---
title: "Unattended AI helpers need caps, approvals and narrow keys"
description: "GitHub lets teams run AI helpers on a schedule with nobody starting each job. Who pays, who approves, and what can it read and touch? From GitHub's own docs."
publishedAt: 2026-10-11
author: Ena Pragma
url: https://enapragma.co/field-notes/unattended-ai-helpers-need-caps-approvals-and-narrow-keys
tags: ["ai-operations", "agent-security", "ai-governance"]
---

A conference talk posted on October 10, 2026, [From Your Laptop to the Pipeline: Scaling Custom Agents with GitHub Copilot](https://www.youtube.com/watch?v=b9UhZkKjX_A), has a description that opens with a familiar problem: "Most teams build an agent once, on one laptop, and never share it." The path it describes ends with AI helpers that run on a schedule or when something happens in a project, with nobody starting each job. This note does not review the talk. It takes the idea and puts three questions to GitHub's own documentation: who pays, who approves, and what can the helper read and touch while a stranger's text is in front of it.

A few words first. An AI helper here is a written set of instructions plus an AI model that can use tools, such as labeling issues, which are tickets in a software project, or opening a change for a person to review. "Unattended" means a schedule or an event starts it, not a person. GitHub's pattern is to write the helper's job down once as a file, share it, and let GitHub run it. We read GitHub's pages on the evening of October 10, 2026, Central time. The source file behind GitHub's page on gh-aw cost caps changed twice on October 10 alone (UTC), so re-read any figure before you rely on it.

## Three GitHub products, named separately

GitHub offers several routes to the same idea, and the answers below differ by route. These are the three this note covers.

| Route | What it is | Where the instructions live | Status |
| --- | --- | --- | --- |
| GitHub Agentic Workflows, called gh-aw | "AI-powered repository automations that you define in markdown and run as GitHub Actions workflows" | A Markdown file in the repository's `.github/workflows/` folder, compiled to a `.lock.yml` file | "in public preview and subject to change" |
| Copilot cloud agent | GitHub's hosted agent, "formerly known as Copilot coding agent." You assign it an issue and can shape it with custom agents, which GitHub calls "Markdown files called agent profiles" | In the repository, or in "the organization's .github or .github-private repository" | Custom agents in JetBrains IDEs, Eclipse and Xcode are in public preview |
| Cloud agent automations | Lets you "run Copilot cloud agent automatically, on a schedule or in response to events in a repository" | "stored separately from your repository's contents" and "not committed to Git" | Released June 2, 2026 |

gh-aw is a public preview. GitHub's own page says it is "subject to change." A fourth route needs no separate product: the Copilot command-line tool can run without a person typing, as a step in your own pipeline. GitHub's guidance there is "Always give minimal permissions."

These are new. GitHub's changelog dates custom agents to October 28, 2025, the gh-aw preview to February 13, 2026 (a public preview from June 11), and cloud agent automations to June 2. GitHub announced on April 27 that Copilot billing would move from premium requests to token-based AI Credits: "Starting June 1, premium request units (PRUs) will be replaced by GitHub AI Credits."

## Question 1: who pays?

There is no single bill. Running a gh-aw workflow "incurs two types of cost: GitHub Actions minutes for compute, and AI inference charged by the model provider." The first, the metered computer time GitHub charges for running automated jobs, goes to the repository's owner: "Actions minutes are billed to the organization or user that owns the repository." The second depends on the engine, meaning the AI service the workflow calls.

| Route and engine | Who is billed for the AI usage |
| --- | --- |
| gh-aw, default Copilot engine | The organization, but only if all three of these hold: central billing is on for the organization's Copilot, the workflow declares a permission called `copilot-requests: write`, and the workflow has been compiled with its updated `.lock.yml` committed. Otherwise the usage is "attributed to (and limited by) the PAT owner’s Copilot entitlements rather than being billed centrally through the organization." A PAT is a personal access token, a secret key tied to one person's account. |
| gh-aw with Claude | "inference is billed directly to your Anthropic account" |
| gh-aw with Codex | "inference is billed directly to your OpenAI account" |
| Cloud agent automation | "This usage is billed to the user who created the automation." Each run "uses GitHub Actions minutes and GitHub AI Credits." |

In the talk, the presenter says the wish is to "run them in the repo on that repo's budget, not on my budget." GitHub's pages show that whose budget it is depends on the route and the setup above.

Caps are not prices. gh-aw's defaults are "1000 AI Credits per workflow run, and 5000 AI Credits per workflow per day (24-hour window)," and "One AIC equals $0.01 USD," where AIC is GitHub's abbreviation for an AI Credit. That makes the defaults $10 per run and $50 per workflow per day, our arithmetic. So the $10 is a hard-stop cap, not a price: GitHub calls the per-run setting "a hard stop for unusually expensive runs." A hard stop limits the damage. It does not tell you what a typical run costs. GitHub's pages state no price for a typical run, and the gh-aw homepage shows a sample cost dashboard without saying the sample is typical, so we do not quote it. These are gh-aw settings, as read at 9:49 PM CDT on October 10. GitHub's own advice on cost is short: "The primary cost lever for most workflows is how often they run."

Why does GitHub bill by tokens now? Its April 27 announcement says "Today, a quick chat question and a multi-hour autonomous coding session can cost the user the same amount," and that "the current premium request model is no longer sustainable." One user, in a GitHub Community thread, wrote that "The biggest problem is that users cannot clearly know how much a task will cost before running it." That is one person's account, with no bill shown, not a measurement.

## Question 2: who approves?

Approval means someone other than the helper decides whether its work takes effect, usually by approving a pull request, which is a proposed change that a person reviews before it is accepted. The cloud agent is the clearest case. GitHub's documentation says "Only users with write access to the repository can trigger Copilot cloud agent to work," that it "only has the ability to push to a single branch," and that it "cannot approve or merge a pull request." By default, workflows on its pull requests "are not triggered until Copilot cloud agent's code is reviewed and a user with write access to the repository clicks the Approve and run workflows button," though you can configure Copilot to let them run automatically. When the agent opens a pull request "under its own app identity, one more approval is required before it can be merged, as long as the repository already requires at least one approval." That extra approval is on by default in rulesets, where administrators can turn it off, and it always applies to branch protection rules.

Automations run Copilot "without a person initiating each task, so they carry some additional risks," in GitHub's words. By default they "ignore events triggered by users who don't have write access to the repository."

For gh-aw, GitHub's overview lists "Keep human review in the loop" as a benefit: workflows "can generate ready-to-review outputs, such as issues, comments, and pull requests, while you control approvals and merges." The gates GitHub documents inside the workflow are automated. The agent job "runs with minimal read-only permissions, while write operations are deferred to separate jobs that execute only after the agent completes," and "a dedicated threat detection job scans all proposed changes before they are applied." A person decides at review and merge, or where the workflow's author builds in a step such as a command typed in an issue comment (GitHub's page says workflows can "respond to /my-bots in issues and comments"). We found no GitHub page that calls that command a built-in approval step.

An approval is only as good as the review behind it. GitHub's own review guide warns about CI, the automated checks that run on every change: "Agents fail CI. When they do, they have an obvious path to get tests passing: remove the tests, skip the lint step, add || true to test commands. Some agents take it." It tells reviewers "Any change that weakens CI is a blocker," and notes that "reviewers, according to the same research, actually feel better about approving it." The guide gives no frequency, so treat it as a warning from the vendor, not a measurement.

## Question 3: what can it read and touch while untrusted text is in front of it?

GitHub's gh-aw homepage names the risky combination: "An agent becomes dangerous when it has private data, untrusted content and outbound access all at once." It explains the three: "Private data means secrets and credentials. Untrusted content means issues and pull request comments. Outbound access means web pages, APIs and writes." Then: "Security researchers call it the lethal trifecta." Developer Simon Willison named the term in a [June 2025 post](https://simonw.substack.com/p/the-lethal-trifecta-for-ai-agents), which the gh-aw page links.

GitHub says "gh-aw defends in depth through six security layers." Workflows "run with read-only permissions by default, and execute inside a sandboxed container behind the Agent Workflow Firewall," and "An API proxy holds the tokens, so the agent never sees them and cannot leak them." GitHub says its design "cuts every leg": "the isolated sandbox keeps private data away from the agent, integrity filtering screens untrusted content, and the agent firewall restricts outbound access." Those are GitHub's descriptions of its own design, and the second report below is one research team's test of it. For the cloud agent, GitHub is direct: it "has access to code and other sensitive information, and could leak it, either accidentally or due to malicious user input." What a helper can touch also depends on its tools. For a custom agent, "If no tools are specified, all available tools are enabled." For an automation, GitHub says selecting tools "is the main way you control the scope," and an automation "can only take action in the single repository it is scoped to."

Two researcher reports show what the risk looks like in practice. Each has a narrow scope, so read them exactly.

The first concerns the Copilot cloud agent, not gh-aw. In a post dated April 15, 2026, a researcher describes hiding instructions in an HTML comment inside a GitHub issue, where GitHub's rendered view hides them. A victim who assigned that issue to Copilot, seeing only the innocent visible text, triggered them, and credentials leaked. His timeline: reported February 8, closed as Informative on March 2, reopened March 4, resolved March 9 with a $500 bounty. As he quotes GitHub's resolution text, it called this "a previously identified architectural limitation" and said "The exposure of environment variables through process inspection is a known consequence of the current runtime design, and we are actively exploring ways to further restrict this." That sentence is about environment variables, not about prompt injection in general, and it is the researcher's account of GitHub's words, not a GitHub publication.

The second concerns gh-aw, and it is a proof of concept. In a post dated July 6, 2026, Noma Labs describes a workflow in its own test repositories that triggered when an issue was assigned, read the issue, could post a comment, and ran "with read access to other repositories (public and private) in the organization." A crafted public issue led the agent to paste a private repository's README into a public comment. Noma reports that adding the keyword "Additionally" "triggered unintended behavior in the model" and got past GitHub's guardrails in its testing. Noma says "GitLost was responsibly disclosed to GitHub." The Hacker News reports that exposure is "limited to organizations that have enabled the preview and wired an agent to read untrusted public input while holding read access to private repositories and are able to post in public." This was one workflow with broad cross-repository access, and we make no claim about whether it has since been fixed. Noma's advice: "Scope permissions to the minimum required. Agents with cross-repository access are especially high-value targets." The Hacker News adds: "scope the token to the one repository the workflow triages rather than the whole organization."

One academic result shows the surface is wide. A May 8, 2026 preprint ran a static analysis over 13,392 agentic workflows on GitHub Actions: 519 were flagged and 496 were confirmed exploitable under the authors' threat model. It studied third-party agent actions, and gh-aw appears in it only as a cited reference. It shows the problem exists across the ecosystem, not that gh-aw or the cloud agent is exposed, and a static analysis is not a count of attacks.

## If you run a small business

We did not create an agent, run gh-aw or start a cloud agent session. Everything above is GitHub's documentation as written, plus the reports named. If a developer or vendor proposes an AI helper that runs without a person, these are the questions to put to them, in our words and not GitHub's:

- Which route is it, and what engine does it use? Whose account is billed for the AI usage, and whose key does it sign in with?
- What stops the bill? Ask for the cap, and ask how often it runs, since GitHub says frequency is the main cost lever.
- Who approves what it produces, and have they reviewed one of its changes for real?
- What can it read, what stranger's text reaches it, and what can it send out? If all three are yes, expect the problem GitHub's own page describes.
- Is the preview label still on it? GitHub says gh-aw is "subject to change."

The helper does not need a person to start it. Someone still has to decide who pays for it, who can overrule it, and what it can reach.

Related field notes: [Agent loops need operational state, not just better prompts](https://enapragma.co/field-notes/agent-loops-need-operational-state) covers the triggers, verifiers and human gates around the model, and [Installing an agent skill is running untrusted code](https://enapragma.co/field-notes/agent-skills-are-untrusted-code) covers the untrusted-text side.

*How this was researched:* GitHub's documentation and changelog pages were read on the evening of October 10, 2026, Central time. Docs pages carry no date of their own, so each is dated by the last commit to its source file, and the live site can lag a commit. The talk's captions are YouTube's auto-generated text, which can garble words. The researcher posts, the Hacker News report and the preprint are the authors' own accounts, and we did not reproduce any of them. Vendor figures that come without a method are not used.

## Sources

- [AI Engineer, From Your Laptop to the Pipeline: Scaling Custom Agents with GitHub Copilot (YouTube)](https://www.youtube.com/watch?v=b9UhZkKjX_A)
- [arXiv, Demystifying and Detecting Agentic Workflow Injection Vulnerabilities in GitHub Actions](https://arxiv.org/abs/2605.07135)
- [GitHub Docs, About GitHub Agentic Workflows (source last changed June 11, 2026)](https://docs.github.com/en/copilot/concepts/agents/about-github-agentic-workflows)
- [GitHub Docs, About Copilot automations (source last changed October 5, 2026)](https://docs.github.com/en/copilot/concepts/agents/cloud-agent/about-automations)
- [GitHub Docs, About custom agents (source last changed September 4, 2026)](https://docs.github.com/en/copilot/concepts/agents/cloud-agent/about-custom-agents)
- [GitHub Docs, Risks and mitigations for GitHub Copilot cloud agent (source last changed September 23, 2026)](https://docs.github.com/en/copilot/concepts/security-governance-and-network-settings/risks-and-mitigations)
- [GitHub Docs, Custom agents configuration reference (source last changed July 9, 2026)](https://docs.github.com/en/copilot/reference/custom-agents-configuration)
- [GitHub Docs, Running the Copilot CLI programmatically (source last changed July 29, 2026)](https://docs.github.com/en/copilot/how-tos/copilot-cli/automate-copilot-cli/run-cli-programmatically)
- [GitHub Agentic Workflows, Billing (source last changed October 6, 2026)](https://github.github.com/gh-aw/reference/billing/)
- [GitHub Agentic Workflows, Cost management (source last changed October 10, 2026)](https://github.github.com/gh-aw/reference/cost-management/)
- [GitHub Agentic Workflows, home page (source last changed October 10, 2026)](https://github.github.com/gh-aw/)
- [GitHub Agentic Workflows, Architecture (source last changed September 23, 2026)](https://github.github.com/gh-aw/introduction/architecture/)
- [GitHub Agentic Workflows, Command triggers (source last changed August 26, 2026)](https://github.github.com/gh-aw/reference/command-triggers/)
- [GitHub Changelog, GitHub Agentic Workflows are now in technical preview](https://github.blog/changelog/2026-02-13-github-agentic-workflows-are-now-in-technical-preview/)
- [GitHub Changelog, GitHub Agentic Workflows is now in public preview](https://github.blog/changelog/2026-06-11-github-agentic-workflows-is-now-in-public-preview/)
- [GitHub Changelog, Schedule and automate tasks with Copilot cloud agent](https://github.blog/changelog/2026-06-02-schedule-and-automate-tasks-with-copilot-cloud-agent/)
- [GitHub Changelog, Research, plan and code with Copilot cloud agent](https://github.blog/changelog/2026-04-01-research-plan-and-code-with-copilot-cloud-agent/)
- [GitHub Changelog, Custom agents for GitHub Copilot (October 28, 2025)](https://github.blog/changelog/2025-10-28-custom-agents-for-github-copilot/)
- [GitHub Blog, GitHub Copilot is moving to usage-based billing](https://github.blog/news-insights/company-news/github-copilot-is-moving-to-usage-based-billing/)
- [GitHub Blog, Agent pull requests are everywhere. Here's how to review them.](https://github.blog/ai-and-ml/generative-ai/agent-pull-requests-are-everywhere-heres-how-to-review-them/)
- [oddguan.com, Comment and Control: prompt injection credential theft in Claude Code, Gemini CLI and GitHub Copilot](https://oddguan.com/blog/comment-and-control-prompt-injection-credential-theft-claude-code-gemini-cli-github-copilot/)
- [Noma Labs, GitLost: How We Tricked GitHub's AI Agent into Leaking Private Repos](https://noma.security/noma-labs/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos)
- [The Hacker News, Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data](https://thehackernews.com/2026/07/public-github-issue-could-trick-github.html)
- [Simon Willison's Newsletter, June 17, 2025 post linked by GitHub](https://simonw.substack.com/p/the-lethal-trifecta-for-ai-agents)
- [GitHub Community, GitHub Copilot AI Credits Are Unfair, Expensive, and Killing Real Development Workflows](https://github.com/orgs/community/discussions/198015)
