You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Excessive Tool Denials: The Copilot SDK hit the max tool denial guardrail and stopped the session early (3/3).
Last denied request
shell(f=/tmp/1790390377956-copilot-tool-output-390-fceec0fe-7c99-4db9-9428-5119988c218f.txt
python3 -c "
import re
content = open('$f').read()
idx = content.find('[{')
content = content[idx:]
import json
data = json.loads(content)
for a in data:
if a['rule']['id'] in ('go/allocation-size-overflow','go/bad-redirect-check'):
print(a['number'], a['rule']['id'], a['most_recent_instance']['location'].get('path'), a['most_recent_instance']['location'].get('start_line'))
" 2>&1 | head -20)
bash(f=/tmp/1790390377956-copilot-tool-output-390-fceec0fe-7c99-4db9-9428-5119988c218f.txt python3 -c " import re content ...)
This is a structured guardrail event (guard.tool_denials_exceeded) captured in events.jsonl.
How to fix this
The prompt attempted actions outside the workflow's allowed tools.
Update the workflow prompt and/or permissions so required actions are permitted:
The workflow daily-compiler-threat-spec-optimizer stopped because the Copilot SDK exceeded its tool denial threshold (3/3).
Last denied request:
shell(f=/tmp/1790390377956-copilot-tool-output-390-fceec0fe-7c99-4db9-9428-5119988c218f.txt
python3 -c "
import re
content = open('$f').read()
idx = content.find('[{')
content = content[idx:]
import json
data = json.loads(content)
for a in data:
if a['rule']['id'] in ('go/allocation-size-overflow','go/bad-redirect-check'):
print(a['number'], a['rule']['id'], a['most_recent_instance']['location'].get('path'), a['most_recent_instance']['location'].get('start_line'))
" 2>&1 | head -20)
Please update the workflow so the prompt only uses tools permitted by the workflow tool policy.
Action Required
Assign this issue to an agent to debug and fix the issue.
Optimize token consumption
This failure was triggered by a guardrail limit (max-tool-denials). Use this prompt with any coding agent (GitHub Copilot, Claude, Gemini, etc.) to analyze token usage and reduce costs:
Optimize the agentic workflow token consumption using https://raw.githubusercontent.com/github/gh-aw/main/optimize.md
The workflow run is at https://github.com/github/gh-aw/actions/runs/36212200280
Debug with any coding agent
Use this prompt with any coding agent (GitHub Copilot, Claude, Gemini, etc.):
Debug the agentic workflow failure using https://raw.githubusercontent.com/github/gh-aw/main/debug.md
The failed workflow run is at https://github.com/github/gh-aw/actions/runs/36212200280
Manually invoke the agent
Debug this workflow failure using your favorite Agent CLI and the agentic-workflows prompt.
Workflow Failure
Workflow: Daily Compiler Threat Spec Optimizer
Branch: main
Run: https://github.com/github/gh-aw/actions/runs/36212200280
Warning
Excessive Tool Denials: The Copilot SDK hit the max tool denial guardrail and stopped the session early (
3/3).Last denied request
Last 5 tool calls
bash(github list_code_scanning_alerts '{"owner":"github","repo":"gh-aw","state":"open","severity":"critical,high"}' 2>&1 |...)bash(f=$(ls -t /tmp/*copilot-tool-output* | head -1); echo $f; python3 -c " import json with open('$f') as fh: content = f...)bash(f=/tmp/1790390377956-copilot-tool-output-390-fceec0fe-7c99-4db9-9428-5119988c218f.txt; wc -l "$f"; grep -o '"number":...)bash(f=/tmp/1790390377956-copilot-tool-output-390-fceec0fe-7c99-4db9-9428-5119988c218f.txt grep -o '"number":[0-9]*' "$f" ...)bash(f=/tmp/1790390377956-copilot-tool-output-390-fceec0fe-7c99-4db9-9428-5119988c218f.txt python3 -c " import re content ...)This is a structured guardrail event (
guard.tool_denials_exceeded) captured inevents.jsonl.How to fix this
The prompt attempted actions outside the workflow's allowed tools.
Update the workflow prompt and/or permissions so required actions are permitted:
Action Required
Assign this issue to an agent to debug and fix the issue.
Optimize token consumption
This failure was triggered by a guardrail limit (max-tool-denials). Use this prompt with any coding agent (GitHub Copilot, Claude, Gemini, etc.) to analyze token usage and reduce costs:
Debug with any coding agent
Use this prompt with any coding agent (GitHub Copilot, Claude, Gemini, etc.):
Manually invoke the agent
Debug this workflow failure using your favorite Agent CLI and the
agentic-workflowsprompt.agentic-workflowsskill from.github/skills/agentic-workflows/SKILL.mdor https://github.com/github/gh-aw/blob/main/.github/skills/agentic-workflows/SKILL.mddebug the agentic workflow daily-compiler-threat-spec-optimizer failure in https://github.com/github/gh-aw/actions/runs/36212200280Tip
Stop reporting this workflow as a failure
To stop a workflow from creating failure issues, set
report-failure-as-issue: falsein its frontmatter: