Skip to content

sessionStart  hook stops running after adding  sandbox.userPolicy.filesystem  paths #5098

Description

@wibeck1

Describe the bug

Actual: The hook ran at session start, and its log showed it. After I added  readonlyPaths  ( /home//.copilot ,  /home//.nvm ) and  readwritePaths  ( …/.copilot/.cache/copilot/marketplaces ,  …/.copilot/installed-plugins ,  …/.copilot/plugin-data ) to  sandbox.userPolicy.filesystem , it never runs again.  /env  still lists the hook. The hook's first statement in the command appends a line to  $COPILOT_PLUGIN_DATA/hook-invoked.log , and that file is never created. No warning is shown, and the process logs contain no hook entries. Run by hand, the same command works.
Also unclear in the docs: The settings reference documents only  filesystem.deniedPaths . It doesn't document  readonlyPaths  or  readwritePaths , though the hooks docs say to grant hooks access via  sandbox.userPolicy .

Affected version

GitHub Copilot CLI 1.0.94.

Steps to reproduce the behavior

  1. Enable Sandbox
  2. Configure and install a sessionStart-Hook
  3. add readonly-Paths and readwrite-Paths (see above for which) to settings.json
  4. restart session, exit and then check whether the hook wrote logs -> no log written
  5. exit copilot
  6. run the hook's command manually -> log written

Expected behavior

Expected: A plugin's  hooks/hooks.json   SessionStart  command hook runs at every fresh start.

Additional context

WSL2 (Ubuntu), sandbox enabled.

Activity

  1. added theissue type on Oct 9, 2026
  2. caarlos0 commented on Oct 9, 2026

    @caarlos0
    Member

    Hi!

    You don't need to add ~/.copilot and what not as readonly - everything that's outside CWD, and not explicitly allowed, is already read only by default.

    That said, would need some logs (you can run /collect-debug-logs and send via email at my username github.com or post it in here.

    Also note that the sessionStart hook only runs when you actually send a message.

    FWIW, here's an example of what you should see if the hook tries to do something its sandbox policy wouldn't allow:

    Image
  3. added
    area:permissionsTool approval, security boundaries, sandbox mode, and directory restrictions
    area:pluginsPlugin system, marketplace, hooks, skills, extensions, and custom agents
    and removed on Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:permissionsTool approval, security boundaries, sandbox mode, and directory restrictionsarea:pluginsPlugin system, marketplace, hooks, skills, extensions, and custom agents

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions