github / github/copilot-cli

Command blocked in autopilot mode

Ouverte
#2,258 1 commentaire 2 réactions 0 personnes assignées Voir sur GitHub
area:agents
Langage dominant
Shell
Étoiles
11.2k
Forks
1.9k
Merge moyen
14 h 16 min
PR mergées (30 j)
6

Description

### Describe the bug

I'm running in autopilot and yolo mode to debug Github CI failures. The agent keeps issuing commands to check on progress bug then blocks them. These command blocks should not be there in autopilot yolo mode.

### Affected version

GitHub Copilot CLI 1.0.11.

### Steps to reproduce the behavior

1. Ask copilot to debug some Github CI/CD fail.
2. Sometimes it issues commands that are blocked.

Example:
```
● Now trigger and monitor with shorter check intervals:

● Trigger iOS CI (shell)
│ cd /Users/cdeil/code/stocadro/stocadro-ai && gh workflow run "Release iOS (TestFlight)" && sleep 5 && gh run list -w "Release iOS (TestFlight)" -L 1
└ 8 lines...

✗ Check job progress after 3 min (shell)
│ cd /Users/cdeil/code/stocadro/stocadro-ai && sleep 180 && gh run view --job=$(gh api repos/stocadro/stocadro-ai/actions/runs/23493270159/jobs --jq '.jobs[0].id') 2>&1 | head -25
└ Command blocked: contains dangerous shell expansion patterns (e.g., parameter transformation, indirect expansion, or nested command substitution) that could enable arbitrary code
execution. Please rewrite the command without these expansion patterns.
```

### Expected behavior

In YOLO and autopilot mode no command should be blocked. Certainly such typical shell expansion patterns shouldn't be blocked.

### Additional context

_No response_

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Start by reproducing the shown gh workflow command in GitHub Copilot CLI 1.0.11 with autopilot and YOLO enabled, then trace the command-safety check that reports dangerous shell expansion patterns. Done means valid commands are not blocked in those modes while unsafe commands remain protected.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
shell
Domaine
cli, security
Type d'issue
Bug
Difficulté
4/5
Temps estimé
3-5 jours
Activité
Calme
Clarté
Plutôt claire
Accessibilité débutants
45/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.