Updated
Updated · github.blog · Oct 7
GitHub Copilot Makes Local Sandboxing Generally Available Across 3 Surfaces
Updated
Updated · github.blog · Oct 7

GitHub Copilot Makes Local Sandboxing Generally Available Across 3 Surfaces

3 articles · Updated · github.blog · Oct 7

Summary

  • GitHub Copilot’s local sandboxing is now generally available in the CLI, Copilot app, and VS Code sessions using Agent Host, giving agent workflows a secure execution boundary on developers’ own machines.
  • MXC powers the feature by translating one sandbox policy into native controls on Windows, macOS, and Linux, restricting filesystem, network, credential, and other system access for Copilot-initiated tools and commands.
  • Developers and organizations can limit which files agents read or modify, control internet and local-network access, and apply the same isolation to local tools and services, including supported MCP and language servers.
  • Enterprise-managed settings can require sandboxing and enforce policies developers cannot weaken, separating tool-execution controls from model choice as Copilot expands local and more autonomous workflows.

Insights

Can Microsoft's new sandboxing truly prevent autonomous coding agents from executing malicious commands on your local machine?
Are developers being forced to buy expensive 128GB memory laptops just to keep their AI coding workflows private?
Will shifting a massive 53GB AI model to local laptops silently destroy your battery life and hardware performance?