Copilot local sandboxing is GA — and it ships switched off
GitHub Copilot local sandboxing is now GA in the CLI, app and VS Code at no extra cost. It is off by default. Here is what it fences and where it leaks.
GitHub made Copilot local sandboxing generally available on October 7. It fences what Copilot's agent can read, write, reach on the network, and authenticate as — on Windows, macOS, and Linux, at no extra cost. One detail did not make the headline: it is off by default. Until someone types /sandbox enable, every command your coding agent runs has the same access you do.
What actually happened
Per the GitHub changelog, local sandboxing is GA in Copilot CLI, the Copilot app, and VS Code sessions using Agent Host. It runs on Microsoft eXecution Container (MXC), which maps one policy to each operating system's native controls. The policy applies no matter which model Copilot is using.
The docs fill in the parts that matter:
- Off until enabled. Run
/sandbox enablein a CLI session. It persists until you disable it. - What the CLI can fence: read-only or read/write paths, denied paths, internet and local network access, per-host allow and deny rules, Git and
ghcredentials, extra environment variables, local MCP and LSP servers, and the macOS keychain. - Credentials become placeholders. Sandboxed tools get stand-ins. A local proxy injects the real credential only for approved HTTPS destinations.
- Admins can lock it. Managed settings can require sandboxing so developers cannot switch it off.
sandbox.failIfUnavailableblocks the agent entirely on hosts that cannot enforce it.
And the parts GitHub is honest about. It is OS-level containment, not a VM or container. Remote MCP servers are never sandboxed. The CLI's built-in file tools run in-process and only check the policy on a best-effort basis. On Windows, network rules depend on programs honoring proxy settings — weaker than on macOS and Linux. Turning it on in the CLI does not turn it on in the app.
Why it matters for your business
A coding agent is a process with your laptop's permissions and a stranger's instructions. One poisoned README, one issue with an injected prompt, and the agent that was "just fixing a test" is reading ~/.aws/credentials. The sandbox is the cheapest fix for that we have seen ship this year — free, cross-platform, and centrally enforceable.
But a free control that defaults to off protects nobody. That is the operator's whole job here:
Turn it on for every seat, from policy, not from a wiki page. If you have Business or Enterprise, push managed settings. A toggle each developer owns is a suggestion.
Deny network by default, then allowlist. npm, PyPI, your Git host. An agent that cannot call out cannot exfiltrate.
Know the holes. Remote MCP servers sit outside the fence. Audit which ones your team has connected — they run with whatever tokens you gave them.
Windows shops: treat it as a speed bump. Proxy-honoring enforcement stops well-behaved tools, not hostile ones.
Key takeaways
- Copilot local sandboxing went GA on October 7 in Copilot CLI, the Copilot app, and VS Code Agent Host sessions, at no extra cost
- It is off by default — enable with
/sandbox enable, or enforce through managed settings - It fences filesystem paths, network hosts, Git and
ghcredentials, environment variables, and local MCP/LSP servers - Real credentials are swapped for placeholders and injected only for approved HTTPS destinations
- Not a VM: remote MCP servers are unsandboxed, built-in file tools are best-effort, and Windows network enforcement is weaker
Your coding agent can probably reach more than you think. We set up agent workflows with sandbox policies, network allowlists, and secrets the agent never sees in plaintext — then test that the fence holds. See how we build dev tooling, or tell us what your agents run on today.
Sources: GitHub Changelog, GitHub Docs: About cloud and local sandboxes.
- #github-copilot
- #agent-security
- #sandbox
- #dev-tools
- #coding-agents
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
NetScaler CVE-2026-107406: last week's SAML patch isn't enough
Citrix NetScaler CVE-2026-107406 (CVSS 9.5) hits SAML IdP builds up to 14.1-73.41, the fix for last week's KEV bug. Patch to 14.1-73.46 or 13.1-64.29.
Read itHarness buys Augment Code assets: coding agents consolidate
Harness bought Augment Code's Cosmos, Auggie CLI and Context Engine. Coding agent vendors are consolidating. Keep your context and workflow portable.
Read it