Fix agentic workflow markers removed from safe outputs - #132011

Merged
vitek-karas merged 4 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-fix-agentic-workflow-markers
Aug 12, 2026
Merged

Fix agentic workflow markers removed from safe outputs#132011
vitek-karas merged 4 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-fix-agentic-workflow-markers

Conversation

@vitek-karas

Copy link
Copy Markdown
Member

Summary

Several agentic workflows used HTML comments as machine-readable markers. That does not work: gh-aw removes agent-provided HTML comments when it sanitizes safe-output text. The comments were therefore not present in the posted issue or PR content, so later workflow runs could not reliably recognize earlier work. On #128405, this allowed ci-failure-fix to post two different handoff comments.

This change replaces those comments with markers that survive publishing:

  • safe-outputs.data where the output type supports structured data.
  • Stable visible Markdown fields where structured data is not supported or would break the required content format.

Existing visible markers are still recognized so older workflow output continues to work.

Changes by workflow

  • ci-failure-fix: Adds structured identifiers to fix PRs, help-wanted PRs, and handoff comments. Deduplication now checks every comment instead of assuming comments are at a fixed position, and it still recognizes older visible markers.
  • closed-issue-reference-check: Adds structured identifiers to advisory comments. The pre-check skips issues that contain either the new structured marker or the older workflow-specific marker and advisory heading.
  • ci-failure-scan: Moves KBE authoring guidance and the verified-match count into collapsed, clearly labeled sections. KBE bodies still contain exactly one JSON block, as required by Build Analysis.
  • ci-failure-scan-feedback: Reads the new ci-failure-fix identifiers while keeping compatibility with older markers. Its tracker identity and window are stored in a collapsed visible section, and tracker updates explicitly replace the body instead of appending to it.

The shared workflow guidance now documents that HTML comments are removed and explains when to use structured data or visible fields. The affected generated workflows were refreshed with gh-aw v0.83.5.

Related change

#131996 is the repository-wide mechanical refresh to gh-aw v0.83.5. This PR contains the workflow behavior and authoring changes, and regenerates the affected workflows with the same compiler version.

Validation

  • Compiled and validated the affected workflows with gh-aw v0.83.5.
  • Ran poutine and zizmor on the changed workflows.
  • Checked the KBE templates keep exactly one JSON block and contain the required collapsed guidance and metadata.

Note

This PR description was generated with GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI lite review requested due to automatic review settings August 7, 2026 15:32
@github-actionsgithub-actionsBot added the area-skills Agent Skills label Aug 7, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates several agentic workflow prompts and regenerated lockfiles to stop using agent-authored HTML comments (<!-- ... -->) as persisted markers (since safe-output sanitization strips them), replacing them with either safe-outputs.data structured identifiers or stable visible Markdown fields.

Changes:

  • Introduces safe-outputs.data schemas and corresponding prompt guidance for workflows that need machine-readable identity/deduplication.
  • Updates the shared KBE templates and eval specs to use collapsed <details> blocks for authoring guidance and workflow-owned match-count metadata (while preserving the “exactly one fenced JSON block” KBE constraint).
  • Regenerates the affected *.lock.yml workflows to the newer gh-aw compiler/runtime versions.

Reviewed changes

Copilot reviewed 14 out of 14 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
.github/workflows/shared/create-kbe.instructions.mdMoves KBE guidance + verification metadata into collapsed <details> blocks while keeping exactly one JSON signature block.
.github/workflows/README.mdDocuments that safe outputs strip HTML/XML comments and recommends safe-outputs.data or visible fields.
.github/workflows/evals/README.mdUpdates eval expectations to require collapsed guidance + metadata blocks.
.github/workflows/evals/ci-failure-scan.eval.yamlUpdates graders to validate the new <details>-based KBE template requirements.
.github/workflows/closed-issue-reference-check.mdAdds safe-outputs.data schema + updates dedup logic to detect prior advisory comments via structured or legacy visible markers.
.github/workflows/ci-failure-scan.mdUpdates scanner match-count gating language to require the new collapsed verification block.
.github/workflows/ci-failure-scan.lock.ymlRegenerated workflow lockfile (compiler/runtime/tooling version and infra script updates).
.github/workflows/ci-failure-scan-feedback.mdUpdates feedback workflow prompt to identify artifacts via structured data or legacy visible blocks; stores tracker metadata in visible collapsed block.
.github/workflows/ci-failure-scan-feedback.lock.ymlRegenerated workflow lockfile (compiler/runtime/tooling version and infra script updates).
.github/workflows/ci-failure-fix.mdAdds safe-outputs.data schema + updates prompt guidance for dedup/identity via structured data with legacy fallback.
.github/aw/actions-lock.jsonUpdates pinned gh-aw setup action entry to v0.83.5 and removes older entries.
.github/agents/agentic-workflows.agent.mdAdds repo guidance explaining sanitization behavior and when to use safe-outputs.data vs visible fields.

Comment thread.github/workflows/closed-issue-reference-check.md Outdated
Comment thread.github/workflows/ci-failure-fix.md Outdated
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI review requested due to automatic review settings August 10, 2026 13:56

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 13 out of 13 changed files in this pull request and generated no new comments.

Suppressed comments (2)

.github/workflows/closed-issue-reference-check.md:161

  • The structured-data dedup check matches exact substrings like "workflow_artifact": "..." (note the space after :). If the appended JSON is ever minified (e.g., "workflow_artifact":"...") or otherwise formatted differently, this will false-negative and allow duplicate advisory comments. Using a regex (test) that tolerates whitespace makes the dedup more robust.
 data_workflow='"workflow_artifact": "closed-issue-reference-check"'
data_kind='"artifact_kind": "advice"'
legacy_call_id='gh-aw-workflow-call-id: dotnet/runtime/closed-issue-reference-check'
legacy_workflow_id='gh-aw-workflow-id: closed-issue-reference-check'
legacy_agentic_id='workflow_id: closed-issue-reference-check'

.github/agents/agentic-workflows.agent.md:196

  • safe-outputs.data appends a fenced Structured data: JSON block to the posted body, but it isn’t necessarily a second JSON block (it’s only “second” if the body already contains one). Rewording this avoids confusing future workflow authors.
`safe-outputs.data` is not available on every output type; notably, `update_issue` cannot attach it. It also appends a second fenced JSON block to the posted body, which is incompatible with formats such as Known Build Error issues that require exactly one fenced JSON block. In those cases, use narrowly formatted visible fields in the body and preserve them on every rewrite.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI review requested due to automatic review settings August 10, 2026 15:06
@vitek-karas

Copy link
Copy Markdown
MemberAuthor

Fixed the small updates based on the review - this should be final now - @PureWeen or @kotlarmilos could you please re-approve?

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 13 out of 13 changed files in this pull request and generated no new comments.

Suppressed comments (1)

.github/workflows/closed-issue-reference-check.md:164

  • marker_present currently downloads all pages of issue comments (gh api --paginate --slurp ...) before checking for structured/legacy advisory markers. This removes the prior early-exit behavior and can significantly increase API usage and runtime for heavily-commented issues (and makes rate-limit/transient failures more likely).

Consider restoring a short-circuiting scan: fetch the newest page first and walk backwards until a match is found, or stream gh api --paginate into jq using first(...)/select(...) so the pipeline can terminate as soon as a matching comment is detected.

 marker_present() {
local num="$1" pages
pages="$(gh api --paginate --slurp "repos/${REPO}/issues/${num}/comments?per_page=100" 2>/dev/null)" || return 2
jq -e \

@vitek-karas
vitek-karas merged commit 573d5a0 into dotnet:mainAug 12, 2026
23 checks passed
@vitek-karas
vitek-karas deleted the vitek-karas-fix-agentic-workflow-markers branch August 12, 2026 20:05
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-skillsAgent Skills

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@vitek-karas@PureWeen@kotlarmilos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Fix agentic workflow markers removed from safe outputs - #132011

Merged
vitek-karas merged 4 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-fix-agentic-workflow-markers
Aug 12, 2026
Merged

Fix agentic workflow markers removed from safe outputs#132011
vitek-karas merged 4 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-fix-agentic-workflow-markers

Conversation

@vitek-karas

Copy link
Copy Markdown
Member

Summary

Several agentic workflows used HTML comments as machine-readable markers. That does not work: gh-aw removes agent-provided HTML comments when it sanitizes safe-output text. The comments were therefore not present in the posted issue or PR content, so later workflow runs could not reliably recognize earlier work. On #128405, this allowed ci-failure-fix to post two different handoff comments.

This change replaces those comments with markers that survive publishing:

  • safe-outputs.data where the output type supports structured data.
  • Stable visible Markdown fields where structured data is not supported or would break the required content format.

Existing visible markers are still recognized so older workflow output continues to work.

Changes by workflow

  • ci-failure-fix: Adds structured identifiers to fix PRs, help-wanted PRs, and handoff comments. Deduplication now checks every comment instead of assuming comments are at a fixed position, and it still recognizes older visible markers.
  • closed-issue-reference-check: Adds structured identifiers to advisory comments. The pre-check skips issues that contain either the new structured marker or the older workflow-specific marker and advisory heading.
  • ci-failure-scan: Moves KBE authoring guidance and the verified-match count into collapsed, clearly labeled sections. KBE bodies still contain exactly one JSON block, as required by Build Analysis.
  • ci-failure-scan-feedback: Reads the new ci-failure-fix identifiers while keeping compatibility with older markers. Its tracker identity and window are stored in a collapsed visible section, and tracker updates explicitly replace the body instead of appending to it.

The shared workflow guidance now documents that HTML comments are removed and explains when to use structured data or visible fields. The affected generated workflows were refreshed with gh-aw v0.83.5.

Related change

#131996 is the repository-wide mechanical refresh to gh-aw v0.83.5. This PR contains the workflow behavior and authoring changes, and regenerates the affected workflows with the same compiler version.

Validation

  • Compiled and validated the affected workflows with gh-aw v0.83.5.
  • Ran poutine and zizmor on the changed workflows.
  • Checked the KBE templates keep exactly one JSON block and contain the required collapsed guidance and metadata.

Note

This PR description was generated with GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI lite review requested due to automatic review settings August 7, 2026 15:32
@github-actionsgithub-actionsBot added the area-skills Agent Skills label Aug 7, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates several agentic workflow prompts and regenerated lockfiles to stop using agent-authored HTML comments (<!-- ... -->) as persisted markers (since safe-output sanitization strips them), replacing them with either safe-outputs.data structured identifiers or stable visible Markdown fields.

Changes:

  • Introduces safe-outputs.data schemas and corresponding prompt guidance for workflows that need machine-readable identity/deduplication.
  • Updates the shared KBE templates and eval specs to use collapsed <details> blocks for authoring guidance and workflow-owned match-count metadata (while preserving the “exactly one fenced JSON block” KBE constraint).
  • Regenerates the affected *.lock.yml workflows to the newer gh-aw compiler/runtime versions.

Reviewed changes

Copilot reviewed 14 out of 14 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
.github/workflows/shared/create-kbe.instructions.mdMoves KBE guidance + verification metadata into collapsed <details> blocks while keeping exactly one JSON signature block.
.github/workflows/README.mdDocuments that safe outputs strip HTML/XML comments and recommends safe-outputs.data or visible fields.
.github/workflows/evals/README.mdUpdates eval expectations to require collapsed guidance + metadata blocks.
.github/workflows/evals/ci-failure-scan.eval.yamlUpdates graders to validate the new <details>-based KBE template requirements.
.github/workflows/closed-issue-reference-check.mdAdds safe-outputs.data schema + updates dedup logic to detect prior advisory comments via structured or legacy visible markers.
.github/workflows/ci-failure-scan.mdUpdates scanner match-count gating language to require the new collapsed verification block.
.github/workflows/ci-failure-scan.lock.ymlRegenerated workflow lockfile (compiler/runtime/tooling version and infra script updates).
.github/workflows/ci-failure-scan-feedback.mdUpdates feedback workflow prompt to identify artifacts via structured data or legacy visible blocks; stores tracker metadata in visible collapsed block.
.github/workflows/ci-failure-scan-feedback.lock.ymlRegenerated workflow lockfile (compiler/runtime/tooling version and infra script updates).
.github/workflows/ci-failure-fix.mdAdds safe-outputs.data schema + updates prompt guidance for dedup/identity via structured data with legacy fallback.
.github/aw/actions-lock.jsonUpdates pinned gh-aw setup action entry to v0.83.5 and removes older entries.
.github/agents/agentic-workflows.agent.mdAdds repo guidance explaining sanitization behavior and when to use safe-outputs.data vs visible fields.

Comment thread.github/workflows/closed-issue-reference-check.md Outdated
Comment thread.github/workflows/ci-failure-fix.md Outdated
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI review requested due to automatic review settings August 10, 2026 13:56

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 13 out of 13 changed files in this pull request and generated no new comments.

Suppressed comments (2)

.github/workflows/closed-issue-reference-check.md:161

  • The structured-data dedup check matches exact substrings like "workflow_artifact": "..." (note the space after :). If the appended JSON is ever minified (e.g., "workflow_artifact":"...") or otherwise formatted differently, this will false-negative and allow duplicate advisory comments. Using a regex (test) that tolerates whitespace makes the dedup more robust.
 data_workflow='"workflow_artifact": "closed-issue-reference-check"'
data_kind='"artifact_kind": "advice"'
legacy_call_id='gh-aw-workflow-call-id: dotnet/runtime/closed-issue-reference-check'
legacy_workflow_id='gh-aw-workflow-id: closed-issue-reference-check'
legacy_agentic_id='workflow_id: closed-issue-reference-check'

.github/agents/agentic-workflows.agent.md:196

  • safe-outputs.data appends a fenced Structured data: JSON block to the posted body, but it isn’t necessarily a second JSON block (it’s only “second” if the body already contains one). Rewording this avoids confusing future workflow authors.
`safe-outputs.data` is not available on every output type; notably, `update_issue` cannot attach it. It also appends a second fenced JSON block to the posted body, which is incompatible with formats such as Known Build Error issues that require exactly one fenced JSON block. In those cases, use narrowly formatted visible fields in the body and preserve them on every rewrite.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI review requested due to automatic review settings August 10, 2026 15:06
@vitek-karas

Copy link
Copy Markdown
MemberAuthor

Fixed the small updates based on the review - this should be final now - @PureWeen or @kotlarmilos could you please re-approve?

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 13 out of 13 changed files in this pull request and generated no new comments.

Suppressed comments (1)

.github/workflows/closed-issue-reference-check.md:164

  • marker_present currently downloads all pages of issue comments (gh api --paginate --slurp ...) before checking for structured/legacy advisory markers. This removes the prior early-exit behavior and can significantly increase API usage and runtime for heavily-commented issues (and makes rate-limit/transient failures more likely).

Consider restoring a short-circuiting scan: fetch the newest page first and walk backwards until a match is found, or stream gh api --paginate into jq using first(...)/select(...) so the pipeline can terminate as soon as a matching comment is detected.

 marker_present() {
local num="$1" pages
pages="$(gh api --paginate --slurp "repos/${REPO}/issues/${num}/comments?per_page=100" 2>/dev/null)" || return 2
jq -e \

@vitek-karas
vitek-karas merged commit 573d5a0 into dotnet:mainAug 12, 2026
23 checks passed
@vitek-karas
vitek-karas deleted the vitek-karas-fix-agentic-workflow-markers branch August 12, 2026 20:05
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-skillsAgent Skills

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@vitek-karas@PureWeen@kotlarmilos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix agentic workflow markers removed from safe outputs - #132011

Merged
vitek-karas merged 4 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-fix-agentic-workflow-markers
Aug 12, 2026
Merged

Fix agentic workflow markers removed from safe outputs#132011
vitek-karas merged 4 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-fix-agentic-workflow-markers

Conversation

@vitek-karas

Copy link
Copy Markdown
Member

Summary

Several agentic workflows used HTML comments as machine-readable markers. That does not work: gh-aw removes agent-provided HTML comments when it sanitizes safe-output text. The comments were therefore not present in the posted issue or PR content, so later workflow runs could not reliably recognize earlier work. On #128405, this allowed ci-failure-fix to post two different handoff comments.

This change replaces those comments with markers that survive publishing:

  • safe-outputs.data where the output type supports structured data.
  • Stable visible Markdown fields where structured data is not supported or would break the required content format.

Existing visible markers are still recognized so older workflow output continues to work.

Changes by workflow

  • ci-failure-fix: Adds structured identifiers to fix PRs, help-wanted PRs, and handoff comments. Deduplication now checks every comment instead of assuming comments are at a fixed position, and it still recognizes older visible markers.
  • closed-issue-reference-check: Adds structured identifiers to advisory comments. The pre-check skips issues that contain either the new structured marker or the older workflow-specific marker and advisory heading.
  • ci-failure-scan: Moves KBE authoring guidance and the verified-match count into collapsed, clearly labeled sections. KBE bodies still contain exactly one JSON block, as required by Build Analysis.
  • ci-failure-scan-feedback: Reads the new ci-failure-fix identifiers while keeping compatibility with older markers. Its tracker identity and window are stored in a collapsed visible section, and tracker updates explicitly replace the body instead of appending to it.

The shared workflow guidance now documents that HTML comments are removed and explains when to use structured data or visible fields. The affected generated workflows were refreshed with gh-aw v0.83.5.

Related change

#131996 is the repository-wide mechanical refresh to gh-aw v0.83.5. This PR contains the workflow behavior and authoring changes, and regenerates the affected workflows with the same compiler version.

Validation

  • Compiled and validated the affected workflows with gh-aw v0.83.5.
  • Ran poutine and zizmor on the changed workflows.
  • Checked the KBE templates keep exactly one JSON block and contain the required collapsed guidance and metadata.

Note

This PR description was generated with GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI lite review requested due to automatic review settings August 7, 2026 15:32
@github-actionsgithub-actionsBot added the area-skills Agent Skills label Aug 7, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates several agentic workflow prompts and regenerated lockfiles to stop using agent-authored HTML comments (<!-- ... -->) as persisted markers (since safe-output sanitization strips them), replacing them with either safe-outputs.data structured identifiers or stable visible Markdown fields.

Changes:

  • Introduces safe-outputs.data schemas and corresponding prompt guidance for workflows that need machine-readable identity/deduplication.
  • Updates the shared KBE templates and eval specs to use collapsed <details> blocks for authoring guidance and workflow-owned match-count metadata (while preserving the “exactly one fenced JSON block” KBE constraint).
  • Regenerates the affected *.lock.yml workflows to the newer gh-aw compiler/runtime versions.

Reviewed changes

Copilot reviewed 14 out of 14 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
.github/workflows/shared/create-kbe.instructions.mdMoves KBE guidance + verification metadata into collapsed <details> blocks while keeping exactly one JSON signature block.
.github/workflows/README.mdDocuments that safe outputs strip HTML/XML comments and recommends safe-outputs.data or visible fields.
.github/workflows/evals/README.mdUpdates eval expectations to require collapsed guidance + metadata blocks.
.github/workflows/evals/ci-failure-scan.eval.yamlUpdates graders to validate the new <details>-based KBE template requirements.
.github/workflows/closed-issue-reference-check.mdAdds safe-outputs.data schema + updates dedup logic to detect prior advisory comments via structured or legacy visible markers.
.github/workflows/ci-failure-scan.mdUpdates scanner match-count gating language to require the new collapsed verification block.
.github/workflows/ci-failure-scan.lock.ymlRegenerated workflow lockfile (compiler/runtime/tooling version and infra script updates).
.github/workflows/ci-failure-scan-feedback.mdUpdates feedback workflow prompt to identify artifacts via structured data or legacy visible blocks; stores tracker metadata in visible collapsed block.
.github/workflows/ci-failure-scan-feedback.lock.ymlRegenerated workflow lockfile (compiler/runtime/tooling version and infra script updates).
.github/workflows/ci-failure-fix.mdAdds safe-outputs.data schema + updates prompt guidance for dedup/identity via structured data with legacy fallback.
.github/aw/actions-lock.jsonUpdates pinned gh-aw setup action entry to v0.83.5 and removes older entries.
.github/agents/agentic-workflows.agent.mdAdds repo guidance explaining sanitization behavior and when to use safe-outputs.data vs visible fields.

Comment thread.github/workflows/closed-issue-reference-check.md Outdated
Comment thread.github/workflows/ci-failure-fix.md Outdated
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI review requested due to automatic review settings August 10, 2026 13:56

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 13 out of 13 changed files in this pull request and generated no new comments.

Suppressed comments (2)

.github/workflows/closed-issue-reference-check.md:161

  • The structured-data dedup check matches exact substrings like "workflow_artifact": "..." (note the space after :). If the appended JSON is ever minified (e.g., "workflow_artifact":"...") or otherwise formatted differently, this will false-negative and allow duplicate advisory comments. Using a regex (test) that tolerates whitespace makes the dedup more robust.
 data_workflow='"workflow_artifact": "closed-issue-reference-check"'
data_kind='"artifact_kind": "advice"'
legacy_call_id='gh-aw-workflow-call-id: dotnet/runtime/closed-issue-reference-check'
legacy_workflow_id='gh-aw-workflow-id: closed-issue-reference-check'
legacy_agentic_id='workflow_id: closed-issue-reference-check'

.github/agents/agentic-workflows.agent.md:196

  • safe-outputs.data appends a fenced Structured data: JSON block to the posted body, but it isn’t necessarily a second JSON block (it’s only “second” if the body already contains one). Rewording this avoids confusing future workflow authors.
`safe-outputs.data` is not available on every output type; notably, `update_issue` cannot attach it. It also appends a second fenced JSON block to the posted body, which is incompatible with formats such as Known Build Error issues that require exactly one fenced JSON block. In those cases, use narrowly formatted visible fields in the body and preserve them on every rewrite.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI review requested due to automatic review settings August 10, 2026 15:06
@vitek-karas

Copy link
Copy Markdown
MemberAuthor

Fixed the small updates based on the review - this should be final now - @PureWeen or @kotlarmilos could you please re-approve?

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 13 out of 13 changed files in this pull request and generated no new comments.

Suppressed comments (1)

.github/workflows/closed-issue-reference-check.md:164

  • marker_present currently downloads all pages of issue comments (gh api --paginate --slurp ...) before checking for structured/legacy advisory markers. This removes the prior early-exit behavior and can significantly increase API usage and runtime for heavily-commented issues (and makes rate-limit/transient failures more likely).

Consider restoring a short-circuiting scan: fetch the newest page first and walk backwards until a match is found, or stream gh api --paginate into jq using first(...)/select(...) so the pipeline can terminate as soon as a matching comment is detected.

 marker_present() {
local num="$1" pages
pages="$(gh api --paginate --slurp "repos/${REPO}/issues/${num}/comments?per_page=100" 2>/dev/null)" || return 2
jq -e \

@vitek-karas
vitek-karas merged commit 573d5a0 into dotnet:mainAug 12, 2026
23 checks passed
@vitek-karas
vitek-karas deleted the vitek-karas-fix-agentic-workflow-markers branch August 12, 2026 20:05
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-skillsAgent Skills

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@vitek-karas@PureWeen@kotlarmilos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix agentic workflow markers removed from safe outputs - #132011

Merged
vitek-karas merged 4 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-fix-agentic-workflow-markers
Aug 12, 2026
Merged

Fix agentic workflow markers removed from safe outputs#132011
vitek-karas merged 4 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-fix-agentic-workflow-markers

Conversation

@vitek-karas

Copy link
Copy Markdown
Member

Summary

Several agentic workflows used HTML comments as machine-readable markers. That does not work: gh-aw removes agent-provided HTML comments when it sanitizes safe-output text. The comments were therefore not present in the posted issue or PR content, so later workflow runs could not reliably recognize earlier work. On #128405, this allowed ci-failure-fix to post two different handoff comments.

