AEV-2026-0048
gh-aw kept a delegated dynamic enclave's GitHub MCP backend routable to the primary agent with no independent tools.github grant (issue 59045, PR 59046)
GitHub's own Agentic Workflows compiler needed a GitHub MCP backend registered in a run so a dynamically delegated, narrowly bounded enclave identity could reach it. Issue 59045 and its merged pull request 59046, both read directly at github/gh-aw, confirm the runtime also carried that same backend into the primary agent's own unrestricted, routable server set whenever a dynamic enclave was configured, independent of the workflow's own top level tools.github grant. The fix derives the primary agent's routable servers from its own grants and is confirmed present in release v0.88.5, published 7 September 2026 and marked pre release.
Affected
- Organisation
- GitHub
- Product
- gh-aw (GitHub Agentic Workflows)
- Component
- The compiler's dynamic repository enclave delegation wiring and the primary agent's own routable MCP server list derivation
- Versions
- Present before pull request 59046 merged on 7 September 2026; the fix is confirmed present in release v0.88.5, published the same day and marked pre release by GitHub's own listing
- Configurations
- A workflow configuring at least one dynamic repository enclave under an enclaves.dynamic entry; The same workflow granting the primary agent no independent top level tools.github access
Execution authority facts
Fields the evidence does not establish are shown as unknown rather than guessed.
- Intended task
- Let a workflow request a bounded, runtime issued GitHub read policy for a dynamically delegated identity, while the primary agent's own GitHub access continues to depend solely on its own separately configured top level tools.github grant
- Agent
- gh-aw's own compiler and runtime, deriving both the delegated enclave identity's routable servers and the primary agent's routable servers for the same run
- Delegating actor
- The workflow's own dynamic enclave configuration, compiled and reconciled through gh-aw's delegation controller wiring
- Action
- The runtime's own routable server derivation carried the GitHub MCP backend, registered so the delegated identity could reach it, into the primary agent's own unrestricted routable server set
- Target resource
- The GitHub MCP backend registered inside the run's own MCP gateway process
- Environment
- The GitHub Agentic Workflows runtime executing the workflow's own run
- Credentials used
- unknown; issue 59045 and pull request 59046 describe a routing and registration gap rather than naming a specific credential the primary agent used once routed to the backend
- Privileges available
- Whatever the GitHub MCP backend itself is configured to reach, since the routing gap gave the primary agent a route to the backend rather than a separately narrowed credential
- Authority presented
- The GitHub MCP backend's own registration in the runtime, required so a dynamically delegated identity could reach it
- Authority required
- An independent, top level tools.github grant to the primary agent specifically, per the workflow's own configuration
- Applicable policy
- The primary agent's own routable server derivation, which issue 59045 states must exclude a backend registered only for delegated use absent that independent grant
- Approval mechanism
- none
- Required approver
- unknown
- Independent approval
- no
- Action binding
- The registration decision, that a backend exists in the runtime because a delegated identity needs it, was not independently rechecked against a separate, principal specific routability decision for the primary agent
- Sequence context
- Present whenever a workflow configured a dynamic enclave, independent of any separate top level tools.github configuration, per issue 59045's own description of the pre fix behavior
Impact
- Consequence
- A route from the primary agent to a GitHub capable MCP backend existed with no independent grant behind it; this entry found no report that the primary agent was ever demonstrated exercising that route against a real repository, so it is recorded as a reached but not demonstrably executed consequential exposure rather than an observed material loss
- Reach
- organisational
- Reversibility
- unknown
- Detectability
- unknown
- Propagation
- A concrete path existed, from a registered backend to the primary agent's own routable set, but this entry found no report of it being observed operating against a real workflow run
- Recovery
- Fixed by pull request 59046, merged 7 September 2026: the primary agent's own routable servers are now derived from the primary agent's own grants rather than from the backend's mere registration for delegated use, confirmed present in gh-aw release v0.88.5, published the same day.
Evidence
Primary sources
- Wire dynamic enclave delegation controller into the workflow runtime (Issue #59045) (github/gh-aw (GitHub Issues))
- Wire dynamic enclave delegation controller into the workflow runtime (Pull Request #59046) (github/gh-aw (GitHub Pull Requests))
Supporting sources
- Private Repository Enclaves: policy and version requirements (.github/aw/enclaves.md at v0.88.5) (github/gh-aw (GitHub repository))
- actions-lock.json, pinned action and container versions (at v0.88.5) (github/gh-aw (GitHub repository))
- Release v0.88.5 (github/gh-aw (GitHub Releases))
- Reproduction status
- First party: GitHub's own repository issue and merged pull request describe and fix the gap in the same sitting. This session did not itself run a gh-aw workflow with a dynamic enclave configured; it read the issue, the merged pull request and the repository's own checked in documentation and lock file directly through this session's automated page fetch and summarization tool rather than a raw diff, raw file byte read or an authenticated GitHub API call, and independently confirmed the delegated policy's exact tool set and the mcpg version actually pinned at the v0.88.5 tag rather than relying on the pull request's own prose alone.
- Evidence state
- Confirmed
Known unknowns
- Whether any real workflow run was ever affected while the routing gap was live, given issue 59045's own account that the delegation controller itself was rejected by the mcpg version then in place and dynamic policies were rejected outright.
- The exact internal logic gh-aw's own compiler and runtime use to derive the primary agent's routable server list, before and after the fix, since this session did not read the repository's Go source directly.
- Whether a companion mcpg gateway version upgrade beyond v0.4.16 has shipped; this session's own direct read of actions-lock.json at the v0.88.5 tag found no v0.4.17 entry, and this entry does not adopt an earlier, less directly sourced description of one.
- Whether gh-aw v0.88.5, marked pre release by GitHub's own listing, has since been superseded by a stable release carrying the same fix.
Limitations
- Every source in this entry was retrieved through this session's automated page fetch and summarization tool rather than a raw diff, a raw file byte read or an authenticated GitHub API call, consistent with this session's own GitHub access being scoped to a different repository.
- This session did not clone or run gh-aw, and does not independently confirm the pre fix or post fix routing behavior beyond what the issue's own text, the pull request's own stated changes, and the repository's own checked in documentation and lock file state establish.
Claim provenance
- verified
Fetched directly on 7 September 2026. Confirmed title, opened and closed dates, and the issue's own stated requirement to keep the GitHub backend registered for delegated identities while removing it from the primary agent's own policy absent an independent top level tools.github grant, and its own account that a provisional delegation controller configuration was rejected by the mcpg version then in place.
The Backend Was Registered For The Delegate. The Primary Agent Kept The Route. - verified
Fetched directly on 7 September 2026. Confirmed merged state, the merge time and a merge commit beginning e79e368, and the pull request's own stated fix to the primary agent's own routable server list. Did not corroborate this same fetch pass's own description of a companion mcpg v0.4.17 upgrade against this entry's own separate, direct read of actions-lock.json at the v0.88.5 tag.
The Backend Was Registered For The Delegate. The Primary Agent Kept The Route. - verified
Fetched directly, twice independently, on 7 September 2026. Both passes agree the github-repository-read-v1 policy grants exactly list_issues and issue_read as its entire permitted tool set, with GraphQL, search, writes and every other GitHub tool denied.
The Backend Was Registered For The Delegate. The Primary Agent Kept The Route. - verified
Fetched directly on 7 September 2026 and searched in full for every occurrence of mcpg. Found exactly two pinned ghcr.io/github/gh-aw-mcpg entries at this tag, v0.4.15 and v0.4.16, and no v0.4.17 entry anywhere in the file.
The Backend Was Registered For The Delegate. The Primary Agent Kept The Route. - verified
Fetched directly on 7 September 2026. Confirmed pull request 59046 is named in this release's own notes, that the release is dated 7 September 2026, and that GitHub's own release listing marks this tag pre release.
The Backend Was Registered For The Delegate. The Primary Agent Kept The Route.
