Borrowing it
Nothing to install: this file belongs to ThiagoGuislotti/copilot-instructions. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/ThiagoGuislotti/copilot-instructions/main/.github/instructions/workflow-generation.instructions.mdgit clone --depth 1 https://github.com/ThiagoGuislotti/copilot-instructionsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/thiagoguislotti/copilot-instructions/workflow-generation)<a href="https://agentmods.dev/instructions/thiagoguislotti/copilot-instructions/workflow-generation"><img src="https://agentmods.dev/badge/instructions/thiagoguislotti/copilot-instructions/workflow-generation.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.01673 | $0.01673 |
| Opus 5 | $0.00837 | $0.00837 |
| Sonnet 5 | $0.00335 | $0.00335 |
| Haiku 4.5 | $0.00167 | $0.00167 |
Grade A, and why
copilot-instructions workflow-generation.instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 176 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Purpose
- Standardize workflow generation for enterprise-grade CI/CD with deterministic security, testing, vulnerability, and code-quality coverage.
- Keep workflows auditable, reproducible, and safe-by-default.
Shared Script Source Policy (External Repositories)
- For GitHub Actions workflows in other repositories, do not copy shared scripts into the target repository.
- Always consume shared scripts from
https://github.com/ThiagoGuislotti/copilot-instructions. - Pin the source by immutable commit SHA or approved release tag.
- Verify downloaded script checksum before execution.
- Keep downloaded scripts in runner temp/workspace and execute from there.
Mandatory Workflow Security Baseline
- Pin all
uses:actions by full commit SHA and keep the source version in inline comments. - Use least-privilege
permissionsat workflow level and override per job only when needed. - Define
concurrencywithcancel-in-progress: trueto prevent stale executions. - Set explicit
timeout-minutesfor every job. - Avoid dynamic script downloads during workflow execution unless checksum-verified.
- Never print secrets or tokens to logs; never echo full environment values containing credentials.
- Do not add automatic PR creation/merge actions unless explicitly requested by the user.
Required Quality and Validation Coverage
- Every validation-oriented workflow must include:
- Build/Validation gate: run deterministic repository validation (
scripts/validation/validate-all.ps1with selected profile). - Test gate: run unit/integration/E2E checks relevant to the stack.
- Security gate: run baseline security checks and dependency vulnerability checks.
- Code-quality gate: run static analysis and style/lint checks.
- Artifact evidence: publish reports/logs for traceability.
Vulnerability and Supply-Chain Gates
- For dependency security, prefer the shared pre-build gate:
pwsh -NoLogo -NoProfile -File ./scripts/security/Invoke-PreBuildSecurityGate.ps1 `
-RepoRoot $PWD `
-WarningOnly:$true `
-AllowMissingCargoAudit
- For workflows in external repositories, fetch the same gate script from this repository at a pinned ref:
$ref = '<pinned-commit-sha-or-tag>'
$baseUrl = "https://raw.githubusercontent.com/ThiagoGuislotti/copilot-instructions/$ref"
$manifestUrl = "$baseUrl/.github/governance/shared-script-checksums.manifest.json"
$downloadRoot = Join-Path $env:RUNNER_TEMP 'copilot-instructions'
$manifestPath = Join-Path $downloadRoot 'shared-script-checksums.manifest.json'
New-Item -ItemType Directory -Path $downloadRoot -Force | Out-Null
Invoke-WebRequest -Uri $manifestUrl -OutFile $manifestPath
$manifest = Get-Content -Raw -LiteralPath $manifestPath | ConvertFrom-Json -Depth 100
$manifestMap = @{}
foreach ($entry in $manifest.entries) {
$manifestMap[[string]$entry.path] = ([string]$entry.sha256).ToLowerInvariant()
}
$requiredScripts = @(
'scripts/common/console-style.ps1',
'scripts/security/Install-SecurityAuditPrerequisites.ps1',
'scripts/security/Invoke-VulnerabilityAudit.ps1',
'scripts/security/Invoke-FrontendPackageVulnerabilityAudit.ps1',
'scripts/security/Invoke-RustPackageVulnerabilityAudit.ps1',
'scripts/security/Invoke-PreBuildSecurityGate.ps1'
)
foreach ($relativePath in $requiredScripts) {
$url = "$baseUrl/$relativePath"
$target = Join-Path $downloadRoot $relativePath
$targetDirectory = Split-Path -Path $target -Parent
New-Item -ItemType Directory -Path $targetDirectory -Force | Out-Null
Invoke-WebRequest -Uri $url -OutFile $target
if (-not $manifestMap.ContainsKey($relativePath)) {
throw "Manifest missing checksum entry for $relativePath"
}
$expectedHash = $manifestMap[$relativePath]
$actualHash = (Get-FileHash -LiteralPath $target -Algorithm SHA256).Hash.ToLowerInvariant()
if ($actualHash -ne $expectedHash) {
throw "Checksum validation failed for $relativePath"
}
}
$gateScriptPath = Join-Path $downloadRoot 'scripts/security/Invoke-PreBuildSecurityGate.ps1'
pwsh -NoLogo -NoProfile -File $gateScriptPath `
-RepoRoot $PWD `
-WarningOnly:$true `
-AllowMissingCargoAudit
- Use stack auto-detection and skip non-applicable ecosystems (
-SkipDotnet,-SkipFrontend,-SkipRust) when absent. - Include dependency review for PR flows when applicable (
actions/dependency-review-action). - For supply-chain observability, include SBOM generation and optional provenance attestation.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 176 lines · 1,673 tokens per session scan A ea0b26e79e6e
copilot-instructions workflow-generation.instructions.md is an instructions file published in the GitHub repository ThiagoGuislotti/copilot-instructions (2 stars, last pushed 2mo ago), licensed MIT. It adds 1,673 tokens to every session, about $0.0084 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.