github

From one-off prompts to workflows: How to use custom agents in GitHub Copilot CLI (opens in new tab)

Custom agents in GitHub Copilot CLI turn repeated terminal tasks into reusable, consistent workflows. Defined as Markdown profiles in a repository, they encode team-specific expertise, tools, standards, and safety rules instead of relying on one-off prompts. This makes workflows easier to review, version, share, and reuse across the CLI, IDE, and GitHub.

What Custom Agents Are

  • A custom agent is a specialized Copilot agent configured through a Markdown file.
  • Its profile specifies:
    • Role and area of expertise
    • Available tools
    • Required standards and procedures
    • Guardrails and expected output formats
  • Teams can tailor agents to requirements such as:
    • WCAG accessibility standards
    • Formatting and testing conventions
    • Security and privacy policies
    • Review and ownership requirements
  • Because profiles live in the repository, they can be versioned, reviewed, and shared like code.

Creating and Using Agents in Copilot CLI

  • Invoke Copilot CLI from the terminal and use the /agent command to select an agent.
  • Store the profile in the repository’s .github/agents directory.
  • Agent files use YAML frontmatter and typically end in .agent.md, such as accessibility.agent.md.
  • The profile defines the agent’s name, description, model, tools, instructions, scope, and guardrails.
  • Copilot CLI is especially suitable for these agents because it can execute scripts, call APIs, inspect repositories, and work directly with command-line tooling.

Automating Repeated Workflows

Custom agents are most useful for recurring tasks that span the terminal, IDE, and pull requests.

  • A security audit agent can:
    • Run standard checks across repositories
    • Group findings by Critical, High, Medium, and Low severity
    • Produce a pull-request-ready checklist with owners and next steps
  • It can use tools such as gitleaks, trivy, semgrep, gh, git, and jq.
  • Agents should prefer existing repository configuration files, including .semgrep.yml, .trivyignore, and .gitleaks.toml.
  • Missing security tools should be reported as coverage gaps rather than replaced with invented results.
  • Instructions can require secrets to be redacted, inclusive terminology, and consistent date formats.
  • Ownership mappings can assign findings to teams based on affected paths, using CODEOWNERS when available or defined defaults otherwise.

Custom agents provide a practical way to capture team expertise once and apply it consistently. Start by converting a repetitive, execution-heavy task into a narrowly scoped .github/agents profile with explicit tools, outputs, and safety rules.