session/request_permission.
Interactive sessions (chat)
By default the daemon auto-approves non-mutating kinds:readsearchthinkfetch
edit, delete, move, and execute are forwarded for human approval.
Override with GPR_AUTO_APPROVE_TOOL_KINDS (comma-separated). Set none to disable auto-approve.
Task (unattended) sessions
Task runs extend the auto-approve set withexecute because work happens in an isolated git worktree. Shell commands needed for builds/tests can proceed without tapping Approve on every call.
edit / delete / move still forward for approval unless you widen GPR_TASK_AUTO_APPROVE_TOOL_KINDS.
Why execute is gated in chat
ACP does not distinguish git status from destructive shell. Blanket-approving execute in interactive mode would auto-allow both.
Practical guidance
- Keep defaults for interactive work.
- Watch the phone for permission prompts on edits during tasks if your agent emits them.
- Do not set broad auto-approve on shared machines you do not trust.
