github / github/copilot-cli

Add sandbox mode to restrict Copilot CLI file access to a specified working directory

未關閉
#892 12 則留言 49 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
Shell
星號
11.2k
分支
1.9k
平均合併
14 小時 16 分鐘
30 天內合併 PR
6

描述

### Describe the feature or problem you'd like to solve

Please add a sandbox capability to copilot-cli that constrains the code agent’s filesystem permissions so it can only read/write within a specified working directory (workspace root), and is prevented from accessing or modifying any paths outside that directory. This should be similar in spirit to the sandbox/workspace isolation provided by tools like Codex and Claude Code.

### Proposed solution

- Add an opt-in flag and/or config, e.g. --sandbox, --workspace , or sandbox=true
- When enabled:
- All file reads/writes are allowed only under the workspace root (including subdirectories)
- Block path traversal (..), absolute paths, and symlink escapes that would resolve outside the workspace, with a clear error message
- (Optional) Support an allowlist for explicitly permitted additional directories (e.g., temp/cache)

### Example prompts or workflows

_No response_

### Additional context

https://github.com/anthropic-experimental/sandbox-runtime

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。