Skip to content

Steering message in preToolUse "ask" denial is silently dropped #4237

Description

@sfuqua

Describe the bug

When preToolUse returns permissionDecision: 'ask'. the CLI shows a specialized permission prompt for the tool that includes any rationale the hook returned, along with a confirm/deny prompt.

The deny prompt allows custom text, similar to the standard permissionRequest prompt.

However, this custom text does not make it back to the session, so no steering is possible.

Image Image

Affected version

1.0.74-4

Steps to reproduce the behavior

  1. Scaffold a basic project with .github\hooks and one file:

.github\hooks\pre-tool-use-demo.json

{
  "version": 1,
  "hooks": {
    "preToolUse": [
      {
        "type": "command",
        "powershell": "'{\"permissionDecision\":\"ask\",\"permissionDecisionReason\":\"preToolUse Demo: Allow the agent to use a tool?\"}'",
        "cwd": ".",
        "timeoutSec": 10
      }
    ]
  }
}
  1. Invoke copilot inside of the scaffolded "project".
  2. Ask the session to use any tool, e.g.
Please use your `view` tool to read `.github/hooks/pre-tool-use-demo.json`
  1. Deny the prompt with a steering message, such as "Please confirm you see this response"
  2. Observe that the custom steering message is not passed to the agent

Expected behavior

The steering message should be passed to the agent, allowing correcting behavior via HITL.

Additional context

No response

Activity

added theissue type on Jul 23, 2026
added
area:permissionsTool approval, security boundaries, sandbox mode, and directory restrictions
and removed on Jul 24, 2026

sfuqua commented on Aug 13, 2026

@sfuqua
Author

Notably -

SDK docs say about permissionDecisionReason

Explanation shown to user (for deny/ask)

General GHCP docs say

Reason shown to the agent. Required when decision is "deny".

Claude Code docs say

For "allow" and "ask", shown to the user but not Claude. For "deny", shown to Claude. For "defer", ignored

This seems like a clear bug in the CLI mixing the behavior of the field between "ask" and "deny" and ignoring user steering input. For "ask", the field should be shown to the user and the user's input (on denial) should be shown to the agent.

This is an interop issue.

copilot-cli-bot commented on Sep 19, 2026

@copilot-cli-bot

This appears to be resolved as of GitHub Copilot CLI v1.0.86. Please update to that release or a newer stable version. We're closing this as completed. If it still happens, please comment with your version and reproduction steps.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:permissionsTool approval, security boundaries, sandbox mode, and directory restrictions

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions