Analysis Date: 2026-10-09
Repository: github/gh-aw
Scope: 333 workflows, 115 using Copilot (20 simple engine: copilot, 95 extended id: copilot)
📊 Executive Summary
Key Findings
- The compiler supports many Copilot CLI flags:
--allow-all-tools, --allow-tool/--deny-tool, --no-ask-user, --autopilot/--max-autopilot-continues, --log-level, --add-dir, --disable-builtin-mcps, --agent. The --share flag does not appear in the copilot*.go files.
- Workflow configuration is very uniform. Only 3 workflows override the model and 1 uses
engine.args.
- 12 workflows have no
timeout-minutes, and 10 use strict: false.
- The 227 workflows that mention
github: rely mostly on toolsets: [default] (44 workflows) or custom lists.
- Repo-memory (28 workflows) is used much less than cache-memory (109 workflows).
Primary recommendation: add explicit timeout-minutes to the 12 workflows without one, then review the 10 strict: false workflows.
Critical Findings
🔴 High Priority
- Missing timeouts (12 workflows). Runaway agents are costly. Set a timeout of 10–45 minutes, following the existing distribution (30 min is the most common).
strict: false (10 workflows). Each one should carry a documented justification, or be moved to strict mode with a tighter network.allowed list.
🟡 Medium Priority
- Narrow GitHub toolsets. Prefer
[repos, pull_requests]-style lists over [default] where possible, to reduce tool-schema tokens. This is already done in about 14 workflows.
- Model selection. Few workflows set
model:. Cheap, simple workflows (triage, labeling) could use a smaller model to cut cost.
- Conversation transcripts.
--share is not wired into the compiler. The agent session logs are already collected, so a share/export option would be a modest addition.
- Memory consolidation. Review the 109 cache-memory workflows for durable state that belongs in repo-memory.
View Full Analysis
Usage Statistics
- Engines in
engine: X form: claude 37, copilot 20, pi 19, codex 7. A further 95 workflows use the extended id: copilot form.
- Timeouts (most common first): 30 min (76), 10 min (70), 20 min (47), 15 min (40), 45 min (36).
- Custom
agent: is set in 151 workflows.
- Sandbox is configured in 140. Network is configured in 172 (152 with an allow list, 6 with
allowed: [], 5 with network: {}).
- Playwright is used in 15. Imports are used in 300. Top-level
mcp-servers: appears in 0.
- Version pinning of the Copilot CLI appears in 1 workflow (1.0.92). The previous run counted 11, but the grep patterns differ, so the two are not comparable.
Feature Usage Matrix
| Category |
Used |
Gap |
| CLI flags |
allow-tool, deny-tool, no-ask-user, autopilot, log-level, add-dir, agent |
--share |
| Engine config |
id, agent, max-turns |
model (3), args (1), version (1) |
| Memory |
cache-memory 109, repo-memory 28 |
consolidation |
| Network |
allowed lists 152 |
5 empty network: {} blocks to review |
Trends
Compared with the previous run (2026-09-08: 299 workflows), the repository grew by 34 workflows. Previous data came from a different grep method, so absolute counts are not directly comparable.
Best Practices
- Always set
timeout-minutes.
- Keep strict mode on unless a documented exception exists.
- Use minimal toolsets and explicit network allowlists.
Action Items
Immediate: [ ] Add timeouts to the 12 workflows. [ ] Audit the 10 strict: false workflows.
Short-term: [ ] Trial smaller models on triage workflows. [ ] Narrow the GitHub toolsets.
Long-term: [ ] Evaluate --share support. [ ] Consolidate memory strategy.
Generated by Copilot CLI Deep Research (Run: 37881404753)
Generated by 🔬 Copilot CLI Deep Research Agent · copilot · auto · 12.1 AIC · ⌖ 0.679 AIC · ⊞ 10.7K · ◷
Analysis Date: 2026-10-09
Repository: github/gh-aw
Scope: 333 workflows, 115 using Copilot (20 simple
engine: copilot, 95 extendedid: copilot)📊 Executive Summary
Key Findings
--allow-all-tools,--allow-tool/--deny-tool,--no-ask-user,--autopilot/--max-autopilot-continues,--log-level,--add-dir,--disable-builtin-mcps,--agent. The--shareflag does not appear in thecopilot*.gofiles.engine.args.timeout-minutes, and 10 usestrict: false.github:rely mostly ontoolsets: [default](44 workflows) or custom lists.Primary recommendation: add explicit
timeout-minutesto the 12 workflows without one, then review the 10strict: falseworkflows.Critical Findings
🔴 High Priority
strict: false(10 workflows). Each one should carry a documented justification, or be moved to strict mode with a tighternetwork.allowedlist.🟡 Medium Priority
[repos, pull_requests]-style lists over[default]where possible, to reduce tool-schema tokens. This is already done in about 14 workflows.model:. Cheap, simple workflows (triage, labeling) could use a smaller model to cut cost.--shareis not wired into the compiler. The agent session logs are already collected, so a share/export option would be a modest addition.View Full Analysis
Usage Statistics
engine: Xform: claude 37, copilot 20, pi 19, codex 7. A further 95 workflows use the extendedid: copilotform.agent:is set in 151 workflows.allowed: [], 5 withnetwork: {}).mcp-servers:appears in 0.Feature Usage Matrix
--sharenetwork: {}blocks to reviewTrends
Compared with the previous run (2026-09-08: 299 workflows), the repository grew by 34 workflows. Previous data came from a different grep method, so absolute counts are not directly comparable.
Best Practices
timeout-minutes.Action Items
Immediate: [ ] Add timeouts to the 12 workflows. [ ] Audit the 10
strict: falseworkflows.Short-term: [ ] Trial smaller models on triage workflows. [ ] Narrow the GitHub toolsets.
Long-term: [ ] Evaluate
--sharesupport. [ ] Consolidate memory strategy.Generated by Copilot CLI Deep Research (Run: 37881404753)