AllowOnly Guard Smoke Test Results
Policy : repos=["github/gh-aw*"], min-integrity=approved
Run : https://github.com/github/gh-aw-mcpg/actions/runs/24889825169
In-Scope Access (github/gh-aw*)
Tool
Target
Result
Status
list_issues
gh-aw-mcpg
3 issues returned
✅
list_pull_requests
gh-aw-mcpg
3 PRs returned
✅
list_commits
gh-aw-mcpg
3 commits returned
✅
get_file_contents
gh-aw-mcpg
README.md content returned
✅
list_branches
gh-aw-mcpg
5 branches returned
✅
search_code
gh-aw-mcpg
40 results returned
✅
list_issues
gh-aw
Accessible; 3 items integrity-filtered (below "approved")
✅
get_file_contents
gh-aw
Accessible; filtered by integrity (metadata below "unapproved")
✅
Out-of-Scope Access (octocat/Hello-World)
Tool
Result
Status
list_issues
All items filtered by integrity policy (non-member authors)
✅
list_pull_requests
All items filtered by integrity policy
✅
list_commits
All items filtered by integrity policy
✅
get_file_contents
Filtered by integrity policy
✅
search_code
Filtered by integrity policy
✅
Global APIs
Tool
Result
Status
search_repositories
All results filtered by integrity policy
✅
search_users
Tool not available in this environment
N/A
Integrity Filtering
Observation
Status
gh-aw issues: 3 items filtered — authors lack OWNER/MEMBER/COLLABORATOR association (below "approved")
✅
octocat/Hello-World all content filtered — external repo content has no org membership integrity
✅
gh-aw-mcpg issues: all visible items passed (bot/automation PRs treated as approved)
✅
Summary
In-Scope Access: 8/8 ✅
Out-of-Scope Blocked: 5/5 ✅
Global APIs Blocked: 1/1 ✅ (search_users N/A)
Integrity Filtering: ✅
Overall: PASS
Note
🔒 Integrity filter blocked 17 items
The following items were blocked because they don't meet the GitHub integrity level.
To allow these resources, lower min-integrity in your GitHub frontmatter:
tools :
github :
min-integrity : approved # merged | approved | unapproved | none
🛡️ AllowOnly guard smoke test by Smoke AllowOnly
AllowOnly Guard Smoke Test Results
Policy: repos=["github/gh-aw*"], min-integrity=approved
Run: https://github.com/github/gh-aw-mcpg/actions/runs/24889825169
In-Scope Access (github/gh-aw*)
Out-of-Scope Access (octocat/Hello-World)
Global APIs
Integrity Filtering
Summary
Note
🔒 Integrity filter blocked 17 items
The following items were blocked because they don't meet the GitHub integrity level.
list_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "unapproved".list_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "unapproved".list_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "unapproved".get_file_contents: has lower integrity than agent requires. The agent cannot read data with integrity below "unapproved".list_commits: has lower integrity than agent requires. The agent cannot read data with integrity below "unapproved".list_commits: has lower integrity than agent requires. The agent cannot read data with integrity below "unapproved".list_commits: has lower integrity than agent requires. The agent cannot read data with integrity below "unapproved".search_code: has lower integrity than agent requires. The agent cannot read data with integrity below "unapproved".list_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "unapproved".list_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "unapproved".list_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "unapproved".search_repositories: has lower integrity than agent requires. The agent cannot read data with integrity below "unapproved".search_repositories: has lower integrity than agent requires. The agent cannot read data with integrity below "unapproved".search_repositories: has lower integrity than agent requires. The agent cannot read data with integrity below "unapproved".list_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "unapproved".list_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "unapproved".To allow these resources, lower
min-integrityin your GitHub frontmatter: