Agent Suggestions
Date: 2026-04-05
Expires: 24h
1. gh-aw-adoption-doctor
Trigger: weekly schedule + workflow_dispatch (optionally slash command /aw audit-workflows for targeted checks)
Purpose: Detect and remediate downstream workflow integration drift for elastic/ai-github-actions/.github/workflows/gh-aw-*.lock.yml usage (permissions, required secrets, and trigger wiring), then open one concise remediation report with concrete patch guidance (or PR draft) per repository.
Proposed safe outputs: create-issue (summary + actionable checklist), create-pull-request (optional mechanical fixes), add-comment (manual run result/noop).
Current pain points and evidence:
Downstream repos are repeatedly making manual fixes to AW workflow wiring.
In this repository, AW is currently only an ingress entrypoint (.github/workflows/oblt-aw.yml) and does not perform cross-repo adoption audits.
Why not covered already:
Existing oblt-aw.yml only forwards local events for this repository; it does not inventory/validate downstream consumer repos for configuration drift.
Open local tracking items (#856, #528, #533) do not provide a recurring downstream adoption audit/remediation loop.
Expected benefits:
Reduces recurring manual AW migration/fix PRs across downstream repos.
Improves first-pass workflow correctness (permissions/secrets/trigger compatibility).
Shortens time from AW changes to safe downstream rollout and reduces broken-workflow noise.
Trade-offs and rollout considerations:
Requires a curated allowlist of downstream repos and minimal false-positive tuning.
Should start as report-only (issue/comment) for 1-2 weeks before enabling optional PR generation.
Needs clear guardrails for edit scope (workflow files only) and duplicate suppression per repo.
Duplicate Checks
Downstream Signals
Suggested Next Steps
Note
🔒 Integrity filter blocked 110 items
The following items were blocked because they don't meet the GitHub integrity level.
#526 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
#464 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
#512 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
#471 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
#262 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
#527 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
#230 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
#144 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
#229 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
#155 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
#704 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
#1 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
#49648 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
#3 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
#49589 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
#17935 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
... and 94 more items
To allow these resources, lower min-integrity in your GitHub frontmatter:
tools :
github :
min-integrity : approved # merged | approved | unapproved | none
What is this? | From workflow: Observability Agentic Workflow Entrypoint
Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.
Agent Suggestions
Date: 2026-04-05
Expires: 24h
1.
gh-aw-adoption-doctorTrigger: weekly
schedule+workflow_dispatch(optionally slash command/aw audit-workflowsfor targeted checks)Purpose: Detect and remediate downstream workflow integration drift for
elastic/ai-github-actions/.github/workflows/gh-aw-*.lock.ymlusage (permissions, required secrets, and trigger wiring), then open one concise remediation report with concrete patch guidance (or PR draft) per repository.Proposed safe outputs:
create-issue(summary + actionable checklist),create-pull-request(optional mechanical fixes),add-comment(manual run result/noop).Current pain points and evidence:
elastic/oblt-awPR Add oblt-cli/cluster-credentials action #10 fixed missing required permission for a nested AW workflow (actions: read): fix: addactions: readpermission to dependency-review workflow oblt-aw#10elastic/beatsPR #49648 switched fromgh-aw-stale-issues.lock.ymltogh-aw-stale-issues-investigator.lock.yml: Switch stale-issues to stale-issues-investigator beats#49648elastic/integrationsPR #17935 changed AW trigger model (status->check_run) and added AW sweeper workflows: Update PR Buildkite Detective and add defect detection workflows integrations#17935.github/workflows/oblt-aw.yml) and does not perform cross-repo adoption audits.Why not covered already:
oblt-aw.ymlonly forwards local events for this repository; it does not inventory/validate downstream consumer repos for configuration drift.#856,#528,#533) do not provide a recurring downstream adoption audit/remediation loop.Expected benefits:
Trade-offs and rollout considerations:
Duplicate Checks
repo:elastic/oblt-actions is:issue in:title "[oblt-aw][agent-suggestions]"(no matching reports)Downstream Signals
elastic/oblt-aw: fix: addactions: readpermission to dependency-review workflow oblt-aw#10elastic/beats: Switch stale-issues to stale-issues-investigator beats#49648elastic/integrations: Update PR Buildkite Detective and add defect detection workflows integrations#17935Suggested Next Steps
gh-aw-adoption-doctorin report-only mode on 3 known downstream repos.Note
🔒 Integrity filter blocked 110 items
The following items were blocked because they don't meet the GitHub integrity level.
search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".To allow these resources, lower
min-integrityin your GitHub frontmatter:What is this? | From workflow: Observability Agentic Workflow Entrypoint
Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.