GitHub Actions Failure Analysis
ykdojo/claude-code-tips
Investigates a failed GitHub Actions run from its URL: pinpoints the real failure, checks the job's history for flakiness, and finds the breaking commit and any existing fix PR.
Guides your agent through diagnosing failed GitHub Agentic Workflows by downloading run logs, auditing individual runs and reading the artifacts they leave behind.
$ npx skills add github/gh-aw --skill debugging-workflows -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install github/gh-aw debugging-workflows --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/debugging-workflows .claude/skills/debugging-workflows && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "debugging-workflows" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/debugging-workflows into .claude/skills/debugging-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "debugging-workflows", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/github/gh-aw/tree/main/.github/skills/debugging-workflowsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add github/gh-aw --skill debugging-workflows -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install github/gh-aw debugging-workflows --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/debugging-workflows .agents/skills/debugging-workflows && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "debugging-workflows" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/debugging-workflows into .agents/skills/debugging-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "debugging-workflows", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add github/gh-aw --skill debugging-workflows -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install github/gh-aw debugging-workflows --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/debugging-workflows .cursor/skills/debugging-workflows && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "debugging-workflows" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/debugging-workflows into .cursor/skills/debugging-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "debugging-workflows", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/github/gh-aw.git --path .github/skills/debugging-workflows--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add github/gh-aw --skill debugging-workflows -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install github/gh-aw debugging-workflows --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/debugging-workflows .gemini/skills/debugging-workflows && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "debugging-workflows" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/debugging-workflows into .gemini/skills/debugging-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "debugging-workflows", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install github/gh-aw debugging-workflowsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add github/gh-aw --skill debugging-workflows -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/debugging-workflows .github/skills/debugging-workflows && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "debugging-workflows" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/debugging-workflows into .github/skills/debugging-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "debugging-workflows", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add github/gh-aw --skill debugging-workflows -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install github/gh-aw debugging-workflows --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/debugging-workflows .opencode/skills/debugging-workflows && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "debugging-workflows" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/debugging-workflows into .opencode/skills/debugging-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "debugging-workflows", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
debugging-workflowsGuides your agent through diagnosing failed GitHub Agentic Workflows by downloading run logs, auditing individual runs and reading the artifacts they leave behind.
This is an evidence and command reference for working out why a gh-aw workflow failed. The agent uses `gh aw logs` to pull artifacts and logs from GitHub Actions runs, with filters for date ranges and options for a JSON summary, and `gh aw audit` to examine one run by its ID.
It lists what each download contains: engine configuration in `aw_info.json`, the agent's final output in `safe_output.jsonl`, agent stdio logs, the git patch of changes made during the run, per-job Actions logs and a `summary.json` with metrics for all runs. The page defers to a separate shared debugging strategy for any reproduction, fix or live test, and says that diagnosis should never dispatch a run just to collect evidence.
Read from SKILL.md and the folder at commit eb63040. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghjqFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
gh-aw Workflow Diagnosis loads about 3.9k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 1,063 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from github/gh-aw at commit eb63040, republished under its MIT licence (© github). 1,063 words, ~3,853 tokens.
.claude/skills/debugging-workflows/SKILL.md (or your agent's skills folder).Use this reference to diagnose workflows: download/analyze existing logs, audit runs, and trace failures. These reads are not an active debug loop.
Follow the shared local-first strategy for all reproduction, fixes, uploads, and live tests. This page is an evidence and CLI reference, not a separate execution policy. Respect explicit no-dispatch contexts. Apply its live-outcome table, credential triage and untrusted-evidence rules. Without accessible existing logs, use source/fixtures; never dispatch for evidence.
# Download logs from the last 24 hours
gh aw logs --start-date -1d -o .github/aw/logs/recent
# Download logs for a specific workflow
gh aw logs weekly-research --start-date -1d
# Download logs with JSON output for programmatic analysis
gh aw logs --json# Audit by run ID
gh aw audit 1234567890
# Audit from a GitHub Actions URL
gh aw audit https://github.com/owner/repo/actions/runs/1234567890
# Audit with JSON output
gh aw audit 1234567890 --jsonThe gh aw logs command downloads workflow run artifacts and logs from GitHub Actions for analysis.
# Download logs for all workflows (last 10 runs)
gh aw logs
# Download logs for a specific workflow
gh aw logs <workflow-name>
# Download with custom output directory
gh aw logs -o .github/aw/logs/custom# Filter by date range
gh aw logs --start-date 2024-01-01 --end-date 2024-01-31
gh aw logs --start-date -1w # Last week
gh aw logs --start-date -1mo # Last month
# Filter by AI engine
gh aw logs --engine copilot
gh aw logs --engine claude
gh aw logs --engine codex
# Filter by count
gh aw logs -c 5 # Last 5 runs
# Filter by branch/tag
gh aw logs --ref main
gh aw logs --ref feature-xyz
# Filter by run ID range
gh aw logs --after-run-id 1000 --before-run-id 2000
# Filter firewall-enabled runs
gh aw logs --firewall # Only firewall-enabled
gh aw logs --no-firewall # Only non-firewall# Generate JSON summary
gh aw logs --json
# Parse agent logs and generate Markdown reports
gh aw logs --parse
# Generate Mermaid tool sequence graph
gh aw logs --tool-graph
# Set download timeout
gh aw logs --timeout 300 # 5 minute timeoutWhen you run gh aw logs, the following artifacts are downloaded for each run:
| File | Description |
|---|---|
aw_info.json | Engine configuration and workflow metadata |
safe_output.jsonl | Agent's final output content (when non-empty) |
agent_output/ | Agent logs directory |
agent-stdio.log | Agent standard output/error logs |
aw.patch | Git patch of changes made during execution |
workflow-logs/ | GitHub Actions job logs (organized by job) |
summary.json | Complete metrics and run data for all runs |
# Download failed runs from last week
gh aw logs --start-date -1w -o .github/aw/logs/debug
# Check the summary for patterns
cat .github/aw/logs/debug/summary.json | jq '.runs[] | select(.conclusion == "failure")'The gh aw audit command investigates a single workflow run in detail, downloading artifacts, detecting errors, and generating a report.
# Audit by numeric run ID
gh aw audit 1234567890
# Audit from GitHub Actions URL
gh aw audit https://github.com/owner/repo/actions/runs/1234567890
# Audit from job URL (extracts first failing step)
gh aw audit https://github.com/owner/repo/actions/runs/1234567890/job/9876543210
# Audit from job URL with specific step
gh aw audit https://github.com/owner/repo/actions/runs/1234567890/job/9876543210#step:7:1# JSON output for programmatic analysis
gh aw audit 1234567890 --json
# Custom output directory
gh aw audit 1234567890 -o ./audit-reports
# Parse agent logs and firewall logs
gh aw audit 1234567890 --parse
# Verbose output
gh aw audit 1234567890 -v# Compare existing runs, without dispatching new ones
gh aw audit 1234567890 1234567891 1234567892 --group --jsonUse grouped per-run finding codes/counts, then cached individual reports/logs for exact signatures. Plain multi-run diffs focus on metrics/firewall/tools; absent findings or skipped runs do not prove the error disappeared. Match the first failing boundary and normalized error/tool/status signature across comparable workflows, revisions, triggers/inputs and configurations. Count each matching run once, report matching/inspectable runs and IDs, and keep missing evidence unknown. Repeated HTTP 403 alone does not establish one root cause.
The audit command provides:
# Get detailed audit report
gh aw audit 1234567890 --json > audit.json
# Extract key information
cat audit.json | jq '{
status: .overview.status,
conclusion: .overview.conclusion,
errors: .errors,
missing_tools: .missing_tools,
tool_usage: .tool_usage
}'Understanding the workflow architecture helps in debugging.
Agentic workflows use a markdown + YAML frontmatter format:
---
on:
issues:
types: [opened]
permissions:
contents: read
timeout-minutes: 10
engine: copilot
tools:
github:
mode: remote
toolsets: [default]
safe-outputs:
staged: true
create-issue:
labels: [ai-generated]
---
# Workflow Title
Natural language instructions for the AI agent.
Use GitHub context like ${{ github.event.issue.number }}.1. Trigger Event (issue opened, PR created, schedule, etc.)
↓
2. Activation Job
- Validates permissions
- Processes mcp-scripts
- Sanitizes context
↓
3. AI Agent Job
- Loads MCP servers and tools
- Executes AI agent with prompt
- Agent makes tool calls
- Agent produces output
↓
4. Safe Outputs Job
- Processes agent output
- Creates GitHub resources (issues, PRs, etc.)
- Applies labels, comments
↓
5. Completion
- Workflow summary generated
- Artifacts uploaded| Component | Purpose | Configuration |
|---|---|---|
| Engine | AI model to use | engine: copilot, claude, codex |
| Tools | APIs available to agent | tools: section with MCP servers |
| MCP Scripts | Context passed to agent | mcp-scripts: with GitHub expressions |
| Safe-Outputs | Resources agent can create | safe-outputs: with allowed operations |
| Permissions | GitHub token permissions | permissions: block |
| Network | Allowed network access | network: with domain/ecosystem lists |
# Compile workflow to GitHub Actions YAML
gh aw compile <workflow-name>
# Result: .github/workflows/<name>.md → .github/workflows/<name>.lock.ymlThe .lock.yml file is the actual GitHub Actions workflow that runs.
Symptoms:
Solution: Add GitHub MCP server configuration:
tools:
github:
mode: remote
toolsets: [default]Symptoms:
Solution: First distinguish SAML/token-source denial from missing permissions using the shared credential triage. Grant required read permissions to the agent and configure writes through safe outputs. Keep debugging outputs staged; inspect individual job/token permissions rather than adding write permissions to the agent:
permissions:
contents: read
safe-outputs:
staged: true
create-issue: {}Symptoms:
Solution: Configure mcp-scripts:
mcp-scripts:
issue:
script: |
return { title: process.env.ISSUE_TITLE, body: process.env.ISSUE_BODY };
env:
ISSUE_TITLE: ${{ github.event.issue.title }}
ISSUE_BODY: ${{ github.event.issue.body }}Symptoms:
Solution: Enable safe-outputs:
safe-outputs:
staged: true # Preview safe outputs while debugging
create-issue:
labels: [ai-generated]Symptoms:
Process Safe Outputs reports multiple failed messages in one runupdate_pull_request message includes a 403 workflows-permission warningadd_comment) include Bad credentialsWhat this means:
update_pull_request can be expected/non-fatal in some workflows.Bad credentials error on other messages is a separate authentication failure that needs its own fix.Diagnostic steps:
# Summarize failed safe-output messages and types
gh aw audit <run-id>
# Include additional artifacts when diagnosis needs more context
gh aw audit <run-id> --artifacts usage,github-api,mcp,agent
# Escalate to full artifact collection for hard-to-classify failures
gh aw audit <run-id> --artifacts all
# Inspect full failing job logs to classify each message failure
gh run view <run-id> --job=<job-id> --logpermissions: for missing scopes when 403 errors appear.Symptoms:
Solution: Configure network access:
network:
allowed:
- defaults
- python # For PyPI
- node # For npm
- "api.example.com" # Custom domainsSymptoms:
Solution: Increase timeout or optimize prompt:
timeout-minutes: 30 # Increase from defaultClassify command exit separately from workflow outcome. A nonzero audit exit may
mean artifacts are not ready: confirm the same run with
gh run view <run-id> --json status,headSha,conclusion, then poll within the
approved interval/deadline. Audit/log permission denial blocks further live
iteration; report evidence unavailable, not workflow failure. Follow the shared
outcome table for dispatch timeouts and SHA mismatches; never redispatch for logs.
Preflight declarations, startup effects and isolated test bindings using the shared strategy before commands that can start/connect servers.
# Inspect MCP servers for a workflow
gh aw mcp inspect <workflow-name>
# List all workflows with MCP servers
gh aw mcp list# Show status of all agentic workflows
gh aw status# Download only the agent log artifact
GH_REPO=owner/repo gh run download <run-id> -n agent-stdio.log# View specific job logs
gh run view <run-id>
gh run view --job <job-id> --log# Parse firewall logs for network issues
gh aw logs --parse
# Check firewall-enabled runs
gh aw logs --firewall# Strict/staged development compilation with checks and warnings as errors
gh aw compile <workflow> --dry-run
# Recommended when using a reviewed test environment
gh aw compile <workflow> --dry-run --environment gh-aw-debug| Command | Description |
|---|---|
gh aw logs | Download logs for all workflows |
gh aw logs <workflow> | Download logs for specific workflow |
gh aw logs --json | Output as JSON |
gh aw logs --start-date -1d | Filter by date |
gh aw logs --engine copilot | Filter by engine |
gh aw logs --parse | Generate Markdown reports |
| Command | Description |
|---|---|
gh aw audit <run-id> | Audit specific run |
gh aw audit <url> | Audit from GitHub URL |
gh aw audit <run-id> --json | Output as JSON |
gh aw audit <run-id> --parse | Parse logs to Markdown |
gh aw audit <id1> <id2> ... --group --json | Group existing-run findings for recurrence |
| Command | Description |
|---|---|
gh aw mcp list | List workflows with MCP servers |
gh aw mcp inspect <workflow> | Inspect MCP configuration |
| Command | Description |
|---|---|
gh aw status | Show all workflow status |
gh aw compile | Compile all workflows |
gh aw compile <workflow> | Compile specific workflow |
gh aw compile <workflow> --dry-run | Enforce shared development-testing checks |
| Command | Description |
|---|---|
gh aw run <workflow> --ref <reviewed-ref> | Only after shared human-validation gates; explicit no-dispatch rules take precedence |
gh run view <run-id> --json status,headSha,conclusion | Same-run monitoring within approved bounds |
© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/debugging-workflows of github/gh-aw.
Open the folder on GitHubat commit eb63040
gh-aw Workflow Diagnosis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| gh-aw Workflow Diagnosis this skillgithub/gh-aw | 5.3k | — | ~3.9k | Automated safety check: Pass | MIT | |
| GitHub Actions Failure Analysisykdojo/claude-code-tips | 10k | — | ~639 | Automated safety check: Pass | Custom licence | |
| CI/CD Failure Troubleshootingruby-git/ruby-git | 1.8k | — | ~1.9k | Automated safety check: Pass | MIT | |
| Debugging Workflowsgithub/gh-aw-firewall | 148 | — | ~2.7k | Automated safety check: Notes | MIT | |
| Authoring CI WorkflowsPostHog/posthog-foss | 721 | — | ~11k | Automated safety check: Pass | MIT | |
| Megatron-LM CI Failure TriageNVIDIA/Megatron-LM | 18k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 |
ykdojo/claude-code-tips
Investigates a failed GitHub Actions run from its URL: pinpoints the real failure, checks the job's history for flakiness, and finds the breaking commit and any existing fix PR.
ruby-git/ruby-git
Diagnoses and fixes failing GitHub Actions runs by identifying the failure, fetching only the relevant logs, finding the root cause and reproducing it locally.
github/gh-aw-firewall
Debug GitHub Actions workflows by downloading logs, analyzing summaries, and understanding how agentic workflows and the AWF firewall work together.
PostHog/posthog-foss
A skill your agent uses when adding or editing a GitHub Actions workflow, composite action, or reusable workflow under .github/ — new CI jobs, triggers, matrices, checkout/clone tuning, action…
NVIDIA/Megatron-LM
Investigates a failing GitHub Actions run or job for Megatron-LM, finds the root cause plus the PR and test author involved, and files a structured bug issue.
PostHog/posthog-foss
Debugs failing GitHub Actions CI runs for PostHog PRs, commits, and branches, and answers broad CI-health questions ("is CI red?", "is master green today?", "what's broken right now?").
github/gh-aw
Drives a real browser from the command line with playwright-cli to open pages, interact, mock requests, save state and work with Playwright tests.
github/gh-aw
Designs and verifies a deterministic grader that measures whether a GitHub Agentic Workflow run reached its real-world or repository outcome.
github/gh-aw
Scaffolds, edits, reloads and debugs a canvas extension that the GitHub Copilot CLI can open in its side panel.
github/gh-aw
Drives an open pull request to merge-ready from inside a GitHub Copilot cloud agent, resolving review threads and local checks concurrently, without merging or retriggering CI.
github/gh-aw
Bumps gh-aw's pinned gh-aw-firewall version, rebuilds generated artifacts, and flags upstream spec or schema changes that need follow-up work.
github/gh-aw
Guide to the console struct tag system in gh-aw: headers, titles, number and cost formats, omitempty, and how structs, slices and maps render in the terminal.
Works with
Categories
Guides your agent through diagnosing failed GitHub Agentic Workflows by downloading run logs, auditing individual runs and reading the artifacts they leave behind. This is an evidence and command reference for working out why a gh-aw workflow failed. The agent uses `gh aw logs` to pull artifacts and logs from GitHub Actions runs, with filters for date ranges and options for a JSON summary, and `gh aw audit` to examine one run by its ID.
gh-aw Workflow Diagnosis fits situations like: A gh-aw workflow run failed and you need to find the cause from its logs; auditing a single agentic workflow run by its run ID; collecting recent failed runs across workflows to look for a pattern; checking what an agent produced in a run, from its output file and patch.
Run `npx skills add github/gh-aw --skill debugging-workflows -a claude-code`. Or copy the skill folder (.github/skills/debugging-workflows in github/gh-aw) into .claude/skills/debugging-workflows in your project. Claude Code loads it when a task matches its description.
Run `npx skills add github/gh-aw --skill debugging-workflows -a codex`. Or copy the skill folder (.github/skills/debugging-workflows in github/gh-aw) into .agents/skills/debugging-workflows in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/gh-aw --skill debugging-workflows -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/debugging-workflows, .gemini/skills/debugging-workflows, .github/skills/debugging-workflows and .opencode/skills/debugging-workflows in your project.
Going by SKILL.md and its folder, gh-aw Workflow Diagnosis needs the command-line tools its instructions call (gh and jq). Our summary lists: The GitHub CLI with the `gh aw` extension; Access to existing GitHub Actions run logs for the workflows.
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
gh-aw Workflow Diagnosis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.9k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with gh-aw Workflow Diagnosis: GitHub Actions Failure Analysis (ykdojo/claude-code-tips, 10k stars), CI/CD Failure Troubleshooting (ruby-git/ruby-git, 1.8k stars), Debugging Workflows (github/gh-aw-firewall, 148 stars) and Authoring CI Workflows (PostHog/posthog-foss, 721 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
github (a GitHub organization, an official publisher) maintains it in github/gh-aw, which has 5,350 GitHub stars. The repository holds 52 skills in this directory. The repository was last updated on October 7, 2026.
Source: github/gh-aw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.