Analysis Date: 2026-10-06
Repository: github/gh-aw
Scope: 321 total workflows, 113 using the Copilot engine (~35%)
📊 Executive Summary
Key Findings
- Core features are widely adopted: safe-outputs (269), timeout-minutes (309), toolsets (186), network config (180), custom
agent: (144), sandbox (137).
- Advanced or niche Copilot CLI features have almost no adoption.
--share, --add-dir, disable-builtin-mcps and plugins each appear in 0 workflows.
- The explicit
sandbox: block is set in ~43% of workflows, so the rest rely on defaults.
max-turns is set in only 37 workflows, while engine version is pinned in 25. Model selection is fragmented (small, copilot/auto, copilot/gpt-5.4, claude-haiku-4.5, openai/gpt-5.6-sol).
repo-memory is used by 30 workflows; cache-memory by 109.
Primary Recommendation: Standardize a small set of shared engine and model presets (imports) and make the budget guardrails (max-turns, pinned version) the default for long-running Copilot workflows.
Critical Findings
🔴 High Priority
- Unbounded runs: 76 Copilot workflows have no
max-turns. This risks runaway cost on scheduled workflows.
- Unpinned CLI version: only 25 workflows pin
engine.version. Upstream CLI changes can silently alter behavior of scheduled workflows.
🟡 Medium Priority
- Model fragmentation: 5+ model identifiers are in use. Move to shared imports or aliases such as
small.
- Sandbox not explicit in ~60% of workflows. Make the intent explicit for security audits.
- Plugins (0 usage): not leveraged for reusable skills or tools.
--add-dir / --share (0 usage): the latter would give session transcripts for debugging failures.
View Full Analysis
Feature Usage Matrix
| Category |
Used |
Not used / rarely used |
Rate |
| CLI flags |
agent, model |
--share, --add-dir, disable-builtin-mcps |
low |
| Engine config |
model (~50+), version (25), max-turns (37) |
plugins |
mixed |
| MCP / tools |
github toolsets (186), bash (214) |
custom MCP scoping |
medium |
| Network |
network (180) |
tighter ecosystem allowlists |
~56% |
| Sandbox |
sandbox (137) |
explicit config elsewhere |
~43% |
Recommendations by Priority
- High: add
max-turns to workflows lacking it; pin the version for scheduled workflows.
- Medium: shared model presets via imports; explicit sandbox; use
repo-memory instead of ad-hoc state for recurring analyzers; scope toolsets narrowly for the ~135 workflows without them.
- Low: trial
--share on a few diagnostic workflows; document --add-dir and plugins with examples.
Trends
Compared with the last run (2026-09-08: 299 workflows, 88 extended Copilot): workflow count grew by ~22. --share and --add-dir use dropped from 1 to 0. plugins is still 0. max-turns rose from 30 to 37, repo-memory fell from 38 to 30, and agent usage fell from 232 to 144 under a different counting pattern. The counting methods differ, so the numbers are indicative only.
Best Practices
- Always set
timeout-minutes and max-turns for scheduled agents.
- Pin the CLI version where reproducibility matters.
- Use shared imports for common engine/model/network config.
Methodology
Counted frontmatter patterns across .github/workflows/*.md with grep and compared them with the previous snapshot in repo-memory. Counts are heuristic. This run did not re-read the Go engine sources in depth.
Action Items
Generated by Copilot CLI Deep Research (Run: 37410946764)
Generated by 🔬 Copilot CLI Deep Research Agent · copilot · auto · 12.5 AIC · ⌖ 11.6 AIC · ⊞ 10.7K · ◷
Analysis Date: 2026-10-06
Repository: github/gh-aw
Scope: 321 total workflows, 113 using the Copilot engine (~35%)
📊 Executive Summary
Key Findings
agent:(144), sandbox (137).--share,--add-dir,disable-builtin-mcpsandpluginseach appear in 0 workflows.sandbox:block is set in ~43% of workflows, so the rest rely on defaults.max-turnsis set in only 37 workflows, while engineversionis pinned in 25. Model selection is fragmented (small,copilot/auto,copilot/gpt-5.4,claude-haiku-4.5,openai/gpt-5.6-sol).repo-memoryis used by 30 workflows;cache-memoryby 109.Primary Recommendation: Standardize a small set of shared engine and model presets (imports) and make the budget guardrails (
max-turns, pinnedversion) the default for long-running Copilot workflows.Critical Findings
🔴 High Priority
max-turns. This risks runaway cost on scheduled workflows.engine.version. Upstream CLI changes can silently alter behavior of scheduled workflows.🟡 Medium Priority
small.--add-dir/--share(0 usage): the latter would give session transcripts for debugging failures.View Full Analysis
Feature Usage Matrix
--share,--add-dir,disable-builtin-mcpsRecommendations by Priority
max-turnsto workflows lacking it; pin the version for scheduled workflows.repo-memoryinstead of ad-hoc state for recurring analyzers; scopetoolsetsnarrowly for the ~135 workflows without them.--shareon a few diagnostic workflows; document--add-dirand plugins with examples.Trends
Compared with the last run (2026-09-08: 299 workflows, 88 extended Copilot): workflow count grew by ~22.
--shareand--add-diruse dropped from 1 to 0.pluginsis still 0.max-turnsrose from 30 to 37, repo-memory fell from 38 to 30, and agent usage fell from 232 to 144 under a different counting pattern. The counting methods differ, so the numbers are indicative only.Best Practices
timeout-minutesandmax-turnsfor scheduled agents.Methodology
Counted frontmatter patterns across
.github/workflows/*.mdwith grep and compared them with the previous snapshot in repo-memory. Counts are heuristic. This run did not re-read the Go engine sources in depth.Action Items
max-turnsto the ~76 Copilot workflows without itengine.versionon scheduled workflowssandbox:explicit everywhere--shareand plugins; document--add-dirGenerated by Copilot CLI Deep Research (Run: 37410946764)