What happened
On Oct 7 GitHub made Local Sandboxing generally available in Copilot CLI, the Copilot app, and VS Code Agent Host sessions, at no additional cost. Powered by Microsoft eXecution Container (MXC), it translates one sandbox policy into native OS controls across Windows/macOS/Linux to restrict agent-run commands' filesystem, network, and credential access — with enterprise-managed settings developers cannot weaken, covering local MCP and language servers.
Why it matters
This is the GA productization of a near-universal boundary for agentic dev tools: orgs can now mandate that Copilot's autonomous workflows run inside enforced sandboxes (independent of model choice), materially shrinking the blast radius of prompt-injected or malicious tool output on developer machines — the same surface Adversa's Oct 6-7 encrypted prompt-injection research targeted.
Applicability
Enterprises running Copilot agent workflows should enable org-mandated sandboxing now, combine with autopilot URL-fetch policies, and evaluate before approving autonomous workflows in production repos.