GitHub Copilot puts a local sandbox around its coding agents
A public preview lets you cap what Copilot agents can touch — files, networks and credentials — and adds Dev Container support for running them on remote hosts.
GitHub shipped local sandboxing for Copilot agents in public preview this week, giving you a way to “limit agents’ access to files, networks, and credentials” instead of trusting the agent to stay in its lane.
The same release adds Dev Container support for agents running on SSH, Tunnel and WSL hosts, using your remote project’s own tools and dependencies, and it’s rolling out gradually. JetBrains also gets an “assisted approvals” preview that auto-approves low-risk tool calls and only stops you for higher-risk ones. Alongside the tooling, Copilot picked up four new models this week: Claude Opus 5.5, GPT-6 Sol and GPT-6 Luna, and Grok 4.7, spread across the Pro, Pro+, Max, Business and Enterprise plans.
Why it matters: the industry’s own incident reports this month have been full of agents wandering past their intended boundaries during training and evaluation runs. Sandboxing that scopes what a coding agent can read, reach on the network, or authenticate with is the practical version of that same lesson, applied to a tool you’re already running against your own repos.
The caveat: it’s a public preview, and GitHub hasn’t published exactly which platforms or Copilot surfaces get it first. Check your plan and client version before assuming it’s there.