github / github/copilot-cli

Feature Request: Per-Tool Permission Settings for Copilot CLI

Open
#1,995 1 comment 8 reactions 0 assignees View on GitHub
area:configuration area:permissions
Dominant language
Shell
Stars
11.2k
Forks
1.9k
Avg merge
14h 16m
Merged PRs (30d)
6

Description

**Summary:**
Currently, GitHub Copilot CLI requires explicit approval for each tool usage, or allows all tools globally with `/allow-all`. I'd like to request a feature to set persistent approval for specific tools individually.

**Use Case:**
In my workflow, I frequently use certain tools (e.g., `read`, `find`, `sed`) repeatedly throughout the session. Having to approve each tool invocation adds friction and slows down development. While I appreciate the security safeguard, a granular permission model would improve the developer experience.

**Proposed Solution:**
Add a command or configuration to permanently allow specific tools while keeping others in "ask-per-use" mode, such as:
- `/allow-tool ` - Add a tool to the allowed list
- `/deny-tool ` - Remove a tool from the allowed list
- `/list-allowed-tools` - View currently allowed tools

This would give developers finer-grained control over automation while maintaining security boundaries.

**Alternative Consideration:**
Could also be implemented via a configuration file (e.g., `~/.copilot/tool-permissions.json`) to persist settings across sessions.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.