Developers write detailed, evolving instructions for agentic workflows but often skip safety measures

An empirical study of 1,248 GitHub Agentic Workflow files reveals extensive natural-language instructions, sustained maintenance, and sparse prompt-injection defenses

Academic
Jasem Khelifi · Issam Oukhay · Ali Ouni · Mohammed Sayagh · Mohamed Aymen Saied

École de technologie supérieure (ÉTS) · Université Laval

Research Digest··2 min read
The authors analyzed 1,248 Markdown-based GitHub Agentic Workflow files across 276 repositories.

The authors compiled a dataset of 1,248 GitHub Agentic Workflow Markdown files from 276 public repositories.

Why this paper

From École de technologie supérieure (ÉTS) and Université Laval · Part of Agent Security & Attacks, now 45 papers

In one line

GitHub agentic workflows are long, evolving operational specifications, yet explicit prompt-injection defenses appear in only 9.4% of labeled workflows.

What we could check

  • ·No code link found
  • ·No weights link found
  • ·No dataset link found
  • ·No compute details found
  • ·No stated limitations found
  • ✓Reports numbers on named benchmarks

Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.

§
newspaper

Research Digest

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.