fix(cli): plan mode asks for edits outside plan files; sub-agents inherit caller edit restrictions

This commit is contained in:
kirillk
2026-04-06 10:13:32 -04:00
parent e10324aa7f
commit 8816cb8358
2 changed files with 9 additions and 2 deletions
+2 -2
View File
@@ -224,7 +224,7 @@ export namespace Agent {
},
plan: {
name: "plan",
description: "Plan mode. Disallows all edit tools.",
description: "Plan mode. Only allows editing plan files; asks before editing anything else.",
options: {},
permission: PermissionNext.merge(
defaults,
@@ -235,7 +235,7 @@ export namespace Agent {
[path.join(Global.Path.data, "plans", "*")]: "allow",
},
edit: {
"*": "deny",
"*": "ask", // kilocode_change: ask (not deny) so user can approve edits outside plan files
[path.join(".kilo", "plans", "*.md")]: "allow", // kilocode_change
[path.join(".opencode", "plans", "*.md")]: "allow", // kilocode_change: .opencode fallback
[path.relative(Instance.worktree, path.join(Global.Path.data, path.join("plans", "*.md")))]: "allow",
+7
View File
@@ -63,6 +63,12 @@ export const TaskTool = Tool.define("task", async (ctx) => {
const allowsTask = agent.permission.some((rule) => rule.permission === "task" && rule.action === "allow") // kilocode_change
// kilocode_change start — inherit edit restrictions from the calling agent so sub-agents
// cannot perform actions the parent agent is not allowed to perform.
const caller = await Agent.get(ctx.agent)
const editRules = caller?.permission.filter((r) => r.permission === "edit") ?? []
// kilocode_change end
const session = await iife(async () => {
if (params.task_id) {
const found = await Session.get(params.task_id).catch(() => {})
@@ -97,6 +103,7 @@ export const TaskTool = Tool.define("task", async (ctx) => {
action: "allow" as const,
permission: t,
})) ?? []),
...editRules, // kilocode_change — propagate caller's edit restrictions
],
})
})