Anything you type that is not one of the named commands is treated as a plain language request.

please "clean up branches that are already merged into main"
please "what changed in the last 3 commits"
please "I broke something, undo my last commit"
please "open a PR for this branch"

The AI figures out how to do it and acts on your behalf. It never edits files directly. It only acts through git, gh, or another please subcommand, and it can call please itself recursively where that helps. For example, commit and clean up merged branches might run please commit, then please cleanup.

The agent explains itself before it acts

Before any tool call runs, the agent’s own reasoning for it is printed to your terminal — so a confirmation prompt is never something you’re answering blind. You see why it wants to stash, not just that it wants to.

Three tiers of risk, not a guess list

Read only calls, git status, git log, please status, please stash list, and so on, run immediately. Everything else is one of two things:

  • Confirmed once. Any git or gh call that isn’t on the small read only allowlist, and any please subcommand that mutates the repo, please stash, please sync, please undo, please cleanup, please branch <name>, and the rest, stops and asks you [y/N] first. This is deliberately an allowlist of what’s safe rather than a blocklist of what’s dangerous: please doesn’t have to guess every risky flag combination in advance, everything not proven safe defaults to asking.
  • Refused outright. A handful of please subcommands, discard, purge, revert, squash, sync exactly, stash drop, and switching to a branch that doesn’t exist yet, can only be confirmed by someone typing at a real keyboard. The agent doesn’t attempt them at all — it tells you to run the command yourself. Switching to a branch that does already exist is checked live against your actual repo state and just confirms normally.

A handful of genuinely destructive git operations, a force push, reset --hard, branch -D, clean -f, get a stronger “this looks destructive” warning in that same confirmation prompt.

How providers plug in

The tool calling conversation is represented in provider neutral terms internally. Only a small adapter per provider, Gemini, Claude, ChatGPT, translates that to and from its own wire format. This is what lets please add new providers without touching the agent loop itself.