No description
  • Go 65.2%
  • JavaScript 31.7%
  • Shell 1.6%
  • TypeScript 1.2%
  • Makefile 0.2%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-07-20 20:29:06 +02:00
.changeset Model alias inventory update 2026-07-20; fix pr-sous-chef review-thread skip contract (#46702) 2026-07-20 07:03:13 +02:00
.claude/skills/playwright-cli Prevent Playwright CLI skills install from timing out on browser downloads (#35314) 2026-05-27 14:44:31 -07:00
.devcontainer feat(init): make --codespaces optional-value; grant discussions/issues write (#46849) 2026-07-20 07:31:05 -07:00
.github Treat expression-backed engine.model as omitted when empty (#46777) 2026-07-20 20:02:58 +02:00
.sentrux feat: add .sentrux/rules.toml with architectural quality gates (#34062) 2026-05-22 09:19:09 -07:00
.serena Add preconfigured Copilot PAT onboarding in gh aw add-wizard (#45987) 2026-07-16 17:26:02 +02:00
.skill-optimizer fix(skill-optimizer): update workflow for v2.0.0 CLI interface (#29902) 2026-05-03 06:10:43 -07:00
.smoke-tests chore: bump Claude Code → 2.1.49, Copilot → 0.0.412, GitHub MCP Server → v0.31.0 (#17120) 2026-02-20 03:45:44 -08:00
.vscode remove extension recommendations 2026-05-23 14:17:15 +00:00
actions Treat expression-backed engine.model as omitted when empty (#46777) 2026-07-20 20:02:58 +02:00
cmd fix(cli): address 16 CLI consistency issues from 2026-07-20 audit (#46854) 2026-07-20 10:51:52 -07:00
docs Refactor bootstrap profile runner into focused modules (#46855) 2026-07-20 20:29:06 +02:00
eslint-factory Recognize global.getOctokit() aliases in no-github-request-interpolated-route (#46856) 2026-07-20 18:15:31 +02:00
internal/tools search and replace githubnext/gh-aw to github/gh-aw (#13335) 2026-02-02 12:33:07 -08:00
pkg Refactor bootstrap profile runner into focused modules (#46855) 2026-07-20 20:29:06 +02:00
research research: update Ubuntu runner image analysis to 20260705.232.1 (#45889) 2026-07-16 06:47:36 +02:00
schema-demos feat: add schema coverage demo for max-turn-cache-misses (#40753) 2026-06-22 07:43:45 -07:00
schemas Handle degenerate REVIEW_REQUIRED PR state in dismiss_pull_request_review (#43657) 2026-07-05 19:55:29 -07:00
scratchpad [docs] Consolidate developer specifications into instructions file (v9.21) (#46447) 2026-07-18 18:05:00 +02:00
scripts Update Safe Outputs conformance checker to spec v1.26.0 (#46715) 2026-07-20 07:45:50 +02:00
socials chore(shell): disable history expansion in bash scripts and MCP CLI wrappers (#27851) 2026-04-22 13:54:24 -07:00
specs spec: bump threat detection spec to v1.0.17 (2026-07-20 audit) (#46701) 2026-07-20 06:31:47 +02:00
tmp Move "Generate agentic run info" to activation job; merge workflow overview into it; rename activation artifact (#18843) 2026-02-28 09:10:22 -08:00
.architecture.yml Configure Architecture Guardian thresholds via repository-level .architecture.yml (#26664) 2026-04-16 08:56:35 -07:00
.gitattributes Add PowerShell installer path for gh-aw and cover it in Windows CI (#44953) 2026-07-13 08:31:31 +02:00
.gitignore Render workshop content through Astro-generated markdown sources (#46406) 2026-07-18 15:27:53 +02:00
.golangci.yml Reduce standalone gosec exclusions to restore actionable detection of new findings (#44705) 2026-07-10 16:43:00 +02:00
