Local sandboxing for GitHub Copilot is generally available, restricting agent commands’ file, network and credential access with enforceable enterprise policies
Tools and commands Copilot runs on a developer’s own machine can now run inside a policy-restricted sandbox, at no extra cost.
// Key points
- Generally available in Copilot CLI, the Copilot app and VS Code sessions using Agent Host, included with Copilot at no additional cost.
- Limits which files and directories agent-run commands can read or modify, and controls access to the internet, local networks, Git credentials and GitHub CLI credentials; it also covers local MCP and language servers where supported.
- Powered by Microsoft eXecution Container (MXC), which translates one sandbox policy into native OS controls on Windows, macOS and Linux; enterprises can require sandboxing through managed settings that developers cannot weaken.
- Sandbox policies apply to tool execution regardless of which model Copilot uses.
Builder's takeThe biggest worry about letting coding agents run freely has always been what they can touch on your machine. I'd set the team default to: write only to the current repo, no access to Git credentials, network via an allowlist, with local MCP servers included. That beats reviewing every command after the fact, and teams on other coding agents should hold their isolation to the same bar.
// Background · from #Coding agents
Full timeline →- Oct 8 GitHub ships a purpose-built model for leaked secrets that reads surrounding code to catch unformatted passwords, coming to push protection and Copilot /security-review
- Oct 6 AWS releases the aws-ai-ml skill so Claude Code, Codex and Kiro can benchmark SageMaker inference endpoints and generate deployment code
- Oct 5 GitHub Copilot code review gets REST and GraphQL APIs; Balanced becomes the default effort level