Rubber Duck Thursdays | Let's talk about GitHub Agentic Workflows!

GitHubAbout 6 min readFeb 20, 2026Watch original
THE SUMMARYAI-generated

GitHub Agentic Workflows: A Deep Dive

Key Concepts:

  • Agentic Workflows: A new GitHub feature enabling the execution of workflows defined using natural language (Markdown).
  • Copilot CLI: The command-line interface for GitHub Copilot, utilized within agentic workflows to execute prompts.
  • Guardrails: Security measures implemented within agentic workflows to control input, processing, and output, mitigating risks like prompt injection.
  • Safe Outputs: A configuration setting defining the permissible actions an agentic workflow can perform (e.g., creating issues, but not modifying files).
  • Prompt Injection: A security vulnerability where malicious input manipulates the behavior of a language model.
  • Deterministic Extraction: Using reliable code to extract data before analysis by a language model.
  • I18N Ops: A design pattern for automating internationalization (translation) of content within a repository.
  • gh (GitHub CLI): The GitHub command-line interface used for interacting with GitHub repositories and workflows.
  • gh aw compile: A command within the GitHub CLI used to compile Markdown-based agentic workflows into executable GitHub Actions workflows.

1. Introduction & Core Functionality

GitHub Agentic Workflows represent a paradigm shift in how developers interact with their repositories. Instead of traditional YAML-based workflows, these workflows are defined using Markdown, allowing developers to express desired actions in natural language. The core principle is to leverage GitHub Copilot CLI within a secure environment to execute these prompts. Cassidy initially described this as instructing the system to "create a report for me in an issue every single day showing me like the number of contributors in my repo and like what are the most high priority issues," and having it automatically execute this task. Bruno clarified that agentic workflows trigger the Copilot CLI during action runner execution, with the prompt being the workflow.

2. Security Considerations & Guardrails

A primary focus of agentic workflows is security. Directly executing Copilot CLI prompts within workflows (without agentic workflows) poses significant risks, particularly prompt injection, where malicious input could compromise the system. Agentic workflows address this by introducing a security layer around input, processing, and output. This is achieved through features like "Safe Outputs," which restrict the actions an agentic workflow can perform. For example, a workflow might be permitted to create an issue but prohibited from modifying files or accessing secrets. A specific example highlighted was the redaction of URLs generated by Copilot within issues to prevent potential exposure of hidden information or sending secrets to external servers. Pali, a GitHub engineer, explained this URL redaction as a proactive security measure against prompt injection attacks.

3. Technical Implementation & Workflow Compilation

The process involves writing a Markdown file containing the workflow description. This Markdown is then compiled into a standard GitHub Actions workflow file using the gh aw compile command. This compilation process incorporates the necessary toolsets and security layers. The resulting workflow file (with a .yml extension) is then executed by GitHub Actions. The header section of the Markdown file defines the workflow's configuration (schedule, permissions, tools), while the body contains the natural language prompt. The compiled workflow includes a "safe outputs" section, explicitly defining the permissible actions. Bruno demonstrated this process live, showcasing the compilation of a workflow to generate a daily repository status report.

4. Use Cases & Design Patterns

Several potential use cases were discussed:

  • Daily Reporting: Generating daily reports on repository activity (contributors, issues, pull requests).
  • Data Ops: Extracting, analyzing, and summarizing data from various sources (GitHub API, databases, REST APIs). This was highlighted as a particularly powerful application, enabling enrichment of raw data.
  • I18N Ops: Automating the translation of content within a repository, potentially assigning translation tasks to language experts based on the target language.
  • Chat Ops: Triggering actions based on commands within chat platforms.
  • Issue Management: Automating tasks related to issue creation, categorization, and assignment.

GitHub provides pre-built design patterns (accessible via the "agent factory") to accelerate workflow development.

5. Practical Demonstration & CLI Usage

Bruno demonstrated the creation and execution of an agentic workflow using the GitHub CLI. He initialized a repository with agentic workflow support using gh a init, then created a Markdown file defining a daily Hacker News digest workflow. He then used gh aw compile to compile the Markdown into a GitHub Actions workflow. The demonstration highlighted the ability to trigger workflows from the command line and the automatic creation of pull requests for workflow changes. He also showcased the use of the gh audit command for troubleshooting failed workflows.

6. Slash Commands & Agent Interaction

Agentic workflows can be triggered by slash commands within GitHub (e.g., /new-ideas). This allows users to interact with the workflow directly from within the repository interface. Bruno demonstrated this by creating a /new-ideas command that triggered a workflow to generate ideas based on a given issue. He emphasized the difference between using a slash command with an agentic workflow (which provides more control and security) versus simply prompting Copilot directly.

7. Troubleshooting & Auditing

GitHub provides tools for troubleshooting agentic workflows. The gh audit command allows developers to analyze failed workflows and identify potential issues. Furthermore, Pali has developed a system where a broken workflow can automatically trigger a pull request with a proposed fix, leveraging Copilot to diagnose and resolve the problem.

8. Data & Statistics (Limited)

While specific statistics weren't heavily emphasized, the demonstration showed the workflow generating a daily report including:

  • Number of merged pull requests (5 in the example)
  • Total patterns across categories (99 in the example)
  • Number of issues closed (9 in the example)

9. Notable Quotes:

  • Bruno: "If we are a product person we promote the product if we are a devro person we complain about the product and we can do vice versa so it's the same."
  • Cassidy: "The guard rails are like they're probably one of those unsung heroes where it's it's things that like when when they're there you don't notice them at all and and like when they don't it's bad and so it's it's like a really good and exciting thing to have those guard rails even though it's something that people will probably never really think about."
  • Bruno: "The value of agentic workflows is that it can do so much more than just a prompt and a chat and you know an an output."

Conclusion:

GitHub Agentic Workflows offer a promising new approach to automating tasks within repositories. By combining the power of natural language with the security of a controlled environment, they empower developers to create sophisticated workflows with greater ease and confidence. The emphasis on security, coupled with the flexibility of Markdown-based definitions, positions agentic workflows as a valuable tool for streamlining development processes and enhancing repository management. The integration with Copilot and the availability of design patterns and troubleshooting tools further contribute to their practicality and appeal.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.