This prompt guides you, a coding agent, to debug workflow failures in GitHub Agentic Workflows (gh-aw).
Share this file's URL with any AI assistant or coding agent:
Debug this workflow run using https://github.com/raw/github/gh-aw/main/debug.md
Run URL: https://github.com/OWNER/REPO/actions/runs/RUN_ID
The agent will follow the steps below to install gh aw, analyze the logs, and apply fixes.
Check if gh aw is installed by running
gh aw versionIf it is installed, run:
gh extension upgrade awto upgrade to the latest non-prerelease. This can lag behind prereleases; see Model and engine misconfiguration. If it is not installed, run the installation script from the main branch of the gh-aw repository:
curl -sL https://github.com/raw/github/gh-aw/main/install-gh-aw.sh | bashWhat this does: Downloads and installs the gh-aw binary to ~/.local/share/gh/extensions/gh-aw/
Verify installation:
gh aw versionYou should see version information displayed. If you encounter an error, check that:
- GitHub CLI (
gh) is installed and authenticated - The installation script completed without errors
~/.local/share/gh/extensionsis in your PATH
Follow carefully the instructions in the appropriate prompt file. Read ALL the instructions in the prompt file before taking any action.
Below, ROOT is the location where you found this file. For example,
- if this file is at
https://github.com/raw/github/gh-aw/main/debug.mdthen the ROOT ishttps://github.com/raw/github/gh-aw/main - if this file is at
https://github.com/raw/github/gh-aw/v0.35.1/debug.mdthen the ROOT ishttps://github.com/raw/github/gh-aw/v0.35.1
Prompt file: ROOT/.github/aw/debug-agentic-workflow.md
Use cases:
- "Why is this workflow failing?"
- "Analyze the logs for workflow X"
- "Investigate missing tool calls in run #12345"
- "Debug this workflow run: https://github.com/owner/repo/actions/runs/12345"
If gh-aw version is in [0.68.4, 0.71.3], stop debugging and tell the user to upgrade because those versions were retired.
After identifying the root cause:
- Edit the workflow markdown file (
.github/workflows/<workflow-name>.md) - Recompile the workflow:
gh aw compile <workflow-name>- Check for syntax errors or validation warnings.
For AWF model/endpoint 400s, silent cross-family sub-agent failures, model: auto
failures, install-step 404s after a version pin, or questions about version fields, use the
full checklist:
- Check the compiler first. Read
compiler_versionfrom the lock file'sgh-aw-metadataheader andcli_versionfromaw_info.json. Compare withgh release list --repo github/gh-aw --limit 20, including prereleases.gh extension installandgh extension upgradedefault to the latest non-prerelease. To install a specific prerelease, usegh extension install github/gh-aw --force --pin TAG, then verify and recompile. In the October 2026 case, v0.89.21 predated wire-API inference (#64177); v0.91.7 was the reported newest prerelease, not a permanent latest tag. - Check model/endpoint compatibility. The harness resolves
autoto a concrete model. Withengine.model-routing, AWF's per-model endpoint metadata (/reflectsupported_endpoints) takes precedence and is checked at startup; a mismatch fails withModel endpoint mismatch: … Pin a compatible model, remove the COPILOT_PROVIDER_WIRE_API override, or upgrade gh-aw.Otherwise, the normal CLI wire-API precedence is explicitengine.envoverride → catalogwire_api→-utilitybase-model catalog fallback →gpt-5+name rule → CLI default/chat/completions.COPILOT_PROVIDER_WIRE_API=responsesuses/responses;completionsuses/chat/completions. In default CLI mode one wire API applies to the whole session, including sub-agents; use a sub-agent model supporting the main session's endpoint. When available,engine.copilot-sdk: trueuses a provider per model, allowing a Claude sub-agent under a GPT main.Cannot translate Copilot request feature,Unsupported Responses custom tool,model_policy_violation,not accessible via the … endpoint, andRouting model "<model>" to /chat/completions is incompatiblewarrant model/endpoint or model-policy investigation, not transient retries or prompt tuning. Formodel_policy_violation, check the model allowlist/denylist and rejected model; policy rejection alone does not establish an endpoint mismatch. Cross-family sub-agent failures can be silent: on AWF v0.28.50, a sub-agent can receive this 400 while the main model retries its work and the run succeeds. Look forsubagent.failedinusage/aw_session.jsonl, plus the Sub-agent Failed finding anddeviatedrequests ingh aw audit RUN_ID. - Apply fixes in this order:
- Upgrade gh-aw and recompile.
- Pin a model that supports the required endpoint.
- Remove a conflicting
COPILOT_PROVIDER_WIRE_APIoverride. - Use sub-agent models from the main model's family in default CLI mode.
Verify endpoint compatibility; see
github/gh-aw#67460 and
github/copilot-cli#5103.
When available, SDK mode (
engine.copilot-sdk: true) supports per-model providers and different model families. Switching to an older model is a last resort if these fail: leading withmodel: gpt-4.1trades capability for a workaround and leaves the underlying misconfiguration in place.
- Check the version field.
engine.versionis the agent CLI version (Copilot CLI, 1.0.x in the customer case): Install GitHub Copilot CLI 404s point here.sandbox.agent.versionis the AWF release invX.Y.Zform and must match a GitHub release ofgithub/gh-aw-firewall: Install AWF binary failures point here. There is noengine.copilot.versionfield. Usually remove the misplaced pin and recompile to use the compiled default. - Read the evidence. Inspect
[copilot-harness]alias andCOPILOT_PROVIDER_WIRE_APIlines inagent-stdio.log; model and path per request insandbox/firewall/logs/api-proxy-logs/token-usage.jsonl; andmodel,requested_model,cli_version(gh-aw),version(agent CLI), andawf_versioninaw_info.json. Usegh aw audit RUN_IDfor the combined view. Older runs may omit diagnostics; do not assume routing was correct.
Commit the changes, e.g.
git add .github/workflows/<workflow-name>.md .github/workflows/<workflow-name>.lock.yml
git commit -m "Fix agentic workflow: <describe fix>"
git pushIf there is branch protection on the default branch, create a pull request instead and report the link to the pull request.
See the separate guides on troubleshooting common issues.
When a user interacts with you:
- Extract the run URL or workflow name from the user's request
- Fetch and read the debug prompt from
ROOT/.github/aw/debug-agentic-workflow.md - Follow the loaded prompt's instructions exactly
- If uncertain, ask clarifying questions
# Download and analyze workflow logs
gh aw logs <workflow-name>
# Audit a specific workflow run
gh aw audit <run-id>
# Diff two or more workflow runs (multi-run diff mode)
gh aw audit <base-run-id> <compare-run-id>
gh aw audit <base-run-id> <compare-run-id-1> <compare-run-id-2>
# Compile workflows after fixing
gh aw compile <workflow-name>
# Show status of all workflows
gh aw statusgh aw audit <run-id> --json→ Detailed run analysis with missing tools and errorsgh aw audit <base-run-id> <compare-run-id> --json→ Diff two runs to detect regressions (firewall, MCP, metrics)gh aw logs <workflow-name> --json→ Download and analyze recent workflow logsgh aw compile <workflow-name> --strict→ Validate workflow with strict security checks