How Qwen Code Approval Mode Works and What the --yolo Flag Does
The approval mode in Qwen Code controls whether tool executions require user confirmation, and the --yolo flag automatically approves all actions by setting the mode to ApprovalMode.YOLO.
Qwen Code is an AI-powered coding assistant that executes tools like file edits, shell commands, and web fetches on your behalf. To balance automation with safety, it implements a configurable approval mode system that determines when the system must pause for user consent. This article explains how the approval subsystem works and specifically what happens when you use the --yolo command-line flag.
The Four Approval Modes Explained
The approval mode is stored in ServerConfig.approvalMode and defined in packages/core/src/config/config.ts as the ApprovalMode enum. Each mode represents a different trust level between the user and the AI agent:
| Mode | Behavior | Best For |
|---|---|---|
| default | Every mutable tool prompts for explicit approval. | Interactive sessions requiring full control. |
| plan | Only read-only tools execute; mutable operations are rejected automatically. | Dry-run planning without side effects. |
| auto-edit | File edit tools (write, diff) auto-approve; other tools still prompt. | Fast editing when you trust the model's file modifications. |
| yolo | All tools auto-approve without user prompts. | CI pipelines, unattended runs, or maximum automation. |
Where Approval Mode is Defined
The canonical definition lives in packages/core/src/config/config.ts:
export enum ApprovalMode {
PLAN = 'plan',
DEFAULT = 'default',
AUTO_EDIT = 'auto-edit',
YOLO = 'yolo',
}
This file also exports APPROVAL_MODE_INFO, which provides human-readable labels and descriptions for UI rendering. The ServerConfig class maintains the current state and exposes getApprovalMode() and setApprovalMode() methods for runtime changes.
How to Set Approval Mode
Using the --yolo CLI Flag
The --yolo flag (alias -y) is defined in packages/cli/src/config/config.ts:
.option('yolo', {
alias: 'y',
type: 'boolean',
description:
'Automatically accept all actions (aka YOLO mode, see https://www.youtube.com/watch?v=xvFZjo5PgG0 for more details)?',
default: false,
})
Important: The flag is mutually exclusive with --approval-mode. The CLI enforces this conflict at lines 538-540:
if (argv['yolo'] && argv['approvalMode']) {
return 'Cannot use both --yolo (-y) and --approval-mode together. Use --approval-mode=yolo instead.';
}
When --yolo is passed, the CLI translates it to approvalMode: 'yolo' (handled around line 745), effectively bypassing all confirmation prompts.
Runtime Configuration via UI
You can change modes mid-session using the VSCode companion or web UI. The command /approval-mode <mode> routes through packages/vscode-ide-companion/src/services/qwenAgentManager.ts, which calls Config.setApprovalMode(mode). This allows dynamic switching between cautious and permissive behaviors without restarting the agent.
Programmatic Configuration
When using the SDK directly:
import { ServerConfig, ApprovalMode } from '@qwen/code-sdk';
const cfg = await ServerConfig.load(...);
cfg.setApprovalMode(ApprovalMode.YOLO); // All future tool calls bypass approval
How Approval Mode Affects Tool Execution
Core Scheduler Logic
The central gatekeeper is CoreToolScheduler.scheduleToolCalls in packages/core/src/core/coreToolScheduler.ts. It checks the current mode before deciding whether to prompt:
if (this.config.getApprovalMode() === ApprovalMode.YOLO ||
doesToolInvocationMatch(toolCall.tool, invocation, allowedTools)) {
// auto‑approve
this.setToolCallOutcome(reqInfo.callId, ToolConfirmationOutcome.ProceedAlways);
this.setStatusInternal(reqInfo.callId, 'scheduled');
}
When ApprovalMode.YOLO is active, the scheduler immediately sets the outcome to ProceedAlways, skipping the confirmation UI entirely.
Tool-Specific Implementations
Individual tools also perform early-exit checks to optimize performance:
-
Web Fetch (
packages/core/src/tools/web-fetch.ts):if (this.config.getApprovalMode() === ApprovalMode.AUTO_EDIT || this.config.getApprovalMode() === ApprovalMode.PLAN) { // bypass user prompt } -
File Edit (
packages/core/src/tools/edit.ts):if (this.config.getApprovalMode() === ApprovalMode.AUTO_EDIT) { // apply edit without asking } -
Shell Processor (
packages/cli/src/services/prompt-processors/shellProcessor.ts):if (config.getApprovalMode() === ApprovalMode.YOLO) { // run command immediately }
Practical Usage Examples
Unattended Automation with --yolo
For CI pipelines or batch processing where no human is present to confirm actions:
qwen-code --yolo "Refactor all utility functions to use async/await"
This executes file edits, shell commands, and web fetches without interruption.
Safe Planning Mode
To preview what the agent would do without risking your codebase:
qwen-code --approval-mode plan "Add TypeScript types to the database layer"
The agent will analyze files but reject any actual write operations.
Dynamic Mode Switching
Start cautiously, then enable faster editing once you trust the session:
/approval-mode default # Initial safe mode
... (review a few edits) ...
/approval-mode auto-edit # Now speed up file modifications
Summary
- Approval mode is a global safety setting stored in
ServerConfigthat determines whether Qwen Code must prompt for user consent before executing tools. - Four modes exist:
default(confirm all),plan(read-only),auto-edit(confirm only non-edit tools), andyolo(confirm nothing). - The
--yoloCLI flag (alias-y) sets the mode toApprovalMode.YOLO, enabling fully unattended execution where all tools auto-approve. - The flag is mutually exclusive with
--approval-mode; use--approval-mode=yoloif you need to specify the mode explicitly. - Internally,
CoreToolSchedulerand individual tool implementations checkconfig.getApprovalMode()to decide whether to render confirmation UI or proceed immediately.
Frequently Asked Questions
What happens if I use --yolo and --approval-mode together?
The CLI will reject the command with an error message: "Cannot use both --yolo (-y) and --approval-mode together. Use --approval-mode=yolo instead." This conflict check is enforced in packages/cli/src/config/config.ts at lines 538-540 to prevent ambiguous configuration.
Is YOLO mode safe for production CI environments?
YOLO mode is designed specifically for unattended automation, making it suitable for CI pipelines where no human operator is available to confirm actions. However, because it auto-approves all tools—including shell commands and file deletions—you should only use it in isolated environments or with highly trusted prompts. For safer automation, consider auto-edit mode which only bypasses confirmation for file modifications.
How do I switch approval modes during an active session?
You can change modes at runtime using the /approval-mode <mode> command in the VSCode companion or web UI. This command routes through packages/vscode-ide-companion/src/services/qwenAgentManager.ts and calls Config.setApprovalMode(), immediately affecting subsequent tool calls without requiring a restart.
What is the difference between auto-edit and yolo mode?
Auto-edit mode (ApprovalMode.AUTO_EDIT) automatically approves only file modification tools (writes, diffs, edits) while still prompting for shell commands, web fetches, and other potentially dangerous operations. YOLO mode (ApprovalMode.YOLO) removes all restrictions, auto-approving every tool including shell execution and network requests. Use auto-edit for faster coding with safety guardrails; use yolo only when you need complete hands-off automation.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →