github / github/copilot-cli

Permission Profiles: named, switchable permission presets (global + per-repo)

Abierto
#3,176 0 comentarios 2 reacciones 0 asignados Ver en GitHub
area:configuration area:permissions
Lenguaje dominante
Shell
Estrellas
11.2k
Forks
1.9k
Merge medio
14 h 16 min
PR fusionados (30 d)
6

Descripción

### Describe the feature or problem you'd like to solve

I typically run with `/allow-all` for maximum productivity, but sometimes I want to restrict the agent (e.g., no shell execution, read-only mode, or limited directory access) for sensitive tasks or specific repos. Currently there's no way to:

1. Save a named permission configuration and switch to it quickly
2. Define per-repo permission defaults so certain repos always start restricted
3. Toggle between "full trust" and "restricted" without manually re-configuring each session

Related issues #3028 and #3050 cover parts of this (MCP tool trust and persistent directories), but neither addresses switchable named profiles.

### Proposed solution

Introduce **permission profiles** — named sets of permission rules that can be defined at two levels:

**Global profiles** (`~/.copilot/permission-profiles.json`):
```json
{
"profiles": {
"full-access": { "allowAll": true },
"read-only": {
"allowedTools": ["view", "grep", "glob", "github-mcp-server-*"],
"denyTools": ["powershell", "edit", "create"]
},
"no-shell": {
"allowAll": true,
"denyTools": ["powershell"]
}
},
"default": "full-access"
}
```

**Per-repo profiles** (`.github/copilot-permissions.json`):
```json
{
"default": "no-shell",
"trustedDirectories": ["."],
"profiles": {
"no-shell": {
"allowAll": true,
"denyTools": ["powershell"]
}
}
}
```

**Switching profiles in-session:**
- `/profile list` — show available profiles
- `/profile use ` — switch to a profile
- `/profile show` — show current active profile and its rules

Per-repo profiles would take precedence over global ones (team-enforced guardrails).

### Example prompts or workflows

1. Start session in infra repo → automatically applies "no-shell" profile (team policy)
2. Working on a PR review → `/profile use read-only` to ensure no accidental edits
3. Ready to implement → `/profile use full-access` to switch back
4. New session in any repo → applies user's global default without needing `/allow-all` each time

### Additional context

GitHub Copilot CLI 1.0.43

This would complement #3028 (granular MCP tool trust) and #3050 (persistent directory allow lists) by providing the overarching framework for managing permission sets.

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Comienza revisando los formatos propuestos para ~/.copilot/permission-profiles.json global y .github/copilot-permissions.json por repositorio; después, sigue cómo la CLI gestiona actualmente la configuración de permisos. Define la precedencia de los perfiles y los comandos /profile list, /profile use y /profile show; se considera terminado cuando se puedan cambiar perfiles con nombre durante la sesión y los valores predeterminados del repositorio tengan prioridad sobre los perfiles globales.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
shell
Área
authorization, cli, security
Tipo de issue
Nueva funcionalidad
Dificultad
5/5
Tiempo estimado
Más de una semana
Estado de actividad
Tranquilo
Claridad
Bastante claro
Aptitud para principiantes
35/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.