Skip to content

[aw-failures] [P1] Sandbox command-injection guard blocks multi-line printf to safeoutputs, causing 5-min timeout — GitHub Remot [Content truncated due to length] #52254

Description

@github-actions

Fix the sandbox'''s shell command-injection detector — it rejects legitimate multi-line printf '''...\n...''' calls to safeoutputs create_discussion, forcing repeated retries that exhaust the step'''s 5-minute timeout and turn a benign test finding into a full workflow failure.

Affected workflow: GitHub Remote MCP Authentication Test (.github/workflows/github-remote-mcp-auth-test.lock.yml)
Run analyzed: §31567984790

Evidence

  • The agent'''s actual test finding was legitimate and worth reporting: unknown tool "get_repository" — the GitHub remote MCP toolset is unavailable in the runner environment.
  • Reporting that finding via safeoutputs create_discussion --title ... --body "...\n..." was rejected twice with: "...indirect expansion, or nested command substitution) that could enable arbitrary code execution. Please rewrite the command without these expansion patterns."
  • After two rejected retries (05:55–05:59 UTC) the agent stalled and ##[error]The action '''Execute GitHub Copilot CLI''' has timed out after 5 minutes. fired — the run failed on a harness timeout, not on the MCP test itself.

Probable root cause

The sandbox'''s static command-injection scanner flags benign -containing printf bodies passed to safeoutputs CLI commands as a command-substitution risk, with no fallback path when the check misfires — the agent has no way to know why it was rejected, so it just retries the identical command until the step times out.

Proposed remediation

  1. Narrow the command-injection heuristic so a literal inside a quoted printf string is not treated as shell expansion.
  2. Return a distinct, actionable rejection message for safeoutputs-CLI commands blocked by this guard (not a bare exit code) so the agent can reformulate immediately instead of repeating the same failing command.
  3. Promote the jq -Rs file-piping pattern (already documented elsewhere in the harness guidance for multi-line bodies) as the canonical safe path, and pre-validate that pattern against the guard so it never trips it.

Success criteria

safeoutputs create_discussion/create_issue with a multi-line -containing body succeeds on first attempt in the sandbox; add a guard-rule unit test for this exact payload shape to prevent regression.

Parent: #52061
Related to #52061

Generated by 🔍 [aw] Failure Investigator (6h) · agent · 165.2 AIC · ⌖ 50.6 AIC · ⊞ 5.3K ·

  • expires on Aug 18, 2026, 11:24 PM UTC-08:00

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions