You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[aw] Daily SPDD Spec Planner is missing required tool #65351
Repeated Permission Denied: The agent was denied permission to run 1 command(s) and stopped retrying.
Denied Commands:
shell(mkdir -p /tmp/gh-aw/cache-memory/spdd-daily && cd /tmp/gh-aw/cache-memory/spdd-daily && ls -la && cat rotation.json 2>&1; touch .pf && rm .pf && echo writable; cd /home/runner/work/gh-aw/gh-aw && find specs docs scratchpad -type f -name "*.md" 2>/dev/null | grep -E '^specs/|specification[^/]*\.md$' | sort)
How to fix this
The agent ran in non-interactive mode (--no-ask-user) and could not request permission at runtime.
To resolve repeated permission denied errors, update the workflow prompt to avoid these commands or use approved alternatives. Use the following prompt with any coding agent:
The agentic workflow daily-spdd-spec-planner encountered repeated permission denied errors for these commands:
`shell(mkdir -p /tmp/gh-aw/cache-memory/spdd-daily && cd /tmp/gh-aw/cache-memory/spdd-daily && ls -la && cat rotation.json 2>&1; touch .pf && rm .pf && echo writable; cd /home/runner/work/gh-aw/gh-aw && find specs docs scratchpad -type f -name "*.md" 2>/dev/null | grep -E '^specs/|specification[^/]*\.md$' | sort)`
Please update the workflow prompt so the agent:
1. Uses built-in tools (GitHub API, file read/write) instead of the denied shell commands
2. Or achieves the same goal through alternative approaches that do not require shell permission
Warning
Engine Failure: The copilot engine terminated unexpectedly.
Last agent output:
{"type":"tool.execution_start","timestamp":"2026-10-03T17:09:18.997Z","data":{"toolName":"bash","mcpServerName":"","toolCallId":"toolu_011TLT4GhhvctGuzWfLGKsg7","input":{"command":"cd specs; cat compiler-threat-detection-compliance/README.md | head -60; echo ======; cat forecast-compliance-fixtures/README.md | head -60; echo =====; cat github-mcp-access-control-compliance/README.md | head -60"},"command":"cd specs; cat compiler-threat-detection-compliance/README.md | head -60; echo ======; cat forecast-compliance-fixtures/README.md | head -60; echo =====; cat github-mcp-access-control-compliance/README.md | head -60"}}
[copilot-sdk-driver] [sdk-driver] permission denied by workflow tool permissions: shell(cd specs; wc -l compiler-threat-detection-changelog.md compiler-threat-detection-compliance/README.md compiler-threat-detection-spec.md forecast-compliance-fixtures/README.md github-mcp-access-control-compliance/README.md; head -50 compiler-threat-detection-changelog.md; grep -n '^#' compiler-threat-detection-spec.md | head -60)
[copilot-sdk-driver] [sdk-driver] tool denial 2/3: permission denied: shell(cd specs; wc -l compiler-threat-detection-changelog.md compiler-threat-detection-compliance/README.md compiler-threat-detection-spec.md forecast-compliance-fixtures/README.md github-mcp-access-control-compliance/README.md; head -50 compiler-threat-detection-changelog.md; grep -n '^#' compiler-threat-detection-spec.md | head -60)
[copilot-sdk-driver] [sdk-driver] permission denied by workflow tool permissions: shell(cd specs; cat compiler-threat-detection-compliance/README.md | head -60; echo ======; cat forecast-compliance-fixtures/README.md | head -60; echo =====; cat github-mcp-access-control-compliance/README.md | head -60)
[copilot-sdk-driver] [sdk-driver] tool denial 3/3: permission denied: shell(cd specs; cat compiler-threat-detection-compliance/README.md | head -60; echo ======; cat forecast-compliance-fixtures/README.md | head -60; echo =====; cat github-mcp-access-control-compliance/README.md | head -60)
{"type":"guard.tool_denials_exceeded","timestamp":"2026-10-03T17:09:19.002Z","data":{"denialCount":3,"threshold":3,"reason":"permission denied: shell(cd specs; cat compiler-threat-detection-compliance/README.md | head -60; echo ======; cat forecast-compliance-fixtures/README.md | head -60; echo =====; cat github-mcp-access-control-compliance/README.md | head -60)"}}
[copilot-sdk-driver] [sdk-driver] max tool denials threshold reached (3/3); stopping SDK session early
[copilot-sdk-driver] [sdk-driver] warning: denial guard force-exit fired after 15000ms — sendAndWait did not settle on its own
[copilot-sdk-driver] [sdk-driver] error: max tool denials threshold reached (3/3)
{"type":"result","num_turns":2,"usage":{"input_tokens":72472,"output_tokens":794,"cache_read_input_tokens":42297,"cache_creation_input_tokens":25017}}
Action Required
Assign this issue to an agent to debug and fix the issue.
Debug with any coding agent
Use this prompt with any coding agent (GitHub Copilot, Claude, Gemini, etc.):
Debug the agentic workflow failure using https://raw.githubusercontent.com/github/gh-aw/main/debug.md
The failed workflow run is at https://github.com/github/gh-aw/actions/runs/37139318868
Manually invoke the agent
Debug this workflow failure using your favorite Agent CLI and the agentic-workflows prompt.
Workflow Failure
Workflow: Daily SPDD Spec Planner
Branch: main
Run: https://github.com/github/gh-aw/actions/runs/37139318868
Warning
Repeated Permission Denied: The agent was denied permission to run 1 command(s) and stopped retrying.
Denied Commands:
shell(mkdir -p /tmp/gh-aw/cache-memory/spdd-daily && cd /tmp/gh-aw/cache-memory/spdd-daily && ls -la && cat rotation.json 2>&1; touch .pf && rm .pf && echo writable; cd /home/runner/work/gh-aw/gh-aw && find specs docs scratchpad -type f -name "*.md" 2>/dev/null | grep -E '^specs/|specification[^/]*\.md$' | sort)How to fix this
The agent ran in non-interactive mode (
--no-ask-user) and could not request permission at runtime.To resolve repeated permission denied errors, update the workflow prompt to avoid these commands or use approved alternatives. Use the following prompt with any coding agent:
Warning
Engine Failure: The
copilotengine terminated unexpectedly.Last agent output:
Action Required
Assign this issue to an agent to debug and fix the issue.
Debug with any coding agent
Use this prompt with any coding agent (GitHub Copilot, Claude, Gemini, etc.):
Manually invoke the agent
Debug this workflow failure using your favorite Agent CLI and the
agentic-workflowsprompt.agentic-workflowsskill from.github/skills/agentic-workflows/SKILL.mdor https://github.com/github/gh-aw/blob/main/.github/skills/agentic-workflows/SKILL.mddebug the agentic workflow daily-spdd-spec-planner failure in https://github.com/github/gh-aw/actions/runs/37139318868Tip
Stop reporting this workflow as a failure
To stop a workflow from creating failure issues, set
report-failure-as-issue: falsein its frontmatter: