Trending:

GitHub Copilot adds general availability for local sandboxing across CLI, app, and VS Code

Diagram showing local sandboxing boundaries around Copilot agent workflows on a developer machine
TechStaged-owned

Summary

  • Local sandboxing for GitHub Copilot is generally available in Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host.
  • Sandboxing provides a secure execution boundary for agentic workflows on developers’ machines with restricted access to filesystem, network, and credentials.
  • Local sandboxing is powered by Microsoft eXecution Container (MXC), translating a common policy into native OS controls across Windows, macOS, and Linux.

GitHub has made local sandboxing for Copilot generally available in the Copilot CLI, the GitHub Copilot app, and VS Code sessions that use Agent Host. The feature provides a secure execution boundary for agentic workflows on developers’ own machines.

WHAT LOCAL SANDBOXING DOES

Sandbox policies govern how tools and commands initiated by Copilot can access system resources. Sandboxes restrict access to the filesystem, network, credentials, and other capabilities, based on policies defined by the developer or their organization. TechStaged has also covered GitHub Copilot PR Context Makes AI Code Review Easier to Manage.

CAPABILITIES AND CONTROLS

Local sandboxing translates a common sandbox policy into native OS controls so it works across Windows, macOS, and Linux. Developers can implement protections such as:

  • Limit which files and directories Copilot agents can read or modify
  • Control access to the internet and to local networks
  • Restrict access to Git credentials and GitHub CLI credentials
  • Apply sandboxing to local tools and services (including local MCP and language servers where supported)
  • Enforce enterprise-managed settings to require sandboxing and prevent policy weakening

WHERE IT’S AVAILABLE AND AT WHAT COST

The feature is available in GitHub Copilot across Copilot CLI, the Copilot app, and VS Code sessions using Agent Host. Local sandboxing is included with GitHub Copilot at no additional cost.

ENTERPRISE CONTROLS AND POLICY FIDELITY

Organizations can define and enforce sandbox policies to ensure developers cannot bypass protections. Sandboxing policies apply to tool execution regardless of which Copilot model is used.

GETTING STARTED

GitHub’s documentation points developers to the About cloud and local sandboxes for GitHub Copilot for setup and guidance on policy configuration and enforcement.

Reporting by Owen Blackridge; editing by TechStaged editors

Editorial disclosure: This article was prepared with AI assistance from a source-limited research package and passed TechStaged's automated factual, originality, licensing, and publication checks.

Our Standards: The TechStaged Editorial Principles.

f in

Owen Blackridge

Owen Blackridge

Technology Editor

Owen covers platform shifts, AI launches, and the practical impact of emerging technology on small teams.