Better Auth Security Best Practices
EpicenterHQ/epicenter
Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.
Diagnose an AWF (Agentic Workflow Firewall) failure from an error, workflow run URL, or symptom.
$ npx skills add github/gh-aw-firewall --skill diagnose-awf -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install github/gh-aw-firewall diagnose-awf --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/diagnose-awf .claude/skills/diagnose-awf && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "diagnose-awf" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.claude/skills/diagnose-awf into .claude/skills/diagnose-awf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "diagnose-awf", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/github/gh-aw-firewall/tree/main/.claude/skills/diagnose-awfType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add github/gh-aw-firewall --skill diagnose-awf -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install github/gh-aw-firewall diagnose-awf --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/diagnose-awf .agents/skills/diagnose-awf && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "diagnose-awf" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.claude/skills/diagnose-awf into .agents/skills/diagnose-awf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "diagnose-awf", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add github/gh-aw-firewall --skill diagnose-awf -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install github/gh-aw-firewall diagnose-awf --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/diagnose-awf .cursor/skills/diagnose-awf && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "diagnose-awf" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.claude/skills/diagnose-awf into .cursor/skills/diagnose-awf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "diagnose-awf", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/github/gh-aw-firewall.git --path .claude/skills/diagnose-awf--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add github/gh-aw-firewall --skill diagnose-awf -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install github/gh-aw-firewall diagnose-awf --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/diagnose-awf .gemini/skills/diagnose-awf && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "diagnose-awf" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.claude/skills/diagnose-awf into .gemini/skills/diagnose-awf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "diagnose-awf", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install github/gh-aw-firewall diagnose-awfInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add github/gh-aw-firewall --skill diagnose-awf -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/diagnose-awf .github/skills/diagnose-awf && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "diagnose-awf" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.claude/skills/diagnose-awf into .github/skills/diagnose-awf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "diagnose-awf", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add github/gh-aw-firewall --skill diagnose-awf -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install github/gh-aw-firewall diagnose-awf --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/diagnose-awf .opencode/skills/diagnose-awf && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "diagnose-awf" agent skill from https://github.com/github/gh-aw-firewall/tree/main/.claude/skills/diagnose-awf into .opencode/skills/diagnose-awf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "diagnose-awf", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
diagnose-awfDiagnose an AWF (Agentic Workflow Firewall) failure from an error, workflow run URL, or symptom.
Diagnose Awf is an agent skill from github/gh-aw-firewall, published by the product's own GitHub organization. Diagnose an AWF (Agentic Workflow Firewall) failure from an error, workflow run URL, or symptom. Covers auth (api-proxy, enterprise/BYOK Copilot, OIDC, mcpg), ARC/DinD and self-hosted runners, alternative runtimes (gVisor/Kata/chroot), Squid/DNS/egress denials, CI and gh-aw safe-output failures, and suspected security regressions. Routes to the canonical diagnosis registry in docs/diagnostics.
Its SKILL.md is about 830 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering OAuth and OpenID Connect. It works with GitHub. The repository describes itself as: GitHub Agentic Workflows Firewall. The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 681e932. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
Bash(docker:*)Bash(gh:*)Bash(npx:*)Bash(npm:*)Bash(grep:*)ReadFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npx and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Diagnose Awf loads about 829 tokens when it runs. Until then it costs about 102 tokens; SKILL.md has 278 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from github/gh-aw-firewall at commit 681e932, republished under its MIT licence (© github). 278 words, ~829 tokens.
.claude/skills/diagnose-awf/SKILL.md (or your agent's skills folder).Single entry point for diagnosing AWF failures. The canonical knowledge lives in the diagnosis registry — this skill only routes and reports.
Read the index — docs/diagnostics/README.md
for boundary routing and specialist references, and
docs/diagnostics/agent-playbook.md
for the report shape and safety rules.
Fingerprint the run: AWF version, runner type (GitHub-hosted /
self-hosted / ARC+DinD / GHES / GHEC), DOCKER_HOST, GITHUB_SERVER_URL,
container runtime, provider, auth mode. Use unknown where unverified.
Classify the failing boundary: runner, runtime, network, auth,
ci, security.
Load only matching records:
npx tsx scripts/diagnostics/cli.ts search "<redacted error string>" --boundary <boundary>Without a clone, use the portable artifact
.github/agents/diagnose-awf.md (prefer a tag matching your AWF version).
Probe with the matched finding's read-only probe when the match is ambiguous — one probe at a time.
Report: observed symptom, matched finding ID and evidence, affected version/topology, safe next probe, fix/workaround, citations.
AUTH-001, AUTH-002AUTH-001, docs/auth-matrix.mdAUTH-003Check configuration presence/shape, route and health status, and redacted error classes only.
Authorization headers, environment
dumps, inference probes, or token exchanges.--env-all, disabling isolation, or broadening the domain
allowlist by default.SEC-001 and
the repository security review process..github/workflows/shared/self-hosted-failure-modes.md — full runner catalog.github/skills/debug-firewall/SKILL.md — Squid, iptables, container state.github/skills/awf-debug-tools/SKILL.md — log parsing helpers.github/skills/debugging-workflows/SKILL.md — GitHub Actions log retrievaldocs/auth-matrix.md, docs/compatibility.md, docs/troubleshooting.mdFollow docs/diagnostics/patterns.md.
Edit the canonical record, run npm run diagnostics:render, and open a reviewed
PR. Never edit generated artifacts or .lock.yml files by hand.
© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/diagnose-awf of github/gh-aw-firewall.
Open the folder on GitHubat commit 681e932
Diagnose Awf next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Diagnose Awf this skillgithub/gh-aw-firewall | 148 | — | ~829 | Automated safety check: Pass | MIT | |
| Better Auth Security Best PracticesEpicenterHQ/epicenter | 4.8k | — | ~896 | Automated safety check: Pass | Custom licence | |
| GitHub OAuth Nango IntegrationAgentWorkforce/relay | 865 | 1 repos | ~3.4k | Automated safety check: Pass | Apache-2.0 | |
| EmulateUsefulSoftwareCo/executor | 4.1k | — | ~2.2k | Automated safety check: Notes | MIT | |
| Nuget Trusted Publishingrodri-oliveira-dev/Dapper-FluentMap | 453 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Auth Setupbutterbase-ai/butterbase-skills | 534 | — | ~2.2k | Automated safety check: Pass | MIT |
EpicenterHQ/epicenter
Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.
AgentWorkforce/relay
A skill your agent uses when implementing GitHub OAuth + GitHub App authentication with Nango - provides two-connection pattern for user login and repo access with webhook handling
UsefulSoftwareCo/executor
Use the @executor-js/emulate service emulators (GitHub, Google, Stripe, Resend, WorkOS, …) to test integrations for real — full OpenAPI specs, working OAuth flows, mintable credentials, and a…
rodri-oliveira-dev/Dapper-FluentMap
Review, maintain, or set up NuGet trusted publishing (OIDC) for GitHub Actions.
butterbase-ai/butterbase-skills
A skill your agent uses when configuring OAuth providers (Google/GitHub/Apple/X/etc.), setting up post-login auth hooks, tuning JWT lifetimes, or generating service API keys
rome-os/rome
Add a new Rome-managed OAuth integration for a third-party service so a user can delegate access by clicking Connect, and Rome can act on the service with the delegated token (the GitHub/Slack model…
github/gh-aw-firewall
Practical Python scripts for debugging awf - parse logs, diagnose issues, inspect containers, test domains
github/gh-aw-firewall
Regenerate and post-process all agentic workflows. An agent skill from github/gh-aw-firewall.
github/gh-aw-firewall
Decide and implement how to support a new LLM provider or agent engine in AWF - either as a proxied provider (api-proxy adapter) or a direct-API engine (domain allowlist only), e.g.
github/gh-aw-firewall
Debug the AWF firewall by inspecting Docker containers (awf-squid, awf-agent), analyzing Squid access logs, checking iptables rules, and troubleshooting blocked domains or network issues.
github/gh-aw-firewall
Debug GitHub Actions workflows by downloading logs, analyzing summaries, and understanding how agentic workflows and the AWF firewall work together.
Works with
Categories
Diagnose an AWF (Agentic Workflow Firewall) failure from an error, workflow run URL, or symptom. Diagnose Awf is an agent skill from github/gh-aw-firewall, published by the product's own GitHub organization. Diagnose an AWF (Agentic Workflow Firewall) failure from an error, workflow run URL, or symptom.
Diagnose Awf fits situations like: tasks that involve OAuth and OpenID Connect.
Run `npx skills add github/gh-aw-firewall --skill diagnose-awf -a claude-code`. Or copy the skill folder (.claude/skills/diagnose-awf in github/gh-aw-firewall) into .claude/skills/diagnose-awf in your project. Claude Code loads it when a task matches its description.
Run `npx skills add github/gh-aw-firewall --skill diagnose-awf -a codex`. Or copy the skill folder (.claude/skills/diagnose-awf in github/gh-aw-firewall) into .agents/skills/diagnose-awf in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/gh-aw-firewall --skill diagnose-awf -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/diagnose-awf, .gemini/skills/diagnose-awf, .github/skills/diagnose-awf and .opencode/skills/diagnose-awf in your project.
Going by SKILL.md and its folder, Diagnose Awf needs the command-line tools its instructions call (npx and npm). Our summary lists: Node.js; Docker. Its frontmatter pre-approves these tools: Bash(docker:*), Bash(gh:*), Bash(npx:*), Bash(npm:*), Bash(grep:*), Read.
SKILL.md contains no URLs. Its commands use npx and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Diagnose Awf is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 829 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Diagnose Awf: Better Auth Security Best Practices (EpicenterHQ/epicenter, 4.8k stars), GitHub OAuth Nango Integration (AgentWorkforce/relay, 865 stars), Emulate (UsefulSoftwareCo/executor, 4.1k stars) and Nuget Trusted Publishing (rodri-oliveira-dev/Dapper-FluentMap, 453 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
github (a GitHub organization, an official publisher) maintains it in github/gh-aw-firewall, which has 148 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 7, 2026.
Source: github/gh-aw-firewall on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.