GitHub Copilot app adds local sandboxing for files, network access and credentials
GitHub has added local sandboxing to the GitHub Copilot app in public preview, allowing developers to restrict filesystem, network and credential access for agent-driven local sessions.
KX3 News — U.S. / Global Edition
GitHub added local sandboxing to the GitHub Copilot app on September 23, 2026, giving developers a way to limit the damage an unintended agent command can cause on a local machine.
Control files, networking and credentials
Sandbox policies are configured per project. Developers can define additional read/write locations, read-only paths and denied folders, while also controlling outbound internet and local network access.
Credential controls determine whether Git credentials for authenticated HTTPS operations and GitHub CLI credentials are available to the agent session.
Off by default and currently in public preview
Sandboxing is disabled by default. Users can enable it for new sessions in project settings or turn it on for an active session with the /sandbox on command. GitHub says the shell fails rather than silently running unsandboxed if the operating system cannot enforce the requested policy.
The feature applies to local repository and working tree sessions in the GitHub Copilot app. Cloud sandboxes and remote-host sessions are separate.
KX3 perspective
As coding agents gain the ability to edit files and execute tools autonomously, containment becomes part of product quality. Reliable AI development is increasingly about pairing capable models with explicit permission boundaries, narrow credentials and recoverable execution environments.
Primary source: GitHub Changelog
Featured image: Photo by Chris Ried / Unsplash.
コメントを残す