Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 9 additions & 5 deletions .github/agents/agentic-workflows.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ This is a **dispatcher agent** that routes your request to the appropriate speci

- **Creating new workflows**: Routes to `create` prompt
- **Updating existing workflows**: Routes to `update` prompt
- **Debugging workflows**: Routes to `debug` prompt
- **Diagnosis, patching, and active debugging**: Routes to `debug-agentic-workflow` for the local-first strategy, evidence triage and live gates
- **Upgrading workflows**: Routes to `upgrade-agentic-workflows` prompt
- **Creating report-generating workflows**: Routes to `report` prompt — consult this whenever the workflow posts status updates, audits, analyses, or any structured output as issues, discussions, or comments
- **Creating shared components**: Routes to `create-shared-agentic-workflow` prompt
Expand All @@ -47,7 +47,8 @@ Workflows may optionally include:
## Problems This Solves

- **Workflow Creation**: Design secure, validated agentic workflows with proper triggers, tools, and permissions
- **Workflow Debugging**: Analyze logs, identify missing tools, investigate failures, and fix configuration issues
- **Diagnosis and Patching**: Analyze evidence and produce regression-backed fixes without requiring live runs
- **Active Debugging**: Run bounded edit/test/run/audit loops where permitted, stopping on dispatch 403 responses
- **Version Upgrades**: Migrate workflows to new gh-aw versions, apply codemods, fix breaking changes
- **Component Design**: Create reusable shared workflow components that wrap MCP servers

Expand Down Expand Up @@ -83,11 +84,14 @@ When you interact with this agent, it will:
- "Update the PR reviewer to use discussions instead of issues"
- "Improve the prompt for the weekly-research workflow"

### Debug Workflow
### Diagnose, Patch, or Debug a Workflow
**Load when**: User needs to investigate, audit, debug, or understand a workflow, troubleshoot issues, analyze logs, or fix errors

**Prompt file**: `https://raw.githubusercontent.com/github/gh-aw/main/.github/aw/debug-agentic-workflow.md`

The shared strategy distinguishes diagnosis/patching from permitted active debug
loops using explicit live gates and includes existing-run evidence triage.

**Use cases**:
- "Why is this workflow failing?"
- "Analyze the logs for workflow X"
Expand Down Expand Up @@ -196,7 +200,7 @@ gh aw init
# Generate the lock file for a workflow
gh aw compile [workflow-name]

# Trigger a workflow on demand (preferred over gh workflow run)
# Only where permitted and human-validated under debug-agentic-workflow.md:
gh aw run <workflow-name> # interactive input collection
gh aw run <workflow-name> --ref main # run on a specific branch

Expand Down Expand Up @@ -229,5 +233,5 @@ gh aw compile --validate
- Follow security best practices: minimal permissions, explicit network access, no template injection
- **Network configuration**: Use ecosystem identifiers (`node`, `python`, `go`, etc.) or explicit FQDNs in `network.allowed`. Bare shorthands like `npm` or `pypi` are **not** valid. See `https://raw.githubusercontent.com/github/gh-aw/main/.github/aw/network.md` for the full list of valid ecosystem identifiers and domain patterns.
- **Single-file output**: When creating a workflow, produce exactly **one** workflow `.md` file. Do not create separate documentation files (architecture docs, runbooks, usage guides, etc.). If documentation is needed, add a brief `## Usage` section inside the workflow file itself.
- **Triggering runs**: Always use `gh aw run <workflow-name>` to trigger a workflow on demand — not `gh workflow run <file>.lock.yml`. `gh aw run` handles workflow resolution by short name, input parsing and validation, and correct run-tracking for agentic workflows. Use `--ref <branch>` to run on a specific branch.
- **Triggering runs**: Only where permitted and human-validated under `debug-agentic-workflow.md`, prefer `gh aw run <workflow-name>` over `gh workflow run <file>.lock.yml` for workflow resolution, input validation and run-tracking. Use the reviewed remote ref; explicit no-dispatch rules override user requests.
- **CLI commands reference**: For a complete guide on all `gh aw` commands and their MCP tool equivalents (for restricted environments), see `https://raw.githubusercontent.com/github/gh-aw/main/.github/aw/cli-commands.md`
42 changes: 36 additions & 6 deletions .github/aw/actions-lock.json
Original file line number Diff line number Diff line change
@@ -1,14 +1,14 @@
{
"entries": {
"github/gh-aw-actions/setup-cli@v0.91.2": {
"github/gh-aw-actions/setup-cli@v0.91.4": {
"repo": "github/gh-aw-actions/setup-cli",
"version": "v0.91.2",
"sha": "412fe67603b37050ffd87e02cf22892153dfc577"
"version": "v0.91.4",
"sha": "a63fe074b43ff5f66bcf1af0dc77f7bfc85b9d93"
},
"github/gh-aw-actions/setup@v0.91.2": {
"github/gh-aw-actions/setup@v0.91.4": {
"repo": "github/gh-aw-actions/setup",
"version": "v0.91.2",
"sha": "412fe67603b37050ffd87e02cf22892153dfc577"
"version": "v0.91.4",
"sha": "a63fe074b43ff5f66bcf1af0dc77f7bfc85b9d93"
}
},
"containers": {
Expand All @@ -17,25 +17,55 @@
"digest": "sha256:26a8af4e5566485b02f52af59ee03803ae798271a9619d4767e94d07806deb9b",
"pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.42@sha256:26a8af4e5566485b02f52af59ee03803ae798271a9619d4767e94d07806deb9b"
},
"ghcr.io/github/gh-aw-firewall/agent:0.28.31": {
"image": "ghcr.io/github/gh-aw-firewall/agent:0.28.31",
"digest": "sha256:c4ab1d48d533cc7daaa5f2e1193d1a644888242fb8813d49c6de46d129224b76",
"pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.28.31@sha256:c4ab1d48d533cc7daaa5f2e1193d1a644888242fb8813d49c6de46d129224b76"
},
"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.42": {
"image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.42",
"digest": "sha256:944f2686c9ab9bec338fd14b662461662f77cd12cd0ea8a3e7cb8c0987cd1607",
"pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.42@sha256:944f2686c9ab9bec338fd14b662461662f77cd12cd0ea8a3e7cb8c0987cd1607"
},
"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.31": {
"image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.28.31",
"digest": "sha256:a5a37489635109334a5e2b5cb2eaba32e8c8f1a89d8dea6009baa962a8904c4a",
"pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.28.31@sha256:a5a37489635109334a5e2b5cb2eaba32e8c8f1a89d8dea6009baa962a8904c4a"
},
"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.42": {
"image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.42",
"digest": "sha256:da006bf96d2d246dd269d57b233c1798d2ad63d6cd64ca02f7bf71045028781f",
"pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.42@sha256:da006bf96d2d246dd269d57b233c1798d2ad63d6cd64ca02f7bf71045028781f"
},
"ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.31": {
"image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.31",
"digest": "sha256:505df66052e6688cf419ad248a511d17093475bd66a958618078d3c9cdf95083",
"pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.31@sha256:505df66052e6688cf419ad248a511d17093475bd66a958618078d3c9cdf95083"
},
"ghcr.io/github/gh-aw-firewall/squid:0.27.42": {
"image": "ghcr.io/github/gh-aw-firewall/squid:0.27.42",
"digest": "sha256:42dfeb649c680a8558cd5423dbc530b653a69413e35ffbe5e71da5d48c94bdf0",
"pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.42@sha256:42dfeb649c680a8558cd5423dbc530b653a69413e35ffbe5e71da5d48c94bdf0"
},
"ghcr.io/github/gh-aw-firewall/squid:0.28.31": {
"image": "ghcr.io/github/gh-aw-firewall/squid:0.28.31",
"digest": "sha256:90a46d2e6e910ace2c09c2dcf6b56dc374ed513d9da642a4e9fcfcd6e9248a9d",
"pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.28.31@sha256:90a46d2e6e910ace2c09c2dcf6b56dc374ed513d9da642a4e9fcfcd6e9248a9d"
},
"ghcr.io/github/gh-aw-mcpg:v0.4.29": {
"image": "ghcr.io/github/gh-aw-mcpg:v0.4.29",
"digest": "sha256:ec08867ac8a4823e01efb2de2ba85a313199bb7ae666ef70ae58effc162a9bf3",
"pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.4.29@sha256:ec08867ac8a4823e01efb2de2ba85a313199bb7ae666ef70ae58effc162a9bf3"
},
"ghcr.io/github/gh-aw-node": {
"image": "ghcr.io/github/gh-aw-node",
"digest": "sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748",
"pinned_image": "ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748"
},
"ghcr.io/github/github-mcp-server:v1.12.2": {
"image": "ghcr.io/github/github-mcp-server:v1.12.2",
"digest": "sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6",
"pinned_image": "ghcr.io/github/github-mcp-server:v1.12.2@sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6"
}
}
}
4 changes: 2 additions & 2 deletions .github/skills/agentic-workflows/SKILL.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: agentic-workflows
description: Route gh-aw workflow design/create/debug/upgrade requests to the right prompts.
description: Route gh-aw design, creation, diagnosis, patching, active debugging, and upgrade requests to the right strategies.
---

