It appears that none of the non-github mcp servers are being configured with the correct guard policies, i.e., a write-sink with accept set to "*". https://github.com/github/gh-aw/actions/runs/23179147368/job/67348177774#step:41:1