aw-firewall --skill debug-firewall -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install github/gh-aw-firewall debug-firewall --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/debug-firewall .gemini/skills/debug-firewall && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "debug-firewall" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.claude/skills/debug-firewall into .gemini/skills/debug-firewall/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "debug-firewall", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install github/gh-aw-firewall debug-firewallInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add github/gh-aw-firewall --skill debug-firewall -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/debug-firewall .github/skills/debug-firewall && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "debug-firewall" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.claude/skills/debug-firewall into .github/skills/debug-firewall/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "debug-firewall", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add github/gh-aw-firewall --skill debug-firewall -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install github/gh-aw-firewall debug-firewall --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/debug-firewall .opencode/skills/debug-firewall && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "debug-firewall" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.claude/skills/debug-firewall into .opencode/skills/debug-firewall/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "debug-firewall", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
debug-firewallDebug the AWF firewall by inspecting Docker containers (awf-squid, awf-agent), analyzing Squid access logs, checking iptables rules, and troubleshooting blocked domains or network issues.
Debug Firewall is an agent skill from github/gh-aw-firewall, published by the product's own GitHub organization. Debug the AWF firewall by inspecting Docker containers (awf-squid, awf-agent), analyzing Squid access logs, checking iptables rules, and troubleshooting blocked domains or network issues.
Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Containers and Debugging. It works with GitHub and Docker. The repository describes itself as: GitHub Agentic Workflows Firewall. The licence is MIT.
Read from SKILL.md and the folder at commit f748e41. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
Bash(docker:*)Bash(sudo:*)Bash(dmesg:*)Bash(ls:*)Bash(cat:*)ReadFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
dockerFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Debug Firewall loads about 1.2k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 150 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
sudo iptables -t filter -L FW_WRAPPER -n -vsudo dmesg | grep "FW_BLOCKED"sudo cat /tmp/awf-*/squid-logs/access.logsudo cat $(ls -t /tmp/squid-logs-*/access.log 2>/dev/null | head -1)sudo awf \sudo iptables -t filter -L FW_WRAPPER -nsudo dmesg | grep "FW_DNS"sudo iptables -t filter -F FW_WRAPPER 2>/dev/nullsudo iptables -t filter -X FW_WRAPPER 2>/dev/nullAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from github/gh-aw-firewall at commit f748e41, republished under its MIT licence (© github). 150 words, ~1,171 tokens.
.claude/skills/debug-firewall/SKILL.md (or your agent's skills folder).Use this skill when you need to debug the awf firewall, inspect container state, analyze traffic, or troubleshoot network issues.
Container Names:
awf-squid - Squid proxy container (IP: 172.30.0.10)awf-agent - Agent execution container (IP: 172.30.0.20)Network: awf-net (subnet: 172.30.0.0/24)
docker ps | grep awf
docker inspect awf-squid --format='{{.State.Running}}'
docker inspect awf-agent --format='{{.State.ExitCode}}'# Real-time logs
docker logs -f awf-squid
docker logs -f awf-agent
# Squid access log (traffic decisions)
docker exec awf-squid cat /var/log/squid/access.logSquid Decision Codes:
TCP_TUNNEL:HIER_DIRECT = ALLOWED (HTTPS)TCP_MISS:HIER_DIRECT = ALLOWED (HTTP)TCP_DENIED:HIER_NONE = BLOCKED# Find blocked domains
docker exec awf-squid grep "TCP_DENIED" /var/log/squid/access.log | awk '{print $3}' | sort -u
# Count blocked by domain
docker exec awf-squid grep "TCP_DENIED" /var/log/squid/access.log | awk '{print $3}' | sort | uniq -c | sort -rn
# All unique domains accessed
docker exec awf-squid awk '{print $3}' /var/log/squid/access.log | sort -u
# Real-time blocked traffic
docker exec awf-squid tail -f /var/log/squid/access.log | grep --line-buffered TCP_DENIED# Host-level firewall chain
sudo iptables -t filter -L FW_WRAPPER -n -v
# Agent container NAT rules (redirects to Squid)
docker exec awf-agent iptables -t nat -L OUTPUT -n -v
# Kernel logs for blocked non-HTTP traffic
sudo dmesg | grep "FW_BLOCKED"# Network details
docker network inspect awf-net
# Test Squid connectivity
docker exec awf-agent nc -zv 172.30.0.10 3128
# DNS configuration
docker exec awf-agent cat /etc/resolv.conf# Squid config
docker exec awf-squid cat /etc/squid/squid.conf
# Docker compose config
cat /tmp/awf-*/docker-compose.yml
# Agent environment
docker exec awf-agent env | grep -E "PROXY|DNS"With --keep-containers: Logs remain at work directory
/tmp/awf-<timestamp>/squid-logs/access.log/tmp/awf-<timestamp>/agent-logs/ (only if Copilot CLI logs exist)Normal execution: Logs moved after cleanup
/tmp/squid-logs-<timestamp>/access.log/tmp/awf-agent-logs-<timestamp>/# Find work directories and preserved logs
ls -ldt /tmp/awf-* /tmp/squid-logs-* 2>/dev/null | head -5
# View Squid logs from work dir (with --keep-containers)
sudo cat /tmp/awf-*/squid-logs/access.log
# View preserved Squid logs (after normal cleanup)
sudo cat $(ls -t /tmp/squid-logs-*/access.log 2>/dev/null | head -1)# 1. Run with debug logging and keep containers
sudo awf \
--allow-domains github.com \
--log-level debug \
--keep-containers \
'curl https://api.github.com'
# 2. Inspect containers (they remain running)
docker ps | grep awf
docker logs awf-squid
docker exec awf-squid grep "TCP_DENIED" /var/log/squid/access.log
# 3. Check iptables
sudo iptables -t filter -L FW_WRAPPER -n
# 4. Manual cleanup when done
docker rm -f awf-squid awf-agent
docker network rm awf-netDomain blocked unexpectedly:
# Check exact domain being requested
docker exec awf-squid tail -20 /var/log/squid/access.log
# Look at the Host header (3rd column) - may need subdomain allowlistedDNS resolution failing:
# Check DNS servers in use
docker exec awf-agent cat /etc/resolv.conf
# Verify DNS allowed in iptables
sudo dmesg | grep "FW_DNS"# Manual cleanup
./scripts/ci/cleanup.sh
# Or individually:
docker rm -f awf-squid awf-agent
docker network rm awf-net
sudo iptables -t filter -F FW_WRAPPER 2>/dev/null
sudo iptables -t filter -X FW_WRAPPER 2>/dev/null
rm -rf /tmp/awf-*If you are diagnosing a failure rather than exploring, enter through the
diagnose-awf skill and the canonical diagnosis registry in
docs/diagnostics/README.md. This skill is one of the
specialist references it routes to.
© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/debug-firewall of github/gh-aw-firewall.
Open the folder on GitHubat commit f748e41
Debug Firewall next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Debug Firewall this skillgithub/gh-aw-firewall | 149 | — | ~1.2k | Automated safety check: Notes | MIT | |
| Debugging Local Task Agent RunsPostHog/posthog | 40k | — | ~2.1k | Automated safety check: Notes | Custom licence | |
| Borg Live Debugkaranhudia/borg-ui | 1.7k | — | ~1.4k | Automated safety check: Notes | AGPL-3.0 | |
| .NET Crash Dump Collectiondotnet/skills | 5.6k | 2 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Releasebmeares/Meerschaum | 154 | — | ~1.1k | Automated safety check: Notes | Apache-2.0 | |
| Releasematrixorigin/memoria | 609 | — | ~494 | Automated safety check: Pass | Apache-2.0 |
PostHog/posthog
Debug the output of local PostHog task runs — the wizard cloud-run path that executes inside a Docker sandbox under the local Temporal process-task workflow (the wizard that integrates PostHog, then…
karanhudia/borg-ui
Live Borg debugging by exec-ing into the borg-web-ui Docker container.
dotnet/skills
Configures automatic crash dumps or captures dumps from running processes for modern .NET apps on Linux, macOS and Windows, including Docker and Kubernetes.
bmeares/Meerschaum
Meerschaum release process — bump version, update changelog, stage dev→main PR, run CI, publish to PyPI, tag, GitHub release, build/push Docker images, rebuild docs on prod VPS.
matrixorigin/memoria
Cut a Memoria release. An agent skill from matrixorigin/memoria.
nrwl/nx
The single skill for reproducing an nx issue. An agent skill from nrwl/nx.
github/gh-aw-firewall
Practical Python scripts for debugging awf - parse logs, diagnose issues, inspect containers, test domains
github/gh-aw-firewall
Regenerate and post-process all agentic workflows. An agent skill from github/gh-aw-firewall.
github/gh-aw-firewall
Decide and implement how to support a new LLM provider or agent engine in AWF - either as a proxied provider (api-proxy adapter) or a direct-API engine (domain allowlist only), e.g.
github/gh-aw-firewall
Debug GitHub Actions workflows by downloading logs, analyzing summaries, and understanding how agentic workflows and the AWF firewall work together.
github/gh-aw-firewall
Diagnose an AWF (Agentic Workflow Firewall) failure from an error, workflow run URL, or symptom.
Categories
Debug the AWF firewall by inspecting Docker containers (awf-squid, awf-agent), analyzing Squid access logs, checking iptables rules, and troubleshooting blocked domains or network issues. Debug Firewall is an agent skill from github/gh-aw-firewall, published by the product's own GitHub organization. Debug the AWF firewall by inspecting Docker containers (awf-squid, awf-agent), analyzing Squid access logs, checking iptables rules, and troubleshooting blocked domains or network issues.
Debug Firewall fits situations like: tasks that involve Containers; tasks that involve Debugging.
Run `npx skills add github/gh-aw-firewall --skill debug-firewall -a claude-code`. Or copy the skill folder (.claude/skills/debug-firewall in github/gh-aw-firewall) into .claude/skills/debug-firewall in your project. Claude Code loads it when a task matches its description.
Run `npx skills add github/gh-aw-firewall --skill debug-firewall -a codex`. Or copy the skill folder (.claude/skills/debug-firewall in github/gh-aw-firewall) into .agents/skills/debug-firewall in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/gh-aw-firewall --skill debug-firewall -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/debug-firewall, .gemini/skills/debug-firewall, .github/skills/debug-firewall and .opencode/skills/debug-firewall in your project.
Going by SKILL.md and its folder, Debug Firewall needs the command-line tools its instructions call (docker). Our summary lists: Docker. Its frontmatter pre-approves these tools: Bash(docker:*), Bash(sudo:*), Bash(dmesg:*), Bash(ls:*), Bash(cat:*), Read.
SKILL.md names 1 domain. In commands or code: api.github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Debug Firewall is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Debug Firewall: Debugging Local Task Agent Runs (PostHog/posthog, 40k stars), Borg Live Debug (karanhudia/borg-ui, 1.7k stars), .NET Crash Dump Collection (dotnet/skills, 5.6k stars) and Release (bmeares/Meerschaum, 154 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
github (a GitHub organization, an official publisher) maintains it in github/gh-aw-firewall, which has 149 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 9, 2026.
Source: github/gh-aw-firewall on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.