Skip to content

Record blocked operational-value design for setup security audit - #58543

Closed
mnkiefer with Copilot wants to merge 2 commits into
mainfrom
copilot/operational-value-studypaper-v1
Closed

Record blocked operational-value design for setup security audit#58543
mnkiefer with Copilot wants to merge 2 commits into
mainfrom
copilot/operational-value-studypaper-v1

Conversation

Copilot AI commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

The daily setup-action security audit requires a deterministic direct operational-value metric with replayable historical assignment. The workflow’s free-form finding reports do not provide a stable finding-to-remediation binding.

  • Study record

    • Adds the required operational-value study JSON.
    • Records a blocked outcome and the evidence limitation.
    • Documents rejected activity/output proxies, assignment ambiguity, and unavailable comparable baseline evidence.
  • Scope

    • Does not add an evaluator or alter workflow behavior, avoiding a non-defensible remediation metric.
Original prompt

[operational-value-study:paper-v1] daily-action-setup-security-audit

Use the repository's .github/skills/operational-value-designer/SKILL.md to design
and verify one deterministic operational-value grader for github/gh-aw
workflow daily-action-setup-security-audit. This is a fresh research run; do not copy another
workflow's metric or contract.

Requirements:

  • Recover adoption-time intent and pre-adoption evidence independently.
  • Use exactly one direct primary attainment metric in [0,1]. Keep diagnostics separate.
  • Treat unavailable evidence as null, never zero. Make maturation explicit and stable.
  • Support historical assignment reconstruction when case and event are null.
  • If no direct operational metric is defensible, create only the study record below with designOutcome "blocked" and explain why. Never substitute activity, output volume, traces, or agent judgment.
  • Change only .github/workflows/daily-action-setup-security-audit.md, its generated lock file,
    .github/graders/daily-action-setup-security-audit-operational-value.sh, and .github/graders/daily-action-setup-security-audit-operational-value-study.json.
  • Do not add generated historical reports to the pull request.

Write .github/graders/daily-action-setup-security-audit-operational-value-study.json as JSON with this exact top-level shape:
{
"schemaVersion": 1,
"repository": "github/gh-aw",
"workflowId": "daily-action-setup-security-audit",
"recordedAt": "ISO-8601 timestamp",
"recorder": "copilot-coding-agent",
"designOutcome": "accepted|rejected|blocked",
"rejectionReason": null,
"classification": {
"domain": "short research domain",
"subdomain": null,
"taskArchetype": "short label",
"interventionType": "short label",
"outcomeType": "short label",
"evidenceDirectness": "direct|proxy|activity",
"evidenceLocality": "same-repository|cross-repository|external",
"measurementLevel": "nominal|ordinal|interval|ratio",
"metricForm": "binary|proportion|rate|distance-to-target|index",
"assignmentDeterminism": "deterministic|bounded-ambiguity|ambiguous",
"intentExplicitness": "explicit|implicit|mixed",
"markdownSpecificity": "exact|bounded|open-ended",
"outcomeObservability": "immediate|delayed",
"causalClaim": "observational|comparative-not-causal"
},
"decisions": [{
"type": "intent|opportunity|assignment|evidence|maturation|metric|baseline|diagnostic",
"selected": "observable selected design",
"alternatives": ["observable rejected alternative"],
"rationale": "concise evidence-backed rationale, not hidden reasoning",
"evidenceReferences": ["commit, issue, PR, or file reference"],
"changedDuringReview": false
}],
"uncertainties": [{
"type": "measurement|assignment|evidence-availability|temporal|baseline|domain-fit|causal-attribution",
"level": "low|medium|high|unknown",
"description": "specific limitation",
"mitigation": null,
"evidenceReferences": []
}]
}

For blocked/rejected designs, rejectionReason must be a non-empty string. Record
observable contract choices and alternatives only; do not record chain-of-thought.

Validation for accepted designs:

  1. .github/skills/operational-value-designer/scripts/verify-operational-value-evaluator.sh .github/graders/daily-action-setup-security-audit-operational-value.sh
  2. gh aw compile .github/workflows/daily-action-setup-security-audit.md

Keep the pull request limited to this workflow. The local study runner will replay
history and archive reports after this task completes.

Co-authored-by: mnkiefer <8320933+mnkiefer@users.noreply.github.com>
Copilot AI changed the title [WIP] Design operational-value grader for security audit workflow Record blocked operational-value design for setup security audit Sep 4, 2026
Copilot AI requested a review from mnkiefer September 4, 2026 15:18
@mnkiefer mnkiefer closed this Sep 4, 2026
@mnkiefer
mnkiefer deleted the copilot/operational-value-studypaper-v1 branch September 4, 2026 15:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants