CLion Copilot CLI
I'm struggling with this one a bit because the answer seems to lie somewhere between MS/GitHub/Copilot-plugin/CLion.
I don't seem to be able to find a definitive answer about how to configure copilot in CLion (using the copilot CLI harness).
In particular, right now I'm looking at tool approvals. For example, I want it to be able to run `cd`, `cat`, `head`, etc without asking me for permission each time.
Question 1:
The copilot docs say that operations are separated into “read-only" actions which are automatically allowed, and “tools that can modify your system” which require explicit approval. However, empirically, this is not the case, because my clion copilot CLI session is asking me for permission to `cd`. So, what is the tool approval model for copilot CLI running in clion?
Question 2:
Linux tools are… many-faceted. Take find as an example.
- `find -name ‘foo.*’` is innocuous.
- `find -name ‘foo.*’ -delete` is not.
- `find -name ‘foo.*’ -exec …` depends.
When I receive an approval popup in clion, it asks me to approve `find`, or approve `git`. What am I actually approving in that case? All applications of find/git/etc? Or only read-only applications of those tools? Is there documentation that lists exactly what operations we're approving under each of these?
Question 3:
After running into the above, I attempted to get more detailed in my approvals by using manual configuration, which is supposed to support regexes. Here, my problem is that there are a bunch of documented locations to put this config, and none of them appear to work. I have tried:
- ~/.copilot/permissions-config.json
- ~/.config/github-copilot/intellij/permissions-config.json
- adding entries to Settings | Tools | GitHub Copilot | Chat | Auto Approve
None of these appear to work.
Any tips/pointers?
Please sign in to leave a comment.
In the meantime:
1) Plugin version 1.18.0 (18 Sep 2026) added "Assisted Approvals" (Public Preview) for Copilot agent sessions. It approves low-risk tool calls automatically and still prompts for higher-risk ones, which is close to the read-only behavior you want. Details are in "What's New" at https://plugins.jetbrains.com/plugin/17718-github-copilot--your-ai-pair-programmer
2) For the standalone Copilot CLI, GitHub documents that approving a tool for the session allows it "with any options": https://docs.github.com/en/copilot/how-tos/use-copilot-agents/use-copilot-cli. If the plugin's popup uses the same model, approving `find` also covers `find -delete`. I have not verified this in the plugin itself.
If you use GitHub Copilot from the agent picker in the JetBrains AI Chat instead, let me know. That integration has its own approval prompts, and an option to auto-approve read-only commands there is requested in https://youtrack.jetbrains.com/issue/LLM-30092