Skip to content
Agents tracked: 258 Downloads (7d): 219M up 6.1% GitHub stars: 5.5M VS Code installs: 148M Releases (7d): 293 Agent status: 2 with issues Updated Oct 7, 2026
Case study GitHub

How GitHub expanded secret validity checks with Copilot coding agent

GitHub's Secret Protection team had engineers do the research, then gave Copilot coding agent the repetitive work of adding validators for more leaked-token types. Coverage grew quickly.

The problem

Secret Protection checks whether a leaked credential is still valid by testing it against a harmless API endpoint. Only 32 token types were covered, and adding less common types through the existing framework was slow.

How they did it

  1. Engineers researched which API endpoints could validate each new token type.
  2. A GitHub workflow turned that research into detailed issues that served as prompts for the agent.
  3. Copilot coding agent opened pull requests, and engineers reviewed, tested and asked for changes through PR comments.
  4. New validators first ran in 'darkship' mode to observe results safely.
  5. Copilot then made the configuration changes to fully release them.

Results

  • As reported by GitHub: the team went from validating '32 partner token types' to onboarding 'almost 90 new types in just a few weeks'.

As reported by the source (GitHub blog (engineering)); AgentGid did not measure these figures.

Takeaway. Keep the research and judgment with engineers, then give the agent many similar, well-specified issues to implement.
AgentGid's take

This suits a team with engineers who can research each item and write detailed issues, plus the review capacity to test every PR. The "almost 90 types in a few weeks" figure is GitHub's own report, and the cloud agent draws on monthly AI Credits (Pro includes 1,500 at $10/mo), so heavy batches of issues may use them up. Zed (Free + $10/mo) is an open-source option if you want to try a similar workflow with your own API keys.

The agent used here

Similar use cases

Guides