github / github/copilot-cli

Add support for blocked_tools / allowed_tools for Copilot CLI task tool sub-agents

未關閉
#3,133 0 則留言 1 個 reaction 已指派 0 人 在 GitHub 檢視
area:agents area:permissions
主要語言
Shell
星號
11.2k
分支
1.9k
平均合併
14 小時 16 分鐘
30 天內合併 PR
6

描述

### Describe the feature or problem you'd like to solve

When launching sub-agents via the "task" tool, there's no way to restrict which tools the agent can access. I run a multi-model PR review skill that launches parallel general-purpose agents to review ADO PRs. These agents need ADO read tools to fetch diffs, but should never call write tools like repo_pull_request_thread_write. Despite strong prompt instructions (boxed warnings, banned tool lists, repeated reminders), agents occasionally post full review comments directly to PRs under my identity without authorization. This happened on 4 PRs before I caught it.

### Proposed solution

Add optional blocked_tools and/or allowed_tools parameters to the task tool:

agent_type: general-purpose
mode: background
blocked_tools: ["repo_pull_request_thread_write", "repo_pull_request_write"]

The runtime would reject blocked tool calls before they reach the MCP server. Text-only instructions aren't reliable -- LLMs sometimes override them. The explore agent type removes all MCP tools, but that's too restrictive (loses read access too). There's no middle ground today.

### Example prompts or workflows

_No response_

### Additional context

_No response_

貢獻指南

開啟貢獻指南

研究方向

從 task tool 的參數處理以及分派 sub-agents tool 呼叫的執行階段路徑著手;比較 general-purpose 和 explore agents 如何取得 tool 存取權。完成的標準是遵循選用的 allowed_tools 或 blocked_tools 設定,並在遭封鎖的呼叫到達 MCP server 之前拒絕它們。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
shell
領域
cli, security
Issue 類型
功能
難度
5/5
預估耗時
一週以上
活躍度
冷清
描述清晰度
基本清楚
新手友好度
45/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。