From 8816cb83584a83f2faaa52d0a18c196668ca1c93 Mon Sep 17 00:00:00 2001 From: kirillk Date: Mon, 6 Apr 2026 10:13:32 -0400 Subject: [PATCH] fix(cli): plan mode asks for edits outside plan files; sub-agents inherit caller edit restrictions --- packages/opencode/src/agent/agent.ts | 4 ++-- packages/opencode/src/tool/task.ts | 7 +++++++ 2 files changed, 9 insertions(+), 2 deletions(-) diff --git a/packages/opencode/src/agent/agent.ts b/packages/opencode/src/agent/agent.ts index 8bfbe786a21..9055c646337 100644 --- a/packages/opencode/src/agent/agent.ts +++ b/packages/opencode/src/agent/agent.ts @@ -224,7 +224,7 @@ export namespace Agent { }, plan: { name: "plan", - description: "Plan mode. Disallows all edit tools.", + description: "Plan mode. Only allows editing plan files; asks before editing anything else.", options: {}, permission: PermissionNext.merge( defaults, @@ -235,7 +235,7 @@ export namespace Agent { [path.join(Global.Path.data, "plans", "*")]: "allow", }, edit: { - "*": "deny", + "*": "ask", // kilocode_change: ask (not deny) so user can approve edits outside plan files [path.join(".kilo", "plans", "*.md")]: "allow", // kilocode_change [path.join(".opencode", "plans", "*.md")]: "allow", // kilocode_change: .opencode fallback [path.relative(Instance.worktree, path.join(Global.Path.data, path.join("plans", "*.md")))]: "allow", diff --git a/packages/opencode/src/tool/task.ts b/packages/opencode/src/tool/task.ts index 7b7eafdcb84..a36b8715a2e 100644 --- a/packages/opencode/src/tool/task.ts +++ b/packages/opencode/src/tool/task.ts @@ -63,6 +63,12 @@ export const TaskTool = Tool.define("task", async (ctx) => { const allowsTask = agent.permission.some((rule) => rule.permission === "task" && rule.action === "allow") // kilocode_change + // kilocode_change start — inherit edit restrictions from the calling agent so sub-agents + // cannot perform actions the parent agent is not allowed to perform. + const caller = await Agent.get(ctx.agent) + const editRules = caller?.permission.filter((r) => r.permission === "edit") ?? [] + // kilocode_change end + const session = await iife(async () => { if (params.task_id) { const found = await Session.get(params.task_id).catch(() => {}) @@ -97,6 +103,7 @@ export const TaskTool = Tool.define("task", async (ctx) => { action: "allow" as const, permission: t, })) ?? []), + ...editRules, // kilocode_change — propagate caller's edit restrictions ], }) })