github / github/copilot-cli

[ACP] toolCall.title contains high-level summary instead of executable command, hiding shell command in client approval modals

Đang mở
#4,335 0 bình luận 4 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

area:non-interactive area:tools
Ngôn ngữ chính
Shell
Star
11.2k
Fork
1.9k
Merge trung bình
14 giờ 16 phút
Pull request đã merge (30 ngày)
6

Mô tả

Describe the bug

When running the GitHub Copilot CLI in Agent Context Protocol (ACP) mode (e.g., connected to host editors like Zed), toolCall.title is populated with a high-level natural language summary (e.g., "Search whole monorepo for double-entry") while the actual shell execution string is nested deep inside toolCall.rawInput.command.

Because ACP host clients rely on standard fields like title or top-level arguments to render command preview cards in their permission dialogs, users are asked to approve tool execution without being able to see the underlying shell command, flags, or parameters.

During a tool approval request, Copilot CLI ACP emits a JSON-RPC payload structured as follows:

{
  "sessionId": "d32e979a-eaa8-4e53-a31a-f9a1dba6bc09",
  "toolCall": {
    "toolCallId": "call-9480410f-3f47-441c-bcc3-decf647077aa-15",
    "title": "Search whole monorepo for double-entry",
    "kind": "execute",
    "status": "pending",
    "rawInput": {
      "command": "grep -rn -i 'double.entry\\|double_entry\\|DoubleEntry' ./ --include='*.ts' 2>/dev/null | head -50; ls ./",
      "commands": [
        "grep -rn -i 'double.entry\\|double_entry\\|DoubleEntry' ./ --include='*.ts' 2>/dev/null | head -50; ls ./"
      ]
    }
  },
  "options": [
    {
      "optionId": "allow_once",
      "kind": "allow_once",
      "name": "Allow once"
    },
    {
      "optionId": "allow_always",
      "kind": "allow_always",
      "name": "Always allow"
    },
    {
      "optionId": "reject_once",
      "kind": "reject_once",
      "name": "Deny"
    }
  ]
}

toolCall.title contains the high-level intent: "Search whole monorepo for double-entry".

The actual raw command string is only present inside rawInput.command / rawInput.commands.

In ACP host clients (such as Zed), the UI permission modal displays toolCall.title as the title/code snippet preview, causing the actual executable string to remain completely hidden from the user during authorization

Affected version

GitHub Copilot CLI 1.0.77

Steps to reproduce the behavior
Steps to Reproduce
  1. Configure GitHub Copilot CLI as an ACP server in Zed (via the ACP Registry or in settings.json):
{
  "agent_servers": {
    "Copilot": {
      "type": "custom",
      "command": "copilot",
      "args": ["--acp"]
    }
  }
}

  1. Open any workspace or codebase in Zed.
  2. Open the Agent Panel (Cmd+? on macOS / Ctrl+? on Linux/Windows) and start a new thread using the Copilot ACP agent.
  3. Enter a prompt that triggers a shell tool call requiring client approval (e.g., "Search the whole monorepo for double-entry pattern").
  4. When Zed displays the tool execution approval dialog, observe the command preview card.
Observed Result

The approval card displays the natural-language intent string ("Search whole monorepo for double-entry") in place of the executable command. The actual shell command (grep -rn -i ...) remains hidden inside toolCall.rawInput.command.

Expected Result

The approval dialog should render the actual raw shell command string (or include it within toolCall.title / standard tool arguments), allowing the user to inspect the exact flags, paths, and commands before granting execution authorization.

Expected behavior

toolCall.title should explicitly contain or start with the raw command string being executed (e.g., grep -rn -i ...),

Additional context

No response

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Hướng nghiên cứu

Bắt đầu bằng cách tái hiện luồng ACP với máy chủ --acp trong Zed và kiểm tra cách toolCall.title, rawInput.commandrawInput.commands được điền cho các yêu cầu phê duyệt. Theo dõi quá trình tạo payload phê duyệt ACP và xác minh rằng phần xem trước của client tạo ra hiển thị chính xác lệnh shell, bao gồm cả các flag và tham số, trước khi ủy quyền.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
shell
Lĩnh vực
cli, security
Loại issue
Lỗi
Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức độ hoạt động
Ít trao đổi
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
48/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.