diff --git a/workshop/04-github-actions-intro.md b/workshop/04-github-actions-intro.md index c0a42ff0..560c2c49 100644 --- a/workshop/04-github-actions-intro.md +++ b/workshop/04-github-actions-intro.md @@ -75,7 +75,7 @@ Traditional workflows execute a fixed script path. [Agentic workflows](https://g |---|---|---| | Trigger (`on:`) | Same — schedule, push, PR, dispatch | Same | | Runner (`runs-on:`) | GitHub-hosted or self-hosted | Same | -| Steps | Shell commands you define | AI agent executes a plain-English task brief | +| Steps | Shell commands you define | AI agent executes a plain-English [task brief](https://github.github.com/gh-aw/reference/markdown/) | | Output | Files, logs, deploy artifacts | GitHub comments, issues, PRs, or other API writes | The agentic workflow file you'll author in this workshop is a `.md` file with the same `on:` and `runs-on:` keys you see above, plus a Markdown task brief that tells the AI agent what to do. diff --git a/workshop/05b-agentic-workflows-security.md b/workshop/05b-agentic-workflows-security.md index 2d96d9f3..8d1d93cb 100644 --- a/workshop/05b-agentic-workflows-security.md +++ b/workshop/05b-agentic-workflows-security.md @@ -17,9 +17,9 @@ Letting an AI agent act on your repository on a [schedule](https://github.github ## Safe by design: sandbox + guardrailed outputs - **A [sandbox](https://github.github.com/gh-aw/reference/sandbox/) around the agent.** The agent runs isolated inside the [Agent Workflow Firewall](https://github.github.com/gh-aw/reference/sandbox/), with **read-only** access to your repo and [network egress](https://github.github.com/gh-aw/reference/network/) limited to the domains you allow. Even if a [prompt injection](https://github.github.com/gh-aw/reference/threat-detection/) or a compromised tool tries to reach out or exfiltrate data, the firewall blocks anything outside the allowlist. -- **A guardrailed [safe-output](https://github.github.com/gh-aw/reference/safe-outputs/) system for writes.** The agent never holds write permissions. Instead, it emits a *structured request* — "create this issue," "post this comment" — and a separate, permission-scoped job validates and executes it, applying per-operation limits (max counts, label and title constraints, allowed repos). That separation gives you least privilege, defense against prompt injection, and a full audit trail of every action. +- **A guardrailed [safe-output](https://github.github.com/gh-aw/reference/safe-outputs/) system for writes.** The agent never holds write permissions. Instead, it emits a *structured request* — "create this issue," "post this comment" — and a separate, permission-scoped job validates and executes it, applying per-operation limits (max counts, label and title constraints, allowed repos). That separation gives you [least privilege](https://github.github.com/gh-aw/reference/glossary/#least-privilege), defense against prompt injection, and a full [audit trail](https://github.github.com/gh-aw/reference/artifacts/#audit-trail-is-at) of every action. -The security jobs in the run log above map to these boundaries: **activation** checks the agent is authorized to run, the **agent** runs sandboxed behind the firewall, **detection** scans for malicious behavior, and **safe-outputs** applies changes within the guardrails. +The security jobs in the run log above map to these boundaries: **[activation](https://github.github.com/gh-aw/reference/artifacts/#activation)** checks the agent is authorized to run, the **agent** runs sandboxed behind the firewall, **detection** scans for malicious behavior, and **safe-outputs** applies changes within the guardrails.
Why can't the agent just write to the repo directly? diff --git a/workshop/05c-agentic-workflows-practice.md b/workshop/05c-agentic-workflows-practice.md index 6ad0642a..f87ba6d0 100644 --- a/workshop/05c-agentic-workflows-practice.md +++ b/workshop/05c-agentic-workflows-practice.md @@ -6,7 +6,7 @@ - You've read [What Are Agentic Workflows?](05-agentic-workflows-intro.md) -These exercises help you apply what you just learned — deciding when to use an agentic workflow and drafting your first task brief. +These exercises help you apply what you just learned — deciding when to use an agentic workflow and drafting your first [task brief](https://github.github.com/gh-aw/reference/markdown/). ## Try it: agentic or standard? diff --git a/workshop/07-your-first-workflow.md b/workshop/07-your-first-workflow.md index 1df31c7d..c04e05bd 100644 --- a/workshop/07-your-first-workflow.md +++ b/workshop/07-your-first-workflow.md @@ -6,7 +6,7 @@ _Writing your first workflow is the moment theory becomes practice — let's mak ## :dart: What You'll Do -You'll use Copilot to create `.github/workflows/daily-report-status.md` — a scheduled workflow that also supports manual dispatch. You'll configure it with [`permissions`](https://github.github.com/gh-aw/reference/permissions/), [`safe-outputs`](https://github.github.com/gh-aw/reference/safe-outputs/), and a task brief, then compile it to produce `daily-report-status.lock.yml`, the file [GitHub Actions](https://github.github.com/gh-aw/guides/github-actions-primer/) runs. +You'll use Copilot to create `.github/workflows/daily-report-status.md` — a scheduled workflow that also supports manual dispatch. You'll configure it with [`permissions`](https://github.github.com/gh-aw/reference/permissions/), [`safe-outputs`](https://github.github.com/gh-aw/reference/safe-outputs/), and a [task brief](https://github.github.com/gh-aw/reference/markdown/), then compile it to produce `daily-report-status.lock.yml`, the file [GitHub Actions](https://github.github.com/gh-aw/guides/github-actions-primer/) runs. diff --git a/workshop/09-agentic-editing.md b/workshop/09-agentic-editing.md index debe0715..babbf472 100644 --- a/workshop/09-agentic-editing.md +++ b/workshop/09-agentic-editing.md @@ -130,7 +130,7 @@ The skill applies techniques such as removing redundant instructions, consolidat
:desktop_computer: Terminal path -Review the Markdown body of your workflow and remove any sentences that repeat the same constraint or restate something already enforced by frontmatter (for example, "post only one comment" if `safe-outputs` already limits you to one comment). Recompile after each removal so you can verify nothing breaks. +Review the Markdown body of your workflow and remove any sentences that repeat the same constraint or restate something already enforced by [frontmatter](https://github.github.com/gh-aw/reference/frontmatter/) (for example, "post only one comment" if `safe-outputs` already limits you to one comment). Recompile after each removal so you can verify nothing breaks.