github / github/copilot-cli

subagent permission approval lacks context and is confusing

Open
#3,684 1 comment 0 reactions 0 assignees View on GitHub
area:agents area:permissions
Dominant language
Shell
Stars
11.2k
Forks
1.9k
Avg merge
14h 16m
Merged PRs (30d)
6

Description

### Describe the bug

Linux subagents can run commands that the permission pattern only captures "/" as the directory which is super dangerous, without giving me the exact command will be run and context around it like a regular agent.

### Affected version

_No response_

### Steps to reproduce the behavior

1. run copilot-cli
2. ask it to run a command in subagent that require additional permission
3. find that permission itself got prompted, but reasoning/context isn't

### Expected behavior

I should be able to see which agent and its full glory

### Additional context

_No response_

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the permission prompt with the listed copilot-cli steps, then trace the subagent permission approval flow. Done means the prompt shows the full command, the agent identity, relevant reasoning or context, and the actual directory scope instead of only "/".

Written by the indexing model from the issue text.

Assessment

Tech stack
shell
Domain
cli, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.