Intelligent GitHub repository automation, with your own agents.

Copilot, Claude Code, Codex or Gemini triage issues, investigate failures and open pull requests on your repo. Safely, with strong guardrails, in GitHub Actions.

Create a workflowPaste into your favourite coding agentInitialize this repository for GitHub Agentic Workflows using https://raw.githubusercontent.com/github/gh-aw/main/install.md

Prefer a guided form? Try the workflow wizard

Start every day with a better repository, improved while you sleep.

The coding agents you know and love triage issues, investigate failures and open pull requests overnight. Under your rules, in GitHub Actions.

Create a workflowPaste into your favourite coding agentInitialize this repository for GitHub Agentic Workflows using https://raw.githubusercontent.com/github/gh-aw/main/install.md

Prefer a guided form? Try the workflow wizard

Continuous AI for every repository, always running.

A third pillar beside CI and CD: coding agents that keep improving your repository, triaging, documenting, testing and fixing in GitHub Actions, under guardrails you control.

Create a workflowPaste into your favourite coding agentInitialize this repository for GitHub Agentic Workflows using https://raw.githubusercontent.com/github/gh-aw/main/install.md

Prefer a guided form? Try the workflow wizard

Watch it run

Create and run your first workflow in under two minutes.

Install the extension, add a sample workflow and trigger the first run. Follow the quick start →

Ask Copilot in your repository's Agents tab to write the workflow for you. Create a workflow →

Safe by default

Agents read by default. Every write is checked before it lands.

An agent becomes dangerous when it has private data, untrusted content and outbound access all at once. Security researchers call it the lethal trifecta. gh-aw defends in depth through six security layers that prevent agents from leaking private data.

Diagram of the lethal trifecta: three capabilities that are dangerous when an agent holds all of them at once. Private data means secrets and credentials. Untrusted content means issues and pull request comments. Outbound access means web pages, APIs and writes. Each one would reach the agent at the centre, but gh-aw cuts every leg: the isolated sandbox keeps private data away from the agent, integrity filtering screens untrusted content, and the agent firewall restricts outbound access.

Step through the layers.

The agent
  1. Compile-time validation

    Schema validation, expression allowlisting and pinned actions are checked before a workflow can ever run.

    Learn more
  2. Sandboxed agent

    The agent runs read-only by default, with optional Cloud Hypervisor microVMs for stronger isolation.

    Learn more
  3. Credential isolation

    An API proxy holds the tokens, so the agent never sees them and cannot leak them.

    Learn more
  4. Integrity filtering

    Untrusted GitHub content is filtered before the agent sees it.

    Learn more
  5. Threat detection

    A separate job scans proposed outputs and blocks suspicious ones.

    Learn more
  6. Safe outputs

    Only the writes you declared are applied, by a separate job with its own permissions.

    Learn more
Your repository

Try it safely: staged: true previews every output without writing anything.

How it works

Prompt your coding agent to create a workflow. GitHub compiles it into an Actions workflow and runs it.

  1. Prompt

    Ask your coding agent for a workflow in plain language, then refine it with /agentic-workflow optimize it.

  2. Compile

    gh aw compile turns it into a hardened, pinned Actions workflow.

  3. Run

    Your chosen agent runs in GitHub Actions; approved outputs are applied.

Runs the coding agent you choose

Bring your own engine Import OpenCode, Cursor, Kiro, Aider, Crush or your own definition.

Cost under control

Set a budget per run and see where every credit goes.

issue-triageCopilot
AI credits
256.9 AIC≈ $2.57
Runs
61 stopped at cap
Tokens
2.0M334K per run
Avg turns
17.3max 44

AI credits per run

  1. Run 18409322715, Sep 25: 28.1 AIC, 11 turns, 2.6m
  2. Run 18409951280, Sep 26: 33.2 AIC, 13 turns, 3.1m
  3. Run 18410763311, Sep 28: 24.9 AIC, 9 turns, 2.2m
  4. Run 18411520968, Sep 29: 100.6 AIC, 44 turns, 9.8m, stopped at cap
  5. Run 18411877042, Oct 1: 38.7 AIC, 15 turns, 3.4m
  6. Run 18412093317, Oct 1: 31.4 AIC, 12 turns, 2.9m
  • Cap every run

    max-ai-credits and max-turns stop a run that runs away. On by default: 1,000 AI Credits per run.

    Set a budget
  • Cap every day

    max-daily-ai-credits limits a workflow across 24 hours, 5,000 AIC by default. Over budget, the agent is skipped.

    Daily limits
  • Find the expensive runs

    gh aw logs lists tokens, AIC and turns per run. gh aw audit breaks one down. 1 AIC is $0.01.

    Monitor cost

Send traces to any OTLP backend with OpenTelemetry, and compare cost with outcomes.

Ready for organizations

Run on your own infrastructure, across every repository.

  • Your own runners

    Run on Linux self-hosted runners, including Actions Runner Controller with Docker-in-Docker.

    Self-hosted runners
  • Every repository

    Roll workflows out across an organization or enterprise and manage them centrally.

    Using at scale

Create your first workflow

Create a workflowPaste into your favourite coding agentInitialize this repository for GitHub Agentic Workflows using https://raw.githubusercontent.com/github/gh-aw/main/install.md

Prefer a guided form? Try the workflow wizard