About this project

GitHub Agentic Workflows (`gh-aw`) is a GitHub CLI extension that enables developers to define AI-powered repository automation using Markdown files with YAML frontmatter. The extension compiles each agentic workflow into a standard GitHub Actions workflow, allowing AI agents to run securely within GitHub Actions. Agentic workflows are designed for tasks that require reasoning or interpretation, such as issue triage, pull-request review, CI failure investigation, documentation maintenance, dependency analysis, and repository reporting. They complement, rather than replace, conventional GitHub Actions used for deterministic builds, tests, linting, deployments, and reproducible scripts. Built-in AI engines include GitHub Copilot, Claude Code, OpenAI Codex, Google Gemini, and Pi. Agent jobs are read-only and sandboxed by default, and configured GitHub writes are normally applied through validated `safe-outputs` jobs with scoped permissions. Security, permissions, and controlled writes are core design concerns. The supported agent-job path defaults to read-only GitHub access and sandboxed execution. Safe outputs buffer configured writes, validate them, and apply them in separate jobs with scoped permissions. These controls are configurable, so workflow authors must review permissions, tools, network access, and generated files before deployment. Quick start: install the extension with `gh extension install github/gh-aw`, then follow the quickstart guide to select an AI engine, add a sample workflow, and run it through GitHub Actions. Documentation covers creating workflows, choosing and authenticating AI engines, examples by task, security architecture, and FAQ. AI agents and retrieval tools can use the published agent prompt index, full prompt corpus, and AI-readable project summary. Note: A security vulnerability was discovered in versions `>= 0.83.3, < 0.85.4`; those releases were retired as a pre-emptive measure.