This change replaces those comments with markers that survive publishing:

  • safe-outputs.data where the output type supports structured data.
  • Stable visible Markdown fields where structured data is not supported or would break the required content format.

Existing visible markers are still recognized so older workflow output continues to work.

Changes by workflow

  • ci-failure-fix: Adds structured identifiers to fix PRs, help-wanted PRs, and handoff comments. Deduplication now checks every comment instead of assuming comments are at a fixed position, and it still recognizes older visible markers.
  • closed-issue-reference-check: Adds structured identifiers to advisory comments. The pre-check skips issues that contain either the new structured marker or the older workflow-specific marker and advisory heading.
  • ci-failure-scan: Moves KBE authoring guidance and the verified-match count into collapsed, clearly labeled sections. KBE bodies still contain exactly one JSON block, as required by Build Analysis.
  • ci-failure-scan-feedback: Reads the new ci-failure-fix identifiers while keeping compatibility with older markers. Its tracker identity and window are stored in a collapsed visible section, and tracker updates explicitly replace the body instead of appending to it.

The shared workflow guidance now documents that HTML comments are removed and explains when to use structured data or visible fields. The affected generated workflows were refreshed with gh-aw v0.83.5.

Related change

#131996 is the repository-wide mechanical refresh to gh-aw v0.83.5. This PR contains the workflow behavior and authoring changes, and regenerates the affected workflows with the same compiler version.

Validation

  • Compiled and validated the affected workflows with gh-aw v0.83.5.
  • Ran poutine and zizmor on the changed workflows.
  • Checked the KBE templates keep exactly one JSON block and contain the required collapsed guidance and metadata.

Note

This PR description was generated with GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI lite review requested due to automatic review settings August 7, 2026 15:32
@github-actionsgithub-actionsBot added the area-skills Agent Skills label Aug 7, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates several agentic workflow prompts and regenerated lockfiles to stop using agent-authored HTML comments (<!-- ... -->) as persisted markers (since safe-output sanitization strips them), replacing them with either safe-outputs.data structured identifiers or stable visible Markdown fields.

Changes:

  • Introduces safe-outputs.data schemas and corresponding prompt guidance for workflows that need machine-readable identity/deduplication.
  • Updates the shared KBE templates and eval specs to use collapsed <details> blocks for authoring guidance and workflow-owned match-count metadata (while preserving the “exactly one fenced JSON block” KBE constraint).
  • Regenerates the affected *.lock.yml workflows to the newer gh-aw compiler/runtime versions.

Reviewed changes

Copilot reviewed 14 out of 14 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
.github/workflows/shared/create-kbe.instructions.mdMoves KBE guidance + verification metadata into collapsed <details> blocks while keeping exactly one JSON signature block.
.github/workflows/README.mdDocuments that safe outputs strip HTML/XML comments and recommends safe-outputs.data or visible fields.
.github/workflows/evals/README.mdUpdates eval expectations to require collapsed guidance + metadata blocks.
.github/workflows/evals/ci-failure-scan.eval.yamlUpdates graders to validate the new <details>-based KBE template requirements.
.github/workflows/closed-issue-reference-check.mdAdds safe-outputs.data schema + updates dedup logic to detect prior advisory comments via structured or legacy visible markers.
.github/workflows/ci-failure-scan.mdUpdates scanner match-count gating language to require the new collapsed verification block.
.github/workflows/ci-failure-scan.lock.ymlRegenerated workflow lockfile (compiler/runtime/tooling version and infra script updates).
.github/workflows/ci-failure-scan-feedback.mdUpdates feedback workflow prompt to identify artifacts via structured data or legacy visible blocks; stores tracker metadata in visible collapsed block.
.github/workflows/ci-failure-scan-feedback.lock.ymlRegenerated workflow lockfile (compiler/runtime/tooling version and infra script updates).
.github/workflows/ci-failure-fix.mdAdds safe-outputs.data schema + updates prompt guidance for dedup/identity via structured data with legacy fallback.
.github/aw/actions-lock.jsonUpdates pinned gh-aw setup action entry to v0.83.5 and removes older entries.
.github/agents/agentic-workflows.agent.mdAdds repo guidance explaining sanitization behavior and when to use safe-outputs.data vs visible fields.

Comment thread.github/workflows/closed-issue-reference-check.md Outdated
Comment thread.github/workflows/ci-failure-fix.md Outdated
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI review requested due to automatic review settings August 10, 2026 13:56

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 13 out of 13 changed files in this pull request and generated no new comments.

Suppressed comments (2)

.github/workflows/closed-issue-reference-check.md:161

  • The structured-data dedup check matches exact substrings like "workflow_artifact": "..." (note the space after :). If the appended JSON is ever minified (e.g., "workflow_artifact":"...") or otherwise formatted differently, this will false-negative and allow duplicate advisory comments. Using a regex (test) that tolerates whitespace makes the dedup more robust.
 data_workflow='"workflow_artifact": "closed-issue-reference-check"'
data_kind='"artifact_kind": "advice"'
legacy_call_id='gh-aw-workflow-call-id: dotnet/runtime/closed-issue-reference-check'
legacy_workflow_id='gh-aw-workflow-id: closed-issue-reference-check'
legacy_agentic_id='workflow_id: closed-issue-reference-check'

.github/agents/agentic-workflows.agent.md:196

  • safe-outputs.data appends a fenced Structured data: JSON block to the posted body, but it isn’t necessarily a second JSON block (it’s only “second” if the body already contains one). Rewording this avoids confusing future workflow authors.
`safe-outputs.data` is not available on every output type; notably, `update_issue` cannot attach it. It also appends a second fenced JSON block to the posted body, which is incompatible with formats such as Known Build Error issues that require exactly one fenced JSON block. In those cases, use narrowly formatted visible fields in the body and preserve them on every rewrite.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI review requested due to automatic review settings August 10, 2026 15:06
@vitek-karas

Copy link
Copy Markdown
MemberAuthor

Fixed the small updates based on the review - this should be final now - @PureWeen or @kotlarmilos could you please re-approve?

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 13 out of 13 changed files in this pull request and generated no new comments.

Suppressed comments (1)

.github/workflows/closed-issue-reference-check.md:164

  • marker_present currently downloads all pages of issue comments (gh api --paginate --slurp ...) before checking for structured/legacy advisory markers. This removes the prior early-exit behavior and can significantly increase API usage and runtime for heavily-commented issues (and makes rate-limit/transient failures more likely).

Consider restoring a short-circuiting scan: fetch the newest page first and walk backwards until a match is found, or stream gh api --paginate into jq using first(...)/select(...) so the pipeline can terminate as soon as a matching comment is detected.

 marker_present() {
local num="$1" pages
pages="$(gh api --paginate --slurp "repos/${REPO}/issues/${num}/comments?per_page=100" 2>/dev/null)" || return 2
jq -e \

@vitek-karas
vitek-karas merged commit 573d5a0 into dotnet:mainAug 12, 2026
23 checks passed
@vitek-karas
vitek-karas deleted the vitek-karas-fix-agentic-workflow-markers branch August 12, 2026 20:05
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-skillsAgent Skills

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@vitek-karas@PureWeen@kotlarmilos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Fix agentic workflow markers removed from safe outputs - #132011

Merged
vitek-karas merged 4 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-fix-agentic-workflow-markers
Aug 12, 2026
Merged

Fix agentic workflow markers removed from safe outputs#132011
vitek-karas merged 4 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-fix-agentic-workflow-markers

Conversation

@vitek-karas

Copy link
Copy Markdown
Member

Summary

Several agentic workflows used HTML comments as machine-readable markers. That does not work: gh-aw removes agent-provided HTML comments when it sanitizes safe-output text. The comments were therefore not present in the posted issue or PR content, so later workflow runs could not reliably recognize earlier work. On #128405, this allowed ci-failure-fix to post two different handoff comments.

