GitHub Copilot local sandboxing reaches general availability
GitHub Copilot adds generally available local sandboxes for CLI, app and VS Code Agent Host sessions, with controlled filesystem and network access.
GitHub makes local Copilot sandboxes generally available. Policy restrictions apply to local tool execution, not automatically to the separate cloud coding agent.
Local sandbox isolation had not yet been announced as generally available across these specified Copilot surfaces.
Local sandboxing is generally available for Copilot CLI, the Copilot app and supported VS Code Agent Host sessions.
On October 7, 2026, GitHub announced general availability of local sandboxing for GitHub Copilot. The release explicitly names Copilot CLI, the Copilot app and Visual Studio Code sessions running through Agent Host. Commands and tools initiated by a local Copilot agent can now operate inside an additional policy-controlled execution boundary on the developer’s machine.
Sandbox policies can restrict which folders agents read or modify and which network destinations they can reach. They can also regulate access to Git credentials, GitHub CLI credentials and other system capabilities. Developers or administrators define the policy. GitHub says the boundary can extend to supported local MCP tools and language servers, making the tool execution surface—not merely the model response—the focus of this security measure.
Microsoft eXecution Container (MXC) provides the underlying mechanism. According to GitHub, MXC maps a common sandbox policy to operating-system enforcement on Windows, macOS and Linux. Enterprise-managed settings can require sandboxing and prevent developers from weakening centrally imposed restrictions. This matters for teams that want more autonomy without granting unrestricted access to local development environments.
The product scope must remain explicit. This announcement concerns local Copilot execution surfaces. It does not establish that the separate GitHub Copilot cloud coding agent uses identical sandbox technology, settings or enforcement. GitHub also distinguishes model choice from tool isolation: the local sandbox controls tools regardless of which eligible Copilot model performs the reasoning.
Sandboxing does not remove the need to review repository rights, secret handling or the folders included in a policy. It does provide a documented way to narrow the effects of local agent-driven commands. GitHub states that the capability is included with Copilot at no extra cost; exact platform support and managed-policy configuration should be checked against its primary documentation.
Primary source
Sources behind this update
AgentenCode publishes product changes only after source-first review. The original provider source remains authoritative for current details.
Full context in the evidence profile.
Full context in the evidence profile.
Full context in the evidence profile.