github / github/copilot-cli

Add sandbox mode to restrict Copilot CLI file access to a specified working directory

Đang mở
#892 12 bình luận 49 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
Shell
Star
11.2k
Fork
1.9k
Merge trung bình
14 giờ 16 phút
Pull request đã merge (30 ngày)
6

Mô tả

### Describe the feature or problem you'd like to solve

Please add a sandbox capability to copilot-cli that constrains the code agent’s filesystem permissions so it can only read/write within a specified working directory (workspace root), and is prevented from accessing or modifying any paths outside that directory. This should be similar in spirit to the sandbox/workspace isolation provided by tools like Codex and Claude Code.

### Proposed solution

- Add an opt-in flag and/or config, e.g. --sandbox, --workspace , or sandbox=true
- When enabled:
- All file reads/writes are allowed only under the workspace root (including subdirectories)
- Block path traversal (..), absolute paths, and symlink escapes that would resolve outside the workspace, with a clear error message
- (Optional) Support an allowlist for explicitly permitted additional directories (e.g., temp/cache)

### Example prompts or workflows

_No response_

### Additional context

https://github.com/anthropic-experimental/sandbox-runtime

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.