Skip to content

[aw] Smoke Copilot Network Isolation is missing required tool #9086

Description

@github-actions

Workflow Failure

Workflow: Smoke Copilot Network Isolation
Branch: copilot/refactor-sbx-manager-tests
Run: https://github.com/github/gh-aw-firewall/actions/runs/36337338142
Pull Request: #9078

Warning

Missing Tools Reported: The agent reported missing tools during execution.

Missing Tools:

  • bash/curl execution: bash tool denied executing curl commands ("Permission denied and could not request permission from user") for both egress checks, preventing verification of allow/deny network isolation behavior.

Alternatives:

Tool Alternative
bash/curl execution Re-run workflow with bash tool permissions enabled, or manually run the two curl commands inside the sandbox and report results.

Warning

Engine Failure: The copilot engine terminated unexpectedly.

Last agent output:

● add_comment (MCP: safeoutputs) · body: "@lpcox Unable to complete smoke test — the bash tool deni…
  └ {"result":"success","temporary_id":"aw_rdA0EAKV","comment":"#aw_rdA0EAKV...
[safeoutputs-cli] hasTerminalSafeOutput: terminal entry found in /home/runner/work/_temp/gh-aw/safeoutputs/outputs.jsonl: type=add_comment
Both required curl checks were blocked by the sandbox before any network activity occurred ("Permission denied and could not request permission from user"), so no genuine egress verdict could be obtained. I reported this via `missing_tool` and posted a comment noting the inconclusive FAIL result with the required `EGRESS_RESULT` line.
Changes   +0 -0
Duration  16s
Tokens    ↑ 203.9k • ↓ 908 • 162.6k (cached)
Run 'docker run --help' for more information
Run 'docker run --help' for more information
Run 'docker run --help' for more information

Action Required

Assign this issue to an agent to debug and fix the issue.

Debug with any coding agent

Use this prompt with any coding agent (GitHub Copilot, Claude, Gemini, etc.):

Debug the agentic workflow failure using https://raw.githubusercontent.com/github/gh-aw/main/debug.md

The failed workflow run is at https://github.com/github/gh-aw-firewall/actions/runs/36337338142
Manually invoke the agent

Debug this workflow failure using your favorite Agent CLI and the agentic-workflows prompt.

Tip

Stop reporting this workflow as a failure

To stop a workflow from creating failure issues, set report-failure-as-issue: false in its frontmatter:

safe-outputs:
  report-failure-as-issue: false

Generated from Smoke Copilot Network Isolation · copilot · 14.5 AIC · ◷

  • expires on Oct 4, 2026, 5:36 PM UTC

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions