Skip to content

[copilot-cli-research] Copilot CLI Deep Research - 2026-10-10 #67335

Description

@github-actions

Analysis Date: 2026-10-10
Repository: github/gh-aw
Scope: 334 total workflows, ~119 using Copilot engine (21 use simple engine: copilot)

📊 Executive Summary

Key Findings

  • Basic hygiene is strong: 322/334 workflows set timeout-minutes, 282 use safe-outputs, 181 define network.
  • Several Copilot features remain nearly unused: --share (1), manual --add-dir (1), --disable-builtin-mcps (2), plugins (0), model overrides (3).
  • Sandbox is declared in 140 workflows (down from 230 in the prior run's grep; method differences may account for part of this).
  • max-turns/continuations used in 39 workflows, with no consistent policy.

Primary recommendation: define repo-wide guardrails (sandbox, network, timeout, turn limits) through shared imports, and add conversation sharing/tracking for complex workflows.

Note: counts come from grep over .github/workflows/*.md and may undercount imports/shared configs.

🔴 High Priority

  1. Sandbox/firewall consistency – only 140 of 334 workflows declare sandbox:. Add it to Copilot workflows via a shared import so the default is explicit.
  2. Turn-limit policy – only 39 workflows set max-turns; long-running Copilot workflows lack runaway protection. Add engine.max-turns or autopilot max-continuations to the heavy ones.

🟡 Medium Priority

  1. --share conversation tracking (1 use) – add via engine.args: ["--share"] on complex triage/research workflows to ease auditing.
  2. Plugins (0 uses) – evaluate the plugins config for reusable tool bundles instead of repeating tool configs.
  3. Model selection (3 overrides, all copilot/gpt-5.3-codex) – cheap/simple workflows could use a lighter model; use the model env var overrides for experiments.
  4. Narrower GitHub toolsets – 185 use toolsets:; audit the remaining GitHub-tool users for default toolset overreach.
Full Analysis

Capability inventory (from pkg/workflow/copilot_engine_execution.go)

Flags: --disable-builtin-mcps, --no-ask-user, --agent, --autopilot --max-autopilot-continues, --add-dir (auto: /tmp/gh-aw/, cache/drive memory dirs), --log-level all --log-dir, --allow-tool/--deny-tool, --allow-all-paths, --no-custom-instructions; SDK headless mode (--headless --no-auto-update --port); model via env var with BYOK fallback; model routing.

Usage matrix

Feature Workflows
timeout-minutes 322
safe-outputs 282
network 181
toolsets 185
custom agent (agent:) 151
sandbox 140
cache-memory 110
max-turns 39
repo-memory 36
version pin 26
model override 3
--share / --add-dir / disable-builtin-mcps 1 / 1 / 2
plugins 0

Trends vs. 2026-09-08

Workflows 299→334; Copilot extended 88→~119 total; repo-memory 38→36; max-turns 30→39; agent 232→151 and sandbox 230→140 (likely counting method differences); plugins still 0; share still 1.

Best practices

  1. Centralize sandbox/network/timeout defaults in shared imports.
  2. Pin versions only where reproducibility matters; otherwise use defaults.
  3. Bound agent runs with turn/continuation limits.

Action Items

  • Immediate: add turn limits to the longest-running Copilot workflows.
  • Short-term: shared import with sandbox + network baseline; pilot --share.
  • Long-term: evaluate plugins and per-workflow model tiering.

Methodology

Grep counts over workflow markdown, review of pkg/workflow/copilot_engine_execution.go, comparison with repo-memory latest.json.

Generated by Copilot CLI Deep Research (Run: 38022056720)

Generated by 🔬 Copilot CLI Deep Research Agent · copilot · auto · 13.1 AIC · ⌖ 0.677 AIC · ⊞ 10.7K · ◷

  • expires on Oct 10, 2026, 7:56 PM UTC-08:00

Activity

  1. github-actions commented on Oct 11, 2026

    @github-actions
    ContributorAuthor

    This issue is being closed as outdated. A newer issue has been created: #67605

    View newer issue


    This action was performed automatically by the Copilot CLI Deep Research Agent workflow.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions