Skip to content

Conversation

Copy link
Contributor

Copilot AI commented Jan 27, 2026

Security Guard Agent was triggering "No Safe Outputs Generated" warnings when correctly finding no security issues. The workflow exited silently instead of signaling explicit completion.

Changes

  • Added noop: to safe-outputs config - Enables the agent to explicitly signal "analyzed, nothing to report"
  • Updated prompt instructions - Replaced "exit gracefully" with "call noop" in decision points and example scenarios

Before/After

# Before - no way to signal successful completion without findings
safe-outputs:
  add-comment:
    max: 1

# After - agent can now explicitly signal no action needed
safe-outputs:
  add-comment:
    max: 1
  noop:

Prompt now instructs:

- **NO SECURITY CONCERNS FOUND**: Call `noop` to explicitly signal that no security issues were detected.
Original prompt

This section details on the original issue you should resolve

<issue_title>[agentics] Security Guard Agent 🛡️ failed</issue_title>
<issue_description>### Workflow Failure

Workflow: Security Guard Agent 🛡️
Branch: HEAD
Run URL: https://github.com/githubnext/gh-aw/actions/runs/21409179321

⚠️ No Safe Outputs Generated: The agent job succeeded but did not produce any safe outputs. This typically indicates:

  • The safe output server failed to run
  • The prompt failed to generate any meaningful result
  • The agent should have called noop to explicitly indicate no action was taken

Action Required

Debug this workflow failure using the agentic-workflows agent:

/agent agentic-workflows

When prompted, instruct the agent to debug this workflow failure.

Generated from Security Guard Agent 🛡️

  • expires on Feb 3, 2026, 6:30 PM UTC

<agent_instructions>investigate this</agent_instructions>

Comments on the Issue (you are @copilot in this section)

Custom agent used: agentic-workflows
GitHub Agentic Workflows (gh-aw) - Create, debug, and upgrade AI-powered workflows with intelligent prompt routing


💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.

Add `noop:` to safe-outputs configuration and update prompt to instruct
agent to call noop instead of exiting silently. This fixes the "No Safe
Outputs Generated" warning when the agent correctly finds no security
concerns.

Fixes #12054

Co-authored-by: Mossaka <5447827+Mossaka@users.noreply.github.com>
Copilot AI changed the title [WIP] Debug workflow failure of Security Guard Agent Fix Security Guard Agent to call noop when no security concerns found Jan 27, 2026
Copilot AI requested a review from Mossaka January 27, 2026 19:12
@pelikhan
Copy link
Contributor

Noop should be a builtin. Fixing in other PR

@Mossaka Mossaka marked this pull request as ready for review January 27, 2026 20:25
@pelikhan pelikhan merged commit 3d9ba93 into main Jan 27, 2026
11 of 56 checks passed
@pelikhan pelikhan deleted the copilot/debug-security-guard-agent branch January 27, 2026 21:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[agentics] Security Guard Agent 🛡️ failed

3 participants