<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Selin Orlov</title>
    <description>The latest articles on DEV Community by Selin Orlov (@selinorlov).</description>
    <link>https://dev.to/selinorlov</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4136771%2F78d38ed0-6abd-480b-9380-ffae862ddc72.png</url>
      <title>DEV Community: Selin Orlov</title>
      <link>https://dev.to/selinorlov</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/selinorlov"/>
    <language>en</language>
    <item>
      <title>Copilot CLI in Late 2026: The Flags I Actually Use in Scripts</title>
      <dc:creator>Selin Orlov</dc:creator>
      <pubDate>Wed, 07 Oct 2026 03:13:48 +0000</pubDate>
      <link>https://dev.to/selinorlov/copilot-cli-in-late-2026-the-flags-i-actually-use-in-scripts-4b0g</link>
      <guid>https://dev.to/selinorlov/copilot-cli-in-late-2026-the-flags-i-actually-use-in-scripts-4b0g</guid>
      <description>&lt;p&gt;Most Copilot CLI guides I find are prompt catalogs: "ask it to write a Terraform module", "ask it to explain a failing workflow". That part is easy. What took me longer was the boring layer underneath: which flags make GitHub Copilot CLI safe to run from a script, what changed in the last few months of releases, and where the sharp edges are.&lt;/p&gt;

&lt;p&gt;This is that layer, written against the docs and changelog as of early October 2026 (the repo shipped 1.0.92 on October 5). I run platform tooling for a small team, so my bias is headless use: cron jobs, CI steps, one-off batch fixes. If you mostly use it interactively, the permissions and worktree sections still apply.&lt;/p&gt;

&lt;p&gt;One scoping note before the flags: I don't use a terminal agent for everything. When someone needs a marketing page or a quick front end for an internal tool, I hand that to &lt;a href="https://begin.sh/?utm_source=devto&amp;amp;utm_medium=ugc&amp;amp;utm_campaign=selinorlov&amp;amp;utm_content=copilot-cli-intro" rel="noopener noreferrer"&gt;Begin&lt;/a&gt;, which builds the site with hosting and sign-in already wired, and I keep Copilot CLI for work inside existing repos.&lt;/p&gt;

&lt;h2&gt;
  
  
  Install and auth: one thing changed
&lt;/h2&gt;

&lt;p&gt;Install is the same as it has been:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;macOS/Linux: &lt;code&gt;brew install copilot-cli&lt;/code&gt; or &lt;code&gt;curl -fsSL https://gh.io/copilot-install | bash&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;Windows: &lt;code&gt;winget install GitHub.Copilot&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;Anywhere with Node: &lt;code&gt;npm install -g @github/copilot&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Each has a prerelease channel (&lt;code&gt;copilot-cli@prerelease&lt;/code&gt;, &lt;code&gt;GitHub.Copilot.Prerelease&lt;/code&gt;, &lt;code&gt;@github/copilot@prerelease&lt;/code&gt;). The docs now say Copilot CLI is available on all Copilot plans. If you get Copilot through an org, an admin still has to enable the CLI policy.&lt;/p&gt;

&lt;p&gt;The change that bit me: token lookup order. Older posts say &lt;code&gt;GH_TOKEN&lt;/code&gt; wins over &lt;code&gt;GITHUB_TOKEN&lt;/code&gt;. The current reference checks &lt;strong&gt;&lt;code&gt;COPILOT_GITHUB_TOKEN&lt;/code&gt; first&lt;/strong&gt;, then &lt;code&gt;GH_TOKEN&lt;/code&gt;, then &lt;code&gt;GITHUB_TOKEN&lt;/code&gt;. On a CI runner that already exports &lt;code&gt;GITHUB_TOKEN&lt;/code&gt; for other steps, setting &lt;code&gt;COPILOT_GITHUB_TOKEN&lt;/code&gt; keeps the Copilot credential separate. The token is a fine-grained PAT with the "Copilot Requests" permission. By default the CLI redacts the values of &lt;code&gt;GITHUB_TOKEN&lt;/code&gt; and &lt;code&gt;COPILOT_GITHUB_TOKEN&lt;/code&gt; from its output. For anything else sensitive, there's &lt;code&gt;--secret-env-vars&lt;/code&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Copilot CLI flags that matter for automation
&lt;/h2&gt;

&lt;p&gt;Here is the short list I keep pinned. All of these come from the current command reference.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Flag&lt;/th&gt;
&lt;th&gt;What it does&lt;/th&gt;
&lt;th&gt;When I reach for it&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;code&gt;-p&lt;/code&gt;, &lt;code&gt;--prompt&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;Runs one prompt and exits&lt;/td&gt;
&lt;td&gt;Every scripted run&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;code&gt;-s&lt;/code&gt;, &lt;code&gt;--silent&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;Prints only the agent response, no usage stats&lt;/td&gt;
&lt;td&gt;When stdout feeds another tool&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;--output-format=json&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Emits JSONL, one object per line&lt;/td&gt;
&lt;td&gt;Logging runs for later inspection&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;--allow-all-tools&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Runs tools without confirmation&lt;/td&gt;
&lt;td&gt;The reference lists it as required for programmatic use&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;--deny-tool=...&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Blocks specific tools or commands&lt;/td&gt;
&lt;td&gt;Always, alongside the line above&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;--autopilot&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Keeps going until the agent calls &lt;code&gt;task_complete&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;Multi-step fixes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;--max-autopilot-continues=N&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Caps autopilot continuation messages&lt;/td&gt;
&lt;td&gt;Every autopilot run&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;--plan --mode autopilot&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Plans first, then implements without waiting for approval&lt;/td&gt;
&lt;td&gt;Larger changes where I want a plan in the log&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;code&gt;-w&lt;/code&gt;, &lt;code&gt;--worktree[=NAME]&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;Starts the session in an isolated git worktree&lt;/td&gt;
&lt;td&gt;Anything that edits code unattended&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;--no-ask-user&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Disables the &lt;code&gt;ask_user&lt;/code&gt; tool&lt;/td&gt;
&lt;td&gt;Headless runs, so it never waits on stdin&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;--share=PATH&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Writes the session to Markdown after a &lt;code&gt;-p&lt;/code&gt; run&lt;/td&gt;
&lt;td&gt;CI artifacts and review&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;--model=auto&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Lets Copilot pick the model&lt;/td&gt;
&lt;td&gt;When I don't care which model runs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;--max-ai-credits=N&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Soft cap on AI Credits per response&lt;/td&gt;
&lt;td&gt;Cost guardrails on scheduled jobs&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;A few of those need more than a table cell.&lt;/p&gt;

&lt;h3&gt;
  
  
  Deny beats allow, even under --allow-all
&lt;/h3&gt;

&lt;p&gt;This is the line in the docs I wish more guides quoted: &lt;strong&gt;deny rules always take precedence over allow rules, even when &lt;code&gt;--allow-all&lt;/code&gt; is set.&lt;/strong&gt; That is what makes &lt;code&gt;--allow-all-tools&lt;/code&gt; acceptable to me in a script. I grant broadly, then carve out what must never happen.&lt;/p&gt;

&lt;p&gt;The pattern syntax is small:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;shell(git:*)&lt;/code&gt; matches &lt;code&gt;git push&lt;/code&gt;, &lt;code&gt;git pull&lt;/code&gt; and so on. The &lt;code&gt;:*&lt;/code&gt; suffix matches the command stem followed by a space, so it does not match &lt;code&gt;gitea&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;shell(git push)&lt;/code&gt; matches that exact command.&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;write(src/*.ts)&lt;/code&gt; limits file writes by glob.&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;url(github.com)&lt;/code&gt; scopes URL access.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The reference example is exactly the shape I use: allow all of git, deny push.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;copilot &lt;span class="nt"&gt;--allow-tool&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;'shell(git:*)'&lt;/span&gt; &lt;span class="nt"&gt;--deny-tool&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;'shell(git push)'&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;For multiple rules, pass a quoted, comma-separated list. Malformed patterns are rejected with an error rather than silently ignored, which I appreciate.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;--yolo&lt;/code&gt; and &lt;code&gt;--allow-all&lt;/code&gt; are the same switch (tools + paths + URLs). There is also &lt;code&gt;COPILOT_ALLOW_ALL&lt;/code&gt; for harnesses that can only set environment variables. I treat all three as "only inside a container or a throwaway worktree".&lt;/p&gt;

&lt;h3&gt;
  
  
  Autopilot needs a ceiling
&lt;/h3&gt;

&lt;p&gt;Autopilot (&lt;code&gt;--autopilot&lt;/code&gt;, or &lt;code&gt;Shift+Tab&lt;/code&gt; interactively) keeps the agent working until it decides the task is done. An older changelog entry says continuations were capped at 5 by default. The current reference lists the default for &lt;code&gt;--max-autopilot-continues&lt;/code&gt; as &lt;strong&gt;unlimited&lt;/strong&gt;. I don't rely on either: every autopilot run I script sets the cap explicitly.&lt;/p&gt;

&lt;p&gt;One gotcha: &lt;code&gt;--plan&lt;/code&gt; cannot be combined with &lt;code&gt;--autopilot&lt;/code&gt;. If you want plan-then-execute, the supported form is &lt;code&gt;--plan --mode autopilot&lt;/code&gt;. The session starts in plan mode and moves to autopilot once the plan is ready. For harnesses that can't pass flags, the same behavior is behind &lt;code&gt;COPILOT_PLAN_THEN_AUTOPILOT&lt;/code&gt;.&lt;/p&gt;

&lt;h3&gt;
  
  
  Worktrees keep unattended edits off your branch
&lt;/h3&gt;

&lt;p&gt;&lt;code&gt;--worktree&lt;/code&gt; used to require experimental mode. It no longer does. It creates or reuses a worktree under &lt;code&gt;&amp;lt;repo&amp;gt;.worktrees/&lt;/code&gt; and starts the session there. A &lt;code&gt;worktreeBaseRef&lt;/code&gt; setting decides whether it branches from &lt;code&gt;HEAD&lt;/code&gt; (now the default) or the remote default branch. &lt;code&gt;worktreePathTemplate&lt;/code&gt; lets you put worktrees somewhere else, with placeholders like &lt;code&gt;{repo}&lt;/code&gt; and &lt;code&gt;{branch}&lt;/code&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  A script I actually run
&lt;/h2&gt;

&lt;p&gt;This is the skeleton of a nightly "fix the flaky test" job. The prompt varies; the guardrails don't.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;#!/usr/bin/env bash&lt;/span&gt;
&lt;span class="nb"&gt;set&lt;/span&gt; &lt;span class="nt"&gt;-euo&lt;/span&gt; pipefail

&lt;span class="c"&gt;# Fine-grained PAT with the "Copilot Requests" permission.&lt;/span&gt;
&lt;span class="nb"&gt;export &lt;/span&gt;&lt;span class="nv"&gt;COPILOT_GITHUB_TOKEN&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="k"&gt;${&lt;/span&gt;&lt;span class="nv"&gt;COPILOT_PAT&lt;/span&gt;:?missing&lt;span class="p"&gt; COPILOT_PAT&lt;/span&gt;&lt;span class="k"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;

copilot &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-p&lt;/span&gt; &lt;span class="s2"&gt;"Read test-results/junit.xml, find the root cause of the failing test, fix it, and run the test suite again. Only edit files under src/ and tests/."&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;--worktree&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;nightly-flaky-fix &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;--allow-all-tools&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;--deny-tool&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;'shell(git push),shell(rm:*)'&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;--no-ask-user&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;--autopilot&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;--max-autopilot-continues&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;8 &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;--silent&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;--share&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;./artifacts/copilot-session.md
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Why each piece is there:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;--worktree&lt;/code&gt; means whatever it does lands on a separate branch I can diff in the morning.&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;--deny-tool&lt;/code&gt; blocks pushes and &lt;code&gt;rm&lt;/code&gt;. Because deny wins, &lt;code&gt;--allow-all-tools&lt;/code&gt; can't override it.&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;--no-ask-user&lt;/code&gt; stops the run from hanging on a question nobody will answer.&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;--share&lt;/code&gt; gives me the full transcript as a build artifact. Prompt mode exits non-zero if that export fails, so a broken artifact fails the job instead of passing quietly.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If a background shell or subagent outlives the turn, &lt;code&gt;-p&lt;/code&gt; honors &lt;code&gt;COPILOT_TASK_WAIT_TIMEOUT_SECONDS&lt;/code&gt;, which is worth setting on CI so a stuck process can't hold the runner.&lt;/p&gt;

&lt;h2&gt;
  
  
  Newer features worth knowing
&lt;/h2&gt;

&lt;p&gt;These weren't in the guides I first learned from:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Scheduling inside a session.&lt;/strong&gt; &lt;code&gt;/every 1h Run frontend tests and report any failures&lt;/code&gt; repeats a prompt. &lt;code&gt;/after&lt;/code&gt; runs one once after a delay. Handy for watching a long migration from a session you leave open.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Sandboxing.&lt;/strong&gt; &lt;code&gt;/sandbox enable&lt;/code&gt; restricts what the commands Copilot runs can touch on your filesystem and network. The CLI process itself isn't sandboxed. &lt;code&gt;copilot --cloud&lt;/code&gt; runs the whole session remotely in an isolated environment. The per-run &lt;code&gt;--sandbox&lt;/code&gt; flag is experimental-only for now.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;&lt;code&gt;copilot config&lt;/code&gt;.&lt;/strong&gt; Added in 1.0.92: subcommands to list, read, set and remove settings from the shell, so you can provision settings without opening &lt;code&gt;/settings&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Built-in agents.&lt;/strong&gt; The default set is now Explore, Task, General purpose, Code review, Research and Rubber duck. The last one is consulted automatically, not picked from &lt;code&gt;/agent&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Usage is shown in AI Credits.&lt;/strong&gt; &lt;code&gt;/usage&lt;/code&gt; reports AI Credits used per session, and &lt;code&gt;--max-ai-credits&lt;/code&gt; plus &lt;code&gt;/limits&lt;/code&gt; let you cap them.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Things that haven't changed: &lt;code&gt;@path&lt;/code&gt; adds a file to the prompt, &lt;code&gt;!cmd&lt;/code&gt; runs a shell command without calling the model, &lt;code&gt;/add-dir&lt;/code&gt; and &lt;code&gt;/cwd&lt;/code&gt; manage directories, and &lt;code&gt;copilot --continue&lt;/code&gt; resumes the most recent session. Instructions still load from &lt;code&gt;.github/copilot-instructions.md&lt;/code&gt;, &lt;code&gt;.github/instructions/**/*.instructions.md&lt;/code&gt; and &lt;code&gt;AGENTS.md&lt;/code&gt;. Pass &lt;code&gt;--no-custom-instructions&lt;/code&gt; when you want a clean run.&lt;/p&gt;

&lt;p&gt;For the full list, &lt;code&gt;copilot help permissions&lt;/code&gt; and &lt;code&gt;copilot help environment&lt;/code&gt; are faster than searching. The &lt;a href="https://docs.github.com/en/copilot/how-tos/copilot-cli/use-copilot-cli/overview" rel="noopener noreferrer"&gt;official usage guide&lt;/a&gt; is the canonical reference.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where it still needs care
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Approving a tool "for the rest of the session" is broad.&lt;/strong&gt; The docs say it plainly: approving &lt;code&gt;rm&lt;/code&gt; that way lets Copilot delete any file under the current directory without asking again. Interactively, I approve once and only use the session-wide option for harmless commands.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Trusting a folder permanently&lt;/strong&gt; (option 2 at startup) skips the prompt in every future session from that folder. I only do it for my own repos, never for a fresh clone.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Release pace.&lt;/strong&gt; The changelog moves fast: five releases between September 22 and October 5. Pin &lt;code&gt;VERSION=&lt;/code&gt; in the install script (or the npm version) on CI. Then a default change shows up in a PR, not as a surprise in a nightly job.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Is Copilot CLI the same as &lt;code&gt;gh copilot&lt;/code&gt;?&lt;/strong&gt;&lt;br&gt;
No. This guide covers the standalone &lt;code&gt;copilot&lt;/code&gt; command from the &lt;code&gt;github/copilot-cli&lt;/code&gt; repo. It's an agent that can edit files and run commands. The GitHub CLI (&lt;code&gt;gh&lt;/code&gt;) is a separate tool.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Can I use Copilot CLI without a paid plan?&lt;/strong&gt;&lt;br&gt;
The docs say it's available on all Copilot plans. If you get Copilot through an organization, an admin must also enable the Copilot CLI policy, or you can't use it even with a seat.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How do I run Copilot CLI non-interactively in CI?&lt;/strong&gt;&lt;br&gt;
Use &lt;code&gt;-p&lt;/code&gt; with a prompt, authenticate with &lt;code&gt;COPILOT_GITHUB_TOKEN&lt;/code&gt;, and add &lt;code&gt;--allow-all-tools&lt;/code&gt; with explicit &lt;code&gt;--deny-tool&lt;/code&gt; rules. Add &lt;code&gt;--no-ask-user&lt;/code&gt; so it never waits for input, and &lt;code&gt;--silent&lt;/code&gt; or &lt;code&gt;--output-format=json&lt;/code&gt; for clean output.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How do I stop autopilot from running forever?&lt;/strong&gt;&lt;br&gt;
Set &lt;code&gt;--max-autopilot-continues&lt;/code&gt; every time. The current reference lists its default as unlimited.&lt;/p&gt;

&lt;h2&gt;
  
  
  Wrapping up
&lt;/h2&gt;

&lt;p&gt;The prompts are the easy part of Copilot CLI. The guardrails are the real work: deny rules, a continuation cap, a worktree, and a transcript you can read later. Get those four in place and headless runs stop being scary.&lt;/p&gt;

&lt;p&gt;And when a request turns out to be "we need a whole new site or app" rather than "fix this repo", I don't try to make a terminal agent do it. That goes to &lt;a href="https://begin.sh/?utm_source=devto&amp;amp;utm_medium=ugc&amp;amp;utm_campaign=selinorlov&amp;amp;utm_content=copilot-cli-outro" rel="noopener noreferrer"&gt;Begin&lt;/a&gt;, which builds a website, iOS app, Android app or Chrome extension from a prompt.&lt;/p&gt;

</description>
      <category>githubcopilot</category>
      <category>cli</category>
      <category>devops</category>
      <category>productivity</category>
    </item>
  </channel>
</rss>
