Add architectural constraints and security patterns to agentic workflow prompts #13214
+216
−0
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Discussion #13212 research found the agent overpromises capabilities (3.0/5.0 score on multi-stage pipelines) and inconsistently educates on security risks.
Changes
Architectural Constraints
Document single-job execution model limitations:
jobs:+needs:dependenciesSecurity Education
Add risk guidance for common patterns:
Safer Alternatives Pattern
Structured approach: ask alternatives → present risks upfront → require confirmation → document in workflow
Example
User: "Create workflow: staging migrations → wait for deployment → tests → production migrations with rollback"
Agent response:
Files
.github/aw/create-agentic-workflow.md(+152 lines).github/aw/update-agentic-workflow.md(+64 lines)Original prompt
✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.