Developer, Coding & Automation · GitHub · October 7
Copilot’s local sandbox becomes a standard boundary for agent execution
Generally available controls restrict local tools’ access to files, networks, and credentials.
Tools: GitHub Copilot
What happened
GitHub made local sandboxing generally available on October 7 in Copilot CLI, the Copilot app, and VS Code sessions using Agent Host. Microsoft eXecution Container translates policies into operating-system controls on Windows, macOS, and Linux. Developers and administrators can restrict filesystem, network, and credential access, including supported local tools. GitHub says the capability is included with Copilot at no additional charge.
Roseram analysis
This changes the practical question from whether an agent can run a command to what that command is allowed to reach. Tool isolation is separate from model choice. A sandbox is a defined boundary, not proof that generated changes are correct: representative tests, review, and permissions appropriate to the task remain necessary.