Restrict outbound domains for GitHub Agentic Workflows before repository agents can browse freely with gh-aw-firewall
Run GitHub Agentic Workflow jobs behind a domain allowlist and optional API-key sidecar instead of giving repository agents broad outbound access.
What it does
Restrict outbound domains for GitHub Agentic Workflows before repository agents can browse freely with gh-aw-firewall
Run GitHub Agentic Workflow jobs behind a domain allowlist and optional API-key sidecar instead of giving repository agents broad outbound access.
Prerequisites
Docker 20.10+, Docker Compose v2, Linux host or compatible runtime
Installation
Requirements and caveats from upstream:
- awf runs your command inside a Docker sandbox with three containers:
- Docker: 20.10+ with Docker Compose v2
- Node.js: 20.19.0+ (for building from source)
Basic usage or getting-started notes:
-
OS: Ubuntu 22.04+ or compatible Linux distribution (x86_64 and arm64)
-
See Compatibility for full details on supported versions and tested configurations.
-
Get started fast
-
Extracted from upstream docs: https://raw.githubusercontent.com/github/gh-aw-firewall/HEAD/README.md
Documentation
Source
Capabilities
Install
Quality
deterministic score 0.45 from registry signals: · indexed on github topic:agent-skills · 8 github stars · SKILL.md body (1,238 chars)