Skip to content

[copilot-cli-research] Copilot CLI Deep Research - 2026-10-07 #66430

Description

@github-actions

Analysis Date: 2026-10-07
Repository: github/gh-aw
Scope: 324 total workflows, ~119 using Copilot engine (25 engine: copilot, 94 extended id: copilot)

📊 Executive Summary

Key Findings

  • Persistent gaps unchanged since prior runs: --share (1 workflow), manual --add-dir (1), plugins: (0), BYOK COPILOT_PROVIDER_* (3).
  • Engine CLI flags emitted by the compiler: --add-dir, --agent, --allow-all-paths, --allow-tool, --deny-tool, --autopilot, --max-autopilot-continues, --disable-builtin-mcps, --no-ask-user, --no-auto-update, --no-custom-instructions, --log-dir, --log-level, --headless/--host/--port.
  • Adoption is solid for timeout-minutes (312/324), agent: (146), cache-memory (109), sandbox (139), max-turns (39), repo-memory (30).

Primary recommendation: pin Copilot CLI versions and enable --share-style transcript capture for high-value workflows.

Critical Findings

🔴 High Priority

  1. Version pinning: only 26 workflows set version:; the rest float, risking unreviewed behavior changes. Pin for production-critical workflows and bump via Dependabot-style updates.
  2. Network hardening: ensure Copilot workflows have explicit network.allowed ecosystems rather than defaults; review those without a sandbox: block (~185 of 324 by top-level grep).

🟡 Medium Priority

  1. --share unused (1 workflow) – add to long-running/failure-prone workflows for debugging via engine.args.
  2. --disable-builtin-mcps used in 2 workflows – use where the GitHub MCP is replaced by gh-proxy mode, reducing tool-list tokens.
  3. Model overrides only in 3 workflows by top-level model:; cost-sensitive triage workflows could use a small model.
  4. max-turns in 39 workflows only; add for open-ended agents to bound cost.
Full Analysis

Feature Usage Matrix

Category Used Not/Rarely used
CLI flags --agent, --allow-tool, --add-dir (compiler) --share (1), manual --add-dir (1), --disable-builtin-mcps (2)
Engine config version (26), agent (146), model (3), max-turns (39) plugins (0), BYOK (3)
Network/Sandbox sandbox (139) explicit config in remaining workflows
Memory cache-memory (109), repo-memory (30) –

Low Priority

  • Agent Plugins (plugins:): schema-supported, zero adoption; create a demo workflow.
  • BYOK: only smoke tests; document patterns.

Trends

Previous run (2026-09-08): 299 workflows → now 324. Gaps --share, --add-dir, plugins, --disable-builtin-mcps flat. Counting method differs (top-level grep), so agent/sandbox/repo-memory numbers are not directly comparable.

Best Practices

  1. Pin engine versions for critical workflows.
  2. Always set timeout-minutes and max-turns.
  3. Prefer explicit network allowlists and sandbox.

Methodology

Reviewed pkg/workflow/copilot_*.go, grepped .github/workflows/*.md, compared with repo-memory copilot-cli-research/latest.json.

Action Items

  • Pin version: for top critical Copilot workflows
  • Add --share to 3–5 pilot workflows
  • Add a plugins: demo workflow
  • Audit workflows lacking sandbox:/explicit network:

Generated by Copilot CLI Deep Research (Run: 37568818939)

Generated by 🔬 Copilot CLI Deep Research Agent · copilot · auto · 14.4 AIC · ⌖ 7.16 AIC · ⊞ 10.7K · ◷

  • expires on Oct 7, 2026, 7:57 PM UTC-08:00

Activity

  1. github-actions commented on Oct 8, 2026

    @github-actions
    ContributorAuthor

    This issue is being closed as outdated. A newer issue has been created: #66770

    View newer issue


    This action was performed automatically by the Copilot CLI Deep Research Agent workflow.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions