Summary
With gh-aw v0.89.21 (AWF v0.28.23), every Claude-engine run logs one TCP_DENIED for api.anthropic.com:443 from the agent container, within a second of Claude Code starting. The run itself is fine. But the denial lands in the firewall summary on every run, and users read it as a regression after upgrading.
Cause
Claude Code fetches Anthropic's MCP registry (GET /mcp-registry/v0/servers on api.anthropic.com, unauthenticated) at startup. The result only marks which configured MCP servers count as "official" for Claude Code's analytics events; nothing functional reads it. The fetch ignores ANTHROPIC_BASE_URL, so it doesn't go through the api-proxy. Since api.anthropic.com is no longer on the agent allowlist, squid denies it, and claude-debug.log records:
[ERROR] Failed to fetch MCP registry: self signed certificate
Claude Code skips this fetch when it runs with --strict-mcp-config.
Proposal
Have the Claude engine pass --strict-mcp-config next to the --mcp-config argument it already adds (pkg/workflow/claude_engine.go). gh-aw is the sole MCP source for the agent, so no gh-aw-configured server is lost. Strict mode also stops Claude from loading MCP config committed in the target repo (for example .mcp.json), which looks consistent with gh-aw owning the agent's MCP surface.
Re-allowlisting api.anthropic.com for the agent would also silence it. But that reopens the direct agent-to-Anthropic path the api-proxy closes, for a call with no functional value.
Evidence
Same workflow (agent-review-pr), Claude Code 2.1.285, Sonnet 5.5, compiled with gh-aw v0.89.21:
- Without the flag:
sandbox/firewall/logs/access.log has 172.30.0.20 api.anthropic.com:443 ... CONNECT 200 TCP_DENIED:HIER_NONE, and the debug log has the error above.
- With
engine.args: ["--strict-mcp-config"]: 0 TCP_DENIED and no api.anthropic.com connection from the agent. There's no registry line in the debug log, and the GitHub MCP server via the MCP gateway still connects (MCP server "github": Successfully connected (transport: http)).
A local check on Claude Code 2.1.287 matches: the debug log shows [mcp-registry] Loaded 294 official MCP URLs by default and no registry fetch with --strict-mcp-config. Setting CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1 also suppresses it, but it turns off feature-flag fetching too, so it seems a poorer default.
As a workaround, users can add engine.args: ["--strict-mcp-config"] to the workflow's engine: block.
Summary
With gh-aw v0.89.21 (AWF v0.28.23), every Claude-engine run logs one
TCP_DENIEDforapi.anthropic.com:443from the agent container, within a second of Claude Code starting. The run itself is fine. But the denial lands in the firewall summary on every run, and users read it as a regression after upgrading.Cause
Claude Code fetches Anthropic's MCP registry (
GET /mcp-registry/v0/serversonapi.anthropic.com, unauthenticated) at startup. The result only marks which configured MCP servers count as "official" for Claude Code's analytics events; nothing functional reads it. The fetch ignoresANTHROPIC_BASE_URL, so it doesn't go through the api-proxy. Sinceapi.anthropic.comis no longer on the agent allowlist, squid denies it, andclaude-debug.logrecords:Claude Code skips this fetch when it runs with
--strict-mcp-config.Proposal
Have the Claude engine pass
--strict-mcp-confignext to the--mcp-configargument it already adds (pkg/workflow/claude_engine.go). gh-aw is the sole MCP source for the agent, so no gh-aw-configured server is lost. Strict mode also stops Claude from loading MCP config committed in the target repo (for example.mcp.json), which looks consistent with gh-aw owning the agent's MCP surface.Re-allowlisting
api.anthropic.comfor the agent would also silence it. But that reopens the direct agent-to-Anthropic path the api-proxy closes, for a call with no functional value.Evidence
Same workflow (agent-review-pr), Claude Code 2.1.285, Sonnet 5.5, compiled with gh-aw v0.89.21:
sandbox/firewall/logs/access.loghas172.30.0.20 api.anthropic.com:443 ... CONNECT 200 TCP_DENIED:HIER_NONE, and the debug log has the error above.engine.args: ["--strict-mcp-config"]: 0TCP_DENIEDand noapi.anthropic.comconnection from the agent. There's no registry line in the debug log, and the GitHub MCP server via the MCP gateway still connects (MCP server "github": Successfully connected (transport: http)).A local check on Claude Code 2.1.287 matches: the debug log shows
[mcp-registry] Loaded 294 official MCP URLsby default and no registry fetch with--strict-mcp-config. SettingCLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1also suppresses it, but it turns off feature-flag fetching too, so it seems a poorer default.As a workaround, users can add
engine.args: ["--strict-mcp-config"]to the workflow'sengine:block.