Analysis Date: 2026-10-03
Repository: github/gh-aw
Scope: 302 total workflows, ~117 using the Copilot engine (24 engine: copilot, 93 id: copilot extended)
📊 Executive Summary
Key findings (quick grep-based survey; counts are approximate):
- The engine (
copilot_engine_execution.go) emits --add-dir, --log-level, --log-dir, --no-custom-instructions, --no-auto-update, --no-ask-user, --autopilot, --max-autopilot-continues, --allow-all-paths, --agent, --disable-builtin-mcps, plus headless --host/--port. Most are compiler-managed.
- Only 1 workflow uses
--share; custom agent: is used in ~145 workflows.
max-turns appears in only 25 workflows, max-continuations in 10.
- 12 workflows lack
timeout-minutes; 11 use strict: false.
- Engine
version pinned in 25 files; model: set in many files (175 matches, includes non-engine uses).
Primary recommendation: add budget guardrails (max-turns/max-continuations + timeout-minutes) to long-running Copilot workflows.
🔴 High Priority
- Missing timeouts – 12 workflows have no
timeout-minutes; set explicit limits (grep -L timeout-minutes .github/workflows/*.md).
strict: false workflows (11) – review whether network/safe-output hardening can be enabled.
🟡 Medium Priority
- Run budgets – only ~8% of Copilot workflows cap turns/continuations; add
max-continuations for autopilot ones.
- Conversation transcripts –
--share used once; enable via engine.args for audit/debug-heavy workflows (e.g. audit and triage agents).
- Pin versions consistently – 25 pinned vs. the rest floating; document policy for when pinning is required.
- Cache/repo-memory – 81 cache-memory vs. 30 repo-memory; periodic report workflows without either could avoid redundant analysis.
🟢 Low Priority
plugins config unused (0 in prior run); BYOK env used in few workflows; document these in engines.md.
Trends
Versus 2026-09-08 (run 34184590907): workflows 299→302; extended Copilot config 88→93; max-turns 30→25; repo-memory 38→30 (counting methods may differ); --share unchanged at 1.
Action Items
Methodology
Grep over .github/workflows/*.md and pkg/workflow/copilot*.go; compared with previous snapshot in repo-memory (copilot-cli-research/latest.json). Docs/CHANGELOG were not exhaustively reviewed.
Generated by Copilot CLI Deep Research (Run: 37095020341)
Generated by 🔬 Copilot CLI Deep Research Agent · copilot · auto · 13.8 AIC · ⌖ 6.94 AIC · ⊞ 10.7K · ◷
Analysis Date: 2026-10-03
Repository: github/gh-aw
Scope: 302 total workflows, ~117 using the Copilot engine (24
engine: copilot, 93id: copilotextended)📊 Executive Summary
Key findings (quick grep-based survey; counts are approximate):
copilot_engine_execution.go) emits--add-dir,--log-level,--log-dir,--no-custom-instructions,--no-auto-update,--no-ask-user,--autopilot,--max-autopilot-continues,--allow-all-paths,--agent,--disable-builtin-mcps, plus headless--host/--port. Most are compiler-managed.--share; customagent:is used in ~145 workflows.max-turnsappears in only 25 workflows,max-continuationsin 10.timeout-minutes; 11 usestrict: false.versionpinned in 25 files;model:set in many files (175 matches, includes non-engine uses).Primary recommendation: add budget guardrails (
max-turns/max-continuations+timeout-minutes) to long-running Copilot workflows.🔴 High Priority
timeout-minutes; set explicit limits (grep -L timeout-minutes .github/workflows/*.md).strict: falseworkflows (11) – review whether network/safe-output hardening can be enabled.🟡 Medium Priority
max-continuationsfor autopilot ones.--shareused once; enable viaengine.argsfor audit/debug-heavy workflows (e.g. audit and triage agents).🟢 Low Priority
pluginsconfig unused (0 in prior run); BYOK env used in few workflows; document these in engines.md.Trends
Versus 2026-09-08 (run 34184590907): workflows 299→302; extended Copilot config 88→93; max-turns 30→25; repo-memory 38→30 (counting methods may differ);
--shareunchanged at 1.Action Items
timeout-minutesto the 12 workflows missing itstrict: falseworkflowsmax-continuationsto autopilot workflows--shareon 2–3 audit workflowsMethodology
Grep over
.github/workflows/*.mdandpkg/workflow/copilot*.go; compared with previous snapshot in repo-memory (copilot-cli-research/latest.json). Docs/CHANGELOG were not exhaustively reviewed.Generated by Copilot CLI Deep Research (Run: 37095020341)