Jose Palafox works on the adoption of developer tools, connecting application security, software-delivery automation, and AI-assisted development. His writing explains how teams can bring specialized security checks into everyday engineering workflows; his more recent work on GitHub Copilot addresses how organizations move agents from individual experiments into shared tools and automated pipelines. At AI Engineer World’s Fair 2026, he spoke as a Field Copilot Specialist at GitHub.
From enterprise technology to developer security
Palafox’s earlier career included work at Intel and Puppet Labs. By 2023, his application-security work at GitHub involved helping large enterprises and technology companies on the West Coast improve their security posture.
His authored writing traces the development of that focus. In 2020 and 2021, he wrote about extending GitHub code scanning with third-party tools, including infrastructure and container scanners and support for additional programming languages. During 2022, his writing expanded into automated assessments of open-source security practices, signed build provenance, and more complete dependency information. These address different weaknesses in software delivery: insecure source code, dependencies that escape detection, and uncertainty about how a distributed package was produced.
Making security part of the workflow
Palafox’s technical guidance explains the integrations that make security findings actionable for developers and security teams:
Security feedback in pull requests: With Daniel Shanahan, Palafox co-authored guidance for application security orchestration using GitHub Actions and code scanning. Their approach lets teams run specialized scanners while returning findings through a familiar review workflow. Container scanners and source-code analyzers inspect different things; bringing their results into pull requests gives developers a common place to act on them.
Verifiable build provenance: His 2022 guide to GitHub Actions and Sigstore addressed the gap between trusting a source repository and trusting a downloaded package. Signing and provenance metadata connect an artifact to its source commit and the workflow that produced it, making its origin inspectable. He explained those supply-chain security concepts through a practical Go-module publishing workflow.
Dependency visibility beyond manifests: In writing co-authored with Brittany O’Shea, Palafox explained how build tools and scanners could submit dependency information that static manifest inspection missed. Container and mobile-app analysis supplied additional components to GitHub’s dependency graph, giving vulnerability detection a more complete account of what software contained.
Security findings with business context: As one of five co-authors of guidance on connecting GitHub Advanced Security to SIEM platforms, Palafox helped explain how alerts, asset information, and audit logs support investigations. Together, those inputs help security teams ask whether an exposed token was subsequently used or which business units depend on vulnerable software. A finding becomes more useful when investigators can connect it to the systems and people it affects.
His OpenSSF Scorecards guidance applied the same emphasis on workflow integration to open-source maintenance: run checks automatically as repositories change and surface risky-practice alerts through GitHub’s code-scanning interface.
From Copilot adoption to shared agents
Palafox’s later work extends that adoption focus to AI-assisted development. In GitHub’s event on measuring Copilot’s impact, he was identified as Strategic AI GTM Lead for the Americas. That work concerns how engineering leaders assess changes in developer productivity and connect Copilot use to delivery and business results.
His World’s Fair 2026 talk on scaling custom agents addresses another organizational obstacle: an agent built on one developer’s laptop may never become useful to the rest of the team. Palafox describes sharing custom agents through an organization-wide marketplace, running them across repositories, and moving them into CI with GitHub Agentic Workflows. Headless Copilot CLI runs in GitHub Actions allow agents to operate unattended, including in response to slash commands in issues.
The examples extend beyond generating code. He describes a repository with about 200 agents handling different parts of a pipeline, including agents that investigate their own cost overruns. These examples develop a recurring concern in his work: how to make a developer capability available across an organization, fit it into existing processes, and understand its operational effects.
Jose Palafox follows custom agents from local instructions to shared organizational tools and unattended CI workflows, where human checkpoints and execution telemetry make their work easier to control and improve.
Custom agents pair task instructions with a model choice. Exploration and second-pass review can use different configurations instead of assigning every job to the largest model.
Generated agent definitions still contain decisions worth editing: the changelog example needs source selection that excludes roadmap items from a summary of changes.
Sharing definitions and executing across repositories are separate problems. Marketplaces distribute agents; Orchestrate starts sub-agents in the repositories where their work belongs.
Agentic Workflows can combine scheduled discovery, human issue selection, automated planning and implementation, and a final human acceptance decision.
Instrumented pipeline runs make cost and tool failures inspectable, enabling investigations of expensive runs and comparisons of instructions or models.