Official agent skill

Firewall AI Gateway Debug

by vercel-labs in vercel-labs/vercel-openclaw-archived

Firewall and Vercel AI Gateway debugging for vercel-openclaw: network policy allowlists, OIDC token refresh, AI Gateway transform rules, firewall learning/enforcement, and sandbox.update…

OfficialMITAuto-check passedDevelopment

Install Firewall AI Gateway Debug

skills CLI
$ npx skills add vercel-labs/vercel-openclaw-archived --skill firewall-ai-gateway-debug -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vercel-labs/vercel-openclaw-archived firewall-ai-gateway-debug --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vercel-labs/vercel-openclaw-archived.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/firewall-ai-gateway-debug .claude/skills/firewall-ai-gateway-debug && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
firewall-ai-gateway-debug
GitHub stars
117
Token cost
~550 tokens
SKILL.md length
199 words
Files
1
Skills in repo
16
Repo updated
First seen
Licence
MIT

At a glance

Firewall and Vercel AI Gateway debugging for vercel-openclaw: network policy allowlists, OIDC token refresh, AI Gateway transform rules, firewall learning/enforcement, and sandbox.update…

  • Firewall policy application fails
  • SKILL.md covers Evidence First, Critical Splits, Invariants and Fix Boundaries, plus 1 more section
  • Calls node
  • Tasks that involve OAuth and OpenID Connect

What it does

Firewall AI Gateway Debug is an agent skill from vercel-labs/vercel-openclaw-archived, published by the product's own GitHub organization. Firewall and Vercel AI Gateway debugging for vercel-openclaw: network policy allowlists, OIDC token refresh, AI Gateway transform rules, firewall learning/enforcement, and sandbox.update networkPolicy calls. Use when model calls, egress, token refresh, or firewall policy application fails.

Its SKILL.md is about 550 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering OAuth and OpenID Connect and Debugging. It works with Vercel. The repository describes itself as: Deploy OpenClaw on Vercel. The licence is MIT.

When your agent uses it

  • Firewall policy application fails
  • Tasks that involve OAuth and OpenID Connect
  • Tasks that involve Debugging

Example prompts

  • “/firewall-ai-gateway-debug”

What it can do on your machine

Read from SKILL.md and the folder at commit d592f7b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Firewall AI Gateway Debug loads about 550 tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 199 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~550

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vercel-labs/vercel-openclaw-archived at commit d592f7b, republished under its MIT licence (© vercel-labs). 199 words, ~550 tokens.

Download SKILL.mdSave it as .claude/skills/firewall-ai-gateway-debug/SKILL.md (or your agent's skills folder).
name
firewall-ai-gateway-debug
description
Firewall and Vercel AI Gateway debugging for vercel-openclaw: network policy allowlists, OIDC token refresh, AI Gateway transform rules, firewall learning/enforcement, and sandbox.update networkPolicy calls. Use when model calls, egress, token refresh, or firewall policy application fails.

Firewall AI Gateway Debug

Use this skill for model-call failures, egress blocks, network policy drift, or AI Gateway token refresh problems.

Evidence First

Collect:

  • GET /api/admin/preflight or launch verification preflight evidence.
  • GET /api/admin/logs filtered for firewall., token., gateway., watchdog..
  • GET /api/admin/sandbox-diag.
  • Current firewall mode and learned/allowed domains from admin surfaces.
  • Sanitized model-call or gateway error body. Do not print Authorization tokens.

Critical Splits

  • AI Gateway credential unavailable vs expired vs circuit-breaker-open.
  • Static API key bypass vs OIDC token path.
  • Firewall learning/allowlist issue vs model provider/API issue.
  • OPENAI_BASE_URL inside sandbox is present, while Authorization is injected by network policy transform.
  • Policy object shape changes when an AI Gateway token exists.

Invariants

  • AI Gateway token never enters sandbox files or env.
  • ai-gateway.vercel.sh stays allowed even in enforcing mode.
  • Token refresh applies sandbox.update({ networkPolicy }); it should not rewrite config files or restart the gateway.
  • Public/admin display URLs must not expose deployment-protection bypass secrets.

Fix Boundaries

  • Primary: src/server/firewall/{domains,policy,state}.ts.
  • Token path: src/server/sandbox/lifecycle.ts, src/server/deploy-preflight.ts.
  • Public URLs: src/server/public-url.ts.
  • Tests: firewall policy tests, token refresh tests, launch-verify/preflight tests.
  • Docs: docs/environment-variables.md, docs/deployment-protection.md, lat.md/sandbox-lifecycle.md.

Verification

bash
node scripts/verify.mjs --steps=test,typecheck
lat check

For live incidents, prove a model call succeeds after the policy/token change and that no token value appears in logs, UI, or sandbox config.

© vercel-labs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/firewall-ai-gateway-debug of vercel-labs/vercel-openclaw-archived.

Open the folder on GitHubat commit d592f7b

Compare with similar skills

Firewall AI Gateway Debug next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Firewall AI Gateway Debug compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Firewall AI Gateway Debug this skillvercel-labs/vercel-openclaw-archived117—~550Automated safety check: PassMIT
Testingdoorkeeper-gem/doorkeeper5.5k—~1.6kAutomated safety check: PassMIT
Vercel Advanced Troubleshootingjeremylongshore/tons-of-skills-marketplace2.8k—~2.1kAutomated safety check: PassMIT
Vercel Common Errorsjeremylongshore/tons-of-skills-marketplace2.8k—~1.8kAutomated safety check: PassMIT
Replica DeployJakeschincariol/replica-skill1.2k—~1.1kAutomated safety check: PassMIT
Access Protected Vercel Deploymentvercel/vercel-plugin301—~1.9kAutomated safety check: NotesCustom licence

Similar skills

  • Testing

    doorkeeper-gem/doorkeeper

    Write correct and complete RSpec tests for Doorkeeper. An agent skill from doorkeeper-gem/doorkeeper.

    5.5k GitHub stars~1.6k tokensUpdated 2 days ago
    Testing & QAAuto-check passed
  • Vercel Advanced Troubleshooting

    jeremylongshore/tons-of-skills-marketplace

    Advanced debugging for hard-to-diagnose Vercel issues including cold starts, edge errors, and function tracing.

    2.8k GitHub stars~2.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Vercel Common Errors

    jeremylongshore/tons-of-skills-marketplace

    Diagnose and fix common Vercel deployment and function errors.

    2.8k GitHub stars~1.8k tokensUpdated today
    Backend & APIsAuto-check passed
  • Replica Deploy

    Jakeschincariol/replica-skill

    Ships an app clone live on the user's own domain: a preflight gate (tests green, parity must-haves done, rebrand sweep clean, listing linted, legal pages up), production database and env vars, the…

    1.2k GitHub stars~1.1k tokensUpdated 6 days ago
    MobileAuto-check passed
  • Official

    Access and test Vercel deployments protected by Vercel Authentication, SSO, or Deployment Protection.

    301 GitHub stars~1.9k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Frontmcp Config

    agentfront/frontmcp

    A skill your agent uses when configuring a FrontMCP server through frontmcp.config or the @FrontMcp options.

    146 GitHub stars~7k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed

More from vercel-labs/vercel-openclaw-archived

All 16 skills in this repo
  • Channel Debug Core

    vercel-labs/vercel-openclaw-archived

    Official

    Channel webhook triage for vercel-openclaw Slack/Telegram/Discord/WhatsApp issues: prove deployment state, collect admin readiness endpoints, build evidence-first handoff before fixes.

    117 GitHub stars~2k tokensUpdated 4 mo ago
    Auto-check: notes
  • Lat Md

    vercel-labs/vercel-openclaw-archived

    Official

    Writing and maintaining lat.md documentation files — structured markdown that describes a project's architecture, design decisions, and test specs.

    117 GitHub starsUsed in 1 repo~1.2k tokens
    Auto-check passed
  • Cron Watchdog Debug

    vercel-labs/vercel-openclaw-archived

    Official

    Cron and watchdog debugging for vercel-openclaw: Vercel Cron auth, persisted OpenClaw jobs, cron wake keys, token refresh, restore oracle, hot spare, and watchdog reports.

    117 GitHub stars~1.6k tokensUpdated 4 mo ago
    Auto-check passed
  • Auth Store Debug

    vercel-labs/vercel-openclaw-archived

    Official

    Auth and store debugging for vercel-openclaw: admin-secret mode, Sign in with Vercel, session cookies, CSRF, LOCALREADONLY, Redis vs memory store, keyspace namespacing, and metadata shape migrations.

    117 GitHub stars~465 tokensUpdated 4 mo ago
    Auto-check passed
  • Gateway Proxy Debug

    vercel-labs/vercel-openclaw-archived

    Official

    Gateway and proxy debugging for vercel-openclaw: /gateway routing, HTML injection, WebSocket rewrite, gateway-token handoff, waiting page, status heartbeat, sandbox port URL cache, and proxy auth.

    117 GitHub stars~573 tokensUpdated 4 mo ago
    Auto-check passed
  • Openclaw Bootstrap Debug

    vercel-labs/vercel-openclaw-archived

    Official

    OpenClaw bootstrap, bundle, config, and restore-asset debugging for vercel-openclaw: openclaw.bundle sidecars, plugin discovery, channel catalog, restart scripts, config hashes, dynamic resume…

    117 GitHub stars~494 tokensUpdated 4 mo ago
    Auto-check passed

Works with

Questions about Firewall AI Gateway Debug

What does Firewall AI Gateway Debug do?

Firewall and Vercel AI Gateway debugging for vercel-openclaw: network policy allowlists, OIDC token refresh, AI Gateway transform rules, firewall learning/enforcement, and sandbox.update…. Firewall AI Gateway Debug is an agent skill from vercel-labs/vercel-openclaw-archived, published by the product's own GitHub organization.update networkPolicy calls.

When should I use Firewall AI Gateway Debug?

Firewall AI Gateway Debug fits situations like: firewall policy application fails; tasks that involve OAuth and OpenID Connect; tasks that involve Debugging.

How do I install Firewall AI Gateway Debug in Claude Code?

Run `npx skills add vercel-labs/vercel-openclaw-archived --skill firewall-ai-gateway-debug -a claude-code`. Or copy the skill folder (.agents/skills/firewall-ai-gateway-debug in vercel-labs/vercel-openclaw-archived) into .claude/skills/firewall-ai-gateway-debug in your project. Claude Code loads it when a task matches its description.

How do I install Firewall AI Gateway Debug in Codex?

Run `npx skills add vercel-labs/vercel-openclaw-archived --skill firewall-ai-gateway-debug -a codex`. Or copy the skill folder (.agents/skills/firewall-ai-gateway-debug in vercel-labs/vercel-openclaw-archived) into .agents/skills/firewall-ai-gateway-debug in your project. Codex loads it when a task matches its description.

Can I use Firewall AI Gateway Debug in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vercel-labs/vercel-openclaw-archived --skill firewall-ai-gateway-debug -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/firewall-ai-gateway-debug, .gemini/skills/firewall-ai-gateway-debug, .github/skills/firewall-ai-gateway-debug and .opencode/skills/firewall-ai-gateway-debug in your project.

What does Firewall AI Gateway Debug need to run?

Going by SKILL.md and its folder, Firewall AI Gateway Debug needs the command-line tools its instructions call (node).

Does Firewall AI Gateway Debug access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Firewall AI Gateway Debug safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Firewall AI Gateway Debug use?

Firewall AI Gateway Debug is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Firewall AI Gateway Debug use?

About 550 tokens (SKILL.md is roughly 2.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Firewall AI Gateway Debug?

Skills that share tags, products or a category with Firewall AI Gateway Debug: Testing (doorkeeper-gem/doorkeeper, 5.5k stars), Vercel Advanced Troubleshooting (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Vercel Common Errors (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Replica Deploy (Jakeschincariol/replica-skill, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Firewall AI Gateway Debug?

vercel-labs (a GitHub organization, an official publisher) maintains it in vercel-labs/vercel-openclaw-archived, which has 117 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on May 15, 2026.

Source: vercel-labs/vercel-openclaw-archived on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.