Intelligent GitHub repository automation, with your own agents.
Copilot, Claude Code, Codex or Gemini triage issues, investigate failures and open pull requests on your repo. Safely, with strong guardrails, in GitHub Actions.
Prefer a guided form? Try the workflow wizard
Start every day with a better repository, improved while you sleep.
The coding agents you know and love triage issues, investigate failures and open pull requests overnight. Under your rules, in GitHub Actions.
Prefer a guided form? Try the workflow wizard
Continuous AI for every repository, always running.
A third pillar beside CI and CD: coding agents that keep improving your repository, triaging, documenting, testing and fixing in GitHub Actions, under guardrails you control.
Prefer a guided form? Try the workflow wizard
Workflows that already work
Ready-made workflows, running in real repositories today. Paste one prompt into your coding agent to add it to your repo.
Repo Assist
Twice a dayA repository assistant that triages issues, fixes bugs and proposes improvements.
Each run it picks tasks to suit the state of your repository: labelling and investigating issues, fixing bugs, adding tests and engineering improvements. It keeps a monthly activity summary so maintainers can see what it did.
Running in 13 open-source repos, Repo Assist has closed 578 issues, with issues closing a median 8X faster.
CI Doctor
When CI failsInvestigates failing CI and opens an issue with the likely cause.
It reads the failed job’s logs alongside the commit and pull request that triggered it, then files one issue with the root cause and next steps. Repeat failures update that issue instead of adding noise.
Repo Status
DailyA daily report of what happened in your repository, posted as an issue.
It gathers pull requests, issues and workflow results, then writes a short status report. Yesterday’s report closes when today’s arrives.
Test Improver
DailyOpens pull requests that improve test coverage where it matters.
It works out how your project builds and measures coverage, finds high-value gaps, and opens pull requests with the measured improvement. It keeps its own pull requests up to date.
Show 12 more workflowsShow fewer
Maintain
Improve code
Report and plan
Watch it run
Create and run your first workflow in under two minutes.
Install the extension, add a sample workflow and trigger the first run. Follow the quick start →
Ask Copilot in your repository's Agents tab to write the workflow for you. Create a workflow →
Safe by default
Agents read by default. Every write is checked before it lands.
An agent becomes dangerous when it has private data, untrusted content and outbound access all at once. Security researchers call it the lethal trifecta. gh-aw defends in depth through six security layers that prevent agents from leaking private data.
Step through the layers.
Compile-time validation
Schema validation, expression allowlisting and pinned actions are checked before a workflow can ever run.
Learn moreSandboxed agent
The agent runs read-only by default, with optional Cloud Hypervisor microVMs for stronger isolation.
Learn moreCredential isolation
An API proxy holds the tokens, so the agent never sees them and cannot leak them.
Learn moreSafe outputs
Only the writes you declared are applied, by a separate job with its own permissions.
Learn more
Try it safely: staged: true previews every output without writing anything.
How it works
Prompt your coding agent to create a workflow. GitHub compiles it into an Actions workflow and runs it.
Prompt
Ask your coding agent for a workflow in plain language, then refine it with
/agentic-workflow optimize it.Compile
gh aw compileturns it into a hardened, pinned Actions workflow.Run
Your chosen agent runs in GitHub Actions; approved outputs are applied.
Runs the coding agent you choose
Bring your own engine Import OpenCode, Cursor, Kiro, Aider, Crush or your own definition.
Cost under control
Set a budget per run and see where every credit goes.
- AI credits
- 256.9 AIC≈ $2.57
- Runs
- 61 stopped at cap
- Tokens
- 2.0M334K per run
- Avg turns
- 17.3max 44
AI credits per run
Cap every run
Set a budgetmax-ai-creditsandmax-turnsstop a run that runs away. On by default: 1,000 AI Credits per run.Cap every day
Daily limitsmax-daily-ai-creditslimits a workflow across 24 hours, 5,000 AIC by default. Over budget, the agent is skipped.Find the expensive runs
Monitor costgh aw logslists tokens, AIC and turns per run.gh aw auditbreaks one down. 1 AIC is $0.01.
Send traces to any OTLP backend with OpenTelemetry, and compare cost with outcomes.
Ready for organizations
Run on your own infrastructure, across every repository.
Your own runners
Run on Linux self-hosted runners, including Actions Runner Controller with Docker-in-Docker.
Self-hosted runnersEvery repository
Roll workflows out across an organization or enterprise and manage them centrally.
Using at scale
Keep going
- Hands-on workshop (opens in a new tab)Guided exercises in the terminal, the browser or Copilot.
- Peli's Agent FactoryA tour of the agents the team runs on its own repositories.
- BlogRelease notes, patterns and stories from the team.
- DocumentationConcepts, guides and the full reference.
- Slide deck (PDF, 11 MB)The technical preview deck: concepts, security model and examples.
- Agentic workflows on GitHub (opens in a new tab)Source, issues and discussions.
Create your first workflow
Prefer a guided form? Try the workflow wizard