github / github/copilot-cli

[ACP] toolCall.title contains high-level summary instead of executable command, hiding shell command in client approval modals

未关闭
#4,335 0 条评论 4 个 reaction 已指派 0 人 在 GitHub 查看
area:non-interactive area:tools
主要语言
Shell
星标
11.2k
派生
1.9k
平均合并
14 小时 16 分钟
30 天内合并 PR
6

描述

### Describe the bug

When running the GitHub Copilot CLI in Agent Context Protocol (ACP) mode (e.g., connected to host editors like Zed), `toolCall.title` is populated with a high-level natural language summary (e.g., `"Search whole monorepo for double-entry"`) while the actual shell execution string is nested deep inside `toolCall.rawInput.command`.

Because ACP host clients rely on standard fields like `title` or top-level arguments to render command preview cards in their permission dialogs, users are asked to approve tool execution without being able to see the underlying shell command, flags, or parameters.

During a tool approval request, Copilot CLI ACP emits a JSON-RPC payload structured as follows:

```
{
"sessionId": "d32e979a-eaa8-4e53-a31a-f9a1dba6bc09",
"toolCall": {
"toolCallId": "call-9480410f-3f47-441c-bcc3-decf647077aa-15",
"title": "Search whole monorepo for double-entry",
"kind": "execute",
"status": "pending",
"rawInput": {
"command": "grep -rn -i 'double.entry\\|double_entry\\|DoubleEntry' ./ --include='*.ts' 2>/dev/null | head -50; ls ./",
"commands": [
"grep -rn -i 'double.entry\\|double_entry\\|DoubleEntry' ./ --include='*.ts' 2>/dev/null | head -50; ls ./"
]
}
},
"options": [
{
"optionId": "allow_once",
"kind": "allow_once",
"name": "Allow once"
},
{
"optionId": "allow_always",
"kind": "allow_always",
"name": "Always allow"
},
{
"optionId": "reject_once",
"kind": "reject_once",
"name": "Deny"
}
]
}
```

`toolCall.title` contains the high-level intent: `"Search whole monorepo for double-entry"`.

The actual raw command string is only present inside `rawInput.command` / `rawInput.commands`.

In ACP host clients (such as Zed), the UI permission modal displays `toolCall.title` as the title/code snippet preview, causing the actual executable string to remain completely hidden from the user during authorization

### Affected version

GitHub Copilot CLI 1.0.77

### Steps to reproduce the behavior

### **Steps to Reproduce**

1. Configure GitHub Copilot CLI as an ACP server in Zed (via the ACP Registry or in `settings.json`):
```json
{
"agent_servers": {
"Copilot": {
"type": "custom",
"command": "copilot",
"args": ["--acp"]
}
}
}

```

2. Open any workspace or codebase in Zed.
3. Open the Agent Panel (`Cmd+?` on macOS / `Ctrl+?` on Linux/Windows) and start a new thread using the **Copilot** ACP agent.
4. Enter a prompt that triggers a shell tool call requiring client approval (e.g., *"Search the whole monorepo for double-entry pattern"*).
5. When Zed displays the tool execution approval dialog, observe the command preview card.

### **Observed Result**

The approval card displays the natural-language intent string (`"Search whole monorepo for double-entry"`) in place of the executable command. The actual shell command (`grep -rn -i ...`) remains hidden inside `toolCall.rawInput.command`.

### **Expected Result**

The approval dialog should render the actual raw shell command string (or include it within `toolCall.title` / standard tool arguments), allowing the user to inspect the exact flags, paths, and commands before granting execution authorization.

### Expected behavior

`toolCall.title` should explicitly contain or start with the raw command string being executed (e.g., `grep -rn -i ...`),

### Additional context

_No response_

贡献指南

打开贡献指南

调研方向

首先,在 Zed 中使用 `--acp` 服务器复现 ACP 流程,并检查在审批请求中如何填充 `toolCall.title`、`rawInput.command` 和 `rawInput.commands`。跟踪 ACP 审批 payload 的生成,并验证生成的客户端预览在授权前会展示确切的 shell 命令,包括 flags 和参数。

由索引模型根据 Issue 内容生成。

评估

技术栈
shell
领域
cli, security
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
冷清
描述清晰度
基本清楚
新手友好度
48/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。