Skip to content

Copilot engine: tools.web-fetch compiles to --allow-tool web_fetch but the tool is unavailable because the CLI runs in offline BYOK mode #65043

Description

@thatapplefreak

Summary

With engine: copilot, tools: web-fetch: compiles to --allow-tool web_fetch, but the agent never receives a web_fetch tool. The compiled workflow runs Copilot CLI in offline BYOK mode (COPILOT_OFFLINE=true + COPILOT_PROVIDER_BASE_URL pointing at the api-proxy sidecar), and Copilot CLI disables its web tools in offline mode. web-fetch: compiles cleanly and silently does nothing.

copilot help environment documents this:

COPILOT_OFFLINE: set to "true" to enable offline mode. When active, the CLI skips all network access: GitHub authentication, telemetry, web tools, GitHub MCP server, and auto-update are disabled.

The new native web-search: (v0.89.21, #62957) is probably affected the same way, since web_search is also a web tool. I have not verified this.

Environment

  • gh-aw v0.88.2 (observed); recompiled with v0.89.21, which still emits --allow-tool web_fetch alongside the same offline setup
  • Copilot CLI 1.0.82 (also checked against 1.0.91 docs)
  • AWF v0.27.44
  • GHE Cloud with data residency (engine.api-target: copilot-api.<tenant>.ghe.com), org billing via copilot-requests: write

Evidence (5 completed runs, same result each time)

  • Copilot CLI process log: Running in offline mode. GitHub features are unavailable.
  • Firewall audit docker-compose.redacted.yml sets COPILOT_OFFLINE: 'true'; the CLI log shows COPILOT_PROVIDER_BASE_URL=http://172.30.0.30:10002.
  • The compiled command includes --allow-tool web_fetch, but web_fetch never appears in the CLI's tool catalog or in any tool definition in the process log (catalog_tool_count: 17, no web_fetch).
  • The Squid access.log has zero TCP_DENIED entries and no requests to any allowlisted advisory domain. The only egress is the Copilot API and git, so network.allowed is never exercised.
  • The agent repeatedly reports it has "no network access / no web-fetch tool" and runs which web-fetch; type web_fetch looking for one.

Repro

engine:
  id: copilot
network:
  allowed: [defaults, "osv.dev"]
tools:
  web-fetch:

Prompt the agent to fetch https://osv.dev/ and list its tools. web_fetch is absent and nothing reaches the firewall.

Expected

One of:

  1. web-fetch: works with the Copilot engine in offline/BYOK mode, for example by falling back to an MCP fetch server routed through the firewall, as already happens for engines without a native fetch tool; or
  2. gh aw compile warns or errors when web-fetch: (or web-search:) is declared but the compiled Copilot run is offline, so the tool cannot exist.

Workaround

Using curl from bash works, but it also needs URL permission because Copilot CLI denies URLs in shell commands under --no-ask-user:

engine:
  id: copilot
  args: ["--allow-all-urls"]   # egress still limited by network.allowed / Squid
tools:
  bash: [..., "curl"]          # compiles to shell(curl:*)

Verified locally with Copilot CLI 1.0.88: --no-ask-user --allow-tool 'shell(curl)' returns Permission denied and could not request permission from user, while adding --allow-url <host> returns HTTP 200.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions