Development·EASYHUB JOURNAL
GitHub Copilot local sandboxing reaches GA with MXC policies for agent access to files, networks and credentials

What changed
GitHub made local sandboxing generally available on October 7 across Copilot CLI, the Copilot app and VS Code sessions using Agent Host. Powered by Microsoft eXecution Container (MXC), the sandbox can restrict which files and directories agent-run commands may access, internet and local-network connectivity, Git and GitHub CLI credentials, and supported local MCP or language-server tools. Enterprise-managed settings can require sandboxing and enforce policies developers cannot weaken. GitHub stresses that model execution and tool isolation are separate concerns: the same sandbox policy applies regardless of the model Copilot uses. Local sandboxing is included with Copilot at no extra charge.
- Original title
- Local sandboxing for GitHub Copilot now generally available
- Source
- GitHub · github.blog
- Topic
- Development
- Source month
- 2026-10
This is a concise EasyHub summary of the linked source, not the full report or original reporting. Availability and preview conditions are described in the summary and original.
Summary page published · Editorial information