github / github/copilot-sdk

Allow trusted host init scripts to preserve direct-script review

Offen
#2,466 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
vs-code
Vorherrschende Sprache
Java
Sterne
10.5k
Forks
1.5k
Ø Merge
1 T. 11 Std.
Gemergte PRs (30 T.)
128

Beschreibung

## Context

VS Code is adopting the public per-session `shell.initScripts` API so the SDK built-in shell tool can load the user's shell profile and activate the workspace-selected Python environment:

https://github.com/microsoft/vscode/pull/332593

## Observed behavior

With no init scripts configured, a direct script invocation can be reviewed using the script and interpreter content under the normal permission flow.

When the same session has any host-provided `shell.initScripts` entry, the direct script invocation instead requires explicit approval because the shell environment can alter the script action.

This is secure as a conservative default, but it means an SDK consumer cannot opt into a known, host-generated activation script without changing approval behavior for otherwise identical direct script commands.

## Ask

Please consider a public SDK contract for trusted host-provided init scripts that preserves safe direct-script review when possible.

Possible shapes include:

- allowing the SDK/runtime to incorporate the exact init-script content into the reviewed action/fingerprint; or
- adding explicit trust metadata for host-generated init scripts, with a conservative default for existing callers.

The behavior must remain secure when init scripts are user-controlled, mutable, unreadable, or otherwise cannot be bound to the reviewed action.

## Consumer requirements

- Per-session and updateable, matching `shell.initScripts`.
- Applies to the built-in shell tool.
- Does not weaken approval for arbitrary or unbound startup scripts.
- Works for Bash and PowerShell host activation scripts.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start by tracing the built-in shell tool's approval and direct-script review flow alongside the public per-session shell.initScripts API. Compare how Bash and PowerShell host activation scripts are represented, then determine how exact content or trust metadata could be bound to the reviewed action without weakening review for user-controlled or unreadable scripts; done means preserving safe direct-script review for explicitly trusted, updateable host scripts.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
java, powershell, python, shell
Bereich
developer-experience, security, tooling
Issue-Typ
Feature
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Aktiv
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.