Permissions
Limit the GitHub and Ellipsis operations a session can perform.
Permissions limit what a session's GitHub and Ellipsis credentials can do. The environment decides which repositories are checked out and which secrets are set.
Read-only GitHub access
The agent can read api-repo but can't push commits or comment on issues and pull requests. It can still edit files in its sandbox.
Allow code and pull request changes
Use this for tasks that push a branch and open a pull request. Permissions can't exceed what the GitHub App is installed with.
permissions.github.repositories limits the credential; environment.repositories decides what is checked out. Set both when you need both.
Limit Ellipsis access
Anything not listed is denied. write includes read, and delete includes both. Reading secrets returns their names, never their values.
Secrets
The agent and its tools can read every secret the environment sets, and GitHub permissions don't limit what those credentials can do. Keep secret values out of prompts, committed YAML, and command output; session logs record what tools print.