Copilot CLI dynamic workflows: let them call the Sume CLI
GitHub added dynamic workflows to Copilot CLI on Oct 1, 2026. Give it the Sume CLI skill pack and the hosted MCP endpoint, and keep paid calls behind a gate.

The GitHub changelog for October 1, 2026 lists "Dynamic workflows in Copilot CLI and the Copilot app" as a new feature. To let those workflows drive Sume, install the Sume CLI skill pack and point an MCP client at https://mcp.sume.com/mcp.
Install the skill pack
The Sume CLI bundles an agent skill. sume skills install writes it into .agents/skills or .claude/skills; use export to review the files first.
sume login
sume skills list
sume skills export sume # read before installing
sume skills installKeep paid work gated
The CLI docs tell agents to use read commands while planning and to require confirmation for writes. --confirm-submit covers non-paid writes; --confirm-paid covers Avatar and Avatar Video generation that can spend credits. Image, Video and Music generation are not CLI submit commands, so call the Developer API for those and use the CLI for job recovery.
sume doctor --agent --jsonsume catalog list --jsonsume jobs status <job_id> --agent --jsonsume jobs result <job_id> --agent --json
Add the MCP endpoint
Hosted MCP works with HTTP MCP clients: point the client at the URL and complete its OAuth login. Default OAuth is read-only (mcp:read); paid and write tools need mcp:write and an idempotency_key. I did not read Copilot's own MCP configuration steps, so follow GitHub's docs for where to add the server.
A safe loop
Let the workflow inspect the catalog, validate the payload, ask a person to confirm spend, submit one bounded job, then recover through status, events and result. Summaries should not paste secrets or signed URLs.
Sources
Related posts
More in Developers
- createSumeClient timeout is 10 minutes per request: tune it for polls
The Sume SDK client waits up to 10 minutes on each HTTP request, so one hung status poll can stall waitForJob for 10 minutes. Use a short-timeout client.
- CrewAI conversational flows: confirm cost before a Sume render
In a CrewAI chat flow, have the step call Sume with dry_run first and ask the user to confirm the cost.
- Cursor Security Review bot on a Sume webhook handler: what to find
Cursor added a Security Review bot on Sep 23. A webhook handler for Sume should pass seven checks: raw body, timestamp window, rotation, empty secret and more.
- Cursor self-hosted machines can't take Sume webhooks on a private URL
Sume rejects localhost, private-network and non-HTTPS webhook URLs. An agent on a self-hosted machine should poll status_url or use a public HTTPS receiver.
Written by Sume