Official agent skill

Recompile Workflows

by github in github/gh-aw-firewall

Regenerate and post-process all agentic workflows. An agent skill from github/gh-aw-firewall.

OfficialMITAuto-check passed

Install Recompile Workflows

skills CLI
$ npx skills add github/gh-aw-firewall --skill recompile-workflows -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install github/gh-aw-firewall recompile-workflows --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/github/gh-aw-firewall.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/recompile-workflows .claude/skills/recompile-workflows && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
recompile-workflows
GitHub stars
148
Token cost
~568 tokens
SKILL.md length
228 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Regenerate and post-process all agentic workflows. An agent skill from github/gh-aw-firewall.

  • Works in 2 steps: Compile or upgrade workflows → Run post-processing script (ALWAYS)
  • Gh-aw is updated
  • SKILL.md covers IMPORTANT: Post-processing is…, Steps, Common Issues and Verification
  • Calls gh, npx and git

What it does

Recompile Workflows is an agent skill from github/gh-aw-firewall, published by the product's own GitHub organization. Regenerate and post-process all agentic workflows. Use when gh-aw is updated, workflow .md files change, or when asked to recompile/regenerate workflows.

Its SKILL.md is about 570 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with GitHub. The repository describes itself as: GitHub Agentic Workflows Firewall. The licence is MIT.

When your agent uses it

  • Gh-aw is updated
  • Workflow .md files change
  • Asked to recompile/regenerate workflows

Example prompts

  • “/recompile-workflows”

Requirements

  • Node.js
  • Pre-approved tools (allowed-tools): Bash(gh:*), Bash(npx:*), Read, Glob, Edit

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. Compile or upgrade workflows
  2. Run post-processing script (ALWAYS)

What it can do on your machine

Read from SKILL.md and the folder at commit 681e932. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(gh:*)
    • Bash(npx:*)
    • Read
    • Glob
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • npx
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, npx and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Recompile Workflows loads about 568 tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 228 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~568

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from github/gh-aw-firewall at commit 681e932, republished under its MIT licence (© github). 228 words, ~568 tokens.

Download SKILL.mdSave it as .claude/skills/recompile-workflows/SKILL.md (or your agent's skills folder).
name
recompile-workflows
description
Regenerate and post-process all agentic workflows. Use when gh-aw is updated, workflow .md files change, or when asked to recompile/regenerate workflows.
allowed-tools
Bash(gh:*), Bash(npx:*), Read, Glob, Edit

Recompile Agentic Workflows

Use this skill when you need to regenerate all agentic workflow lock files and apply post-processing.

IMPORTANT: Post-processing is required after EVERY lock file change

Any time .lock.yml files are regenerated — whether via gh aw compile, gh aw upgrade, or any other gh-aw command — you MUST run the post-processing script afterward. This is not optional.

Steps

1. Compile or upgrade workflows

Use whichever command is appropriate:

bash
# Full upgrade (updates agents, actions, codemods, then compiles)
gh aw upgrade

# Just recompile (when only .md workflow files changed)
gh aw compile

If any workflow fails to compile (e.g., strict mode violations like contents: write), fix the .md source file and re-run.

2. Run post-processing script (ALWAYS)

This step MUST run every time lock files are regenerated, regardless of how they were generated.

The post-processing script replaces the "Install awf binary" step in smoke and build-test workflows with local build+install steps, so CI tests the repo's own code instead of a released binary.

bash
npx ts-node scripts/ci/postprocess-smoke-workflows.ts

This updates these lock files:

  • smoke-copilot.lock.yml
  • smoke-claude.lock.yml
  • smoke-chroot.lock.yml
  • build-test.lock.yml

Common Issues

Strict mode violations

Newer gh-aw versions enforce strict mode which disallows write permissions like contents: write, issues: write, etc. Workflows should use safe-outputs for write operations and only request read permissions.

Discussion category warnings

Warnings about "General" vs "general" discussion category casing are non-blocking.

Verification

After both steps, run git diff --stat to review all changed files. Expect changes in:

  • .github/agents/ - Updated agent files
  • .github/aw/actions-lock.json - Updated action pins
  • .github/workflows/*.lock.yml - Regenerated lock files
  • .github/workflows/*.md - If codemods applied fixes

© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/recompile-workflows of github/gh-aw-firewall.

Open the folder on GitHubat commit 681e932

Compare with similar skills

Recompile Workflows next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Recompile Workflows compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Recompile Workflows this skillgithub/gh-aw-firewall148—~568Automated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Diagnosing Superpowers Sessionsobra/superpowers296k3 repos~1.7kAutomated safety check: PassMIT
GitHub Deep Researchbytedance/deer-flow83k5 repos~1.3kAutomated safety check: PassMIT
Greplooponyx-dot-app/onyx32k4 repos~3.3kAutomated safety check: PassMIT
Update V8 Versionopeninterpreter/openinterpreter69k2 repos~845Automated safety check: PassApache-2.0

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Investigates a session where Superpowers went wrong, reads the transcripts on disk and produces an evidence-cited report, optionally prepared as a bug report for the maintainers.

    296k GitHub starsUsed in 3 repos~1.7k tokens
    Agent WorkflowsAuto-check passed
  • GitHub Deep Research

    bytedance/deer-flow

    Researches a GitHub repository over four rounds using the GitHub API and web search, then writes a structured markdown report with timeline, metrics and Mermaid diagrams.

    83k GitHub starsUsed in 5 repos~1.3k tokens
    Research & ScienceAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed
  • Update V8 Version

    openinterpreter/openinterpreter

    Bumps the pinned v8 and rusty_v8 versions in Codex, validates the release-candidate path with the v8-canary check, and traces failures to upstream build changes.

    69k GitHub starsUsed in 2 repos~845 tokens
    DevOps & CloudAuto-check passed
  • Check PR

    onyx-dot-app/onyx

    Checks a GitHub, GitLab, or Perforce (p4) pull request (or merge request, or shelved changelist) for unresolved review comments, failing status checks, and incomplete PR descriptions.

    32k GitHub starsUsed in 2 repos~2.3k tokens
    DevelopmentAuto-check passed

More from github/gh-aw-firewall

  • Awf Debug Tools

    github/gh-aw-firewall

    Official

    Practical Python scripts for debugging awf - parse logs, diagnose issues, inspect containers, test domains

    148 GitHub stars~2.6k tokensUpdated today
    Auto-check: notes
  • Add LLM Provider

    github/gh-aw-firewall

    Official

    Decide and implement how to support a new LLM provider or agent engine in AWF - either as a proxied provider (api-proxy adapter) or a direct-API engine (domain allowlist only), e.g.

    148 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Debug Firewall

    github/gh-aw-firewall

    Official

    Debug the AWF firewall by inspecting Docker containers (awf-squid, awf-agent), analyzing Squid access logs, checking iptables rules, and troubleshooting blocked domains or network issues.

    148 GitHub stars~1.2k tokensUpdated today
    Auto-check: notes
  • Debugging Workflows

    github/gh-aw-firewall

    Official

    Debug GitHub Actions workflows by downloading logs, analyzing summaries, and understanding how agentic workflows and the AWF firewall work together.

    148 GitHub stars~2.7k tokensUpdated today
    Auto-check: notes
  • Diagnose Awf

    github/gh-aw-firewall

    Official

    Diagnose an AWF (Agentic Workflow Firewall) failure from an error, workflow run URL, or symptom.

    148 GitHub stars~829 tokensUpdated today
    Auto-check passed

Works with

Questions about Recompile Workflows

What does Recompile Workflows do?

Regenerate and post-process all agentic workflows. An agent skill from github/gh-aw-firewall. Recompile Workflows is an agent skill from github/gh-aw-firewall, published by the product's own GitHub organization. Regenerate and post-process all agentic workflows.

When should I use Recompile Workflows?

Recompile Workflows fits situations like: gh-aw is updated; workflow .md files change; asked to recompile/regenerate workflows.

How do I install Recompile Workflows in Claude Code?

Run `npx skills add github/gh-aw-firewall --skill recompile-workflows -a claude-code`. Or copy the skill folder (.claude/skills/recompile-workflows in github/gh-aw-firewall) into .claude/skills/recompile-workflows in your project. Claude Code loads it when a task matches its description.

How do I install Recompile Workflows in Codex?

Run `npx skills add github/gh-aw-firewall --skill recompile-workflows -a codex`. Or copy the skill folder (.claude/skills/recompile-workflows in github/gh-aw-firewall) into .agents/skills/recompile-workflows in your project. Codex loads it when a task matches its description.

Can I use Recompile Workflows in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/gh-aw-firewall --skill recompile-workflows -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/recompile-workflows, .gemini/skills/recompile-workflows, .github/skills/recompile-workflows and .opencode/skills/recompile-workflows in your project.

What does Recompile Workflows need to run?

Going by SKILL.md and its folder, Recompile Workflows needs the command-line tools its instructions call (gh, npx and git). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Bash(gh:*), Bash(npx:*), Read, Glob, Edit.

Does Recompile Workflows access the network?

SKILL.md contains no URLs. Its commands use gh, npx and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Recompile Workflows safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Recompile Workflows use?

Recompile Workflows is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Recompile Workflows use?

About 568 tokens (SKILL.md is roughly 2.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Recompile Workflows?

Skills that share tags, products or a category with Recompile Workflows: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Diagnosing Superpowers Sessions (obra/superpowers, 296k stars), GitHub Deep Research (bytedance/deer-flow, 83k stars) and Greploop (onyx-dot-app/onyx, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Recompile Workflows?

github (a GitHub organization, an official publisher) maintains it in github/gh-aw-firewall, which has 148 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 7, 2026.

Source: github/gh-aw-firewall on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.