This change replaces those comments with markers that survive publishing:

  • safe-outputs.data where the output type supports structured data.
  • Stable visible Markdown fields where structured data is not supported or would break the required content format.

Existing visible markers are still recognized so older workflow output continues to work.

Changes by workflow

  • ci-failure-fix: Adds structured identifiers to fix PRs, help-wanted PRs, and handoff comments. Deduplication now checks every comment instead of assuming comments are at a fixed position, and it still recognizes older visible markers.
  • closed-issue-reference-check: Adds structured identifiers to advisory comments. The pre-check skips issues that contain either the new structured marker or the older workflow-specific marker and advisory heading.
  • ci-failure-scan: Moves KBE authoring guidance and the verified-match count into collapsed, clearly labeled sections. KBE bodies still contain exactly one JSON block, as required by Build Analysis.
  • ci-failure-scan-feedback: Reads the new ci-failure-fix identifiers while keeping compatibility with older markers. Its tracker identity and window are stored in a collapsed visible section, and tracker updates explicitly replace the body instead of appending to it.

The shared workflow guidance now documents that HTML comments are removed and explains when to use structured data or visible fields. The affected generated workflows were refreshed with gh-aw v0.83.5.

Related change

#131996 is the repository-wide mechanical refresh to gh-aw v0.83.5. This PR contains the workflow behavior and authoring changes, and regenerates the affected workflows with the same compiler version.

Validation

  • Compiled and validated the affected workflows with gh-aw v0.83.5.
  • Ran poutine and zizmor on the changed workflows.
  • Checked the KBE templates keep exactly one JSON block and contain the required collapsed guidance and metadata.

Note

This PR description was generated with GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI lite review requested due to automatic review settings August 7, 2026 15:32
@github-actionsgithub-actionsBot added the area-skills Agent Skills label Aug 7, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates several agentic workflow prompts and regenerated lockfiles to stop using agent-authored HTML comments (<!-- ... -->) as persisted markers (since safe-output sanitization strips them), replacing them with either safe-outputs.data structured identifiers or stable visible Markdown fields.

Changes:

  • Introduces safe-outputs.data schemas and corresponding prompt guidance for workflows that need machine-readable identity/deduplication.
  • Updates the shared KBE templates and eval specs to use collapsed <details> blocks for authoring guidance and workflow-owned match-count metadata (while preserving the “exactly one fenced JSON block” KBE constraint).
  • Regenerates the affected *.lock.yml workflows to the newer gh-aw compiler/runtime versions.

Reviewed changes

Copilot reviewed 14 out of 14 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
.github/workflows/shared/create-kbe.instructions.mdMoves KBE guidance + verification metadata into collapsed <details> blocks while keeping exactly one JSON signature block.
.github/workflows/README.mdDocuments that safe outputs strip HTML/XML comments and recommends safe-outputs.data or visible fields.
.github/workflows/evals/README.mdUpdates eval expectations to require collapsed guidance + metadata blocks.
.github/workflows/evals/ci-failure-scan.eval.yamlUpdates graders to validate the new <details>-based KBE template requirements.
.github/workflows/closed-issue-reference-check.mdAdds safe-outputs.data schema + updates dedup logic to detect prior advisory comments via structured or legacy visible markers.
.github/workflows/ci-failure-scan.mdUpdates scanner match-count gating language to require the new collapsed verification block.
.github/workflows/ci-failure-scan.lock.ymlRegenerated workflow lockfile (compiler/runtime/tooling version and infra script updates).
.github/workflows/ci-failure-scan-feedback.mdUpdates feedback workflow prompt to identify artifacts via structured data or legacy visible blocks; stores tracker metadata in visible collapsed block.
.github/workflows/ci-failure-scan-feedback.lock.ymlRegenerated workflow lockfile (compiler/runtime/tooling version and infra script updates).
.github/workflows/ci-failure-fix.mdAdds safe-outputs.data schema + updates prompt guidance for dedup/identity via structured data with legacy fallback.
.github/aw/actions-lock.jsonUpdates pinned gh-aw setup action entry to v0.83.5 and removes older entries.
.github/agents/agentic-workflows.agent.mdAdds repo guidance explaining sanitization behavior and when to use safe-outputs.data vs visible fields.

Comment thread.github/workflows/closed-issue-reference-check.md Outdated
Comment thread.github/workflows/ci-failure-fix.md Outdated
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI review requested due to automatic review settings August 10, 2026 13:56

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 13 out of 13 changed files in this pull request and generated no new comments.

Suppressed comments (2)

.github/workflows/closed-issue-reference-check.md:161

  • The structured-data dedup check matches exact substrings like "workflow_artifact": "..." (note the space after :). If the appended JSON is ever minified (e.g., "workflow_artifact":"...") or otherwise formatted differently, this will false-negative and allow duplicate advisory comments. Using a regex (test) that tolerates whitespace makes the dedup more robust.
 data_workflow='"workflow_artifact": "closed-issue-reference-check"'
data_kind='"artifact_kind": "advice"'
legacy_call_id='gh-aw-workflow-call-id: dotnet/runtime/closed-issue-reference-check'
legacy_workflow_id='gh-aw-workflow-id: closed-issue-reference-check'
legacy_agentic_id='workflow_id: closed-issue-reference-check'

.github/agents/agentic-workflows.agent.md:196

  • safe-outputs.data appends a fenced Structured data: JSON block to the posted body, but it isn’t necessarily a second JSON block (it’s only “second” if the body already contains one). Rewording this avoids confusing future workflow authors.
`safe-outputs.data` is not available on every output type; notably, `update_issue` cannot attach it. It also appends a second fenced JSON block to the posted body, which is incompatible with formats such as Known Build Error issues that require exactly one fenced JSON block. In those cases, use narrowly formatted visible fields in the body and preserve them on every rewrite.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI review requested due to automatic review settings August 10, 2026 15:06
@vitek-karas

Copy link
Copy Markdown
MemberAuthor

Fixed the small updates based on the review - this should be final now - @PureWeen or @kotlarmilos could you please re-approve?

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 13 out of 13 changed files in this pull request and generated no new comments.

Suppressed comments (1)

.github/workflows/closed-issue-reference-check.md:164

  • marker_present currently downloads all pages of issue comments (gh api --paginate --slurp ...) before checking for structured/legacy advisory markers. This removes the prior early-exit behavior and can significantly increase API usage and runtime for heavily-commented issues (and makes rate-limit/transient failures more likely).

Consider restoring a short-circuiting scan: fetch the newest page first and walk backwards until a match is found, or stream gh api --paginate into jq using first(...)/select(...) so the pipeline can terminate as soon as a matching comment is detected.

 marker_present() {
local num="$1" pages
pages="$(gh api --paginate --slurp "repos/${REPO}/issues/${num}/comments?per_page=100" 2>/dev/null)" || return 2
jq -e \

@vitek-karas
vitek-karas merged commit 573d5a0 into dotnet:mainAug 12, 2026
23 checks passed
@vitek-karas
vitek-karas deleted the vitek-karas-fix-agentic-workflow-markers branch August 12, 2026 20:05
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-skillsAgent Skills

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@vitek-karas@PureWeen@kotlarmilos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix agentic workflow markers removed from safe outputs - #132011

Merged
vitek-karas merged 4 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-fix-agentic-workflow-markers
Aug 12, 2026
Merged

Fix agentic workflow markers removed from safe outputs#132011
vitek-karas merged 4 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-fix-agentic-workflow-markers

Conversation

@vitek-karas

Copy link
Copy Markdown
Member

Summary

Several agentic workflows used HTML comments as machine-readable markers. That does not work: gh-aw removes agent-provided HTML comments when it sanitizes safe-output text. The comments were therefore not present in the posted issue or PR content, so later workflow runs could not reliably recognize earlier work. On #128405, this allowed ci-failure-fix to post two different handoff comments.

This change replaces those comments with markers that survive publishing:

  • safe-outputs.data where the output type supports structured data.
  • Stable visible Markdown fields where structured data is not supported or would break the required content format.

Existing visible markers are still recognized so older workflow output continues to work.

Changes by workflow

  • ci-failure-fix: Adds structured identifiers to fix PRs, help-wanted PRs, and handoff comments. Deduplication now checks every comment instead of assuming comments are at a fixed position, and it still recognizes older visible markers.
  • closed-issue-reference-check: Adds structured identifiers to advisory comments. The pre-check skips issues that contain either the new structured marker or the older workflow-specific marker and advisory heading.
  • ci-failure-scan: Moves KBE authoring guidance and the verified-match count into collapsed, clearly labeled sections. KBE bodies still contain exactly one JSON block, as required by Build Analysis.
  • ci-failure-scan-feedback: Reads the new ci-failure-fix identifiers while keeping compatibility with older markers. Its tracker identity and window are stored in a collapsed visible section, and tracker updates explicitly replace the body instead of appending to it.

The shared workflow guidance now documents that HTML comments are removed and explains when to use structured data or visible fields. The affected generated workflows were refreshed with gh-aw v0.83.5.

Related change

#131996 is the repository-wide mechanical refresh to gh-aw v0.83.5. This PR contains the workflow behavior and authoring changes, and regenerates the affected workflows with the same compiler version.

Validation

  • Compiled and validated the affected workflows with gh-aw v0.83.5.
  • Ran poutine and zizmor on the changed workflows.
  • Checked the KBE templates keep exactly one JSON block and contain the required collapsed guidance and metadata.

Note

This PR description was generated with GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI lite review requested due to automatic review settings August 7, 2026 15:32
@github-actionsgithub-actionsBot added the area-skills Agent Skills label Aug 7, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates several agentic workflow prompts and regenerated lockfiles to stop using agent-authored HTML comments (<!-- ... -->) as persisted markers (since safe-output sanitization strips them), replacing them with either safe-outputs.data structured identifiers or stable visible Markdown fields.

Changes:

  • Introduces safe-outputs.data schemas and corresponding prompt guidance for workflows that need machine-readable identity/deduplication.
  • Updates the shared KBE templates and eval specs to use collapsed <details> blocks for authoring guidance and workflow-owned match-count metadata (while preserving the “exactly one fenced JSON block” KBE constraint).
  • Regenerates the affected *.lock.yml workflows to the newer gh-aw compiler/runtime versions.

Reviewed changes

Copilot reviewed 14 out of 14 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
.github/workflows/shared/create-kbe.instructions.mdMoves KBE guidance + verification metadata into collapsed <details> blocks while keeping exactly one JSON signature block.
.github/workflows/README.mdDocuments that safe outputs strip HTML/XML comments and recommends safe-outputs.data or visible fields.
.github/workflows/evals/README.mdUpdates eval expectations to require collapsed guidance + metadata blocks.
.github/workflows/evals/ci-failure-scan.eval.yamlUpdates graders to validate the new <details>-based KBE template requirements.
.github/workflows/closed-issue-reference-check.mdAdds safe-outputs.data schema + updates dedup logic to detect prior advisory comments via structured or legacy visible markers.
.github/workflows/ci-failure-scan.mdUpdates scanner match-count gating language to require the new collapsed verification block.
.github/workflows/ci-failure-scan.lock.ymlRegenerated workflow lockfile (compiler/runtime/tooling version and infra script updates).
.github/workflows/ci-failure-scan-feedback.mdUpdates feedback workflow prompt to identify artifacts via structured data or legacy visible blocks; stores tracker metadata in visible collapsed block.
.github/workflows/ci-failure-scan-feedback.lock.ymlRegenerated workflow lockfile (compiler/runtime/tooling version and infra script updates).
.github/workflows/ci-failure-fix.mdAdds safe-outputs.data schema + updates prompt guidance for dedup/identity via structured data with legacy fallback.
.github/aw/actions-lock.jsonUpdates pinned gh-aw setup action entry to v0.83.5 and removes older entries.
.github/agents/agentic-workflows.agent.mdAdds repo guidance explaining sanitization behavior and when to use safe-outputs.data vs visible fields.

Comment thread.github/workflows/closed-issue-reference-check.md Outdated
Comment thread.github/workflows/ci-failure-fix.md Outdated
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI review requested due to automatic review settings August 10, 2026 13:56

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 13 out of 13 changed files in this pull request and generated no new comments.

Suppressed comments (2)

.github/workflows/closed-issue-reference-check.md:161

  • The structured-data dedup check matches exact substrings like "workflow_artifact": "..." (note the space after :). If the appended JSON is ever minified (e.g., "workflow_artifact":"...") or otherwise formatted differently, this will false-negative and allow duplicate advisory comments. Using a regex (test) that tolerates whitespace makes the dedup more robust.
 data_workflow='"workflow_artifact": "closed-issue-reference-check"'
data_kind='"artifact_kind": "advice"'
legacy_call_id='gh-aw-workflow-call-id: dotnet/runtime/closed-issue-reference-check'
legacy_workflow_id='gh-aw-workflow-id: closed-issue-reference-check'
legacy_agentic_id='workflow_id: closed-issue-reference-check'

.github/agents/agentic-workflows.agent.md:196

  • safe-outputs.data appends a fenced Structured data: JSON block to the posted body, but it isn’t necessarily a second JSON block (it’s only “second” if the body already contains one). Rewording this avoids confusing future workflow authors.
`safe-outputs.data` is not available on every output type; notably, `update_issue` cannot attach it. It also appends a second fenced JSON block to the posted body, which is incompatible with formats such as Known Build Error issues that require exactly one fenced JSON block. In those cases, use narrowly formatted visible fields in the body and preserve them on every rewrite.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI review requested due to automatic review settings August 10, 2026 15:06
@vitek-karas

Copy link
Copy Markdown
MemberAuthor

Fixed the small updates based on the review - this should be final now - @PureWeen or @kotlarmilos could you please re-approve?

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 13 out of 13 changed files in this pull request and generated no new comments.

Suppressed comments (1)

.github/workflows/closed-issue-reference-check.md:164

  • marker_present currently downloads all pages of issue comments (gh api --paginate --slurp ...) before checking for structured/legacy advisory markers. This removes the prior early-exit behavior and can significantly increase API usage and runtime for heavily-commented issues (and makes rate-limit/transient failures more likely).

Consider restoring a short-circuiting scan: fetch the newest page first and walk backwards until a match is found, or stream gh api --paginate into jq using first(...)/select(...) so the pipeline can terminate as soon as a matching comment is detected.

 marker_present() {
local num="$1" pages
pages="$(gh api --paginate --slurp "repos/${REPO}/issues/${num}/comments?per_page=100" 2>/dev/null)" || return 2
jq -e \

@vitek-karas
vitek-karas merged commit 573d5a0 into dotnet:mainAug 12, 2026
23 checks passed
@vitek-karas
vitek-karas deleted the vitek-karas-fix-agentic-workflow-markers branch August 12, 2026 20:05
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-skillsAgent Skills

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@vitek-karas@PureWeen@kotlarmilos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix agentic workflow markers removed from safe outputs - #132011

Merged
vitek-karas merged 4 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-fix-agentic-workflow-markers
Aug 12, 2026
Merged

Fix agentic workflow markers removed from safe outputs#132011
vitek-karas merged 4 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-fix-agentic-workflow-markers

Conversation

@vitek-karas

Copy link
Copy Markdown
Member

Summary

Several agentic workflows used HTML comments as machine-readable markers. That does not work: gh-aw removes agent-provided HTML comments when it sanitizes safe-output text. The comments were therefore not present in the posted issue or PR content, so later workflow runs could not reliably recognize earlier work. On #128405, this allowed ci-failure-fix to post two different handoff comments.

