github / github/copilot-cli

`preToolUse` agent hook denial does not work

Open
#3,874 3 comments 0 reactions 0 assignees View on GitHub
area:permissions area:plugins
Dominant language
Shell
Stars
11.2k
Forks
1.9k
Avg merge
14h 16m
Merged PRs (30d)
6

Description

### Describe the bug

Running chat session from Copilot CLI, I have installed a hook that denies all commands.

### Affected version

- GitHub Copilot Chat Extension `v1.0.65`

### Steps to reproduce the behavior

**.github/hooks/hooks.json**

```json
{
"version": 1,
"hooks": {
"preToolUse": [
{
"cwd": "src",
"bash": "bin/Debug/net10.0/hook",
"powershell": "bin/Debug/net10.0/hook",
"timeoutSec": 15
}
]
}
}
```

A simple C# `hook.exe` program:

**Program.cs**

```csharp
Console.WriteLine("{\"permissionDecision\":\"deny\"}");
Environment.Exit(2);
```

Here is a simple session prompt:

> Give me the latest powershell `Get-Date`

I tried _everything_:

- Exit code `2`
- `{"permissionDecision": "deny"}` response to `preToolUse` hook events.
- `{"behavior":"deny"}` response to `permissionRequest` hook events.

Still, the tool is called and never denied.

### Expected behavior

The tool call SHOULD be denied.

### Additional context

_No response_

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the denial flow from .github/hooks/hooks.json with the C# Program.cs hook and the Copilot CLI session described. Compare the preToolUse exit code and permissionDecision output with the observed tool call; done means the requested tool is not executed when the hook denies it.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp, powershell, shell
Domain
cli, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
58/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.