# Agentic Workflows Router
Expand Down Expand Up @@ -97,7 +97,7 @@ After loading the matching workflow prompt or skill, follow it directly:
- Create new workflows: `.github/aw/create-agentic-workflow.md`
- Configure or add declarative engines: `.github/aw/configure-agentic-engine.md`
- Update existing workflows: `.github/aw/update-agentic-workflow.md`
- Debug, audit, or investigate workflows: `.github/aw/debug-agentic-workflow.md`
- Diagnose, patch, audit, or actively debug workflows: `.github/aw/debug-agentic-workflow.md` (local-first strategy, evidence triage and live gates)
- Upgrade workflows and fix deprecations: `.github/aw/upgrade-agentic-workflows.md`
- Create shared components or MCP wrappers: `.github/aw/create-shared-agentic-workflow.md`
- Create report-generating workflows: `.github/aw/report.md`
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/agentic-auto-upgrade.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# This file was automatically generated by pkg/workflow/auto_update_workflow.go (v0.91.2). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md
# This file was automatically generated by pkg/workflow/auto_update_workflow.go (v0.91.4). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md
#
# ___ _ _
# / _ \ | | (_)
Expand Down Expand Up @@ -52,12 +52,12 @@ jobs:
persist-credentials: false

- name: Install gh-aw
uses: github/gh-aw-actions/setup-cli@412fe67603b37050ffd87e02cf22892153dfc577 # v0.91.2
uses: github/gh-aw-actions/setup-cli@a63fe074b43ff5f66bcf1af0dc77f7bfc85b9d93 # v0.91.4
with:
version: v0.91.2
version: v0.91.4

- name: Setup Scripts
uses: github/gh-aw-actions/setup@412fe67603b37050ffd87e02cf22892153dfc577 # v0.91.2
uses: github/gh-aw-actions/setup@a63fe074b43ff5f66bcf1af0dc77f7bfc85b9d93 # v0.91.4
with:
destination: ${{ runner.temp }}/gh-aw/actions

Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/agentic_commands.yml
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
# gh-aw-commands: {"payload_version":"v1","schema_version":"v1","compiler_version":"v0.91.2","commands":["matt"],"workflows":["mattpocock-skills-reviewer"]}
# gh-aw-commands: {"payload_version":"v1","schema_version":"v1","compiler_version":"v0.91.4","commands":["matt"],"workflows":["mattpocock-skills-reviewer"]}
# Routing summary (sorted):
# slash commands:
# /matt -> mattpocock-skills-reviewer [pull_request_comment,pull_request_review_comment] reaction=eyes
# labels:
# (none)
# This file was automatically generated by gh-aw (v0.91.2). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md
# This file was automatically generated by gh-aw (v0.91.4). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md
#
# ___ _ _
# / _ \ | | (_)
Expand Down Expand Up @@ -54,7 +54,7 @@ jobs:
persist-credentials: false

- name: Setup Scripts
uses: github/gh-aw-actions/setup@412fe67603b37050ffd87e02cf22892153dfc577 # v0.91.2
uses: github/gh-aw-actions/setup@a63fe074b43ff5f66bcf1af0dc77f7bfc85b9d93 # v0.91.4
with:
destination: ${{ runner.temp }}/gh-aw/actions

