Standard collaboration patterns for all squad agents — worktree awareness, decisions, cross-agent communication
日本語の概要は準備中です。原文の説明を表示しています。
Review agentic workflow changes for correctness, security posture, and optimization opportunities with compile, validation, and audit evidence.
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
Use this skill when asked to review .github/workflows/*.md agentic workflows or their generated .lock.yml outputs.
Reference workflow authoring skill guidance at: https://raw.githubusercontent.com/github/gh-aw/main/.github/skills/agentic-workflows/SKILL.md
logs/audit) when available to find optimization opportunities.The agent performs setup, source and runtime-dependency inspection, independent review coordination when required, compilation/scanners, evidence collection, finding resolution and cleanup. Do not give the user a technical preflight checklist to execute. Report concrete blockers and request only authorization or decisions the agent cannot supply. For debugging and live-test gates, follow the shared security-review guidance; the agent prepares the evidence for human validation rather than asking the user to conduct the review.
The user may explicitly authorize live debugging for the current session rather than approve each run. Record the grant and agreed scope/bounds; reuse it for in-scope revisions only after the agent repeats the required technical review. Any compiler security warning invalidates session approval immediately, even if later fixed: resolve it, re-review, and obtain fresh explicit authorization. Follow the shared session authorization rules; a request to update this skill is not itself a session-wide execution grant.
Workflow registration/activation and secret presence, validity, or expiry are runtime readiness checks, not pre-dispatch review gates. Do not require workflow or secret inventories, organization-admin access, or proof of usable credentials before an otherwise authorized run. Dispatch and the workflow's startup/authentication checks establish readiness; report their actual failures without automatic retries or enabling workflows. Continue to review declared credential flows, authorized destinations, permissions, and redaction without retrieving secret values. Missing readiness metadata alone is not a security finding or an UNKNOWN safety verdict.
Run from the repository root:
if gh aw --help >/dev/null 2>&1; then
echo "gh aw is installed"
else
if [ -f ./install-gh-aw.sh ]; then
echo "gh aw is missing. The agent must run the install step before continuing:"
echo " bash ./install-gh-aw.sh"
echo "The agent must then verify:"
echo " gh aw --help"
else
echo "gh aw is missing and ./install-gh-aw.sh is not present in this checkout."
fi
return 1 2>/dev/null || exit 1
fi
Run this scope check in the review step:
BASE_REF="${BASE_REF:-origin/main}"
if git rev-parse --verify "$BASE_REF" >/dev/null 2>&1; then
git diff --name-only "$BASE_REF...HEAD" -- .github/workflows/
else
git diff --name-only -- .github/workflows/
fi
If source .md files changed, treat generated .lock.yml drift as part of the review.
For changed workflows, run strict compilation with validators:
gh aw compile --strict --actionlint --zizmor --poutine --runner-guard --yamllint --shellcheck
If gh aw extension is unavailable but local binary exists:
./gh-aw compile --strict --actionlint --zizmor --poutine --runner-guard --yamllint --shellcheck
For debug/dry-run reviews, the agent runs gh aw compile WORKFLOW --dry-run,
adding available scanners as required by the shared guidance. Do not combine
--dry-run with --no-emit: emitted locks are part of the evidence. A
disposable checkout is optional. Running in the current checkout and reverting
only compiler-generated changes is permitted after snapshotting all affected
files, preserving diagnostic outputs, and checking for concurrent edits.
Restore pre-existing user changes exactly; never use a broad worktree reset.
See the snapshot/restore rules.
Fail review on compilation errors or High/Critical security findings unless explicitly justified.
Require and verify:
permissions: (no write-all without explicit rationale)safe-outputs limits (max, constrained event/action sets)min-integrity)Treat these as suspicious until proven safe:
write scopes or global writes)strict: false, reduced guardrails, disabled scans)safe-outputs limits removed or sharply increased)Use targeted diffs and call out before/after impact.
If workflow run IDs/URLs are available, audit them:
gh aw audit <run-id-or-url>
gh aw logs --start-date -14d --workflow-name <workflow-name>
Look for optimization opportunities:
Recommend minimal, safe optimizations that keep or improve security posture.
Always provide a short user-visible result sentence for each security review and dry-run attempt, including failed, blocked, or unavailable checks. State the artifact/scope, outcome, what was actually checked, and any material finding or coverage gap. Do not leave results only in logs, artifacts, or subagent replies. Keep security-review and dry-run results separate; neither implies live execution or authorization. Follow the shared review result and dry-run result rules.
Return findings in three sections:
Each finding should include severity, file(s), rationale, and a concrete remediation direction.
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Standard collaboration patterns for all squad agents — worktree awareness, decisions, cross-agent communication
日本語の概要は準備中です。原文の説明を表示しています。
Shared hard rules enforced across all squad agents
日本語の概要は準備中です。原文の説明を表示しています。
Route gh-aw design, creation, diagnosis, patching, active debugging, and upgrade requests to the right strategies.
日本語の概要は準備中です。原文の説明を表示しています。
How to write comprehensive architectural proposals that drive alignment before code is written
日本語の概要は準備中です。原文の説明を表示しています。
Upgrade gh-aw to latest gh-aw-firewall release and identify follow-up spec tasks.
日本語の概要は準備中です。原文の説明を表示しています。
Review code that performs git or gh operations against repository checkouts in gh-aw, checking that the right credentials are available at the right time and that sparseness, shallowness and credential-free factors are properly considered.
日本語の概要は準備中です。原文の説明を表示しています。