Skip to content
Back to skills

Copilot Cli Agent

ASecurity

Dispatches bounded tasks and persona-based analysis through GitHub Copilot CLI. Use for authorized task delegation, security audits, code reviews, or fresh-context analysis.

  • 7 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 2, 2026
ai-agentspythongobashgitbackendsecurityperformance

Works with

  • cli

Security analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned October 3, 2026

npx -y skills add richfrem/agent-plugins-skills --skill copilot-cli-agent --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Copilot Cli Agent?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Copilot Cli Agent
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/richfrem-copilot-cli-agent-agent-plugins-skills/badge)](https://www.skillsdirectory.com/skills/richfrem-copilot-cli-agent-agent-plugins-skills)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: copilot-cli-agent
plugin: cli-agents
description: Dispatches bounded tasks and persona-based analysis through GitHub Copilot CLI. Use for authorized task delegation, security audits, code reviews, or fresh-context analysis.
allowed-tools: Bash, Read, Write
---

# Copilot CLI Agent

Dispatch the authorized task using the bundled router.

## Contents

- [Constraints](#constraints)
- [Quick start](#quick-start)
- [Workflow](#workflow)
- [Verification](#verification)
- [Persona Registry](#-persona-registry-agents)
- [Dispatch details](references/copilot-cli-dispatch.md)

## Constraints

Reuse the user's runtime/model/effort choice; do not start an unrequested review.
Use one backend; halt on failure without silent fallback. Analysis uses `--isolated`;
it suppresses dangerous flags and adds instructions, but is not an OS sandbox.
Non-isolated dispatch requires authorization and external containment where needed.

## Quick start

Run from this skill root; input and output paths are supplied by the caller:

```bash
python3 scripts/run_agent.py agents/security-auditor.md <input> <output> "Review supplied source." --cli copilot --isolated --require-input
```

## Workflow

1. Read [dispatch details](references/copilot-cli-dispatch.md) before selecting flags or models.
2. Read [execution rules](references/execution-contract.md) and [backend capabilities](references/backend-capabilities.md); user instructions govern authorization.
3. Use the selected model or catalog tier; inspect the resolved executable/version.
4. Dispatch once, then check exit status, nonempty output and requested acceptance criteria.

[Profile contract](references/capability-profile-contract.md) applies when a caller supplies a profile.

## Verification

Record backend, executable/version, model, effort, scope and result. Empty or failed
output is not a completed review. Log failures in [Map Debt](references/map-debt.md).
For gated reviews, wrap supplied input in `---SOURCE---` blocks and record results through the control-plane `record-critic-review` command using canonical `PASS`, `REVISE`, or `REJECT`; only PASS approves.

## 🎭 Persona Registry (`agents/`)

These personas are mirrored across CLI agent dispatchers to ensure consistent analytical behavior across the ecosystem.

| Persona | Use For |
|:---|:---|
| `security-auditor.md` | Red team, vulnerability scanning, threat modeling |
| `refactor-expert.md` | Optimizing code for readability, performance, and DRY |
| `architect-review.md` | Assessing system design, modularity, and complexity |

### 🧩 Force Agent Behavior

Always add these instructions to your dispatch prompt to prevent the sub-agent from attempting to use external tools:
> "You are operating as an isolated sub-agent. Do NOT use tools. Do NOT access filesystem. Only use the provided input."

### 🛠️ Orchestration Pattern: `run_agent.py` (Cross-Platform)

For reusable sub-agent execution, use the provided Python orchestrator which handles temp file assembly and prompt concatenation reliably across Windows, macOS, and Linux:

```bash
python ./scripts/run_agent.py <PERSONA_FILE> <INPUT_FILE> <OUTPUT_FILE> "<INSTRUCTION>"
```

Files in this skill

  • SKILL.md15 KB
  • acceptance-criteria.md866 B
  • evals/.lock.hashes585 B
  • evals/evals.json1.2 KB
  • evals/experiments/2026-03-13_182514/results.json35.3 KB
  • evals/experiments/2026-03-13_182514/results.tsv10.5 KB
  • evals/experiments/2026-03-13_182514/timing.json1.8 KB
  • evals/experiments/2026-03-13_183006/results.json3 KB
  • evals/experiments/2026-03-13_183006/results.tsv327 B
  • evals/experiments/2026-03-13_183006/timing.json273 B
  • evals/experiments/2026-03-13_183028/results.json5.6 KB
  • evals/experiments/2026-03-13_183028/results.tsv1.5 KB
  • evals/experiments/2026-03-13_183028/timing.json453 B
  • evals/experiments/2026-03-13_183345/logs/improve_iter_1.json9.6 KB
  • evals/experiments/2026-03-13_183345/results.json5.3 KB
  • evals/experiments/2026-03-13_183345/results.tsv778 B
  • evals/experiments/2026-03-13_183345/timing.json453 B
  • evals/results.tsv293 B
  • fallback-tree.md1.1 KB
  • output.md329 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…