Intelligence
AEV-2026-0048

gh-aw kept a delegated dynamic enclave's GitHub MCP backend routable to the primary agent with no independent tools.github grant (issue 59045, PR 59046)

GitHub's own Agentic Workflows compiler needed a GitHub MCP backend registered in a run so a dynamically delegated, narrowly bounded enclave identity could reach it. Issue 59045 and its merged pull request 59046, both read directly at github/gh-aw, confirm the runtime also carried that same backend into the primary agent's own unrestricted, routable server set whenever a dynamic enclave was configured, independent of the workflow's own top level tools.github grant. The fix derives the primary agent's routable servers from its own grants and is confirmed present in release v0.88.5, published 7 September 2026 and marked pre release.

AESS 4.9 mediumConfirmedStatus: resolvedEvent: 6 September 2026Delegated AuthorityExecution AuthorityAgent Identity

Affected

Organisation
GitHub
Product
gh-aw (GitHub Agentic Workflows)
Component
The compiler's dynamic repository enclave delegation wiring and the primary agent's own routable MCP server list derivation
Versions
Present before pull request 59046 merged on 7 September 2026; the fix is confirmed present in release v0.88.5, published the same day and marked pre release by GitHub's own listing
Configurations
A workflow configuring at least one dynamic repository enclave under an enclaves.dynamic entry; The same workflow granting the primary agent no independent top level tools.github access

Execution authority facts

Fields the evidence does not establish are shown as unknown rather than guessed.

Intended task
Let a workflow request a bounded, runtime issued GitHub read policy for a dynamically delegated identity, while the primary agent's own GitHub access continues to depend solely on its own separately configured top level tools.github grant
Agent
gh-aw's own compiler and runtime, deriving both the delegated enclave identity's routable servers and the primary agent's routable servers for the same run
Delegating actor
The workflow's own dynamic enclave configuration, compiled and reconciled through gh-aw's delegation controller wiring
Action
The runtime's own routable server derivation carried the GitHub MCP backend, registered so the delegated identity could reach it, into the primary agent's own unrestricted routable server set
Target resource
The GitHub MCP backend registered inside the run's own MCP gateway process
Environment
The GitHub Agentic Workflows runtime executing the workflow's own run
Credentials used
unknown; issue 59045 and pull request 59046 describe a routing and registration gap rather than naming a specific credential the primary agent used once routed to the backend
Privileges available
Whatever the GitHub MCP backend itself is configured to reach, since the routing gap gave the primary agent a route to the backend rather than a separately narrowed credential
Authority presented
The GitHub MCP backend's own registration in the runtime, required so a dynamically delegated identity could reach it
Authority required
An independent, top level tools.github grant to the primary agent specifically, per the workflow's own configuration
Applicable policy
The primary agent's own routable server derivation, which issue 59045 states must exclude a backend registered only for delegated use absent that independent grant
Approval mechanism
none
Required approver
unknown
Independent approval
no
Action binding
The registration decision, that a backend exists in the runtime because a delegated identity needs it, was not independently rechecked against a separate, principal specific routability decision for the primary agent
Sequence context
Present whenever a workflow configured a dynamic enclave, independent of any separate top level tools.github configuration, per issue 59045's own description of the pre fix behavior

Impact

Consequence
A route from the primary agent to a GitHub capable MCP backend existed with no independent grant behind it; this entry found no report that the primary agent was ever demonstrated exercising that route against a real repository, so it is recorded as a reached but not demonstrably executed consequential exposure rather than an observed material loss
Reach
organisational
Reversibility
unknown
Detectability
unknown
Propagation
A concrete path existed, from a registered backend to the primary agent's own routable set, but this entry found no report of it being observed operating against a real workflow run
Recovery
Fixed by pull request 59046, merged 7 September 2026: the primary agent's own routable servers are now derived from the primary agent's own grants rather than from the backend's mere registration for delegated use, confirmed present in gh-aw release v0.88.5, published the same day.

Evidence

Primary sources

Supporting sources

Reproduction status
First party: GitHub's own repository issue and merged pull request describe and fix the gap in the same sitting. This session did not itself run a gh-aw workflow with a dynamic enclave configured; it read the issue, the merged pull request and the repository's own checked in documentation and lock file directly through this session's automated page fetch and summarization tool rather than a raw diff, raw file byte read or an authenticated GitHub API call, and independently confirmed the delegated policy's exact tool set and the mcpg version actually pinned at the v0.88.5 tag rather than relying on the pull request's own prose alone.
Evidence state
Confirmed

Known unknowns

  • Whether any real workflow run was ever affected while the routing gap was live, given issue 59045's own account that the delegation controller itself was rejected by the mcpg version then in place and dynamic policies were rejected outright.
  • The exact internal logic gh-aw's own compiler and runtime use to derive the primary agent's routable server list, before and after the fix, since this session did not read the repository's Go source directly.
  • Whether a companion mcpg gateway version upgrade beyond v0.4.16 has shipped; this session's own direct read of actions-lock.json at the v0.88.5 tag found no v0.4.17 entry, and this entry does not adopt an earlier, less directly sourced description of one.
  • Whether gh-aw v0.88.5, marked pre release by GitHub's own listing, has since been superseded by a stable release carrying the same fix.

Limitations

  • Every source in this entry was retrieved through this session's automated page fetch and summarization tool rather than a raw diff, a raw file byte read or an authenticated GitHub API call, consistent with this session's own GitHub access being scoped to a different repository.
  • This session did not clone or run gh-aw, and does not independently confirm the pre fix or post fix routing behavior beyond what the issue's own text, the pull request's own stated changes, and the repository's own checked in documentation and lock file state establish.

Claim provenance