Official agent skill

Review Agentic Workflows

by github in github/gh-aw

Review agentic workflow changes for correctness, security posture, and optimization opportunities with compile, validation, and audit evidence.

OfficialMITAuto-check passedLegal & Compliance

Install Review Agentic Workflows

skills CLI
$ npx skills add github/gh-aw --skill review-agentic-workflows -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install github/gh-aw review-agentic-workflows --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/review-agentic-workflows .claude/skills/review-agentic-workflows && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-agentic-workflows
GitHub stars
5.3k
Token cost
~1k tokens
SKILL.md length
364 words
Files
1
Skills in repo
52
Repo updated
First seen
Licence
MIT

At a glance

Review agentic workflow changes for correctness, security posture, and optimization opportunities with compile, validation, and audit evidence.

  • Works in 6 steps: Verify CLI availability → Scope the review → Compile with validation + security tools → …
  • Tasks that involve SOC 2 and security compliance
  • SKILL.md covers Goals, Self-contained setup (do not…, Review workflow and Review output contract
  • Calls gh and git

What it does

Review Agentic Workflows is an agent skill from github/gh-aw, published by the product's own GitHub organization. Review agentic workflow changes for correctness, security posture, and optimization opportunities with compile, validation, and audit evidence.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering SOC 2 and security compliance. It works with GitHub. The repository describes itself as: GitHub Agentic Workflows. The licence is MIT.

When your agent uses it

  • Tasks that involve SOC 2 and security compliance

Example prompts

  • “/review-agentic-workflows”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Verify CLI availability
  2. Scope the review
  3. Compile with validation + security tools
  4. Enforce security best practices
  5. Detect suspicious weakening changes
  6. Audit history and optimize (when run data exists)

What it can do on your machine

Read from SKILL.md and the folder at commit eb63040. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Agentic Workflows loads about 1k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 364 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from github/gh-aw at commit eb63040, republished under its MIT licence (© github). 364 words, ~1,036 tokens.

Download SKILL.mdSave it as .claude/skills/review-agentic-workflows/SKILL.md (or your agent's skills folder).
name
review-agentic-workflows
description
Review agentic workflow changes for correctness, security posture, and optimization opportunities with compile, validation, and audit evidence.

Review Agentic Workflows

Use this skill when asked to review .github/workflows/*.md agentic workflows or their generated .lock.yml outputs. Reference workflow authoring skill guidance at: https://raw.githubusercontent.com/github/gh-aw/main/.github/skills/agentic-workflows/SKILL.md

Goals

  1. Produce a security-first review of workflow changes.
  2. Compile workflows with validation and security scanners.
  3. Flag suspicious changes that weaken protections.
  4. Use run history (logs/audit) when available to find optimization opportunities.

Self-contained setup (do not assume environment is ready)

Step 0) Verify CLI availability

Run from the repository root:

bash
if gh aw --help >/dev/null 2>&1; then
  echo "gh aw is installed"
else
  if [ -f ./install-gh-aw.sh ]; then
    echo "gh aw is missing. Run the install step before continuing:"
    echo "  bash ./install-gh-aw.sh"
    echo "Then verify:"
    echo "  gh aw --help"
  else
    echo "gh aw is missing and ./install-gh-aw.sh is not present in this checkout."
  fi
  return 1 2>/dev/null || exit 1
fi

Review workflow

1) Scope the review

Run this scope check in the review step:

bash
BASE_REF="${BASE_REF:-origin/main}"
if git rev-parse --verify "$BASE_REF" >/dev/null 2>&1; then
  git diff --name-only "$BASE_REF...HEAD" -- .github/workflows/
else
  git diff --name-only -- .github/workflows/
fi

If source .md files changed, treat generated .lock.yml drift as part of the review.

2) Compile with validation + security tools

For changed workflows, run strict compilation with validators:

bash
gh aw compile --strict --actionlint --zizmor --poutine --runner-guard --yamllint --shellcheck

If gh aw extension is unavailable but local binary exists:

bash
./gh-aw compile --strict --actionlint --zizmor --poutine --runner-guard --yamllint --shellcheck

Fail review on compilation errors or High/Critical security findings unless explicitly justified.

3) Enforce security best practices

Require and verify:

  • least-privilege permissions: (no write-all without explicit rationale)
  • pinned third-party actions by full commit SHA
  • safe handling of untrusted GitHub event data (no direct template injection into shell)
  • explicit safe-outputs limits (max, constrained event/action sets)
  • no broadening of network/tool access without justification
  • no integrity downgrades (for example lower min-integrity)
Show full SKILL.md (166 more words)Show less
4) Detect suspicious weakening changes

Treat these as suspicious until proven safe:

  • permission expansion (especially new write scopes or global writes)
  • relaxed security controls (strict: false, reduced guardrails, disabled scans)
  • larger write blast radius (safe-outputs limits removed or sharply increased)
  • reduced provenance controls (unpinning actions, mutable refs)
  • wider external access (new unrestricted network domains/ecosystems)
  • prompt or script edits that reintroduce command/template injection risk

Use targeted diffs and call out before/after impact.

5) Audit history and optimize (when run data exists)

If workflow run IDs/URLs are available, audit them:

bash
gh aw audit <run-id-or-url>
gh aw logs --start-date -14d --workflow-name <workflow-name>

Look for optimization opportunities:

  • high token/cost usage
  • repeated retries/tool failures
  • long-running steps or bottleneck jobs
  • unnecessary MCP/tool invocations
  • firewall denials causing retries or wasted turns

Recommend minimal, safe optimizations that keep or improve security posture.

Review output contract

Return findings in three sections:

  1. Security regressions (must-fix) — high-confidence weakening changes.
  2. Validation/scanner results — compile and tool outcomes.
  3. Optimization opportunities — optional improvements backed by logs/audit evidence.

Each finding should include severity, file(s), rationale, and a concrete remediation direction.

© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/review-agentic-workflows of github/gh-aw.

Open the folder on GitHubat commit eb63040

Compare with similar skills

Review Agentic Workflows next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Agentic Workflows compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Agentic Workflows this skillgithub/gh-aw5.3k—~1kAutomated safety check: PassMIT
Performing Soc2 Type2 Audit Preparationmukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.0
Audit Ready PR ReviewerGRCEngClub/claude-grc-engineering419—~587Automated safety check: NotesCustom licence
Access Review TriageGRCEngClub/claude-grc-engineering419—~2.4kAutomated safety check: NotesCustom licence
Compliance ScanAojdevStudio/Finance-Guru322—~2.6kAutomated safety check: NotesCustom licence
Nist 800 53Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9391 repos~3.3kAutomated safety check: PassMIT

Similar skills

  • Performing Soc2 Type2 Audit Preparation

    mukul975/Anthropic-Cybersecurity-Skills

    Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing…

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Audit Ready PR Reviewer

    GRCEngClub/claude-grc-engineering

    Reviews pull requests for compliance regressions. An agent skill from GRCEngClub/claude-grc-engineering.

    419 GitHub stars~587 tokensUpdated 3 days ago
    Legal & ComplianceAuto-check: notes
  • Access Review Triage

    GRCEngClub/claude-grc-engineering

    Helps you triage a quarterly user access review from an Okta, Azure AD, AWS IAM, GitHub, or generic CSV/JSON export.

    419 GitHub stars~2.4k tokensUpdated 3 days ago
    Documents & OfficeAuto-check: notes
  • Compliance Scan

    AojdevStudio/Finance-Guru

    Privacy and security compliance scanner for the Finance Guru repo.

    322 GitHub stars~2.6k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    939 GitHub starsUsed in 1 repo~3.3k tokens
    Legal & ComplianceAuto-check passed
  • Soc2

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P).

    939 GitHub starsUsed in 1 repo~2.7k tokens
    Legal & ComplianceAuto-check passed

More from github/gh-aw

All 52 skills in this repo
  • Official

    Drives a real browser from the command line with playwright-cli to open pages, interact, mock requests, save state and work with Playwright tests.

    5.3k GitHub starsUsed in 23 repos~2.8k tokens
    Auto-check passed
  • Official

    Designs and verifies a deterministic grader that measures whether a GitHub Agentic Workflow run reached its real-world or repository outcome.

    5.3k GitHub stars~6.8k tokensUpdated today
    Auto-check passed
  • Official

    Scaffolds, edits, reloads and debugs a canvas extension that the GitHub Copilot CLI can open in its side panel.

    5.3k GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • Official

    Drives an open pull request to merge-ready from inside a GitHub Copilot cloud agent, resolving review threads and local checks concurrently, without merging or retriggering CI.

    5.3k GitHub stars~3.8k tokensUpdated today
    Auto-check: warnings
  • Official

    Bumps gh-aw's pinned gh-aw-firewall version, rebuilds generated artifacts, and flags upstream spec or schema changes that need follow-up work.

    5.3k GitHub stars~899 tokensUpdated today
    Auto-check passed
  • Official

    Guide to the console struct tag system in gh-aw: headers, titles, number and cost formats, omitempty, and how structs, slices and maps render in the terminal.

    5.3k GitHub stars~736 tokensUpdated today
    Auto-check passed

Works with

Questions about Review Agentic Workflows

What does Review Agentic Workflows do?

Review agentic workflow changes for correctness, security posture, and optimization opportunities with compile, validation, and audit evidence. Review Agentic Workflows is an agent skill from github/gh-aw, published by the product's own GitHub organization. Review agentic workflow changes for correctness, security posture, and optimization opportunities with compile, validation, and audit evidence.

When should I use Review Agentic Workflows?

Review Agentic Workflows fits situations like: tasks that involve SOC 2 and security compliance.

How do I install Review Agentic Workflows in Claude Code?

Run `npx skills add github/gh-aw --skill review-agentic-workflows -a claude-code`. Or copy the skill folder (.github/skills/review-agentic-workflows in github/gh-aw) into .claude/skills/review-agentic-workflows in your project. Claude Code loads it when a task matches its description.

How do I install Review Agentic Workflows in Codex?

Run `npx skills add github/gh-aw --skill review-agentic-workflows -a codex`. Or copy the skill folder (.github/skills/review-agentic-workflows in github/gh-aw) into .agents/skills/review-agentic-workflows in your project. Codex loads it when a task matches its description.

Can I use Review Agentic Workflows in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/gh-aw --skill review-agentic-workflows -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-agentic-workflows, .gemini/skills/review-agentic-workflows, .github/skills/review-agentic-workflows and .opencode/skills/review-agentic-workflows in your project.

What does Review Agentic Workflows need to run?

Going by SKILL.md and its folder, Review Agentic Workflows needs the command-line tools its instructions call (gh and git).

Does Review Agentic Workflows access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Review Agentic Workflows safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review Agentic Workflows use?

Review Agentic Workflows is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Agentic Workflows use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review Agentic Workflows?

Skills that share tags, products or a category with Review Agentic Workflows: Performing Soc2 Type2 Audit Preparation (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Audit Ready PR Reviewer (GRCEngClub/claude-grc-engineering, 419 stars), Access Review Triage (GRCEngClub/claude-grc-engineering, 419 stars) and Compliance Scan (AojdevStudio/Finance-Guru, 322 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Agentic Workflows?

github (a GitHub organization, an official publisher) maintains it in github/gh-aw, which has 5,350 GitHub stars. The repository holds 52 skills in this directory. The repository was last updated on October 7, 2026.

Source: github/gh-aw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.