`preToolUse` agent hook denial does not work
- 主要語言
- Shell
- 星號
- 11.2k
- 分支
- 1.9k
- 平均合併
- 14 小時 16 分鐘
- 30 天內合併 PR
- 6
描述
### Describe the bug
Running chat session from Copilot CLI, I have installed a hook that denies all commands.
### Affected version
- GitHub Copilot Chat Extension `v1.0.65`
### Steps to reproduce the behavior
**.github/hooks/hooks.json**
```json
{
"version": 1,
"hooks": {
"preToolUse": [
{
"cwd": "src",
"bash": "bin/Debug/net10.0/hook",
"powershell": "bin/Debug/net10.0/hook",
"timeoutSec": 15
}
]
}
}
```
A simple C# `hook.exe` program:
**Program.cs**
```csharp
Console.WriteLine("{\"permissionDecision\":\"deny\"}");
Environment.Exit(2);
```
Here is a simple session prompt:
> Give me the latest powershell `Get-Date`
I tried _everything_:
- Exit code `2`
- `{"permissionDecision": "deny"}` response to `preToolUse` hook events.
- `{"behavior":"deny"}` response to `permissionRequest` hook events.
Still, the tool is called and never denied.
### Expected behavior
The tool call SHOULD be denied.
### Additional context
_No response_
貢獻指南
研究方向
Start by reproducing the denial flow from .github/hooks/hooks.json with the C# Program.cs hook and the Copilot CLI session described. Compare the preToolUse exit code and permissionDecision output with the observed tool call; done means the requested tool is not executed when the hook denies it.
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- csharp, powershell, shell
- 領域
- cli, security
- Issue 類型
- 缺陷
- 難度
- 3/5
- 預估耗時
- 1-2 天
- 活躍度
- 冷清
- 描述清晰度
- 基本清楚
- 新手友好度
- 58/100