Skip to content

Permission prompts should display the specific rule or command characteristic that triggered approval #4386

Description

@deymundson-cx

Describe the feature or problem you'd like to solve

When GitHub Copilot CLI requests permission to execute a command, the prompt does not explain which specific part of the command triggered the safeguard. This makes it difficult to understand why approval is required, evaluate whether the safeguard is behaving correctly, and tune AI behavior to avoid triggering a permission prompt

Proposed solution

Display the specific permission rule(s) or command characteristic(s) that triggered the approval requirement.

Example prompts or workflows

Example 1

Command:
Remove-Item -Recurse .\temp

Reason: Uses Remove-Item

Example 2

Command:
cp file.txt ../other-project/

Reason: Writes outside trusted directory

Example 2

Command:
cp file.txt ../other-project/

Reason: Writes outside trusted directory

Example 3

Command:
Get-Content "$logPath"

Reason: Uses string interpolation

Additional context

Other agent-based coding tools surface the specific action that triggered a permission request. This provides:

  • Better transparency
  • Greater user trust
  • Easier debugging of unexpected prompts
  • Improved understanding of permission boundaries
  • Better feedback when safeguards are overly broad or overly sensitive

Without this information, users are left guessing which command characteristic caused the approval request and cannot easily determine whether the safeguard behaved as intended.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions