github / github/copilot-cli

Permission prompts should display the specific rule or command characteristic that triggered approval

Open
#4,386 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

area:permissions
Dominant language
Shell
Stars
11.2k
Forks
1.9k
Avg merge
14h 16m
Merged PRs (30d)
6

Description

Describe the feature or problem you'd like to solve

When GitHub Copilot CLI requests permission to execute a command, the prompt does not explain which specific part of the command triggered the safeguard. This makes it difficult to understand why approval is required, evaluate whether the safeguard is behaving correctly, and tune AI behavior to avoid triggering a permission prompt

Proposed solution

Display the specific permission rule(s) or command characteristic(s) that triggered the approval requirement.

Example prompts or workflows
Example 1

Command:
Remove-Item -Recurse .\temp

Reason: Uses Remove-Item

Example 2

Command:
cp file.txt ../other-project/

Reason: Writes outside trusted directory

Example 2

Command:
cp file.txt ../other-project/

Reason: Writes outside trusted directory

Example 3

Command:
Get-Content "$logPath"

Reason: Uses string interpolation

Additional context

Other agent-based coding tools surface the specific action that triggered a permission request. This provides:

  • Better transparency
  • Greater user trust
  • Easier debugging of unexpected prompts
  • Improved understanding of permission boundaries
  • Better feedback when safeguards are overly broad or overly sensitive

Without this information, users are left guessing which command characteristic caused the approval request and cannot easily determine whether the safeguard behaved as intended.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start at the Copilot CLI permission-prompt and command-safeguard entry points; trace how approval requests are created for the Remove-Item, cp, and Get-Content examples. Done means each prompt identifies the rule or command characteristic that triggered it, with coverage for the stated workflows.

Written by the indexing model from the issue text.

Assessment

Tech stack
shell
Domain
cli, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.