Summary
With engine: copilot, tools: web-fetch: compiles to --allow-tool web_fetch, but the agent never receives a web_fetch tool. The compiled workflow runs Copilot CLI in offline BYOK mode (COPILOT_OFFLINE=true + COPILOT_PROVIDER_BASE_URL pointing at the api-proxy sidecar), and Copilot CLI disables its web tools in offline mode. web-fetch: compiles cleanly and silently does nothing.
copilot help environment documents this:
COPILOT_OFFLINE: set to "true" to enable offline mode. When active, the CLI skips all network access: GitHub authentication, telemetry, web tools, GitHub MCP server, and auto-update are disabled.
The new native web-search: (v0.89.21, #62957) is probably affected the same way, since web_search is also a web tool. I have not verified this.
Environment
- gh-aw v0.88.2 (observed); recompiled with v0.89.21, which still emits
--allow-tool web_fetch alongside the same offline setup
- Copilot CLI 1.0.82 (also checked against 1.0.91 docs)
- AWF v0.27.44
- GHE Cloud with data residency (
engine.api-target: copilot-api.<tenant>.ghe.com), org billing via copilot-requests: write
Evidence (5 completed runs, same result each time)
- Copilot CLI process log:
Running in offline mode. GitHub features are unavailable.
- Firewall audit
docker-compose.redacted.yml sets COPILOT_OFFLINE: 'true'; the CLI log shows COPILOT_PROVIDER_BASE_URL=http://172.30.0.30:10002.
- The compiled command includes
--allow-tool web_fetch, but web_fetch never appears in the CLI's tool catalog or in any tool definition in the process log (catalog_tool_count: 17, no web_fetch).
- The Squid
access.log has zero TCP_DENIED entries and no requests to any allowlisted advisory domain. The only egress is the Copilot API and git, so network.allowed is never exercised.
- The agent repeatedly reports it has "no network access / no web-fetch tool" and runs
which web-fetch; type web_fetch looking for one.
Repro
engine:
id: copilot
network:
allowed: [defaults, "osv.dev"]
tools:
web-fetch:
Prompt the agent to fetch https://osv.dev/ and list its tools. web_fetch is absent and nothing reaches the firewall.
Expected
One of:
web-fetch: works with the Copilot engine in offline/BYOK mode, for example by falling back to an MCP fetch server routed through the firewall, as already happens for engines without a native fetch tool; or
gh aw compile warns or errors when web-fetch: (or web-search:) is declared but the compiled Copilot run is offline, so the tool cannot exist.
Workaround
Using curl from bash works, but it also needs URL permission because Copilot CLI denies URLs in shell commands under --no-ask-user:
engine:
id: copilot
args: ["--allow-all-urls"] # egress still limited by network.allowed / Squid
tools:
bash: [..., "curl"] # compiles to shell(curl:*)
Verified locally with Copilot CLI 1.0.88: --no-ask-user --allow-tool 'shell(curl)' returns Permission denied and could not request permission from user, while adding --allow-url <host> returns HTTP 200.
Summary
With
engine: copilot,tools: web-fetch:compiles to--allow-tool web_fetch, but the agent never receives aweb_fetchtool. The compiled workflow runs Copilot CLI in offline BYOK mode (COPILOT_OFFLINE=true+COPILOT_PROVIDER_BASE_URLpointing at the api-proxy sidecar), and Copilot CLI disables its web tools in offline mode.web-fetch:compiles cleanly and silently does nothing.copilot help environmentdocuments this:The new native
web-search:(v0.89.21, #62957) is probably affected the same way, sinceweb_searchis also a web tool. I have not verified this.Environment
--allow-tool web_fetchalongside the same offline setupengine.api-target: copilot-api.<tenant>.ghe.com), org billing viacopilot-requests: writeEvidence (5 completed runs, same result each time)
Running in offline mode. GitHub features are unavailable.docker-compose.redacted.ymlsetsCOPILOT_OFFLINE: 'true'; the CLI log showsCOPILOT_PROVIDER_BASE_URL=http://172.30.0.30:10002.--allow-tool web_fetch, butweb_fetchnever appears in the CLI's tool catalog or in any tool definition in the process log (catalog_tool_count: 17, noweb_fetch).access.loghas zeroTCP_DENIEDentries and no requests to any allowlisted advisory domain. The only egress is the Copilot API and git, sonetwork.allowedis never exercised.which web-fetch; type web_fetchlooking for one.Repro
Prompt the agent to fetch
https://osv.dev/and list its tools.web_fetchis absent and nothing reaches the firewall.Expected
One of:
web-fetch:works with the Copilot engine in offline/BYOK mode, for example by falling back to an MCP fetch server routed through the firewall, as already happens for engines without a native fetch tool; orgh aw compilewarns or errors whenweb-fetch:(orweb-search:) is declared but the compiled Copilot run is offline, so the tool cannot exist.Workaround
Using
curlfrom bash works, but it also needs URL permission because Copilot CLI denies URLs in shell commands under--no-ask-user:Verified locally with Copilot CLI 1.0.88:
--no-ask-user --allow-tool 'shell(curl)'returnsPermission denied and could not request permission from user, while adding--allow-url <host>returns HTTP 200.