.nvmrc [docs] Update Astro dependencies - 2026-03-17 (#21394) 2026-03-17 07:36:22 -07:00
.poutine.yml
.prettierignore don't format beads 2026-01-05 02:17:41 +00:00
.prettierrc.json Update @types/node to v20 for Node.js 20 compatibility (#7849) 2025-12-26 17:02:35 -08:00
AGENTS.md Add create-canvas skill for cloud agent canvas extension authoring (#42147) 2026-06-28 16:50:56 -07:00
CHANGELOG.md docs: record breaking change for gh aw add rejecting packages with aw.yml config (#46273) 2026-07-18 07:47:00 +02:00
CODE_OF_CONDUCT.md
CODEOWNERS
CONTRIBUTING.md docs: update release process for weekly/bi-weekly minor cadence (#41087) 2026-06-23 11:44:26 -07:00
create.md Refactor agentic-workflows dispatcher from legacy agent file to skill (#35580) 2026-05-28 17:25:39 -07:00
DEADCODE.md docs: update DEADCODE.md — document completion of dead code removal (#19290) 2026-03-03 01:04:09 +00:00
debug.md Refactor agentic-workflows dispatcher from legacy agent file to skill (#35580) 2026-05-28 17:25:39 -07:00
DEVGUIDE.md feat: fail-fast guardrail for schema file changes without rebuild (#46189) 2026-07-18 13:05:28 +02:00
DICTATION.md docs: update DICTATION.md glossary to 256 terms (#46546) 2026-07-19 08:55:33 +02:00
Dockerfile Add support for GITHUB_ACTOR and GITHUB_REPOSITORY environment variables with --validate-actor flag in mcp-server command (#15084) 2026-02-12 07:02:44 -08:00
gh-aw-wasm Cover wasm-only files in custom lint CI (#42650) 2026-06-30 22:58:46 -07:00
go.mod feat: mode-specific intent guidance for all safe-output mutation tools (#46861) 2026-07-20 08:32:07 -07:00
go.sum chore(deps): update charmbracelet/x/exp/golden to v0.0.0-20260720091843-3eef36eaaa28 (#46800) 2026-07-20 13:56:15 +02:00
install-gh-aw.ps1 Add PowerShell installer path for gh-aw and cover it in Windows CI (#44953) 2026-07-13 08:31:31 +02:00
install-gh-aw.sh fix: increase sendAndWait timeout in sample SDK drivers from 60s to 10min (#39933) 2026-06-17 21:36:02 -07:00
install.md Refactor agentic-workflows dispatcher from legacy agent file to skill (#35580) 2026-05-28 17:25:39 -07:00
LICENSE fix copyright 2026-02-12 18:21:28 +00:00
linters feat(linters): add nilctxpassed analyzer (#45799) 2026-07-15 23:08:33 +02:00
Makefile docs: fix markdown links not rendered inside GFM alert HTML blocks (#46569) 2026-07-19 03:25:48 -07:00
optimize.md feat: add "Optimize token consumption" section to agent failure issues when a guardrail triggers (#39069) 2026-06-13 06:58:17 -07:00
package.md Move specification docs into a dedicated collapsed Specs section (#37160) 2026-06-05 10:52:25 -07:00
README.md [community] Update community contributions in README (#46512) 2026-07-19 05:43:40 +02:00
SECURITY.md
SKILL.md Unblock daily skill-optimizer runs by adding root SKILL surface docs, committed config, and early workflow preflight (#27988) 2026-04-22 23:02:44 -07:00
SUPPORT.md
test-setup-local.sh chore(shell): disable history expansion in bash scripts and MCP CLI wrappers (#27851) 2026-04-22 13:54:24 -07:00
test_dup_import ctxbackground: resolve Background() calls by package identity, not identifier text (#38854) 2026-06-12 14:13:20 -07:00
tools.go chore: remove unused dependencies from go.mod and go.sum 2026-02-25 16:25:35 +00:00

Configure this project with agentic workflows

Hey agent! If this repository hasn't been configured with agentic workflows yet, here is how to set it up.

  1. Install the gh aw CLI extension using the install script (no GitHub token required):

    curl -sL https://raw.githubusercontent.com/github/gh-aw/main/install-gh-aw.sh | bash
    
  2. Run the init command to configure the repository:

    gh aw init
    
  3. Add a daily repo status agentic workflow using the add command:

    gh aw add --create-pull-request
    

    The workflow should:

    • Run on a daily schedule
    • Summarize the repository status (open issues, recent PRs, CI health)
    • Use the Quick Start engine selector to choose your runtime:
      • For copilot, grant copilot-requests: write
      • For claude, set the ANTHROPIC_API_KEY repository secret
      • For codex, set the OPENAI_API_KEY repository secret
      • For gemini, set the GEMINI_API_KEY repository secret

GitHub Agentic Workflows

Write agentic workflows in natural language markdown, and run them in GitHub Actions.

Note

Releases 0.68.4 through 0.71.3 are being retired due to a bug that impacts billing. If you are running one of these versions, please upgrade to the latest release as soon as possible.

Contents

Quick Start

Ready to get your first agentic workflow running? Follow our step-by-step Quick Start Guide to install the extension, add a sample workflow, and see it in action.

Overview

Learn about the concepts behind agentic workflows, explore available workflow types, and understand how AI can automate your repository tasks. See How It Works. Supports GitHub Copilot, Claude (Anthropic), Codex (OpenAI), and Gemini (Google) — pick whichever AI account you already have.

Guardrails

Guardrails, safety and security are foundational to GitHub Agentic Workflows. Workflows run with read-only permissions by default, with write operations only allowed through sanitized safe-outputs. The system implements multiple layers of protection including sandboxed execution, input sanitization, network isolation, supply chain security (SHA-pinned dependencies), tool allow-listing, and compile-time validation. Access can be gated to team members only, with human approval gates for critical operations, ensuring AI agents operate safely within controlled boundaries. See the Security Architecture for comprehensive details on threat modeling, implementation guidelines, and best practices.

Using agentic workflows in your repository requires careful attention to security considerations and careful human supervision, and even then things can still go wrong. Use it with caution, and at your own risk.

Documentation

For complete documentation, examples, and guides, see the Documentation. If you are an agent, see llms.txt source and llms-full.txt source.

If you are running a version between 0.68.4 and 0.71.3, upgrading is strongly recommended due to a bug that impacts billing.

Contributing

For development setup and contribution guidelines, see CONTRIBUTING.md.

Custom Go linters

To build and test repository custom linters:

  • go test ./pkg/linters/<linter-name>/...
  • go build ./cmd/linters
  • make golint-custom

make golint-custom builds cmd/linters and runs the custom analyzers against ./cmd/... and ./pkg/....

🌍 Community Contributions

Community members whose issues were resolved — updated automatically.

@aaronspindler (1) @abillingsley (2) @adam-cobb (1) @adamhenson (2) @adhikjoshi (1) @ahmadabdalla (1) @ajfeldman6 (1) @AkshatRaj00 (1) @alanpeabody (1) @alcastaneda (1) @AlexanderWert (1) @AlexDeMichieli (1) @alexsiilvaa (2) @alondahari (13) @alvistar (1) @AmoebaChant (1) @anthonymastreanvae (10) @aoxiangtianyu-go (1) @apenab (1) @arezero (6) @arthurfvives (8) @Artur- (1) @askpaisa (1) @askpt (1) @astefan (1) @b2pacific (1) @babaakihiro (2) @bartul (1) @bbonafed (23) @beardofedu (1) @benissimo (6) @benvillalobos (12) @bmerkle (3) @boydj (2) @Bra1nFartz (1) @BrandonLewis (1) @bryanchen-d (15) @bryanknox (1) @bshore-bf (1) @Calidus (4) @camposbrunocampos (2) @carlincherry (1) @CatsMiaow (1) @chepa92 (1) @chrisfregly (2) @chrizbo (7) @CiscoRob (2) @cknight (2) @clementbolin (1) @cogni-ai-ee (2) @consulthys (3) @Corb3nik (3) @corygehr (20) @corymhall (1) @dagecko (1) @Daidanny008 (1) @Dan-Albrecht (1) @Dan-Co (2) @danielmeppiel (6) @danquirk (1) @darwin-gonzales (1) @davidahmann (3) @dbudym-cs (1) @DeagleGross (1) @devantler (2) @deyaaeldeen (10) @dfrysinger (2) @dgolombek (1) @dholmes (3) @dhrapson (2) @DimaBir (1) @dkurepa (1) @DogeAmazed (1) @doughgle (1) @drehelis (4) @DrPye (1) @dsibilio (1) @dsolteszopyn (2) @dsyme (32) @duncankmckinnon (1) @eaftan (3) @edburns (1) @edgeq (2) @elika56 (1) @eran-medan (1) @ericchansen (1) @ericstj (2) @Esomoire-consultancy-Company (1) @Evangelink (3) @fbecar22 (1) @ferryhinardi (1) @flatiron32 (2) @fr4nc1sc0-r4m0n (1) @G1Vh (1) @GandrotulaRajesh (1) @github-actions (10) @github-antoine-brechon (4) @GKersten (1) @glitch-ux (1) @grahame-white (9) @h-no (1) @h3y6e (2) @haavamoa (1) @harrisoncramer (2) @heaversm (1) @heiskr (3) @hermanho (1) @holwerda (3) @hpsin (1) @hrishikeshathalye (1) @ianreay (1) @IEvangelist (13) @Infinnerty (1) @insop (1) @ivancea (5) @j-srodka (6) @jamesadevine (4) @JamesNK (4) @JanKrivanek (3) @jaroslawgajewski (26) @JasonYeMSFT (1) @jbaruch (1) @jcooklin (1) @jeffhandley (9) @jeremiah-snee-openx (1) @jfomhover (1) @jitran (3) @joesturge (1) @johnpreed (4) @johnwilliams-12 (11) @jonathanpeppers (3) @joperezr (1) @JoshGreenslade (2) @jsalmassy (1) @jsoref (2) @jsquire (1) @jtracey93 (1) @kaovilai (4) @karl-petter-sj (1) @katriendg (1) @kbreit-insight (5) @KGoovaer (1) @kkruel8100 (1) @Krzysztof-Cieslak (1) @kthompson (1) @labudis (2) @ladamski (1) @lindeberg (1) @look (1) @lpcox (6) @lukeed (1) @lupinthe14th (3) @m-titov (1) @maikelvdh (2) @mark-hingston (1) @mason-tim (8) @matiloti (1) @mattcosta7 (1) @MatthewBunker (2) @MatthewLabasan-NBCU (2) @MattSkala (3) @MauroDruwel (4) @maxbeizer (1) @maxknv (1) @mcantrell (1) @mdashrraf (1) @MH0386 (1) @mhavelock (1) @michen00 (2) @microsasa (9) @mlinksva (1) @mnkiefer (4) @molson504x (2) @Mossaka (3) @mrfelton (4) @mrjf (7) @MrSanchez (1) @mstrathman (1) @mvdbos (2) @nestele (1) @neta-vega (2) @NicoAvanzDev (3) @NicolasRannou (1) @Nikhil-Anand-DSG (1) @NikolajBjorner (2) @norrietaylor (8) @octatone (1) @PaulAylward2 (1) @petercort (1) @pethers (1) @pgaskin (1) @pholleran (4) @Phonesis (1) @Pierrci (1) @plengauer (1) @pmalarme (1) @polmichel (2) @ppusateri (1) @praveenkuttappan (1) @PureWeen (5) @qwert666 (1) @rabo-unumed (4) @racedale (1) @radiantspace (2) @rafael-unloan (1) @reggie-k (1) @rhardouin (2) @rmarinho (1) @romainh-betclic (1) @rspurgeon (4) @Rubyj (3) @ruokun-niu (1) @ryckmansm (2) @salekseev (3) @samuelkahessay (29) @samus-aran (1) @sbodapati-gfm (1) @seangibeault (2) @sg650 (12) @shawnHartsell (1) @shiran-gutsy (1) @shubhamtanwar23 (3) @siyo-rms (1) @srgibbs99 (6) @ssulei7 (1) @stacktick (1) @stefankrzyz (1) @steliosfran (3) @straub (5) @strawgate (44) @susmahad (3) @swimmesberger (1) @szabta89 (3) @tadelesh (1) @Tarekchehahde (2) @theletterf (16) @thi-feonir (1) @timdittler (3) @tinytelly (1) @tomasmed (1) @tore-unumed (16) @trask (4) @tsm-harmoney (5) @tspascoal (2) @tvu4-wowcorp (1) @tylersmalley (1) @UncleBats (2) @v1v (2) @verkyyi (2) @veverkap (3) @ViktorHofer (3) @virenpepper (1) @vishalagrawal-jisr (2) @whoschek (1) @wizardofosmium (1) @wtgodbe (4) @yaananth (1) @Yoyokrazy (2) @yskopets (51) @zarenner (5) @zkoppert (2)

Share Feedback

We welcome your feedback on GitHub Agentic Workflows!

Peli's Agent Factory

See the Peli's Agent Factory for a guided tour through many uses of agentic workflows.

GitHub Agentic Workflows is supported by companion projects that provide additional security and integration capabilities:

  • Agent Workflow Firewall (AWF) - Network egress control for AI agents, providing domain-based access controls and activity logging for secure workflow execution
  • MCP Gateway - Routes Model Context Protocol (MCP) server calls through a unified HTTP gateway for centralized access management
  • gh-aw-actions - Shared library of custom GitHub Actions used by compiled workflows, providing functionality such as MCP server file management

Workshop

Tip

Ready to learn GitHub Agentic Workflows hands-on? The gh-aw-workshop is a self-contained, step-by-step workshop repository designed to teach you how to build, run, and customize agentic workflows from scratch.

Fork the workshop repository and follow along at your own pace.