Add permission checking to the remaining 7 tools that require granular
permissions:
- `edit_file`: Checks path against permission rules
- `delete_path`: Checks path against permission rules
- `move_path`: Checks both source and destination paths
- `create_directory`: Checks path against permission rules
- `save_file`: Checks all paths, denies if any are blocked
- `fetch`: Checks URL against permission rules
- `web_search`: Checks query against permission rules
Each tool follows the pattern established in PR #46155 (terminal tool):
- `Allow` = proceed without prompting
- `Deny` = return error immediately
- `Confirm` = prompt user for confirmation
The deny > confirm > allow precedence is enforced by the
`decide_permission_from_settings()` function.
Release Notes:
- N/A
---------
Co-authored-by: Amp <amp@ampcode.com>
2b6e935b09Richard Feldman committed on 1/12/2026, 4:08:06 PM· committed by GitHubparent8a1cf4d