Skip to content

[aw] Copilot CLI Deep Research Agent exceeded tool denial limit #39022

@github-actions

Description

@github-actions

Workflow Failure

Workflow: Copilot CLI Deep Research Agent
Branch: main
Run: https://github.com/github/gh-aw/actions/runs/27457409699

Warning

Excessive Tool Denials: The Copilot SDK hit the max tool denial guardrail and stopped the session early (5/5).

Last denied request
shell(# Check what's new in CHANGELOG recently (last ~100 lines covers recent changes)
tail -200 /home/runner/work/gh-aw/gh-aw/CHANGELOG.md 2>/dev/null | head -200

# Check current version
grep -m1 "## \[" /home/runner/work/gh-aw/gh-aw/CHANGELOG.md 2>/dev/null | head -5)

This is a structured guardrail event (guard.tool_denials_exceeded) captured in events.jsonl.

How to fix this

The prompt attempted actions outside the workflow's allowed tools.

Update the workflow prompt and/or permissions so required actions are permitted:

The workflow copilot-cli-deep-research stopped because the Copilot SDK exceeded its tool denial threshold (5/5).
Last denied request:
shell(# Check what's new in CHANGELOG recently (last ~100 lines covers recent changes)
tail -200 /home/runner/work/gh-aw/gh-aw/CHANGELOG.md 2>/dev/null | head -200

# Check current version
grep -m1 "## \[" /home/runner/work/gh-aw/gh-aw/CHANGELOG.md 2>/dev/null | head -5)

Please update the workflow so the prompt only uses tools permitted by the workflow tool policy.

Action Required

Assign this issue to an agent to debug and fix the issue.

Debug with any coding agent

Use this prompt with any coding agent (GitHub Copilot, Claude, Gemini, etc.):

Debug the agentic workflow failure using https://github.com/github/gh-aw/main/debug.md

The failed workflow run is at https://github.com/github/gh-aw/actions/runs/27457409699
Manually invoke the agent

Debug this workflow failure using your favorite Agent CLI and the agentic-workflows prompt.

Tip

Stop reporting this workflow as a failure

To stop a workflow from creating failure issues, set report-failure-as-issue: false in its frontmatter:

safe-outputs:
  report-failure-as-issue: false

Generated from Copilot CLI Deep Research Agent · 418.7 AIC ·

  • expires on Jun 13, 2026, 5:33 PM UTC

Metadata

Metadata

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions