Missing codemod candidate: tools.web-fetch + strict mode + engine: copilot
In today's cross-repo compat audit, 5 of 18 compiled repositories fail gh aw compile --strict with the same error, and gh aw fix --write currently leaves it untouched:
error: Validation failed for field 'tools.web-fetch'
Reason: strict mode: Copilot's 'web-fetch' tool does not follow the configured network restrictions
Suggestion: To enforce network restrictions, use Codex or Claude and configure network.hosted-web
separately for hosted tools (network.allowed does not cover them). Example:
engine: codex
network:
hosted-web:
allowed:
- example.com
Alternatively, disable this tool:
tools:
web-fetch: false
Affected repositories (3 of 5 shown): Azure/azure-sdk-for-rust, drasi-project/drasi-platform, microsoft/mcp (also NikiforovAll/keycloak-authorization-services-dotnet, py-why/dowhy).
Why this isn't auto-fixed today
Both remedies in the error's own suggestion change workflow behavior:
- Switching
engine: copilot → engine: codex/claude changes the runtime engine.
- Disabling
tools.web-fetch: false removes a tool the workflow author presumably wanted.
Neither is safe as a default, unconditional codemod.
Proposed options
- Opt-in codemod (e.g.
gh aw fix --write --allow-behavior-change) that applies the error's own suggested rewrite (either disable the tool or restructure network.hosted-web.allowed), clearly flagged as a behavior change in the fix report — not bundled into default --write.
- Earlier warning: surface this as a non-strict-mode warning (e.g. during normal
gh aw compile or gh aw fix dry-run) when a workflow uses engine: copilot + tools.web-fetch + any network: restriction, so authors see it before they turn on strict mode in CI, rather than discovering it only when --strict is enforced.
Repro
git clone --depth 1 https://github.com/microsoft/mcp
cd mcp
gh-aw compile --strict
# .github/workflows/doc-gap-detector.md:1:1: error: Validation failed for field 'tools.web-fetch'
References: gh-aw build under test: 0dc1f7e. See companion daily summary issue for full run metrics.
Generated by 🔧 Daily AW Cross-Repo Compile Check · claude · agent · 346.8 AIC · ⌖ 8.19 AIC · ⊞ 6.4K · ◷
Missing codemod candidate:
tools.web-fetch+ strict mode +engine: copilotIn today's cross-repo compat audit, 5 of 18 compiled repositories fail
gh aw compile --strictwith the same error, andgh aw fix --writecurrently leaves it untouched:Affected repositories (3 of 5 shown):
Azure/azure-sdk-for-rust,drasi-project/drasi-platform,microsoft/mcp(alsoNikiforovAll/keycloak-authorization-services-dotnet,py-why/dowhy).Why this isn't auto-fixed today
Both remedies in the error's own suggestion change workflow behavior:
engine: copilot→engine: codex/claudechanges the runtime engine.tools.web-fetch: falseremoves a tool the workflow author presumably wanted.Neither is safe as a default, unconditional codemod.
Proposed options
gh aw fix --write --allow-behavior-change) that applies the error's own suggested rewrite (either disable the tool or restructurenetwork.hosted-web.allowed), clearly flagged as a behavior change in the fix report — not bundled into default--write.gh aw compileorgh aw fixdry-run) when a workflow usesengine: copilot+tools.web-fetch+ anynetwork:restriction, so authors see it before they turn on strict mode in CI, rather than discovering it only when--strictis enforced.Repro
References: gh-aw build under test:
0dc1f7e. See companion daily summary issue for full run metrics.