Expand Down
46 changes: 23 additions & 23 deletions .github/workflows/agentics-maintenance.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# This file was automatically generated by pkg/workflow/maintenance_workflow.go (v0.91.2). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md
# This file was automatically generated by pkg/workflow/maintenance_workflow.go (v0.91.4). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md
#
# ___ _ _
# / _ \ | | (_)
Expand Down Expand Up @@ -103,7 +103,7 @@ jobs:
discussions: write
steps:
- name: Setup Scripts
uses: github/gh-aw-actions/setup@412fe67603b37050ffd87e02cf22892153dfc577 # v0.91.2
uses: github/gh-aw-actions/setup@a63fe074b43ff5f66bcf1af0dc77f7bfc85b9d93 # v0.91.4
with:
destination: ${{ runner.temp }}/gh-aw/actions

Expand All @@ -126,7 +126,7 @@ jobs:
issues: write
steps:
- name: Setup Scripts
uses: github/gh-aw-actions/setup@412fe67603b37050ffd87e02cf22892153dfc577 # v0.91.2
uses: github/gh-aw-actions/setup@a63fe074b43ff5f66bcf1af0dc77f7bfc85b9d93 # v0.91.4
with:
destination: ${{ runner.temp }}/gh-aw/actions

Expand All @@ -149,7 +149,7 @@ jobs:
pull-requests: write
steps:
- name: Setup Scripts
uses: github/gh-aw-actions/setup@412fe67603b37050ffd87e02cf22892153dfc577 # v0.91.2
uses: github/gh-aw-actions/setup@a63fe074b43ff5f66bcf1af0dc77f7bfc85b9d93 # v0.91.4
with:
destination: ${{ runner.temp }}/gh-aw/actions

Expand All @@ -173,7 +173,7 @@ jobs:
actions: write
steps:
- name: Setup Scripts
uses: github/gh-aw-actions/setup@412fe67603b37050ffd87e02cf22892153dfc577 # v0.91.2
uses: github/gh-aw-actions/setup@a63fe074b43ff5f66bcf1af0dc77f7bfc85b9d93 # v0.91.4
with:
destination: ${{ runner.temp }}/gh-aw/actions

Expand Down Expand Up @@ -206,7 +206,7 @@ jobs:
persist-credentials: false

- name: Setup Scripts
uses: github/gh-aw-actions/setup@412fe67603b37050ffd87e02cf22892153dfc577 # v0.91.2
uses: github/gh-aw-actions/setup@a63fe074b43ff5f66bcf1af0dc77f7bfc85b9d93 # v0.91.4
with:
destination: ${{ runner.temp }}/gh-aw/actions

Expand All @@ -223,9 +223,9 @@ jobs:
await main();

- name: Install gh-aw
uses: github/gh-aw-actions/setup-cli@412fe67603b37050ffd87e02cf22892153dfc577 # v0.91.2
uses: github/gh-aw-actions/setup-cli@a63fe074b43ff5f66bcf1af0dc77f7bfc85b9d93 # v0.91.4
with:
version: v0.91.2
version: v0.91.4

- name: Run operation
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9
Expand Down Expand Up @@ -259,7 +259,7 @@ jobs:
pull-requests: write
steps:
- name: Setup Scripts
uses: github/gh-aw-actions/setup@412fe67603b37050ffd87e02cf22892153dfc577 # v0.91.2
uses: github/gh-aw-actions/setup@a63fe074b43ff5f66bcf1af0dc77f7bfc85b9d93 # v0.91.4
with:
destination: ${{ runner.temp }}/gh-aw/actions

Expand Down Expand Up @@ -312,7 +312,7 @@ jobs:
persist-credentials: false

- name: Setup Scripts
uses: github/gh-aw-actions/setup@412fe67603b37050ffd87e02cf22892153dfc577 # v0.91.2
uses: github/gh-aw-actions/setup@a63fe074b43ff5f66bcf1af0dc77f7bfc85b9d93 # v0.91.4
with:
destination: ${{ runner.temp }}/gh-aw/actions

Expand Down Expand Up @@ -364,7 +364,7 @@ jobs:
persist-credentials: false

- name: Setup Scripts
uses: github/gh-aw-actions/setup@412fe67603b37050ffd87e02cf22892153dfc577 # v0.91.2
uses: github/gh-aw-actions/setup@a63fe074b43ff5f66bcf1af0dc77f7bfc85b9d93 # v0.91.4
with:
destination: ${{ runner.temp }}/gh-aw/actions

Expand All @@ -381,9 +381,9 @@ jobs:
await main();

- name: Install gh-aw
uses: github/gh-aw-actions/setup-cli@412fe67603b37050ffd87e02cf22892153dfc577 # v0.91.2
uses: github/gh-aw-actions/setup-cli@a63fe074b43ff5f66bcf1af0dc77f7bfc85b9d93 # v0.91.4
with:
version: v0.91.2
version: v0.91.4

- name: Create missing labels
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9
Expand Down Expand Up @@ -416,7 +416,7 @@ jobs:
persist-credentials: false

- name: Setup Scripts
uses: github/gh-aw-actions/setup@412fe67603b37050ffd87e02cf22892153dfc577 # v0.91.2
uses: github/gh-aw-actions/setup@a63fe074b43ff5f66bcf1af0dc77f7bfc85b9d93 # v0.91.4
with:
destination: ${{ runner.temp }}/gh-aw/actions

Expand All @@ -433,9 +433,9 @@ jobs:
await main();

- name: Install gh-aw
uses: github/gh-aw-actions/setup-cli@412fe67603b37050ffd87e02cf22892153dfc577 # v0.91.2
uses: github/gh-aw-actions/setup-cli@a63fe074b43ff5f66bcf1af0dc77f7bfc85b9d93 # v0.91.4
with:
version: v0.91.2
version: v0.91.4

- name: Restore activity report logs cache
id: activity_report_logs_cache
Expand Down Expand Up @@ -525,7 +525,7 @@ jobs:
persist-credentials: false

- name: Setup Scripts
uses: github/gh-aw-actions/setup@412fe67603b37050ffd87e02cf22892153dfc577 # v0.91.2
uses: github/gh-aw-actions/setup@a63fe074b43ff5f66bcf1af0dc77f7bfc85b9d93 # v0.91.4
with:
destination: ${{ runner.temp }}/gh-aw/actions

Expand All @@ -542,9 +542,9 @@ jobs:
await main();

- name: Install gh-aw
uses: github/gh-aw-actions/setup-cli@412fe67603b37050ffd87e02cf22892153dfc577 # v0.91.2
uses: github/gh-aw-actions/setup-cli@a63fe074b43ff5f66bcf1af0dc77f7bfc85b9d93 # v0.91.4
with:
version: v0.91.2
version: v0.91.4

- name: Restore forecast report logs cache
id: forecast_report_logs_cache
Expand Down Expand Up @@ -623,7 +623,7 @@ jobs:
issues: write
steps:
- name: Setup Scripts
uses: github/gh-aw-actions/setup@412fe67603b37050ffd87e02cf22892153dfc577 # v0.91.2
uses: github/gh-aw-actions/setup@a63fe074b43ff5f66bcf1af0dc77f7bfc85b9d93 # v0.91.4
with:
destination: ${{ runner.temp }}/gh-aw/actions

Expand Down Expand Up @@ -666,7 +666,7 @@ jobs:
persist-credentials: false

- name: Setup Scripts
uses: github/gh-aw-actions/setup@412fe67603b37050ffd87e02cf22892153dfc577 # v0.91.2
uses: github/gh-aw-actions/setup@a63fe074b43ff5f66bcf1af0dc77f7bfc85b9d93 # v0.91.4
with:
destination: ${{ runner.temp }}/gh-aw/actions

Expand All @@ -683,9 +683,9 @@ jobs:
await main();

- name: Install gh-aw
uses: github/gh-aw-actions/setup-cli@412fe67603b37050ffd87e02cf22892153dfc577 # v0.91.2
uses: github/gh-aw-actions/setup-cli@a63fe074b43ff5f66bcf1af0dc77f7bfc85b9d93 # v0.91.4
with:
version: v0.91.2
version: v0.91.4

- name: Validate workflows and file issue on findings
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/copilot-setup-steps.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ jobs:
with:
persist-credentials: false
- name: Install gh-aw extension
uses: github/gh-aw-actions/setup-cli@412fe67603b37050ffd87e02cf22892153dfc577 # v0.91.2
uses: github/gh-aw-actions/setup-cli@a63fe074b43ff5f66bcf1af0dc77f7bfc85b9d93 # v0.91.4
with:
version: v0.91.2
version: v0.91.4
Loading
Loading