Skip to content

Fix prompt-audit template marker false positive guidance - #470

Merged
strawgate merged 2 commits into
mainfrom
fix/prompt-audit-template-marker-63a5020e9e6c8128
Feb 28, 2026
Merged

strawgate merged 2 commits into
mainfrom
fix/prompt-audit-template-marker-63a5020e9e6c8128

Conversation

@github-actions

@github-actions github-actions Bot commented Feb 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Reword prompt-audit skip guidance in .github/workflows/trigger-prompt-audit.yml to remove a literal placeholder-like token (__GH_AW_*__) that can be interpreted as an unreplaced marker.
  • Keep the original reviewer guidance intent and the \{\\{\#if ...}} example.

Why

Issue #466 reports a prompt-audit failure caused by literal marker text being interpreted as an unreplaced placeholder. This wording change removes the problematic literal while preserving reviewer guidance.

Validation


What is this? | From workflow: Mention in Issue

Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.

Generated by Update PR Body for issue #470

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@strawgate

Copy link
Copy Markdown
Contributor

@copilot move the workflow to the right location in the repo

Copilot AI commented Feb 28, 2026

Copy link
Copy Markdown
Contributor

@strawgate I've opened a new pull request, #471, to work on those changes. Once the pull request is ready, I'll request review from you.

@coderabbitai

coderabbitai Bot commented Feb 28, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between c9f840c and 97062b0.

📒 Files selected for processing (1)
  • .github/workflows/trigger-prompt-audit.yml
✅ Files skipped from review due to trivial changes (1)
  • .github/workflows/trigger-prompt-audit.yml

📝 Walkthrough

Walkthrough

A workflow file's documentation comment is updated to remove a literal placeholder pattern example, replacing it with generic phrasing about placeholder patterns and template syntax. This prevents a validation script from incorrectly flagging the example as an unreplaced placeholder during prompt audits.

🚥 Pre-merge checks | ✅ 2
✅ Passed checks (2 passed)
Check name Status Explanation
Linked Issues check ✅ Passed PR removes literal __GH_AW_*__ token from documentation, directly addressing the false positive reported in #466 while preserving reviewer guidance.
Out of Scope Changes check ✅ Passed Changes are limited to rewording template marker guidance in the workflow file, directly scoped to fixing the prompt-audit false positive issue.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/prompt-audit-template-marker-63a5020e9e6c8128

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In `@github/workflows/trigger-prompt-audit.yml`:
- Around line 1-5: The workflow definition named "Trigger Prompt Audit" (file
trigger-prompt-audit.yml) is placed in the wrong directory so GitHub Actions
won't discover it; move this file into the .github/workflows/ directory (i.e.,
.github/workflows/trigger-prompt-audit.yml), commit the move, and verify the
schedule and workflow_dispatch trigger remain unchanged so the workflow is
picked up by GitHub Actions.

ℹ️ Review info

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 68cf2d1 and c9f840c.

📒 Files selected for processing (1)
  • github/workflows/trigger-prompt-audit.yml

Comment on lines +1 to +5
name: Trigger Prompt Audit
on:
schedule:
- cron: "0 11 * * 1" # Mondays at 11:00 UTC
workflow_dispatch:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

🧩 Analysis chain

🏁 Script executed:

# Find the workflow file mentioned in the review
fd -t f "trigger-prompt-audit.yml" .

Repository: elastic/ai-github-actions

Length of output: 112


🏁 Script executed:

# Check .github/workflows directory structure
ls -la .github/workflows/ 2>/dev/null | head -20

Repository: elastic/ai-github-actions

Length of output: 1501


🌐 Web query:

GitHub Actions workflow file location requirements .github/workflows directory discovery

💡 Result:

GitHub Actions only discovers workflow definitions that are committed to your repository under:

  • .github/workflows/ at the repository root (not inside your app subfolders). GitHub will not run workflow files stored elsewhere. [1]
  • Workflow files must be YAML with a .yml or .yaml extension. [1]
  • For reusable workflows (workflow_call), the called workflow must be a single file directly in .github/workflows/—subdirectories under .github/workflows/ are not supported. [2]

Discovery is branch-specific: GitHub evaluates the workflow files present in the ref/branch where the event occurs. [1]

Sources: [1] GitHub Docs – Workflow syntax for GitHub Actions, [2] GitHub Docs – Reusing workflow configurations


Move file to .github/workflows/ directory.

File is at github/workflows/trigger-prompt-audit.yml but GitHub Actions only discovers workflows in .github/workflows/ (with the dot prefix). Without relocation, this workflow will not be triggered.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@github/workflows/trigger-prompt-audit.yml` around lines 1 - 5, The workflow
definition named "Trigger Prompt Audit" (file trigger-prompt-audit.yml) is
placed in the wrong directory so GitHub Actions won't discover it; move this
file into the .github/workflows/ directory (i.e.,
.github/workflows/trigger-prompt-audit.yml), commit the move, and verify the
schedule and workflow_dispatch trigger remain unchanged so the workflow is
picked up by GitHub Actions.

…rrect location (#471)

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: strawgate <6384545+strawgate@users.noreply.github.com>
@strawgate
strawgate merged commit d604863 into main Feb 28, 2026
13 of 14 checks passed
@strawgate
strawgate deleted the fix/prompt-audit-template-marker-63a5020e9e6c8128 branch February 28, 2026 06:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Prompt audit error

2 participants