github / github/copilot-cli

Local MCP URLs that are supposed to be not covered by MCP approval policy are banned anyway

Open
#2,814 0 comments 0 reactions 0 assignees View on GitHub
area:enterprise area:mcp
Dominant language
Shell
Stars
11.2k
Forks
1.9k
Avg merge
14h 16m
Merged PRs (30d)
6

Description

### Describe the bug

My company uses GH Copilot Enterprise.

Generally MCP servers need to be approved, but several local URLs are supposed to be allowed to be run without any approval:

Image

GH Copilot CLI failed to add the MCP server on http://127.0.0.1:54000/mcp:

Image

### Affected version

1.0.31

### Steps to reproduce the behavior

see above

### Expected behavior

see above

### Additional context

OS: Linux

### Questions

Where in the settings is this list of URLs set?
(I am not an enterprise admin, I need to tell them)

Does this policy exemption really work? Did anybody test it at the GitHub side?

Why might this not be working?

Contributor guide

Open the contributing guide

Research direction

No source file or test is named. Start by reproducing the failure on Linux with Copilot CLI 1.0.31 and the local MCP URL described in the report; trace where the enterprise MCP approval policy is applied. Done means determining why the documented local-URL exemption is rejected and adding a regression check for the expected exemption behavior.

Written by the indexing model from the issue text.

Assessment

Tech stack
github, shell
Domain
cli, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.