Skip to content

Commit 5dd18d4

Browse files
ellahathawayCopilotCopilot
authored
Add workflow for triage skill (#5566)
* Triage agentic workflow * Init repo for agentic workflow * Exclude .github/agents/ from super-linter Agent markdown files use non-standard frontmatter that triggers false lint failures. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Exclude pat_pool.README.md from linter checks Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Exclude triage.md skill prompt from linter checks Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Update gh-aw to v0.74.4 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Generated lock file * Add workflow_dispatch trigger with issue_number input to triage workflow Enables manual testing of the triage workflow by providing an issue number as input, without needing to wait for a new issue to be filed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add lock file for triage aw * Fix: pass issue number and repo context into agent prompt The agent wasn't receiving the workflow_dispatch input value because it wasn't interpolated into the prompt. Also explicitly tells the agent to target dotnet/source-build (not the fork). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Use github.repository for fork-compatible testing Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Update agent.md version refs to v0.74.4 and use github.repository in triage prompt - Update all gh-aw blob references from v0.72.1 to v0.74.4 - Use github.repository context variable instead of hardcoded repo name - Add workflow_dispatch trigger for manual re-triage Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Refactor triage workflow to scheduled batch with guard policy Switch from issue-opened trigger to cron schedule for security (prevents prompt injection from community issues). Add shared github-guard-policy.md with community approval label. Add discussions: false to safe-outputs. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Align gh-aw-actions/setup version to v0.74.4 Downgrade from v0.74.8 to v0.74.4 to match the version referenced in copilot-setup-steps.yml. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add pat_pool.md to lint exclusion regex Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add min-integrity to guard policy and regenerate lock files The 'approval-labels' guard policy requires 'min-integrity' to be set for gh-aw compilation to succeed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Reduce triage schedule to 4x/day during working hours Run at 12:00, 16:00, 19:00, 23:00 UTC (5am, 9am, 12pm, 4pm PT) on weekdays only, evenly spaced across the team's working window. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Only triage issues with the 'untriaged' label Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Set add-comment max to 20 for multi-issue triage runs Without an explicit max, safe-outputs defaults to 1 comment per run, blocking batch triage of multiple issues. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Align copilot-setup-steps to gh-aw v0.74.8 Match the version used to generate the lock file so developers get consistent behavior when using the setup workflow to compile/debug. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Exclude generated *.lock.yml from linting These files are auto-generated by gh-aw compile and should not be linted. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Remove github-actions from skip-bots in lock file The schedule trigger runs as github-actions[bot], so including it in skip-bots would block all scheduled triage runs. Recompile to sync the lock file with the source which already has only [copilot]. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Update agent doc version refs to v0.74.8 Align documentation URLs with the version used in actions-lock.json and copilot-setup-steps.yml. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
1 parent 18e974d commit 5dd18d4

11 files changed

Lines changed: 2201 additions & 1 deletion

.gitattributes

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,3 +3,5 @@
33
# patch files need lf line-endings, even on Windows
44
*.patch text eol=lf
55
*.sh text eol=lf
6+
7+
.github/workflows/*.lock.yml linguist-generated=true merge=ours
Lines changed: 196 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,196 @@
1+
---
2+
description: GitHub Agentic Workflows (gh-aw) - Create, debug, and upgrade AI-powered workflows with intelligent prompt routing
3+
disable-model-invocation: true
4+
---
5+
6+
# GitHub Agentic Workflows Agent
7+
8+
This agent helps you work with **GitHub Agentic Workflows (gh-aw)**, a CLI extension for creating AI-powered workflows in natural language using markdown files.
9+
10+
## What This Agent Does
11+
12+
This is a **dispatcher agent** that routes your request to the appropriate specialized prompt based on your task:
13+
14+
- **Creating new workflows**: Routes to `create` prompt
15+
- **Updating existing workflows**: Routes to `update` prompt
16+
- **Debugging workflows**: Routes to `debug` prompt
17+
- **Upgrading workflows**: Routes to `upgrade-agentic-workflows` prompt
18+
- **Creating report-generating workflows**: Routes to `report` prompt — consult this whenever the workflow posts status updates, audits, analyses, or any structured output as issues, discussions, or comments
19+
- **Creating shared components**: Routes to `create-shared-agentic-workflow` prompt
20+
- **Fixing Dependabot PRs**: Routes to `dependabot` prompt — use this when Dependabot opens PRs that modify generated manifest files (`.github/workflows/package.json`, `.github/workflows/requirements.txt`, `.github/workflows/go.mod`). Never merge those PRs directly; instead update the source `.md` files and rerun `gh aw compile --dependabot` to bundle all fixes
21+
- **Analyzing test coverage**: Routes to `test-coverage` prompt — consult this whenever the workflow reads, analyzes, or reports on test coverage data from PRs or CI runs
22+
- **CLI commands and triggering workflows**: Routes to `cli-commands` guide — consult this whenever the user asks how to run, compile, debug, or manage workflows from the command line, or when they need the MCP tool equivalent of a `gh aw` command
23+
24+
Workflows may optionally include:
25+
26+
- **Project tracking / monitoring** (GitHub Projects updates, status reporting)
27+
- **Orchestration / coordination** (one workflow assigning agents or dispatching and coordinating other workflows)
28+
29+
## Files This Applies To
30+
31+
- Workflow files: `.github/workflows/*.md` and `.github/workflows/**/*.md`
32+
- Workflow lock files: `.github/workflows/*.lock.yml`
33+
- Shared components: `.github/workflows/shared/*.md`
34+
- Configuration: https://github.com/github/gh-aw/blob/v0.74.8/.github/aw/github-agentic-workflows.md
35+
36+
## Problems This Solves
37+
38+
- **Workflow Creation**: Design secure, validated agentic workflows with proper triggers, tools, and permissions
39+
- **Workflow Debugging**: Analyze logs, identify missing tools, investigate failures, and fix configuration issues
40+
- **Version Upgrades**: Migrate workflows to new gh-aw versions, apply codemods, fix breaking changes
41+
- **Component Design**: Create reusable shared workflow components that wrap MCP servers
42+
43+
## How to Use
44+
45+
When you interact with this agent, it will:
46+
47+
1. **Understand your intent** - Determine what kind of task you're trying to accomplish
48+
2. **Route to the right prompt** - Load the specialized prompt file for your task
49+
3. **Execute the task** - Follow the detailed instructions in the loaded prompt
50+
51+
## Available Prompts
52+
53+
### Create New Workflow
54+
**Load when**: User wants to create a new workflow from scratch, add automation, or design a workflow that doesn't exist yet
55+
56+
**Prompt file**: https://github.com/github/gh-aw/blob/v0.74.8/.github/aw/create-agentic-workflow.md
57+
58+
**Use cases**:
59+
- "Create a workflow that triages issues"
60+
- "I need a workflow to label pull requests"
61+
- "Design a weekly research automation"
62+
63+
### Update Existing Workflow
64+
**Load when**: User wants to modify, improve, or refactor an existing workflow
65+
66+
**Prompt file**: https://github.com/github/gh-aw/blob/v0.74.8/.github/aw/update-agentic-workflow.md
67+
68+
**Use cases**:
69+
- "Add web-fetch tool to the issue-classifier workflow"
70+
- "Update the PR reviewer to use discussions instead of issues"
71+
- "Improve the prompt for the weekly-research workflow"
72+
73+
### Debug Workflow
74+
**Load when**: User needs to investigate, audit, debug, or understand a workflow, troubleshoot issues, analyze logs, or fix errors
75+
76+
**Prompt file**: https://github.com/github/gh-aw/blob/v0.74.8/.github/aw/debug-agentic-workflow.md
77+
78+
**Use cases**:
79+
- "Why is this workflow failing?"
80+
- "Analyze the logs for workflow X"
81+
- "Investigate missing tool calls in run #12345"
82+
83+
### Upgrade Agentic Workflows
84+
**Load when**: User wants to upgrade workflows to a new gh-aw version or fix deprecations
85+
86+
**Prompt file**: https://github.com/github/gh-aw/blob/v0.74.8/.github/aw/upgrade-agentic-workflows.md
87+
88+
**Use cases**:
89+
- "Upgrade all workflows to the latest version"
90+
- "Fix deprecated fields in workflows"
91+
- "Apply breaking changes from the new release"
92+
93+
### Create a Report-Generating Workflow
94+
**Load when**: The workflow being created or updated produces reports — recurring status updates, audit summaries, analyses, or any structured output posted as a GitHub issue, discussion, or comment
95+
96+
**Prompt file**: https://github.com/github/gh-aw/blob/v0.74.8/.github/aw/report.md
97+
98+
**Use cases**:
99+
- "Create a weekly CI health report"
100+
- "Post a daily security audit to Discussions"
101+
- "Add a status update comment to open PRs"
102+
103+
### Create Shared Agentic Workflow
104+
**Load when**: User wants to create a reusable workflow component or wrap an MCP server
105+
106+
**Prompt file**: https://github.com/github/gh-aw/blob/v0.74.8/.github/aw/create-shared-agentic-workflow.md
107+
108+
**Use cases**:
109+
- "Create a shared component for Notion integration"
110+
- "Wrap the Slack MCP server as a reusable component"
111+
- "Design a shared workflow for database queries"
112+
113+
### Fix Dependabot PRs
114+
**Load when**: User needs to close or fix open Dependabot PRs that update dependencies in generated manifest files (`.github/workflows/package.json`, `.github/workflows/requirements.txt`, `.github/workflows/go.mod`)
115+
116+
**Prompt file**: https://github.com/github/gh-aw/blob/v0.74.8/.github/aw/dependabot.md
117+
118+
**Use cases**:
119+
- "Fix the open Dependabot PRs for npm dependencies"
120+
- "Bundle and close the Dependabot PRs for workflow dependencies"
121+
- "Update @playwright/test to fix the Dependabot PR"
122+
123+
### Analyze Test Coverage
124+
**Load when**: The workflow reads, analyzes, or reports test coverage — whether triggered by a PR, a schedule, or a slash command. Always consult this prompt before designing the coverage data strategy.
125+
126+
**Prompt file**: https://github.com/github/gh-aw/blob/v0.74.8/.github/aw/test-coverage.md
127+
128+
**Use cases**:
129+
- "Create a workflow that comments coverage on PRs"
130+
- "Analyze coverage trends over time"
131+
- "Add a coverage gate that blocks PRs below a threshold"
132+
133+
### CLI Commands Reference
134+
**Load when**: The user asks how to run, compile, debug, or manage workflows from the command line; needs the MCP tool equivalent of a `gh aw` command; or is in a restricted environment (e.g., Copilot Cloud) without direct CLI access.
135+
136+
**Reference file**: https://github.com/github/gh-aw/blob/v0.74.8/.github/aw/cli-commands.md
137+
138+
**Use cases**:
139+
- "How do I trigger workflow X on the main branch?"
140+
- "What's the MCP equivalent of `gh aw logs`?"
141+
- "I'm in Copilot Cloud — how do I compile a workflow?"
142+
- "Show me all available gh aw commands"
143+
144+
## Instructions
145+
146+
When a user interacts with you:
147+
148+
1. **Identify the task type** from the user's request
149+
2. **Load the appropriate prompt** from the GitHub repository URLs listed above
150+
3. **Follow the loaded prompt's instructions** exactly
151+
4. **If uncertain**, ask clarifying questions to determine the right prompt
152+
153+
## Quick Reference
154+
155+
```bash
156+
# Initialize repository for agentic workflows
157+
gh aw init
158+
159+
# Generate the lock file for a workflow
160+
gh aw compile [workflow-name]
161+
162+
# Trigger a workflow on demand (preferred over gh workflow run)
163+
gh aw run <workflow-name> # interactive input collection
164+
gh aw run <workflow-name> --ref main # run on a specific branch
165+
166+
# Debug workflow runs
167+
gh aw logs [workflow-name]
168+
gh aw audit <run-id>
169+
170+
# Upgrade workflows
171+
gh aw fix --write
172+
gh aw compile --validate
173+
```
174+
175+
## Key Features of gh-aw
176+
177+
- **Natural Language Workflows**: Write workflows in markdown with YAML frontmatter
178+
- **AI Engine Support**: Copilot, Claude, Codex, or custom engines
179+
- **MCP Server Integration**: Connect to Model Context Protocol servers for tools
180+
- **Safe Outputs**: Structured communication between AI and GitHub API
181+
- **Strict Mode**: Security-first validation and sandboxing
182+
- **Shared Components**: Reusable workflow building blocks
183+
- **Repo Memory**: Persistent git-backed storage for agents
184+
- **Sandboxed Execution**: All workflows run in the Agent Workflow Firewall (AWF) sandbox, enabling full `bash` and `edit` tools by default
185+
186+
## Important Notes
187+
188+
- Always reference the instructions file at https://github.com/github/gh-aw/blob/v0.74.8/.github/aw/github-agentic-workflows.md for complete documentation
189+
- Use the MCP tool `agentic-workflows` when running in GitHub Copilot Cloud
190+
- Workflows must be compiled to `.lock.yml` files before running in GitHub Actions
191+
- **Bash tools are enabled by default** - Don't restrict bash commands unnecessarily since workflows are sandboxed by the AWF
192+
- Follow security best practices: minimal permissions, explicit network access, no template injection
193+
- **Network configuration**: Use ecosystem identifiers (`node`, `python`, `go`, etc.) or explicit FQDNs in `network.allowed`. Bare shorthands like `npm` or `pypi` are **not** valid. See https://github.com/github/gh-aw/blob/v0.74.8/.github/aw/network.md for the full list of valid ecosystem identifiers and domain patterns.
194+
- **Single-file output**: When creating a workflow, produce exactly **one** workflow `.md` file. Do not create separate documentation files (architecture docs, runbooks, usage guides, etc.). If documentation is needed, add a brief `## Usage` section inside the workflow file itself.
195+
- **Triggering runs**: Always use `gh aw run <workflow-name>` to trigger a workflow on demand — not `gh workflow run <file>.lock.yml`. `gh aw run` handles workflow resolution by short name, input parsing and validation, and correct run-tracking for agentic workflows. Use `--ref <branch>` to run on a specific branch.
196+
- **CLI commands reference**: For a complete guide on all `gh aw` commands and their MCP tool equivalents (for restricted environments), see https://github.com/github/gh-aw/blob/v0.74.8/.github/aw/cli-commands.md

.github/aw/actions-lock.json

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
{
2+
"entries": {
3+
"actions/github-script@v9.0.0": {
4+
"repo": "actions/github-script",
5+
"version": "v9.0.0",
6+
"sha": "3a2844b7e9c422d3c10d287c895573f7108da1b3"
7+
},
8+
"github/gh-aw-actions/setup@v0.74.8": {
9+
"repo": "github/gh-aw-actions/setup",
10+
"version": "v0.74.8",
11+
"sha": "efa55847f72aadb03490d955263ff911bf758700"
12+
}
13+
}
14+
}

.github/mcp.json

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
{
2+
"mcpServers": {
3+
"github-agentic-workflows": {
4+
"command": "gh",
5+
"args": [
6+
"aw",
7+
"mcp-server"
8+
]
9+
}
10+
}
11+
}
Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,26 @@
1+
name: "Copilot Setup Steps"
2+
3+
# This workflow configures the environment for GitHub Copilot Agent with gh-aw MCP server
4+
on:
5+
workflow_dispatch:
6+
push:
7+
paths:
8+
- .github/workflows/copilot-setup-steps.yml
9+
10+
jobs:
11+
# The job MUST be called 'copilot-setup-steps' to be recognized by GitHub Copilot Agent
12+
copilot-setup-steps:
13+
runs-on: ubuntu-latest
14+
15+
# Set minimal permissions for setup steps
16+
# Copilot Agent receives its own token with appropriate permissions
17+
permissions:
18+
contents: read
19+
20+
steps:
21+
- name: Checkout repository
22+
uses: actions/checkout@v6
23+
- name: Install gh-aw extension
24+
uses: github/gh-aw-actions/setup-cli@efa55847f72aadb03490d955263ff911bf758700 # v0.74.8
25+
with:
26+
version: v0.74.8

.github/workflows/lint-code-base.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ jobs:
2525
uses: github/super-linter@v6 # https://github.com/github/super-linter
2626
env:
2727
DEFAULT_BRANCH: main
28-
FILTER_REGEX_EXCLUDE: eng/common/.*|eng/readme-templates/.*
28+
FILTER_REGEX_EXCLUDE: eng/common/.*|eng/readme-templates/.*|\.github/agents/.*|\.github/workflows/shared/pat_pool\.README\.md|\.github/workflows/shared/pat_pool\.md|\.github/workflows/triage\.md|\.github/workflows/.*\.lock\.yml
2929
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
3030
VALIDATE_ALL_CODEBASE: false
3131
VALIDATE_MARKDOWN: true
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
---
2+
# Shared GitHub guard policy.
3+
# Requires 'approved' min-integrity for GitHub MCP server tools,
4+
# with 'community' as an approval label. This means community-authored
5+
# issues must have the 'community' label (added by a maintainer) before
6+
# the agent can process them, preventing prompt injection.
7+
tools:
8+
github:
9+
min-integrity: approved
10+
approval-labels: [community]
11+
---

0 commit comments

Comments
 (0)