Analysis Date: 2026-10-07
Repository: github/gh-aw
Scope: 324 total workflows, ~119 using Copilot engine (25 engine: copilot, 94 extended id: copilot)
📊 Executive Summary
Key Findings
- Persistent gaps unchanged since prior runs:
--share (1 workflow), manual --add-dir (1), plugins: (0), BYOK COPILOT_PROVIDER_* (3).
- Engine CLI flags emitted by the compiler:
--add-dir, --agent, --allow-all-paths, --allow-tool, --deny-tool, --autopilot, --max-autopilot-continues, --disable-builtin-mcps, --no-ask-user, --no-auto-update, --no-custom-instructions, --log-dir, --log-level, --headless/--host/--port.
- Adoption is solid for
timeout-minutes (312/324), agent: (146), cache-memory (109), sandbox (139), max-turns (39), repo-memory (30).
Primary recommendation: pin Copilot CLI versions and enable --share-style transcript capture for high-value workflows.
Critical Findings
🔴 High Priority
- Version pinning: only 26 workflows set
version:; the rest float, risking unreviewed behavior changes. Pin for production-critical workflows and bump via Dependabot-style updates.
- Network hardening: ensure Copilot workflows have explicit
network.allowed ecosystems rather than defaults; review those without a sandbox: block (~185 of 324 by top-level grep).
🟡 Medium Priority
--share unused (1 workflow) – add to long-running/failure-prone workflows for debugging via engine.args.
--disable-builtin-mcps used in 2 workflows – use where the GitHub MCP is replaced by gh-proxy mode, reducing tool-list tokens.
- Model overrides only in 3 workflows by top-level
model:; cost-sensitive triage workflows could use a small model.
max-turns in 39 workflows only; add for open-ended agents to bound cost.
Full Analysis
Feature Usage Matrix
| Category |
Used |
Not/Rarely used |
| CLI flags |
--agent, --allow-tool, --add-dir (compiler) |
--share (1), manual --add-dir (1), --disable-builtin-mcps (2) |
| Engine config |
version (26), agent (146), model (3), max-turns (39) |
plugins (0), BYOK (3) |
| Network/Sandbox |
sandbox (139) |
explicit config in remaining workflows |
| Memory |
cache-memory (109), repo-memory (30) |
– |
Low Priority
- Agent Plugins (
plugins:): schema-supported, zero adoption; create a demo workflow.
- BYOK: only smoke tests; document patterns.
Trends
Previous run (2026-09-08): 299 workflows → now 324. Gaps --share, --add-dir, plugins, --disable-builtin-mcps flat. Counting method differs (top-level grep), so agent/sandbox/repo-memory numbers are not directly comparable.
Best Practices
- Pin engine versions for critical workflows.
- Always set
timeout-minutes and max-turns.
- Prefer explicit network allowlists and sandbox.
Methodology
Reviewed pkg/workflow/copilot_*.go, grepped .github/workflows/*.md, compared with repo-memory copilot-cli-research/latest.json.
Action Items
Generated by Copilot CLI Deep Research (Run: 37568818939)
Generated by 🔬 Copilot CLI Deep Research Agent · copilot · auto · 14.4 AIC · ⌖ 7.16 AIC · ⊞ 10.7K · ◷
Analysis Date: 2026-10-07
Repository: github/gh-aw
Scope: 324 total workflows, ~119 using Copilot engine (25
engine: copilot, 94 extendedid: copilot)📊 Executive Summary
Key Findings
--share(1 workflow), manual--add-dir(1),plugins:(0), BYOKCOPILOT_PROVIDER_*(3).--add-dir,--agent,--allow-all-paths,--allow-tool,--deny-tool,--autopilot,--max-autopilot-continues,--disable-builtin-mcps,--no-ask-user,--no-auto-update,--no-custom-instructions,--log-dir,--log-level,--headless/--host/--port.timeout-minutes(312/324),agent:(146),cache-memory(109),sandbox(139),max-turns(39),repo-memory(30).Primary recommendation: pin Copilot CLI versions and enable
--share-style transcript capture for high-value workflows.Critical Findings
🔴 High Priority
version:; the rest float, risking unreviewed behavior changes. Pin for production-critical workflows and bump via Dependabot-style updates.network.allowedecosystems rather than defaults; review those without asandbox:block (~185 of 324 by top-level grep).🟡 Medium Priority
--shareunused (1 workflow) – add to long-running/failure-prone workflows for debugging viaengine.args.--disable-builtin-mcpsused in 2 workflows – use where the GitHub MCP is replaced by gh-proxy mode, reducing tool-list tokens.model:; cost-sensitive triage workflows could use a small model.max-turnsin 39 workflows only; add for open-ended agents to bound cost.Full Analysis
Feature Usage Matrix
--agent,--allow-tool,--add-dir(compiler)--share(1), manual--add-dir(1),--disable-builtin-mcps(2)Low Priority
plugins:): schema-supported, zero adoption; create a demo workflow.Trends
Previous run (2026-09-08): 299 workflows → now 324. Gaps
--share,--add-dir,plugins,--disable-builtin-mcpsflat. Counting method differs (top-level grep), so agent/sandbox/repo-memory numbers are not directly comparable.Best Practices
timeout-minutesandmax-turns.Methodology
Reviewed
pkg/workflow/copilot_*.go, grepped.github/workflows/*.md, compared with repo-memorycopilot-cli-research/latest.json.Action Items
version:for top critical Copilot workflows--shareto 3–5 pilot workflowsplugins:demo workflowsandbox:/explicitnetwork:Generated by Copilot CLI Deep Research (Run: 37568818939)