Specifying and Maintaining Agentic Workflows: An Empirical Study of GitHub Agentic Workflows
Source
Jasem Khelifi, Issam Oukhay, Ali Ouni, Mohammed Sayagh, Mohamed Aymen Saied
Author
Jasem Khelifi, Issam Oukhay, Ali Ouni, Mohammed Sayagh, Mohamed Aymen Saied
Date
Key takeaways · AI-distilled
gh-aw workflow instructions are long specifications rather than short prompts: the median file runs 556.5 words, and 62.1% include code blocks.
The files keep changing: 78.2% of those observed for at least 120 days were still being updated in month four, though size-normalized churn drops after the first month.
Tasks, outputs, constraints and process instructions each appear in over 93% of labeled workflows, yet only 9.4% explicitly address prompt-injection defense.
The authors recommend tracking how workflows copied across repositories evolve and adding prompt-injection defenses, resource budgets and evidence-credibility checks where applicable.
Terms in this piece · Glossary
AI agent — An AI system that doesn't just answer once but works toward a goal in a loop — taking actions, reading the results, and deciding what to do next.
Why it matters
Anyone writing or maintaining GitHub Agentic Workflows gets a real-world look at how these specifications drift and what safeguards teams actually use.