Security review for the pull requests Copilot cloud agent opens.

Copilot cloud agent opens the pull request, and GitHub does not let the person who asked for it approve it. Aevral, the AI security reviewer for GitHub pull requests, reviews the diff within your plan's allowance and gives the reviewer a copy-paste fix prompt with each finding.

In plain words

Picture assigning a ticket to a new colleague who works on their own machine and comes back with a pull request for you to review. That is the shape of GitHub Copilot cloud agent: you hand it an issue or a prompt, it works in its own environment on GitHub, and what comes back is a branch and a pull request for a human to review. This page is about that pull request, and who reads it for security before it merges.

How Copilot cloud agent gets to a pull request

From GitHub's own documentation. Each line is in our words, with the quote it rests on underneath.

  • GitHub renamed the product: what used to be called Copilot coding agent is now Copilot cloud agent.

    “Copilot cloud agent (formerly known as Copilot coding agent) is no longer limited to pull-request workflows”

    GitHub changelog, research, plan, and code with Copilot cloud agent, read

  • You give it a task, it researches the repository, plans, and changes code on a branch; the pull request comes when you ask for it.

    “Copilot can research a repository, create an implementation plan, and make code changes on a branch. You can review the diff, iterate, and create a pull request when you're ready.”

    GitHub Docs, about GitHub Copilot cloud agent, read

  • It works in its own GitHub Actions environment on tasks assigned through a GitHub issue or a Copilot Chat prompt.

    “Copilot cloud agent works autonomously in a GitHub Actions-powered environment to complete development tasks assigned through GitHub issues or GitHub Copilot Chat prompts.”

    GitHub Docs, about GitHub Copilot cloud agent (versus agent mode), read

  • One task, one branch, one pull request.

    “Copilot can only work on one branch at a time and can open exactly one pull request to address each task it is assigned.”

    GitHub Docs, about GitHub Copilot cloud agent (limitations), read

  • You can steer it on an existing pull request by mentioning @copilot in a comment.

    “Mention @copilot in a comment on an existing pull request to ask it to make changes.”

    GitHub Docs, about GitHub Copilot cloud agent (entry points), read

Cloud agent, agent mode and code review are three different things

  • Agent mode in your editor works on your machine. It is not the cloud agent that opens pull requests on GitHub.

    “In contrast, agent mode in your IDE makes autonomous edits directly in your local development environment.”

    GitHub Docs, cloud agent versus agent mode, read

  • Copilot code review is the reviewing side: it reviews pull requests, identifies issues and suggests fixes. This page is about the pull requests the cloud agent writes, not about that review.

    “Copilot reviews your pull requests, identifies issues, and suggests fixes you can apply in a couple of clicks.”

    GitHub Docs, about GitHub Copilot code review, read

Why it matters: the person who asked cannot approve

GitHub builds a separation of duties into the cloud agent: the person who asked for the pull request is not allowed to approve it. If the pull request is approved, the approver is someone other than the person who asked for it. In our reading, on a small team that second reviewer is often one person with a queue of other pull requests the same day, and a security question needs the diff in front of them, not the task description.

GitHub also has the agent check its own code for security issues and ask Copilot code review for a second opinion before the pull request completes. Those checks run inside the same vendor's workflow. Aevral is a reviewer from outside that loop, on the pull request itself, reading for access control and business logic among its classes: whether the new endpoint checks who is asking, and whether a tenant can reach another tenant's rows. It is one more reading for the approver, not a replacement for GitHub's checks or for the human review.

What the vendor's docs say

Where Aevral fits: a copy-paste handoff

Aevral reviews a cloud agent pull request like any other pull request on a repository where the Aevral GitHub App is installed: when it is opened or reopened and when new commits are pushed, draft or not, within your plan's review allowance. An agent having opened it changes nothing about the review. A finding is an inline comment on the added line, next to an advisory Check that never blocks the pull request.

Each finding carries a Fix with your agent prompt. To hand it to Copilot, a human copies the prompt, reads it, and pastes it into a new comment on the same pull request that mentions @copilot. The cloud agent can then push to that branch; new commits start a new Aevral review within your allowance, and GitHub's rule that a human reviews and merges the agent's pull request still applies. Aevral posts its own comment; it never writes the @copilot mention for you.

  • The @copilot mention on an existing pull request is GitHub's documented way to ask the cloud agent for changes.

    “Mention @copilot in a comment on an existing pull request to ask it to make changes.”

    GitHub Docs, about GitHub Copilot cloud agent (entry points), read

  • Triggered that way, the cloud agent can write to that pull request's branch.

    “When the agent is triggered by mentioning @copilot on an existing pull request, Copilot has write access to the pull request's branch.”

    GitHub Docs, risks and mitigations (branch limits), read

How the prompt is built and how to use it well: handing a finding to your coding agent.

Setup, the two human clicks

Two clicks, both yours: install the GitHub App on the repositories the agent works in, then log in to the console with GitHub. An agent cannot install the App or finish the login for you; it can read this page and the agent-setup prompt instead.

What this page does not claim

  • Aevral is not affiliated with, endorsed by, or a partner of the company behind GitHub Copilot cloud agent. There is no integration between the two products: Aevral does not call GitHub Copilot cloud agent, and GitHub Copilot cloud agent does not call Aevral.
  • Aevral never commits, pushes, applies or merges a change. The Fix with your agent prompt is text a human copies; what the agent does with it goes through your repository's own review and merge rules.
  • PR review looks for a list of classes on the diff and leaves at most two findings per review. A finding is a lead with evidence, not a verdict, and a quiet review is not proof that the code is safe.
  • The boxed statements about GitHub Copilot cloud agent come from the vendor's own documentation, each with the quote it rests on and the date it was read. The paragraphs around them are Aevral's reading of what those facts mean for a security review. Vendor products change; the vendor's docs win over this page.
  • This page makes no claim about what GitHub's own checks find or miss. It says Aevral is a separate reading on the same pull request.
  • Aevral does not assign issues to Copilot, start a cloud agent session, or read the session log.

Sources

Read next

Log inRead the machine facts: /llms.txt