Skip to content
important AI agents

Local sandboxing in GitHub Copilot is generally available

clearly official source

GitHub has made local sandboxing generally available in GitHub Copilot CLI, the GitHub Copilot app and VS Code editor sessions with Agent Host. The feature, available at no additional charge, restricts access by running tools to system resources according to policies set by the developer or organization.

GitHub announced the general availability of local isolation of tool execution, known as sandboxing, for agent workflows. The feature is available in GitHub Copilot CLI, the GitHub Copilot app and VS Code editor sessions that use Agent Host. It is included in GitHub Copilot at no additional charge.

According to GitHub, tools and commands run through GitHub Copilot have restricted access to the file system, the network, credentials and other system resources. Policies are set by the developer or organization. Microsoft eXecution Container (MXC) translates these policies into native restrictions on Windows, macOS and Linux. The policies apply to tool execution regardless of the model used.

What changed

Why it matters

When assigning agent tasks, developers can specify which resources on their computers the commands being run may access. Tool permissions can be managed independently of the choice of model, so changing the model does not in itself require different isolation policies.

Two audiences, two different impacts

What this means

01

For individuals

Developers working with agents on their own computers can set limits on access to local files, the network and credentials.

What to do Before starting an agent task, set policies governing tool access to resources on your computer.
More practical updates →
02

For a business

Organizations can set policies governing agent tool access to resources on developer computers. There is no additional charge for this feature in GitHub Copilot.

Risks and compliance
What to decide Set organizational policies for agent tool access to files, the network and credentials.
More business impacts →
Agent Host GitHub Copilot GitHub Copilot CLI Microsoft eXecution Container

Check the original

Event sources

clearly official source · 1 publisher, 0 independent. We count feeds from the same owner only once.

1
GitHub Copilot Changelog primary source · first detected Local sandboxing for GitHub Copilot now generally available