published Aug 24, 2026, 7:33 PM · updated Aug 25, 2026, 4:12 AM
Workflow Failure
Workflow: Code Scanning Fixer
Branch: main
Run: https://github.com/github/gh-aw/actions/runs/32766280367
Warning
Excessive Tool Denials: The Copilot SDK hit the max tool denial guardrail and stopped the session early (3/3).
Last denied request
read(...)
Last 5 tool calls
bash(gh api "repos/github/gh-aw/code-scanning/alerts?state=open&per_page=100" > /tmp/gh-aw/agent/alerts.json 2>&1; echo EX...)bash(cat /tmp/gh-aw/agent/alerts.json; echo "---"; python3 -c "import json;d=json.load(open('/tmp/gh-aw/agent/alerts.json'...)bash(jq -r '[.[] | {number, state, sec: (.rule.security_severity_level), sev: (.rule.severity), rule: .rule.id, path: .mos...)bash(python3 - <<'EOF' import json d = json.load(open('/tmp/gh-aw/agent/alerts.json')) sev_rank = {'critical':0,'high':1,'...)grep
This is a structured guardrail event (guard.tool_denials_exceeded) captured in events.jsonl.
How to fix this
The prompt attempted actions outside the workflow's allowed tools.
Update the workflow prompt and/or permissions so required actions are permitted:
The workflow code-scanning-fixer stopped because the Copilot SDK exceeded its tool denial threshold (3/3).
Last denied request:
read(...)
Please update the workflow so the prompt only uses tools permitted by the workflow tool policy.
Agent Timed Out: The agent job exceeded the maximum allowed execution time (20 minutes).
To increase the timeout, add or update the timeout-minutes setting in your workflow's frontmatter:
---
timeout-minutes: 30
---Action Required
Assign this issue to an agent to debug and fix the issue.
Optimize token consumption
This failure was triggered by a guardrail limit (max-tool-denials). Use this prompt with any coding agent (GitHub Copilot, Claude, Gemini, etc.) to analyze token usage and reduce costs:
Optimize the agentic workflow token consumption using https://raw.githubusercontent.com/github/gh-aw/main/optimize.md
The workflow run is at https://github.com/github/gh-aw/actions/runs/32766280367
Debug with any coding agent
Use this prompt with any coding agent (GitHub Copilot, Claude, Gemini, etc.):
Debug the agentic workflow failure using https://raw.githubusercontent.com/github/gh-aw/main/debug.md
The failed workflow run is at https://github.com/github/gh-aw/actions/runs/32766280367
Manually invoke the agent
Debug this workflow failure using your favorite Agent CLI and the agentic-workflows prompt.
- Start your agent
- Load the
agentic-workflowsskill from.github/skills/agentic-workflows/SKILL.mdor https://github.com/github/gh-aw/blob/main/.github/skills/agentic-workflows/SKILL.md - Type
debug the agentic workflow code-scanning-fixer failure in https://github.com/github/gh-aw/actions/runs/32766280367
Tip
Stop reporting this workflow as a failure
To stop a workflow from creating failure issues, set report-failure-as-issue: false in its frontmatter:
safe-outputs:
report-failure-as-issue: falseGenerated from Code Scanning Fixer · copilot · 12.6 AIC · ◷
- expires on Aug 25, 2026, 7:33 AM UTC