This change replaces those comments with markers that survive publishing:

  • safe-outputs.data where the output type supports structured data.
  • Stable visible Markdown fields where structured data is not supported or would break the required content format.

Existing visible markers are still recognized so older workflow output continues to work.

Changes by workflow

  • ci-failure-fix: Adds structured identifiers to fix PRs, help-wanted PRs, and handoff comments. Deduplication now checks every comment instead of assuming comments are at a fixed position, and it still recognizes older visible markers.
  • closed-issue-reference-check: Adds structured identifiers to advisory comments. The pre-check skips issues that contain either the new structured marker or the older workflow-specific marker and advisory heading.
  • ci-failure-scan: Moves KBE authoring guidance and the verified-match count into collapsed, clearly labeled sections. KBE bodies still contain exactly one JSON block, as required by Build Analysis.
  • ci-failure-scan-feedback: Reads the new ci-failure-fix identifiers while keeping compatibility with older markers. Its tracker identity and window are stored in a collapsed visible section, and tracker updates explicitly replace the body instead of appending to it.

The shared workflow guidance now documents that HTML comments are removed and explains when to use structured data or visible fields. The affected generated workflows were refreshed with gh-aw v0.83.5.

Related change

#131996 is the repository-wide mechanical refresh to gh-aw v0.83.5. This PR contains the workflow behavior and authoring changes, and regenerates the affected workflows with the same compiler version.

Validation

  • Compiled and validated the affected workflows with gh-aw v0.83.5.
  • Ran poutine and zizmor on the changed workflows.
  • Checked the KBE templates keep exactly one JSON block and contain the required collapsed guidance and metadata.

Note

This PR description was generated with GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI lite review requested due to automatic review settings August 7, 2026 15:32
@github-actionsgithub-actionsBot added the area-skills Agent Skills label Aug 7, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates several agentic workflow prompts and regenerated lockfiles to stop using agent-authored HTML comments (<!-- ... -->) as persisted markers (since safe-output sanitization strips them), replacing them with either safe-outputs.data structured identifiers or stable visible Markdown fields.

Changes:

  • Introduces safe-outputs.data schemas and corresponding prompt guidance for workflows that need machine-readable identity/deduplication.
  • Updates the shared KBE templates and eval specs to use collapsed <details> blocks for authoring guidance and workflow-owned match-count metadata (while preserving the “exactly one fenced JSON block” KBE constraint).
  • Regenerates the affected *.lock.yml workflows to the newer gh-aw compiler/runtime versions.

Reviewed changes

Copilot reviewed 14 out of 14 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
.github/workflows/shared/create-kbe.instructions.mdMoves KBE guidance + verification metadata into collapsed <details> blocks while keeping exactly one JSON signature block.
.github/workflows/README.mdDocuments that safe outputs strip HTML/XML comments and recommends safe-outputs.data or visible fields.
.github/workflows/evals/README.mdUpdates eval expectations to require collapsed guidance + metadata blocks.
.github/workflows/evals/ci-failure-scan.eval.yamlUpdates graders to validate the new <details>-based KBE template requirements.
.github/workflows/closed-issue-reference-check.mdAdds safe-outputs.data schema + updates dedup logic to detect prior advisory comments via structured or legacy visible markers.
.github/workflows/ci-failure-scan.mdUpdates scanner match-count gating language to require the new collapsed verification block.
.github/workflows/ci-failure-scan.lock.ymlRegenerated workflow lockfile (compiler/runtime/tooling version and infra script updates).
.github/workflows/ci-failure-scan-feedback.mdUpdates feedback workflow prompt to identify artifacts via structured data or legacy visible blocks; stores tracker metadata in visible collapsed block.
.github/workflows/ci-failure-scan-feedback.lock.ymlRegenerated workflow lockfile (compiler/runtime/tooling version and infra script updates).
.github/workflows/ci-failure-fix.mdAdds safe-outputs.data schema + updates prompt guidance for dedup/identity via structured data with legacy fallback.
.github/aw/actions-lock.jsonUpdates pinned gh-aw setup action entry to v0.83.5 and removes older entries.
.github/agents/agentic-workflows.agent.mdAdds repo guidance explaining sanitization behavior and when to use safe-outputs.data vs visible fields.

Comment thread.github/workflows/closed-issue-reference-check.md Outdated
Comment thread.github/workflows/ci-failure-fix.md Outdated
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI review requested due to automatic review settings August 10, 2026 13:56

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 13 out of 13 changed files in this pull request and generated no new comments.

Suppressed comments (2)

.github/workflows/closed-issue-reference-check.md:161

  • The structured-data dedup check matches exact substrings like "workflow_artifact": "..." (note the space after :). If the appended JSON is ever minified (e.g., "workflow_artifact":"...") or otherwise formatted differently, this will false-negative and allow duplicate advisory comments. Using a regex (test) that tolerates whitespace makes the dedup more robust.
 data_workflow='"workflow_artifact": "closed-issue-reference-check"'
data_kind='"artifact_kind": "advice"'
legacy_call_id='gh-aw-workflow-call-id: dotnet/runtime/closed-issue-reference-check'
legacy_workflow_id='gh-aw-workflow-id: closed-issue-reference-check'
legacy_agentic_id='workflow_id: closed-issue-reference-check'

.github/agents/agentic-workflows.agent.md:196

  • safe-outputs.data appends a fenced Structured data: JSON block to the posted body, but it isn’t necessarily a second JSON block (it’s only “second” if the body already contains one). Rewording this avoids confusing future workflow authors.
`safe-outputs.data` is not available on every output type; notably, `update_issue` cannot attach it. It also appends a second fenced JSON block to the posted body, which is incompatible with formats such as Known Build Error issues that require exactly one fenced JSON block. In those cases, use narrowly formatted visible fields in the body and preserve them on every rewrite.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI review requested due to automatic review settings August 10, 2026 15:06
@vitek-karas

Copy link
Copy Markdown
MemberAuthor

Fixed the small updates based on the review - this should be final now - @PureWeen or @kotlarmilos could you please re-approve?

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 13 out of 13 changed files in this pull request and generated no new comments.

Suppressed comments (1)

.github/workflows/closed-issue-reference-check.md:164

  • marker_present currently downloads all pages of issue comments (gh api --paginate --slurp ...) before checking for structured/legacy advisory markers. This removes the prior early-exit behavior and can significantly increase API usage and runtime for heavily-commented issues (and makes rate-limit/transient failures more likely).

Consider restoring a short-circuiting scan: fetch the newest page first and walk backwards until a match is found, or stream gh api --paginate into jq using first(...)/select(...) so the pipeline can terminate as soon as a matching comment is detected.

 marker_present() {
local num="$1" pages
pages="$(gh api --paginate --slurp "repos/${REPO}/issues/${num}/comments?per_page=100" 2>/dev/null)" || return 2
jq -e \

@vitek-karas
vitek-karas merged commit 573d5a0 into dotnet:mainAug 12, 2026
23 checks passed
@vitek-karas
vitek-karas deleted the vitek-karas-fix-agentic-workflow-markers branch August 12, 2026 20:05
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-skillsAgent Skills

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@vitek-karas@PureWeen@kotlarmilos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Fix agentic workflow markers removed from safe outputs - #132011

Merged
vitek-karas merged 4 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-fix-agentic-workflow-markers
Aug 12, 2026
Merged

Fix agentic workflow markers removed from safe outputs#132011
vitek-karas merged 4 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-fix-agentic-workflow-markers

Conversation

@vitek-karas

Copy link
Copy Markdown
Member

Summary

Several agentic workflows used HTML comments as machine-readable markers. That does not work: gh-aw removes agent-provided HTML comments when it sanitizes safe-output text. The comments were therefore not present in the posted issue or PR content, so later workflow runs could not reliably recognize earlier work. On #128405, this allowed ci-failure-fix to post two different handoff comments.

This change replaces those comments with markers that survive publishing:

  • safe-outputs.data where the output type supports structured data.
  • Stable visible Markdown fields where structured data is not supported or would break the required content format.

Existing visible markers are still recognized so older workflow output continues to work.

Changes by workflow

  • ci-failure-fix: Adds structured identifiers to fix PRs, help-wanted PRs, and handoff comments. Deduplication now checks every comment instead of assuming comments are at a fixed position, and it still recognizes older visible markers.
  • closed-issue-reference-check: Adds structured identifiers to advisory comments. The pre-check skips issues that contain either the new structured marker or the older workflow-specific marker and advisory heading.
  • ci-failure-scan: Moves KBE authoring guidance and the verified-match count into collapsed, clearly labeled sections. KBE bodies still contain exactly one JSON block, as required by Build Analysis.
  • ci-failure-scan-feedback: Reads the new ci-failure-fix identifiers while keeping compatibility with older markers. Its tracker identity and window are stored in a collapsed visible section, and tracker updates explicitly replace the body instead of appending to it.

The shared workflow guidance now documents that HTML comments are removed and explains when to use structured data or visible fields. The affected generated workflows were refreshed with gh-aw v0.83.5.

Related change

#131996 is the repository-wide mechanical refresh to gh-aw v0.83.5. This PR contains the workflow behavior and authoring changes, and regenerates the affected workflows with the same compiler version.

Validation

  • Compiled and validated the affected workflows with gh-aw v0.83.5.
  • Ran poutine and zizmor on the changed workflows.
  • Checked the KBE templates keep exactly one JSON block and contain the required collapsed guidance and metadata.

Note

This PR description was generated with GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI lite review requested due to automatic review settings August 7, 2026 15:32
@github-actionsgithub-actionsBot added the area-skills Agent Skills label Aug 7, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates several agentic workflow prompts and regenerated lockfiles to stop using agent-authored HTML comments (<!-- ... -->) as persisted markers (since safe-output sanitization strips them), replacing them with either safe-outputs.data structured identifiers or stable visible Markdown fields.

Changes:

  • Introduces safe-outputs.data schemas and corresponding prompt guidance for workflows that need machine-readable identity/deduplication.
  • Updates the shared KBE templates and eval specs to use collapsed <details> blocks for authoring guidance and workflow-owned match-count metadata (while preserving the “exactly one fenced JSON block” KBE constraint).
  • Regenerates the affected *.lock.yml workflows to the newer gh-aw compiler/runtime versions.

Reviewed changes

Copilot reviewed 14 out of 14 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
.github/workflows/shared/create-kbe.instructions.mdMoves KBE guidance + verification metadata into collapsed <details> blocks while keeping exactly one JSON signature block.
.github/workflows/README.mdDocuments that safe outputs strip HTML/XML comments and recommends safe-outputs.data or visible fields.
.github/workflows/evals/README.mdUpdates eval expectations to require collapsed guidance + metadata blocks.
.github/workflows/evals/ci-failure-scan.eval.yamlUpdates graders to validate the new <details>-based KBE template requirements.
.github/workflows/closed-issue-reference-check.mdAdds safe-outputs.data schema + updates dedup logic to detect prior advisory comments via structured or legacy visible markers.
.github/workflows/ci-failure-scan.mdUpdates scanner match-count gating language to require the new collapsed verification block.
.github/workflows/ci-failure-scan.lock.ymlRegenerated workflow lockfile (compiler/runtime/tooling version and infra script updates).
.github/workflows/ci-failure-scan-feedback.mdUpdates feedback workflow prompt to identify artifacts via structured data or legacy visible blocks; stores tracker metadata in visible collapsed block.
.github/workflows/ci-failure-scan-feedback.lock.ymlRegenerated workflow lockfile (compiler/runtime/tooling version and infra script updates).
.github/workflows/ci-failure-fix.mdAdds safe-outputs.data schema + updates prompt guidance for dedup/identity via structured data with legacy fallback.
.github/aw/actions-lock.jsonUpdates pinned gh-aw setup action entry to v0.83.5 and removes older entries.
.github/agents/agentic-workflows.agent.mdAdds repo guidance explaining sanitization behavior and when to use safe-outputs.data vs visible fields.

Comment thread.github/workflows/closed-issue-reference-check.md Outdated
Comment thread.github/workflows/ci-failure-fix.md Outdated
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI review requested due to automatic review settings August 10, 2026 13:56

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 13 out of 13 changed files in this pull request and generated no new comments.

Suppressed comments (2)

.github/workflows/closed-issue-reference-check.md:161

  • The structured-data dedup check matches exact substrings like "workflow_artifact": "..." (note the space after :). If the appended JSON is ever minified (e.g., "workflow_artifact":"...") or otherwise formatted differently, this will false-negative and allow duplicate advisory comments. Using a regex (test) that tolerates whitespace makes the dedup more robust.
 data_workflow='"workflow_artifact": "closed-issue-reference-check"'
data_kind='"artifact_kind": "advice"'
legacy_call_id='gh-aw-workflow-call-id: dotnet/runtime/closed-issue-reference-check'
legacy_workflow_id='gh-aw-workflow-id: closed-issue-reference-check'
legacy_agentic_id='workflow_id: closed-issue-reference-check'

.github/agents/agentic-workflows.agent.md:196

  • safe-outputs.data appends a fenced Structured data: JSON block to the posted body, but it isn’t necessarily a second JSON block (it’s only “second” if the body already contains one). Rewording this avoids confusing future workflow authors.
`safe-outputs.data` is not available on every output type; notably, `update_issue` cannot attach it. It also appends a second fenced JSON block to the posted body, which is incompatible with formats such as Known Build Error issues that require exactly one fenced JSON block. In those cases, use narrowly formatted visible fields in the body and preserve them on every rewrite.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
CopilotAI review requested due to automatic review settings August 10, 2026 15:06
@vitek-karas

Copy link
Copy Markdown
MemberAuthor

Fixed the small updates based on the review - this should be final now - @PureWeen or @kotlarmilos could you please re-approve?

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 13 out of 13 changed files in this pull request and generated no new comments.

Suppressed comments (1)

.github/workflows/closed-issue-reference-check.md:164

  • marker_present currently downloads all pages of issue comments (gh api --paginate --slurp ...) before checking for structured/legacy advisory markers. This removes the prior early-exit behavior and can significantly increase API usage and runtime for heavily-commented issues (and makes rate-limit/transient failures more likely).

Consider restoring a short-circuiting scan: fetch the newest page first and walk backwards until a match is found, or stream gh api --paginate into jq using first(...)/select(...) so the pipeline can terminate as soon as a matching comment is detected.

 marker_present() {
local num="$1" pages
pages="$(gh api --paginate --slurp "repos/${REPO}/issues/${num}/comments?per_page=100" 2>/dev/null)" || return 2
jq -e \

@vitek-karas
vitek-karas merged commit 573d5a0 into dotnet:mainAug 12, 2026
23 checks passed
@vitek-karas
vitek-karas deleted the vitek-karas-fix-agentic-workflow-markers branch August 12, 2026 20:05
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-skillsAgent Skills

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@vitek-karas@PureWeen@kotlarmilos