Live
Kubernetes Operations Under AI Pressure: Aligning Dev and Ops in Hybrid Edge EnvironmentsBeyond Fast Fixes: Building a Closed‑Loop AI SRE Process for Real ReliabilityContext‑aware AI secret detection model rolls out to GitHub push protection and Copilot security reviewClaude Haiku 5.5 on Amazon Bedrock: Faster, cheaper sub‑agent model for production AI workloadsGitHub Copilot adds local sandboxing to CLI, app, and VS Code – implications for engineersReal‑time ACL Enforcement in Amazon Quick and Bedrock Knowledge BasesThree‑Layer AI Vulnerability Pipeline: From Raw Findings to Actionable AlertsEnforcing Evidence‑Based Triage with an AI Vulnerability Steering FileKubernetes Operations Under AI Pressure: Aligning Dev and Ops in Hybrid Edge EnvironmentsBeyond Fast Fixes: Building a Closed‑Loop AI SRE Process for Real ReliabilityContext‑aware AI secret detection model rolls out to GitHub push protection and Copilot security reviewClaude Haiku 5.5 on Amazon Bedrock: Faster, cheaper sub‑agent model for production AI workloadsGitHub Copilot adds local sandboxing to CLI, app, and VS Code – implications for engineersReal‑time ACL Enforcement in Amazon Quick and Bedrock Knowledge BasesThree‑Layer AI Vulnerability Pipeline: From Raw Findings to Actionable AlertsEnforcing Evidence‑Based Triage with an AI Vulnerability Steering File
GitHub

GitHub Copilot adds local sandboxing to CLI, app, and VS Code – implications for engineers

AI SummaryPowered by AI

GitHub Copilot now ships local sandboxing as a generally available feature in its CLI, desktop app, and VS Code Agent Host sessions. The addition gives engineers a built‑in OS‑level execution boundary that limits file, network, and credential access for Copilot‑driven tools, reducing the attack surface of autonomous workflows.

GitHub Copilot has moved local sandboxing from preview to general availability across its CLI, desktop application, and VS Code sessions that use Agent Host. This gives engineers a built‑in, OS‑level isolation layer for any tool or command that Copilot launches, letting you restrict file system, network, and credential access directly on the developer workstation.

How Local Sandboxing Works

The feature is powered by Microsoft eXecution Container (MXC), which takes a single sandbox policy and maps it to native controls on Windows, macOS, and Linux. The policy defines which files, directories, network endpoints, and credential stores a Copilot‑initiated process may touch. MXC enforces those limits using the host operating system’s mechanisms, so the same policy works consistently across all supported platforms.

Operational Impact

From an operations perspective the change introduces a new configuration artifact – the sandbox policy – that can be authored by individual developers or centrally managed by an organization. Enterprise‑managed settings can require sandboxing and lock down the policy so it cannot be weakened by a user. Because the feature is included with Copilot at no extra charge, the primary effort is defining appropriate policies and validating that existing local tools (e.g., language servers, MCP instances) continue to function under the new constraints.

Security Considerations

Local sandboxing separates the execution of Copilot‑driven tools from the broader system environment. By limiting read/write access to specific paths and controlling outbound network traffic, the sandbox reduces the risk that a compromised or malicious tool can exfiltrate data or affect unrelated parts of the workstation. The policy applies regardless of which underlying AI model Copilot uses, reinforcing that model execution and tool isolation are distinct concerns.

Related CloudNinjas coverage: AI engineering.

What This Means For Practitioners

Teams should start by reviewing the default sandbox policy and tailoring it to the minimum set of resources required for their workflows. Enable the sandbox in the CLI, app, or VS Code Agent Host, then run a suite of typical Copilot‑generated commands to confirm they operate as expected. For organizations, consider adopting the enterprise‑managed setting to enforce sandboxing uniformly and prevent developers from loosening restrictions. Ongoing monitoring of policy compliance will help surface any tool‑specific breakages that need policy adjustments.

Originally published atGitHub Changelog