Official agent skill

Diagnose Awf

by github in github/gh-aw-firewall

Diagnose an AWF (Agentic Workflow Firewall) failure from an error, workflow run URL, or symptom.

OfficialMITAuto-check passedBackend & APIs

Install Diagnose Awf

skills CLI
$ npx skills add github/gh-aw-firewall --skill diagnose-awf -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install github/gh-aw-firewall diagnose-awf --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/diagnose-awf .claude/skills/diagnose-awf && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
diagnose-awf
GitHub stars
148
Token cost
~829 tokens
SKILL.md length
278 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Diagnose an AWF (Agentic Workflow Firewall) failure from an error, workflow run URL, or symptom.

  • Works in 6 steps: Read the index —… → Fingerprint the run: AWF version, runner… → Classify the failing boundary: runner,… → …
  • Tasks that involve OAuth and OpenID Connect
  • SKILL.md covers Procedure, Auth routing, Safety rules and Specialist references, plus 1 more section
  • Calls npx and npm

What it does

Diagnose Awf is an agent skill from github/gh-aw-firewall, published by the product's own GitHub organization. Diagnose an AWF (Agentic Workflow Firewall) failure from an error, workflow run URL, or symptom. Covers auth (api-proxy, enterprise/BYOK Copilot, OIDC, mcpg), ARC/DinD and self-hosted runners, alternative runtimes (gVisor/Kata/chroot), Squid/DNS/egress denials, CI and gh-aw safe-output failures, and suspected security regressions. Routes to the canonical diagnosis registry in docs/diagnostics.

Its SKILL.md is about 830 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering OAuth and OpenID Connect. It works with GitHub. The repository describes itself as: GitHub Agentic Workflows Firewall. The licence is MIT.

When your agent uses it

  • Tasks that involve OAuth and OpenID Connect

Example prompts

  • “/diagnose-awf”

Requirements

  • Node.js
  • Docker
  • Pre-approved tools (allowed-tools): Bash(docker:*), Bash(gh:*), Bash(npx:*), Bash(npm:*), Bash(grep:*), Read

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Read the index — docs/diagnostics/README.md
  2. Fingerprint the run: AWF version, runner type (GitHub-hosted /
  3. Classify the failing boundary: runner, runtime, network, auth,
  4. Load only matching records
  5. Probe with the matched finding's read-only probe when the match is
  6. Report: observed symptom, matched finding ID and evidence, affected

What it can do on your machine

Read from SKILL.md and the folder at commit 681e932. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(docker:*)
    • Bash(gh:*)
    • Bash(npx:*)
    • Bash(npm:*)
    • Bash(grep:*)
    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Diagnose Awf loads about 829 tokens when it runs. Until then it costs about 102 tokens; SKILL.md has 278 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~102
When it runs · the whole SKILL.md, loaded when a task matches
~829

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from github/gh-aw-firewall at commit 681e932, republished under its MIT licence (© github). 278 words, ~829 tokens.

Download SKILL.mdSave it as .claude/skills/diagnose-awf/SKILL.md (or your agent's skills folder).
name
diagnose-awf
description
Diagnose an AWF (Agentic Workflow Firewall) failure from an error, workflow run URL, or symptom. Covers auth (api-proxy, enterprise/BYOK Copilot, OIDC, mcpg), ARC/DinD and self-hosted runners, alternative runtimes (gVisor/Kata/chroot), Squid/DNS/egress denials, CI and gh-aw safe-output failures, and suspected security regressions. Routes to the canonical diagnosis registry in docs/diagnostics.
allowed-tools
Bash(docker:*), Bash(gh:*), Bash(npx:*), Bash(npm:*), Bash(grep:*), Read

Diagnose AWF Failures

Single entry point for diagnosing AWF failures. The canonical knowledge lives in the diagnosis registry — this skill only routes and reports.

Procedure

  1. Read the index — docs/diagnostics/README.md for boundary routing and specialist references, and docs/diagnostics/agent-playbook.md for the report shape and safety rules.

  2. Fingerprint the run: AWF version, runner type (GitHub-hosted / self-hosted / ARC+DinD / GHES / GHEC), DOCKER_HOST, GITHUB_SERVER_URL, container runtime, provider, auth mode. Use unknown where unverified.

  3. Classify the failing boundary: runner, runtime, network, auth, ci, security.

  4. Load only matching records:

    bash
    npx tsx scripts/diagnostics/cli.ts search "<redacted error string>" --boundary <boundary>

    Without a clone, use the portable artifact .github/agents/diagnose-awf.md (prefer a tag matching your AWF version).

  5. Probe with the matched finding's read-only probe when the match is ambiguous — one probe at a time.

  6. Report: observed symptom, matched finding ID and evidence, affected version/topology, safe next probe, fix/workaround, citations.

Auth routing

  • api-proxy sidecar / provider token exchange → AUTH-001, AUTH-002
  • GitHub/Copilot enterprise and BYOK routing → AUTH-001, docs/auth-matrix.md
  • gh-aw-launched mcpg HTTP MCP GitHub OIDC → AUTH-003

Check configuration presence/shape, route and health status, and redacted error classes only.

Safety rules

  • Never request API keys, tokens, JWTs, Authorization headers, environment dumps, inference probes, or token exchanges.
  • Never recommend --env-all, disabling isolation, or broadening the domain allowlist by default.
  • Suspected isolation or credential-boundary regressions route to SEC-001 and the repository security review process.
  • If no record matches, say so, name the smallest missing evidence, and stop. Never invent a fix.

Specialist references

  • .github/workflows/shared/self-hosted-failure-modes.md — full runner catalog
  • .github/skills/debug-firewall/SKILL.md — Squid, iptables, container state
  • .github/skills/awf-debug-tools/SKILL.md — log parsing helpers
  • .github/skills/debugging-workflows/SKILL.md — GitHub Actions log retrieval
  • docs/auth-matrix.md, docs/compatibility.md, docs/troubleshooting.md

Updating knowledge

Follow docs/diagnostics/patterns.md. Edit the canonical record, run npm run diagnostics:render, and open a reviewed PR. Never edit generated artifacts or .lock.yml files by hand.

© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/diagnose-awf of github/gh-aw-firewall.

Open the folder on GitHubat commit 681e932

Compare with similar skills

Diagnose Awf next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Diagnose Awf compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Diagnose Awf this skillgithub/gh-aw-firewall148—~829Automated safety check: PassMIT
Better Auth Security Best PracticesEpicenterHQ/epicenter4.8k—~896Automated safety check: PassCustom licence
GitHub OAuth Nango IntegrationAgentWorkforce/relay8651 repos~3.4kAutomated safety check: PassApache-2.0
EmulateUsefulSoftwareCo/executor4.1k—~2.2kAutomated safety check: NotesMIT
Nuget Trusted Publishingrodri-oliveira-dev/Dapper-FluentMap453—~1.3kAutomated safety check: PassMIT
Auth Setupbutterbase-ai/butterbase-skills534—~2.2kAutomated safety check: PassMIT

Similar skills

  • Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

    4.8k GitHub stars~896 tokensUpdated today
    Backend & APIsAuto-check passed
  • GitHub OAuth Nango Integration

    AgentWorkforce/relay

    A skill your agent uses when implementing GitHub OAuth + GitHub App authentication with Nango - provides two-connection pattern for user login and repo access with webhook handling

    865 GitHub starsUsed in 1 repo~3.4k tokens
    Backend & APIsAuto-check passed
  • Emulate

    UsefulSoftwareCo/executor

    Use the @executor-js/emulate service emulators (GitHub, Google, Stripe, Resend, WorkOS, …) to test integrations for real — full OpenAPI specs, working OAuth flows, mintable credentials, and a…

    4.1k GitHub stars~2.2k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Nuget Trusted Publishing

    rodri-oliveira-dev/Dapper-FluentMap

    Review, maintain, or set up NuGet trusted publishing (OIDC) for GitHub Actions.

    453 GitHub stars~1.3k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Auth Setup

    butterbase-ai/butterbase-skills

    A skill your agent uses when configuring OAuth providers (Google/GitHub/Apple/X/etc.), setting up post-login auth hooks, tuning JWT lifetimes, or generating service API keys

    534 GitHub stars~2.2k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Add a new Rome-managed OAuth integration for a third-party service so a user can delegate access by clicking Connect, and Rome can act on the service with the delegated token (the GitHub/Slack model…

    717 GitHub stars~3.6k tokensUpdated today
    Backend & APIsAuto-check passed

More from github/gh-aw-firewall

  • Awf Debug Tools

    github/gh-aw-firewall

    Official

    Practical Python scripts for debugging awf - parse logs, diagnose issues, inspect containers, test domains

    148 GitHub stars~2.6k tokensUpdated today
    Auto-check: notes
  • Recompile Workflows

    github/gh-aw-firewall

    Official

    Regenerate and post-process all agentic workflows. An agent skill from github/gh-aw-firewall.

    148 GitHub stars~568 tokensUpdated today
    Auto-check passed
  • Add LLM Provider

    github/gh-aw-firewall

    Official

    Decide and implement how to support a new LLM provider or agent engine in AWF - either as a proxied provider (api-proxy adapter) or a direct-API engine (domain allowlist only), e.g.

    148 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Debug Firewall

    github/gh-aw-firewall

    Official

    Debug the AWF firewall by inspecting Docker containers (awf-squid, awf-agent), analyzing Squid access logs, checking iptables rules, and troubleshooting blocked domains or network issues.

    148 GitHub stars~1.2k tokensUpdated today
    Auto-check: notes
  • Debugging Workflows

    github/gh-aw-firewall

    Official

    Debug GitHub Actions workflows by downloading logs, analyzing summaries, and understanding how agentic workflows and the AWF firewall work together.

    148 GitHub stars~2.7k tokensUpdated today
    Auto-check: notes

Works with

Categories

Questions about Diagnose Awf

What does Diagnose Awf do?

Diagnose an AWF (Agentic Workflow Firewall) failure from an error, workflow run URL, or symptom. Diagnose Awf is an agent skill from github/gh-aw-firewall, published by the product's own GitHub organization. Diagnose an AWF (Agentic Workflow Firewall) failure from an error, workflow run URL, or symptom.

When should I use Diagnose Awf?

Diagnose Awf fits situations like: tasks that involve OAuth and OpenID Connect.

How do I install Diagnose Awf in Claude Code?

Run `npx skills add github/gh-aw-firewall --skill diagnose-awf -a claude-code`. Or copy the skill folder (.claude/skills/diagnose-awf in github/gh-aw-firewall) into .claude/skills/diagnose-awf in your project. Claude Code loads it when a task matches its description.

How do I install Diagnose Awf in Codex?

Run `npx skills add github/gh-aw-firewall --skill diagnose-awf -a codex`. Or copy the skill folder (.claude/skills/diagnose-awf in github/gh-aw-firewall) into .agents/skills/diagnose-awf in your project. Codex loads it when a task matches its description.

Can I use Diagnose Awf in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/gh-aw-firewall --skill diagnose-awf -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/diagnose-awf, .gemini/skills/diagnose-awf, .github/skills/diagnose-awf and .opencode/skills/diagnose-awf in your project.

What does Diagnose Awf need to run?

Going by SKILL.md and its folder, Diagnose Awf needs the command-line tools its instructions call (npx and npm). Our summary lists: Node.js; Docker. Its frontmatter pre-approves these tools: Bash(docker:*), Bash(gh:*), Bash(npx:*), Bash(npm:*), Bash(grep:*), Read.

Does Diagnose Awf access the network?

SKILL.md contains no URLs. Its commands use npx and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Diagnose Awf safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Diagnose Awf use?

Diagnose Awf is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Diagnose Awf use?

About 829 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Diagnose Awf?

Skills that share tags, products or a category with Diagnose Awf: Better Auth Security Best Practices (EpicenterHQ/epicenter, 4.8k stars), GitHub OAuth Nango Integration (AgentWorkforce/relay, 865 stars), Emulate (UsefulSoftwareCo/executor, 4.1k stars) and Nuget Trusted Publishing (rodri-oliveira-dev/Dapper-FluentMap, 453 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Diagnose Awf?

github (a GitHub organization, an official publisher) maintains it in github/gh-aw-firewall, which has 148 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 7, 2026.

Source: github/gh-aw-firewall on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.