Skip to content

Add security guard agentic workflow for PR security posture analysis#12069

Merged
Mossaka merged 3 commits intomainfrom
copilot/add-security-guard-workflow
Jan 27, 2026
Merged

Add security guard agentic workflow for PR security posture analysis#12069
Mossaka merged 3 commits intomainfrom
copilot/add-security-guard-workflow

Conversation

Copy link
Contributor

Copilot AI commented Jan 27, 2026

Adds an agentic workflow that automatically reviews PRs for security posture changes. Only comments when concrete evidence of weakened security exists—silent otherwise.

Workflow behavior

  • Triggers on pull_request (opened, synchronize, reopened)
  • Analyzes diffs for security boundary expansions
  • Requires specific evidence (file:line, before/after diff) to comment
  • Exits silently when no concerns found

Security categories covered

  • Permission escalation (readwrite)
  • Network boundary expansion (new domains, wildcards, ecosystem identifiers)
  • Sandbox/AWF weakening (sandbox.agent: false)
  • Tool security relaxation (bash patterns, GitHub toolsets)
  • Safe output limit increases
  • Strict mode changes
  • Trigger security relaxation (forks, roles, bots)
  • Secret/credential exposure
  • Code injection patterns

Permissions (read-only)

permissions:
  contents: read
  pull-requests: read
  actions: read
  security-events: read

Example output format

When security concerns are found, produces structured comment with severity (🔴 Critical / 🟠 High / 🟡 Medium), location, diff evidence, impact assessment, and remediation.

Original prompt

Add a security guard agentic workflow for each PR. The main goal of the security guard is to make sure that the changes are not lowering the security posture of this PR. Anything that potentially expands the security boundary should be noted. The guard should report directly to the PR as a comment on what could have been done diffrently in terms of security concerns.

Skip commenting if the security posture is not being weakened

The report should have strong evidence to show why the security standard is lowered by these changes. If there is no evidence, skip commenting.

Custom agent used: agentic-workflows
GitHub Agentic Workflows (gh-aw) - Create, debug, and upgrade AI-powered workflows with intelligent prompt routing


💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.

Co-authored-by: Mossaka <5447827+Mossaka@users.noreply.github.com>
Copilot AI changed the title [WIP] Add security guard workflow for PR reviews Add security guard agentic workflow for PR security posture analysis Jan 27, 2026
Copilot AI requested a review from Mossaka January 27, 2026 18:05
@Mossaka Mossaka marked this pull request as ready for review January 27, 2026 18:18
@Mossaka Mossaka merged commit 6f19931 into main Jan 27, 2026
56 checks passed
@Mossaka Mossaka deleted the copilot/add-security-guard-workflow branch January 27, 2026 18:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants