github / github/copilot-cli

It should be possible to configure a set of commands the agent can run without permission

未关闭
#2,484 5 条评论 2 个 reaction 已指派 0 人 在 GitHub 查看
area:agents area:permissions
主要语言
Shell
星标
11.2k
派生
1.9k
平均合并
14 小时 16 分钟
30 天内合并 PR
6

描述

### Describe the feature or problem you'd like to solve

_No response_

### Proposed solution

Currently you can only set allow-all to allow the agent to execute commands without permission. Otherwise with every new session i have to approve every command over and over again.

The --allow-all flag bypasses all permission checks, which create real risks:
- Destructive commands like" rm-rf" could be e executed without confirmation
- Permission changes (chmod, chown) could silently alteer system security

A granular allowlist ( eg allow read, find, cat,ls but block rm, chmod, would provide a much better balance between autonomy and safety.

This should be configurable via instruction or agent files

### Example prompts or workflows

_No response_

### Additional context

_No response_

贡献指南

打开贡献指南

调研方向

Start by reviewing the existing --allow-all permission path and how instruction or agent files are configured. Define how a command allowlist coexists with confirmation and blocked commands, then verify that configured safe commands run without repeated approval while destructive commands still require permission.

由索引模型根据 Issue 内容生成。

评估

技术栈
shell
领域
cli, security
Issue 类型
功能
难度
5/5
预计耗时
一周以上
活跃度
冷清
描述清晰度
基本清楚
新手友好度
42/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。