Prevents contributors from pushing compiled YAML (.yml, .yaml, .lock.yml)
or .github/ directories into the workflows/ directory. Only .md markdown
source files are accepted — compilation happens downstream via gh aw compile.
This is a security measure to prevent malicious GitHub Actions code
from being introduced through contributed agentic workflows.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>