From b85b36c712a68a3215c737ad1442b0d1474b593e Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Wed, 29 Jul 2026 22:05:31 +0000 Subject: [PATCH 1/2] Initial plan From c51703886884019ba9fbfb4b37230bc66c01bfc1 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Wed, 29 Jul 2026 22:21:19 +0000 Subject: [PATCH 2/2] fix: pre-read sampled files in delight pre-agent-steps to eliminate tool denials The Delight workflow was hitting the tool-denial guardrail (3/3) because the agent used the built-in view/read tool to open sampled files via absolute paths, which is not in the Copilot SDK allowlist. Fix (DataOps pattern): - Extend pre-agent-steps to pre-read sampled file contents into *-content.txt files so the agent can access them via the already- allowed `cat /tmp/gh-aw/agent/*` bash command. - Update prompt references to use the pre-loaded content files. - Remove the xargs bash allowlist entries (no longer needed). - Recompile delight.lock.yml. Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> --- .github/workflows/delight.lock.yml | 9 +++------ .github/workflows/delight.md | 19 ++++++++++--------- 2 files changed, 13 insertions(+), 15 deletions(-) diff --git a/.github/workflows/delight.lock.yml b/.github/workflows/delight.lock.yml index 9933c59f814..50f2cb17088 100644 --- a/.github/workflows/delight.lock.yml +++ b/.github/workflows/delight.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"0a30c4fc5b5ea614b1ea2eef1a0c450ae4e53547ecd872d483f4ad79282d9473","body_hash":"ea61e886d6214feee1995e631fa9f83b930fa8b04bd096cf7159ad45add40b63","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.75","copilot-sdk":"1.0.8"}} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"f9ac0fc8e5de4d502fcf82b15202f8679508dea468e180cc7841f53b9c1e2f20","body_hash":"a86b5081894f98814fb7867797975569f7dcaafe24c085e71c66d99ab0b5484c","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.75","copilot-sdk":"1.0.8"}} # gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.42","digest":"sha256:26a8af4e5566485b02f52af59ee03803ae798271a9619d4767e94d07806deb9b","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.42@sha256:26a8af4e5566485b02f52af59ee03803ae798271a9619d4767e94d07806deb9b"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.42","digest":"sha256:944f2686c9ab9bec338fd14b662461662f77cd12cd0ea8a3e7cb8c0987cd1607","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.42@sha256:944f2686c9ab9bec338fd14b662461662f77cd12cd0ea8a3e7cb8c0987cd1607"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.42","digest":"sha256:da006bf96d2d246dd269d57b233c1798d2ad63d6cd64ca02f7bf71045028781f","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.42@sha256:da006bf96d2d246dd269d57b233c1798d2ad63d6cd64ca02f7bf71045028781f"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.42","digest":"sha256:42dfeb649c680a8558cd5423dbc530b653a69413e35ffbe5e71da5d48c94bdf0","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.42@sha256:42dfeb649c680a8558cd5423dbc530b653a69413e35ffbe5e71da5d48c94bdf0"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.6","digest":"sha256:fecabec51bbc41f2ad61076d6bcd9a36ef23b142e672a444e054d37fc29de93c","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.6@sha256:fecabec51bbc41f2ad61076d6bcd9a36ef23b142e672a444e054d37fc29de93c"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748","pinned_image":"ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748"},{"image":"ghcr.io/github/github-mcp-server:v1.7.0","digest":"sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308","pinned_image":"ghcr.io/github/github-mcp-server:v1.7.0@sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308"}]} # This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # @@ -564,7 +564,7 @@ jobs: GH_AW_SKILL_DIR: ".github/skills" run: bash "${RUNNER_TEMP}/gh-aw/actions/restore_inline_skills.sh" - name: Sample files and load memory - run: "mkdir -p /tmp/gh-aw/agent\n# Sample documentation files (eliminates agent exploratory find turns)\nfind docs/src/content/docs \\( -name '*.md' -o -name '*.mdx' \\) | shuf -n 2 > /tmp/gh-aw/agent/doc-samples.txt\n# Sample workflows with messages (pre-compute instead of agent grep)\ngrep -rl \"messages:\" .github/workflows/ --include=\"*.md\" | shuf -n 2 > /tmp/gh-aw/agent/workflow-samples.txt\n# Sample validation files\nfind pkg -name '*validation*.go' | shuf -n 1 > /tmp/gh-aw/agent/validation-sample.txt || echo \"No validation files found\" > /tmp/gh-aw/agent/validation-sample.txt\n# Load historical memory (eliminates agent memory-read turns)\ncat memory/delight/previous-findings.json 2>/dev/null > /tmp/gh-aw/agent/previous-findings.json || echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json\ncat memory/delight/improvement-themes.json 2>/dev/null > /tmp/gh-aw/agent/improvement-themes.json || echo \"[]\" > /tmp/gh-aw/agent/improvement-themes.json" + run: "mkdir -p /tmp/gh-aw/agent\n# Sample documentation files (eliminates agent exploratory find turns)\nfind docs/src/content/docs \\( -name '*.md' -o -name '*.mdx' \\) | shuf -n 2 > /tmp/gh-aw/agent/doc-samples.txt\n# Sample workflows with messages (pre-compute instead of agent grep)\ngrep -rl \"messages:\" .github/workflows/ --include=\"*.md\" | shuf -n 2 > /tmp/gh-aw/agent/workflow-samples.txt\n# Sample validation files\nfind pkg -name '*validation*.go' | shuf -n 1 > /tmp/gh-aw/agent/validation-sample.txt || echo \"No validation files found\" > /tmp/gh-aw/agent/validation-sample.txt\n# Load historical memory (eliminates agent memory-read turns)\ncat memory/delight/previous-findings.json 2>/dev/null > /tmp/gh-aw/agent/previous-findings.json || echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json\ncat memory/delight/improvement-themes.json 2>/dev/null > /tmp/gh-aw/agent/improvement-themes.json || echo \"[]\" > /tmp/gh-aw/agent/improvement-themes.json\n# Pre-read file contents (eliminates view/read tool denials)\nxargs -a /tmp/gh-aw/agent/doc-samples.txt cat > /tmp/gh-aw/agent/doc-samples-content.txt 2>/dev/null || echo \"(no doc samples found)\" > /tmp/gh-aw/agent/doc-samples-content.txt\nxargs -a /tmp/gh-aw/agent/workflow-samples.txt cat > /tmp/gh-aw/agent/workflow-samples-content.txt 2>/dev/null || echo \"(no workflow samples found)\" > /tmp/gh-aw/agent/workflow-samples-content.txt\nxargs -a /tmp/gh-aw/agent/validation-sample.txt cat > /tmp/gh-aw/agent/validation-sample-content.txt 2>/dev/null || echo \"(no validation sample found)\" > /tmp/gh-aw/agent/validation-sample-content.txt" - name: Download container images run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.27.42@sha256:26a8af4e5566485b02f52af59ee03803ae798271a9619d4767e94d07806deb9b ghcr.io/github/gh-aw-firewall/api-proxy:0.27.42@sha256:944f2686c9ab9bec338fd14b662461662f77cd12cd0ea8a3e7cb8c0987cd1607 ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.42@sha256:da006bf96d2d246dd269d57b233c1798d2ad63d6cd64ca02f7bf71045028781f ghcr.io/github/gh-aw-firewall/squid:0.27.42@sha256:42dfeb649c680a8558cd5423dbc530b653a69413e35ffbe5e71da5d48c94bdf0 ghcr.io/github/gh-aw-mcpg:v0.4.6@sha256:fecabec51bbc41f2ad61076d6bcd9a36ef23b142e672a444e054d37fc29de93c ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748 ghcr.io/github/github-mcp-server:v1.7.0@sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308 @@ -886,9 +886,6 @@ jobs: # --allow-tool shell(tail) # --allow-tool shell(uniq) # --allow-tool shell(wc) - # --allow-tool shell(xargs -a /tmp/gh-aw/agent/doc-samples.txt cat) - # --allow-tool shell(xargs -a /tmp/gh-aw/agent/validation-sample.txt cat) - # --allow-tool shell(xargs -a /tmp/gh-aw/agent/workflow-samples.txt cat) # --allow-tool shell(yq) # --allow-tool write timeout-minutes: 30 @@ -934,7 +931,7 @@ jobs: COPILOT_MODEL: ${{ vars.GH_AW_MODEL_AGENT_COPILOT || vars.GH_AW_DEFAULT_MODEL_COPILOT || 'auto' }} COPILOT_SDK_URI: http://127.0.0.1:3002 GH_AW_COPILOT_SDK_DRIVER: 1 - GH_AW_COPILOT_SDK_SERVER_ARGS: '["--headless","--no-auto-update","--port","3002","--add-dir","/tmp/gh-aw/","--log-level","all","--log-dir","/tmp/gh-aw/sandbox/agent/logs/","--disable-builtin-mcps","--no-ask-user","--allow-tool","github","--allow-tool","safeoutputs","--allow-tool","shell(./gh-aw * --help)","--allow-tool","shell(./gh-aw --help)","--allow-tool","shell(awk)","--allow-tool","shell(cat .github/workflows/*.md)","--allow-tool","shell(cat /tmp/gh-aw/agent/*)","--allow-tool","shell(cat docs/src/content/docs/*.md)","--allow-tool","shell(cat docs/src/content/docs/*.mdx)","--allow-tool","shell(cat pkg/*/*.go)","--allow-tool","shell(cat)","--allow-tool","shell(date)","--allow-tool","shell(echo)","--allow-tool","shell(find .github/workflows -name \"*.md\")","--allow-tool","shell(find docs/src/content/docs -name \"*.md\" -o -name \"*.mdx\")","--allow-tool","shell(gh:*)","--allow-tool","shell(grep)","--allow-tool","shell(head)","--allow-tool","shell(ls)","--allow-tool","shell(printf)","--allow-tool","shell(pwd)","--allow-tool","shell(safeoutputs:*)","--allow-tool","shell(sed)","--allow-tool","shell(shuf)","--allow-tool","shell(sort)","--allow-tool","shell(tail)","--allow-tool","shell(uniq)","--allow-tool","shell(wc)","--allow-tool","shell(xargs -a /tmp/gh-aw/agent/doc-samples.txt cat)","--allow-tool","shell(xargs -a /tmp/gh-aw/agent/validation-sample.txt cat)","--allow-tool","shell(xargs -a /tmp/gh-aw/agent/workflow-samples.txt cat)","--allow-tool","shell(yq)","--allow-tool","write","--allow-all-paths"]' + GH_AW_COPILOT_SDK_SERVER_ARGS: '["--headless","--no-auto-update","--port","3002","--add-dir","/tmp/gh-aw/","--log-level","all","--log-dir","/tmp/gh-aw/sandbox/agent/logs/","--disable-builtin-mcps","--no-ask-user","--allow-tool","github","--allow-tool","safeoutputs","--allow-tool","shell(./gh-aw * --help)","--allow-tool","shell(./gh-aw --help)","--allow-tool","shell(awk)","--allow-tool","shell(cat .github/workflows/*.md)","--allow-tool","shell(cat /tmp/gh-aw/agent/*)","--allow-tool","shell(cat docs/src/content/docs/*.md)","--allow-tool","shell(cat docs/src/content/docs/*.mdx)","--allow-tool","shell(cat pkg/*/*.go)","--allow-tool","shell(cat)","--allow-tool","shell(date)","--allow-tool","shell(echo)","--allow-tool","shell(find .github/workflows -name \"*.md\")","--allow-tool","shell(find docs/src/content/docs -name \"*.md\" -o -name \"*.mdx\")","--allow-tool","shell(gh:*)","--allow-tool","shell(grep)","--allow-tool","shell(head)","--allow-tool","shell(ls)","--allow-tool","shell(printf)","--allow-tool","shell(pwd)","--allow-tool","shell(safeoutputs:*)","--allow-tool","shell(sed)","--allow-tool","shell(shuf)","--allow-tool","shell(sort)","--allow-tool","shell(tail)","--allow-tool","shell(uniq)","--allow-tool","shell(wc)","--allow-tool","shell(yq)","--allow-tool","write","--allow-all-paths"]' GH_AW_LLM_PROVIDER: github GH_AW_MAX_AI_CREDITS: ${{ vars.GH_AW_DEFAULT_MAX_AI_CREDITS || '1000' }} GH_AW_MAX_TOOL_DENIALS: 3 diff --git a/.github/workflows/delight.md b/.github/workflows/delight.md index c91822e5700..ee4cba2f9a2 100644 --- a/.github/workflows/delight.md +++ b/.github/workflows/delight.md @@ -61,6 +61,10 @@ pre-agent-steps: # Load historical memory (eliminates agent memory-read turns) cat memory/delight/previous-findings.json 2>/dev/null > /tmp/gh-aw/agent/previous-findings.json || echo "[]" > /tmp/gh-aw/agent/previous-findings.json cat memory/delight/improvement-themes.json 2>/dev/null > /tmp/gh-aw/agent/improvement-themes.json || echo "[]" > /tmp/gh-aw/agent/improvement-themes.json + # Pre-read file contents (eliminates view/read tool denials) + xargs -a /tmp/gh-aw/agent/doc-samples.txt cat > /tmp/gh-aw/agent/doc-samples-content.txt 2>/dev/null || echo "(no doc samples found)" > /tmp/gh-aw/agent/doc-samples-content.txt + xargs -a /tmp/gh-aw/agent/workflow-samples.txt cat > /tmp/gh-aw/agent/workflow-samples-content.txt 2>/dev/null || echo "(no workflow samples found)" > /tmp/gh-aw/agent/workflow-samples-content.txt + xargs -a /tmp/gh-aw/agent/validation-sample.txt cat > /tmp/gh-aw/agent/validation-sample-content.txt 2>/dev/null || echo "(no validation sample found)" > /tmp/gh-aw/agent/validation-sample-content.txt strict: true timeout-minutes: 30 tools: @@ -70,9 +74,6 @@ tools: - ./gh-aw --help - ./gh-aw * --help - cat /tmp/gh-aw/agent/* - - xargs -a /tmp/gh-aw/agent/doc-samples.txt cat - - xargs -a /tmp/gh-aw/agent/workflow-samples.txt cat - - xargs -a /tmp/gh-aw/agent/validation-sample.txt cat - cat docs/src/content/docs/*.md - cat docs/src/content/docs/*.mdx - cat .github/workflows/*.md @@ -164,11 +165,11 @@ Apply these principles when evaluating user experience in an enterprise context: **Select 1-2 high-impact documentation files:** -The following files have been pre-sampled for this run: +The following files have been pre-sampled and pre-loaded for this run: ```bash cat /tmp/gh-aw/agent/doc-samples.txt -xargs -a /tmp/gh-aw/agent/doc-samples.txt cat +cat /tmp/gh-aw/agent/doc-samples-content.txt ``` **Evaluate each file for:** @@ -220,11 +221,11 @@ For each selected command, run `./gh-aw [command] --help` and evaluate: **Select 1-2 workflows with custom messages:** -The following workflows have been pre-sampled for this run: +The following workflows have been pre-sampled and pre-loaded for this run: ```bash cat /tmp/gh-aw/agent/workflow-samples.txt -xargs -a /tmp/gh-aw/agent/workflow-samples.txt cat +cat /tmp/gh-aw/agent/workflow-samples-content.txt ``` For each selected workflow, review the messages section: @@ -248,11 +249,11 @@ For each selected workflow, review the messages section: **Select 1 validation file for review:** -The following file has been pre-sampled for this run: +The following file has been pre-sampled and pre-loaded for this run: ```bash cat /tmp/gh-aw/agent/validation-sample.txt -xargs -a /tmp/gh-aw/agent/validation-sample.txt cat +cat /tmp/gh-aw/agent/validation-sample-content.txt ``` Review error messages in the selected file: