mirror of
https://github.com/github/awesome-copilot.git
synced 2026-08-01 23:12:29 +00:00
0648d53070
* feat: add Trojan Skill Hunter agent for auditing AI customization contributions Adds a new agent that audits .agent.md, SKILL.md, .instructions.md, hooks.json, and MCP/plugin manifests for hidden prompt injection, MCP-style tool poisoning/shadowing, unicode steganography, excessive-agency scope mismatches, and rug-pull/supply-chain drift before contributions are merged, installed, or trusted. Mapped to the OWASP Top 10 for LLM Applications (2025) and Invariant Labs' MCP Tool Poisoning Attack research. Includes an explicit self-defense rule so the agent treats reviewed content as untrusted data, never instructions to obey. * fix: reword attack-pattern examples to avoid PR risk-scan false positives The Rule Zero bullet and two rug-pull/unpinned-fetch examples quoted the exact literal phrases (e.g. 'ignore previous instructions', 'curl | bash') that the repo's automated PR Risk Scan greps for. Reworded to convey the identical meaning without the literal trigger strings - confirmed locally with 'node eng/pr-risk-scan.mjs' (0 high/medium/info findings, was 3 high). --------- Co-authored-by: Shubham Jiyani <shubham.jiyani@atqor.com>
⚡ Agentic Workflows
Agentic Workflows are AI-powered repository automations that run coding agents in GitHub Actions. Defined in markdown with natural language instructions, they enable event-triggered and scheduled automation with built-in guardrails and security-first design.
How to Contribute
See CONTRIBUTING.md for guidelines on how to contribute new workflows, improve existing ones, and share your use cases.
How to Use Agentic Workflows
What's Included:
- Each workflow is a single
.mdfile with YAML frontmatter and natural language instructions - Workflows are compiled to
.lock.ymlGitHub Actions files viagh aw compile - Workflows follow the GitHub Agentic Workflows specification
To Install:
- Install the
gh awCLI extension:gh extension install github/gh-aw - Copy the workflow
.mdfile to your repository's.github/workflows/directory - Compile with
gh aw compileto generate the.lock.ymlfile - Commit both the
.mdand.lock.ymlfiles
To Activate/Use:
- Workflows run automatically based on their configured triggers (schedules, events, slash commands)
- Use
gh aw run <workflow>to trigger a manual run - Monitor runs with
gh aw statusandgh aw logs
When to Use:
- Automate issue triage and labeling
- Generate daily status reports
- Maintain documentation automatically
- Run scheduled code quality checks
- Respond to slash commands in issues and PRs
- Orchestrate multi-step repository automation
| Name | Description | Triggers |
|---|---|---|
| Daily Issues Report | Generates a daily summary of open issues and recent activity as a GitHub issue | schedule |
| OSPO Contributors Report | Monthly contributor activity metrics across an organization's repositories. | schedule, workflow_dispatch |
| OSPO Organization Health Report | Comprehensive weekly health report for a GitHub organization. Surfaces stale issues/PRs, merge time analysis, contributor leaderboards, and actionable items needing human attention. | schedule, workflow_dispatch |
| OSPO Stale Repository Report | Identifies inactive repositories in your organization and generates an archival recommendation report. | schedule, workflow_dispatch |
| OSS Release Compliance Checker | Analyzes a target repository against open source release requirements and posts a detailed compliance report as an issue comment. | issues, workflow_dispatch |
| Relevance Check | Slash command to evaluate whether an issue or pull request is still relevant to the project | slash_command, roles |
| Relevance Summary | Manually triggered workflow that summarizes all open issues and PRs with a /relevance-check response into a single issue | workflow_dispatch |
| Weekly Comment Sync | Weekly workflow that finds stale code comments or README snippets, makes text-only synchronization updates, and opens a draft pull request when changes are needed. | schedule, workflow_dispatch |