* Support continuous reads
* Remove adjusted read requests if grep result is not managing it anymore
* Improve adjustment code
* Improve reservation code
* Only emit event if a session is evicted
* More telemetry
* Add setting to package.json
* Refactor code for readability
* Fix test
Long lines in read_file output were getting pruned by the token-budget
prompt renderer, so the agent saw an empty result and looped — adding
unbounded session log size each retry. Truncate any line over 2000
characters at the source with a `[truncated]` marker, and append a
notice when any line was truncated so the model knows the data is
abbreviated rather than missing.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
In the agents window, each chat session has its own working directory
that may differ from the current workspace folders (which change when
switching between sessions). This caused tools to search the wrong
folder, show spurious 'Allow reading external files?' prompts, and
render incorrect workspace_info in the system prompt.
Core plumbing:
- Add workingDirectory to IToolInvocationContext, IToolInvocationPreparationContext,
ILanguageModelToolConfirmationRef, and IChatAgentRequest
- Enrich tool invocation context from model.workingDirectory in invokeTool()
- Include workingDirectory in toolInvocationToken built in extHostTypeConverters
- Pass workingDirectory through LanguageModelToolInvocationOptions and
LanguageModelToolInvocationPrepareOptions (proposed API)
- Revive workingDirectory URI in extHostLanguageModelTools
Tool fixes (when workingDirectory is set, use it exclusively):
- chatExternalPathConfirmation: auto-approve paths within workingDirectory
- isFileExternalAndNeedsConfirmation / isDirExternalAndNeedsConfirmation /
assertFileOkForTool: treat workingDirectory as workspace-internal
- createEditConfirmation: use workingDirectory for edit trust checks
- All edit tools (create_file, replace_string, multi_replace, apply_patch,
insert_edit, edit_notebook, create_directory): pass workingDirectory
- resolveToolUri: resolve relative paths against workingDirectory
- inputGlobToPattern: scope unscoped globs to workingDirectory
- file_search / grep_search: scope searches to workingDirectory
- semantic_search: prefer workingDirectory for cwd
- run_in_terminal: prefer workingDirectory for terminal cwd
- fetchPageTool: check workingDirectory for file URI trust
- readFileTool / listDirTool / viewImageTool: pass workingDirectory
Prompt fixes:
- WorkspaceFoldersHint: show workingDirectory instead of workspace folders
- AgentMultirootWorkspaceStructure: generate file tree from workingDirectory
* Add skillContentRead telemetry event for skill provenance tracking
Adds a new skillContentRead telemetry event fired when the read_file tool
successfully reads a skill file. Separate from readFileToolInvoked and
deferred via queueMicrotask to stay off the critical path.
Captures: skillNameHash, skillStorage (extension/internal/user/local),
extensionIdHash, extensionVersion, contentHash (GH event), plus plaintext
skillName, skillPath, extensionId (enhanced GH event).
Addresses https://github.com/microsoft/vscode/pull/306520#issuecomment-4160588650
* Address review: check skill before getText, use non-caching hash for content
- Move getSkillInfo/getExtensionSkillInfo check before getText() so
non-skill reads don't materialize document text unnecessarily
- Export createSha256HashSyncInsecure and use it for contentHash to
avoid retaining full file content in the global hash cache
- Fix TS2345: new Promise<void>(resolve => queueMicrotask(() => resolve()))
* Address PR review comments: consolidate telemetry, add internal MSFT event
- Merge sendSkillContentReadTelemetry into sendReadFileTelemetry to reuse
already-computed extensionSkillInfo/skillInfo (pwang347 feedback)
- Remove queueMicrotask since sendReadFileTelemetry is already async
fire-and-forget (pwang347 feedback)
- Switch back to getCachedSha256Hash for content hash - skill files are
small and rarely change so caching is appropriate (pwang347 feedback)
- Add sendInternalMSFTTelemetryEvent with plaintext properties (digitarald)
- Extract shared plaintextProps to reduce duplication across GH, enhanced
GH, and internal MSFT events
- Revert createSha256HashSyncInsecure export in crypto.ts (no longer needed)
* Address PR feedback: merge skill telemetry into sendReadFileTelemetry, use hash() from vscode core, add internal MSFT event, remove queueMicrotask
* Move skillStorage classification into platform layer
Borrowed from #4914: adds SkillStorage enum and ISkillInfo interface to
the platform layer, refactors _matchInstructionLocationsFromSkills to
tag storage provenance (Personal/Workspace/Extension/Internal) at
discovery time. Removes local getSkillStorage() from ReadFileTool.
Also adds isSkillMdFile(uri) guard so skillContentRead only fires for
SKILL.md files, not other assets in skill folders.
Switches skillContentRead hashes from SHA-256 to vscode core's hash()
for consistency with skillLoadedIntoContext event.
Move the hardcoded nonDeferredToolNames set from the Anthropic networking
layer to an opt-in `nonDeferred` static property on each tool class.
- Add `nonDeferred?: boolean` to ICopilotToolCtor interface
- Add IToolDeferralService with isNonDeferredTool() for DI-based access
- Mark all 18 frequently-used tools as nonDeferred = true at declaration
- Register IToolDeferralService in prod, unit test, and vscode-node test
- Remove centralized nonDeferredToolNames set from anthropic.ts
- Fix latent bug: old 'ask_questions' entry never matched the real
'vscode_askQuestions' tool name; now correctly included via
ToolName.CoreAskQuestions
Fixesmicrosoft/vscode#303545
* Add dedicated view image tool (Written by Copilot)
* Remove stale read file test import (Written by Copilot)
* Add image extension coverage test (Written by Copilot)
* Update test snapshots
* tools: add binary file support with hexdump display
Adds support for reading and displaying binary files in the read file tool
with a hexdump-formatted view. This enables better handling of binary content
in the IDE context without attempting to interpret them as text.
- Adds hexdump utility to format binary data in a readable hex/ASCII view
- Extends readFileTool to detect binary files and provide formatted output
- Adds binaryFileHexdump prompt component for displaying binary content
- Integrates binary file variable support in file variable display
- Updates test fixtures with binary file handling scenarios
Fixes https://github.com/microsoft/vscode/issues/284178
Fixes https://github.com/microsoft/vscode/issues/299973
(Commit message generated by Copilot)
* pr comments
* baseline update
* baseline update
* Add skill name to readFileToolInvoked telemetry
* Rename telemetry field to nameField
---------
Co-authored-by: Harald Kirschner <digitarald@gmail.com>
* tools: avoid putting fences into file reads by default
We've seen the model get confused here. Looking at vendor tools from Gemini and Codex CLIs, they don't add explicit line number messages like we do (which was motivation behind having the fences there in the first place. So let's try removing them. Controllable with EXP for sanity checking.
* tests and comments
* Add chat.additionalReadAccessPaths setting for read-only access to external folders
Implements a new setting that allows users to specify folders outside the
workspace that Copilot Chat read-only tools (read_file, list_dir) can
access without requiring confirmation.
- Add github.copilot.chat.additionalReadAccessPaths setting (string array)
- Gate additional access behind a readOnly flag on assertFileOkForTool,
isFileExternalAndNeedsConfirmation, and isDirExternalAndNeedsConfirmation
- Edit tools remain workspace-restricted (isFileOkForTool does not pass readOnly)
- .copilotignore rules are still respected for additional paths
Closesmicrosoft/vscode#293386
* Addresses PR feedback
* tool can give alternative definition by model
* Pass IChatEndpoint in getEnabledTools for calling tools' alternativeDefinition
* Introduce a ICopilotToolExtension to support override existing built-in tools and provide alternative definition.
* Fix errors
* add gpt-5-codex
* remove gpt-5
* Codex agent test
* more
* Fix model server for openai
* Some improvements
* Fix tool calling
* Get it building again
* Add output delta event
* stuff
* Add claude-code dependency
* Fix
* Clean up copied anthropic types, and message conversion code
* Update cc sdk
* Set up permission MCP server
* Basic mcp permission tool
* Bump version
* Use a chat session provider for claude code
* Use IChatEndpoint instead of ext api lm
* Cleanup
* Bump engine version
* Delete codex tool
* try to fix paths
This behavior is enabled behind a setting `"github.copilot.chat.virtualTools.enabled": true,`
When enabled, if the tool count is over a threshold value, we'll group
tools into 'virtual tools'. The virtual tools act as directories that
only activate and show the tools they contain when the model calls them.
Grouping is done for an entire extension or MCP server if it presents
a small number of MCP tools, or for a categorization of tools when there
are a large number. Built-in tools are never grouped.
Expanded tool groups are automatically re-collapsed, based on LRU, if
the too limit is exceeded, or optimistically to a lower threshold during
summarization when there's going to be a cache miss anyway.
Todo:
- Better validation of LM categorization (ensure no missing tools)
- General Telemetry
- And logic to ensure that the tool limit can never be hit (heirarchal grouping)
- Explore embeddings as better pre-selection of expanded virtual tools
- Explore subagents as an alternative to expansion
- Success telemetry based on mirrored requests