Official agent skill

Debug Firewall

by github in github/gh-aw-firewall

Debug the AWF firewall by inspecting Docker containers (awf-squid, awf-agent), analyzing Squid access logs, checking iptables rules, and troubleshooting blocked domains or network issues.

OfficialMITAuto-check: notesDevOps & Cloud

Install Debug Firewall

skills CLI
$ npx skills add github/gh-aw-firewall --skill debug-firewall -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install github/gh-aw-firewall debug-firewall --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/debug-firewall .claude/skills/debug-firewall && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
debug-firewall
GitHub stars
149
Token cost
~1.2k tokens
SKILL.md length
150 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Debug the AWF firewall by inspecting Docker containers (awf-squid, awf-agent), analyzing Squid access logs, checking iptables rules, and troubleshooting blocked domains or network issues.

  • Tasks that involve Containers
  • SKILL.md covers Container Information, Quick Debugging Commands, Preserved Logs Locations and Debug Mode Workflow, plus 3 more sections
  • Calls docker; reaches api.github.com
  • Tasks that involve Debugging

What it does

Debug Firewall is an agent skill from github/gh-aw-firewall, published by the product's own GitHub organization. Debug the AWF firewall by inspecting Docker containers (awf-squid, awf-agent), analyzing Squid access logs, checking iptables rules, and troubleshooting blocked domains or network issues.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Containers and Debugging. It works with GitHub and Docker. The repository describes itself as: GitHub Agentic Workflows Firewall. The licence is MIT.

When your agent uses it

  • Tasks that involve Containers
  • Tasks that involve Debugging

Example prompts

  • “/debug-firewall”

Requirements

  • Docker
  • Pre-approved tools (allowed-tools): Bash(docker:*), Bash(sudo:*), Bash(dmesg:*), Bash(ls:*), Bash(cat:*), Read

What it can do on your machine

Read from SKILL.md and the folder at commit f748e41. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(docker:*)
    • Bash(sudo:*)
    • Bash(dmesg:*)
    • Bash(ls:*)
    • Bash(cat:*)
    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Debug Firewall loads about 1.2k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 150 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:62
    sudo iptables -t filter -L FW_WRAPPER -n -v
  • NoteRuns commands with sudoSKILL.md:68
    sudo dmesg | grep "FW_BLOCKED"
  • NoteRuns commands with sudoSKILL.md:110
    sudo cat /tmp/awf-*/squid-logs/access.log
  • NoteRuns commands with sudoSKILL.md:113
    sudo cat $(ls -t /tmp/squid-logs-*/access.log 2>/dev/null | head -1)
  • NoteRuns commands with sudoSKILL.md:120
    sudo awf \
  • NoteRuns commands with sudoSKILL.md:132
    sudo iptables -t filter -L FW_WRAPPER -n
  • NoteRuns commands with sudoSKILL.md:153
    sudo dmesg | grep "FW_DNS"
  • NoteRuns commands with sudoSKILL.md:165
    sudo iptables -t filter -F FW_WRAPPER 2>/dev/null
  • NoteRuns commands with sudoSKILL.md:166
    sudo iptables -t filter -X FW_WRAPPER 2>/dev/null

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from github/gh-aw-firewall at commit f748e41, republished under its MIT licence (© github). 150 words, ~1,171 tokens.

Download SKILL.mdSave it as .claude/skills/debug-firewall/SKILL.md (or your agent's skills folder).
name
debug-firewall
description
Debug the AWF firewall by inspecting Docker containers (awf-squid, awf-agent), analyzing Squid access logs, checking iptables rules, and troubleshooting blocked domains or network issues.
allowed-tools
Bash(docker:*), Bash(sudo:*), Bash(dmesg:*), Bash(ls:*), Bash(cat:*), Read

AWF Firewall Debugging Skill

Use this skill when you need to debug the awf firewall, inspect container state, analyze traffic, or troubleshoot network issues.

Container Information

Container Names:

  • awf-squid - Squid proxy container (IP: 172.30.0.10)
  • awf-agent - Agent execution container (IP: 172.30.0.20)

Network: awf-net (subnet: 172.30.0.0/24)

Quick Debugging Commands

Check Container Status
bash
docker ps | grep awf
docker inspect awf-squid --format='{{.State.Running}}'
docker inspect awf-agent --format='{{.State.ExitCode}}'
View Logs
bash
# Real-time logs
docker logs -f awf-squid
docker logs -f awf-agent

# Squid access log (traffic decisions)
docker exec awf-squid cat /var/log/squid/access.log
Analyze Traffic

Squid Decision Codes:

  • TCP_TUNNEL:HIER_DIRECT = ALLOWED (HTTPS)
  • TCP_MISS:HIER_DIRECT = ALLOWED (HTTP)
  • TCP_DENIED:HIER_NONE = BLOCKED
bash
# Find blocked domains
docker exec awf-squid grep "TCP_DENIED" /var/log/squid/access.log | awk '{print $3}' | sort -u

# Count blocked by domain
docker exec awf-squid grep "TCP_DENIED" /var/log/squid/access.log | awk '{print $3}' | sort | uniq -c | sort -rn

# All unique domains accessed
docker exec awf-squid awk '{print $3}' /var/log/squid/access.log | sort -u

# Real-time blocked traffic
docker exec awf-squid tail -f /var/log/squid/access.log | grep --line-buffered TCP_DENIED
Inspect iptables Rules
bash
# Host-level firewall chain
sudo iptables -t filter -L FW_WRAPPER -n -v

# Agent container NAT rules (redirects to Squid)
docker exec awf-agent iptables -t nat -L OUTPUT -n -v

# Kernel logs for blocked non-HTTP traffic
sudo dmesg | grep "FW_BLOCKED"
Network Inspection
bash
# Network details
docker network inspect awf-net

# Test Squid connectivity
docker exec awf-agent nc -zv 172.30.0.10 3128

# DNS configuration
docker exec awf-agent cat /etc/resolv.conf
View Configuration
bash
# Squid config
docker exec awf-squid cat /etc/squid/squid.conf

# Docker compose config
cat /tmp/awf-*/docker-compose.yml

# Agent environment
docker exec awf-agent env | grep -E "PROXY|DNS"

Preserved Logs Locations

With --keep-containers: Logs remain at work directory

  • Squid: /tmp/awf-<timestamp>/squid-logs/access.log
  • Agent: /tmp/awf-<timestamp>/agent-logs/ (only if Copilot CLI logs exist)

Normal execution: Logs moved after cleanup

  • Squid: /tmp/squid-logs-<timestamp>/access.log
  • Agent: /tmp/awf-agent-logs-<timestamp>/
bash
# Find work directories and preserved logs
ls -ldt /tmp/awf-* /tmp/squid-logs-* 2>/dev/null | head -5

# View Squid logs from work dir (with --keep-containers)
sudo cat /tmp/awf-*/squid-logs/access.log

# View preserved Squid logs (after normal cleanup)
sudo cat $(ls -t /tmp/squid-logs-*/access.log 2>/dev/null | head -1)

Debug Mode Workflow

bash
# 1. Run with debug logging and keep containers
sudo awf \
  --allow-domains github.com \
  --log-level debug \
  --keep-containers \
  'curl https://api.github.com'

# 2. Inspect containers (they remain running)
docker ps | grep awf
docker logs awf-squid
docker exec awf-squid grep "TCP_DENIED" /var/log/squid/access.log

# 3. Check iptables
sudo iptables -t filter -L FW_WRAPPER -n

# 4. Manual cleanup when done
docker rm -f awf-squid awf-agent
docker network rm awf-net

Common Issues

Domain blocked unexpectedly:

bash
# Check exact domain being requested
docker exec awf-squid tail -20 /var/log/squid/access.log
# Look at the Host header (3rd column) - may need subdomain allowlisted

DNS resolution failing:

bash
# Check DNS servers in use
docker exec awf-agent cat /etc/resolv.conf
# Verify DNS allowed in iptables
sudo dmesg | grep "FW_DNS"

Cleanup

bash
# Manual cleanup
./scripts/ci/cleanup.sh

# Or individually:
docker rm -f awf-squid awf-agent
docker network rm awf-net
sudo iptables -t filter -F FW_WRAPPER 2>/dev/null
sudo iptables -t filter -X FW_WRAPPER 2>/dev/null
rm -rf /tmp/awf-*

Start here for diagnosis

If you are diagnosing a failure rather than exploring, enter through the diagnose-awf skill and the canonical diagnosis registry in docs/diagnostics/README.md. This skill is one of the specialist references it routes to.

© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/debug-firewall of github/gh-aw-firewall.

Open the folder on GitHubat commit f748e41

Compare with similar skills

Debug Firewall next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Debug Firewall compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Debug Firewall this skillgithub/gh-aw-firewall149—~1.2kAutomated safety check: NotesMIT
Debugging Local Task Agent RunsPostHog/posthog40k—~2.1kAutomated safety check: NotesCustom licence
Borg Live Debugkaranhudia/borg-ui1.7k—~1.4kAutomated safety check: NotesAGPL-3.0
.NET Crash Dump Collectiondotnet/skills5.6k2 repos~1.1kAutomated safety check: PassMIT
Releasebmeares/Meerschaum154—~1.1kAutomated safety check: NotesApache-2.0
Releasematrixorigin/memoria609—~494Automated safety check: PassApache-2.0

Similar skills

  • Official

    Debug the output of local PostHog task runs — the wizard cloud-run path that executes inside a Docker sandbox under the local Temporal process-task workflow (the wizard that integrates PostHog, then…

    40k GitHub stars~2.1k tokensUpdated today
    DevelopmentAuto-check: notes
  • Borg Live Debug

    karanhudia/borg-ui

    Live Borg debugging by exec-ing into the borg-web-ui Docker container.

    1.7k GitHub stars~1.4k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Official

    Configures automatic crash dumps or captures dumps from running processes for modern .NET apps on Linux, macOS and Windows, including Docker and Kubernetes.

    5.6k GitHub starsUsed in 2 repos~1.1k tokens
    DevOps & CloudAuto-check passed
  • Release

    bmeares/Meerschaum

    Meerschaum release process — bump version, update changelog, stage dev→main PR, run CI, publish to PyPI, tag, GitHub release, build/push Docker images, rebuild docs on prod VPS.

    154 GitHub stars~1.1k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Release

    matrixorigin/memoria

    Cut a Memoria release. An agent skill from matrixorigin/memoria.

    609 GitHub stars~494 tokensUpdated today
    DevOps & CloudAuto-check passed
  • The single skill for reproducing an nx issue. An agent skill from nrwl/nx.

    29k GitHub stars~2.6k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from github/gh-aw-firewall

  • Awf Debug Tools

    github/gh-aw-firewall

    Official

    Practical Python scripts for debugging awf - parse logs, diagnose issues, inspect containers, test domains

    149 GitHub stars~2.6k tokensUpdated today
    Auto-check: notes
  • Recompile Workflows

    github/gh-aw-firewall

    Official

    Regenerate and post-process all agentic workflows. An agent skill from github/gh-aw-firewall.

    149 GitHub stars~568 tokensUpdated today
    Auto-check passed
  • Add LLM Provider

    github/gh-aw-firewall

    Official

    Decide and implement how to support a new LLM provider or agent engine in AWF - either as a proxied provider (api-proxy adapter) or a direct-API engine (domain allowlist only), e.g.

    149 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Debugging Workflows

    github/gh-aw-firewall

    Official

    Debug GitHub Actions workflows by downloading logs, analyzing summaries, and understanding how agentic workflows and the AWF firewall work together.

    149 GitHub stars~2.7k tokensUpdated today
    Auto-check: notes
  • Diagnose Awf

    github/gh-aw-firewall

    Official

    Diagnose an AWF (Agentic Workflow Firewall) failure from an error, workflow run URL, or symptom.

    149 GitHub stars~829 tokensUpdated today
    Auto-check passed

Works with

Questions about Debug Firewall

What does Debug Firewall do?

Debug the AWF firewall by inspecting Docker containers (awf-squid, awf-agent), analyzing Squid access logs, checking iptables rules, and troubleshooting blocked domains or network issues. Debug Firewall is an agent skill from github/gh-aw-firewall, published by the product's own GitHub organization. Debug the AWF firewall by inspecting Docker containers (awf-squid, awf-agent), analyzing Squid access logs, checking iptables rules, and troubleshooting blocked domains or network issues.

When should I use Debug Firewall?

Debug Firewall fits situations like: tasks that involve Containers; tasks that involve Debugging.

How do I install Debug Firewall in Claude Code?

Run `npx skills add github/gh-aw-firewall --skill debug-firewall -a claude-code`. Or copy the skill folder (.claude/skills/debug-firewall in github/gh-aw-firewall) into .claude/skills/debug-firewall in your project. Claude Code loads it when a task matches its description.

How do I install Debug Firewall in Codex?

Run `npx skills add github/gh-aw-firewall --skill debug-firewall -a codex`. Or copy the skill folder (.claude/skills/debug-firewall in github/gh-aw-firewall) into .agents/skills/debug-firewall in your project. Codex loads it when a task matches its description.

Can I use Debug Firewall in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/gh-aw-firewall --skill debug-firewall -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/debug-firewall, .gemini/skills/debug-firewall, .github/skills/debug-firewall and .opencode/skills/debug-firewall in your project.

What does Debug Firewall need to run?

Going by SKILL.md and its folder, Debug Firewall needs the command-line tools its instructions call (docker). Our summary lists: Docker. Its frontmatter pre-approves these tools: Bash(docker:*), Bash(sudo:*), Bash(dmesg:*), Bash(ls:*), Bash(cat:*), Read.

Does Debug Firewall access the network?

SKILL.md names 1 domain. In commands or code: api.github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Debug Firewall safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Debug Firewall use?

Debug Firewall is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Debug Firewall use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Debug Firewall?

Skills that share tags, products or a category with Debug Firewall: Debugging Local Task Agent Runs (PostHog/posthog, 40k stars), Borg Live Debug (karanhudia/borg-ui, 1.7k stars), .NET Crash Dump Collection (dotnet/skills, 5.6k stars) and Release (bmeares/Meerschaum, 154 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Debug Firewall?

github (a GitHub organization, an official publisher) maintains it in github/gh-aw-firewall, which has 149 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 9, 2026.

Source: github/gh-aw-firewall on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.