Solutions  ·  2026-10-11

GitHub Copilot Local Sandboxing reaches GA — MXC-powered execution boundary for agentic coding

SolutionsHigh impactGlobal
On Oct 7 GitHub made Local Sandboxing generally available in Copilot CLI, the Copilot app, and VS Code Agent Host sessions, at no additional cost. Powered by Microsoft eXecution Container (MXC), it translates one sandbox policy into native OS controls across Windows/macOS/Linux to restrict agent-run commands' filesystem, network, and credential access — with enterprise-managed settings developers cannot weaken, covering local MCP and language servers.
This is the GA productization of a near-universal boundary for agentic dev tools: orgs can now mandate that Copilot's autonomous workflows run inside enforced sandboxes (independent of model choice), materially shrinking the blast radius of prompt-injected or malicious tool output on developer machines — the same surface Adversa's Oct 6-7 encrypted prompt-injection research targeted.
Enterprises running Copilot agent workflows should enable org-mandated sandboxing now, combine with autopilot URL-fetch policies, and evaluate before approving autonomous workflows in production repos.
GitHub changelog — Local sandboxing generally availablePlain English guide
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →