Sandbox Support in GH CLI
Los mantenedores suelen responder en 1 día
@patniko ya está trabajando en esto.
Desde el 19/5/2026.
Evaluación
Este issue todavía no se ha evaluado.
Descripción
Summary
Add first-class sandbox execution support for Copilot SDK sessions, so SDK consumers can run agent file edits, shell commands, MCP servers, and custom tools inside an isolated, resumable workspace rather than relying on the host process filesystem/network boundary.
Current state
From the public docs and examples, the SDK currently exposes several useful building blocks:
workingDirectory/ session workspace configurationavailableTools/excludedToolsonPermissionRequestonPreToolUseandonPostToolUsehooks- custom tools that can replace built-ins
- a virtual filesystem sample that disables built-ins and backs file tools with an in-memory store
Those are helpful, but they do not appear to provide a first-class sandbox lifecycle or provider abstraction. As far as I can tell, there is no SDK-level API for:
- creating or attaching a sandbox execution environment per session/run
- selecting a sandbox provider, such as local process, Docker/container, hosted sandbox, or custom provider
- mounting repositories/directories/object stores into the sandbox workspace
- enforcing filesystem/network/process isolation below the tool-permission layer
- snapshotting/restoring the sandbox workspace across sessions
- running MCP servers inside the same restricted boundary
- exposing sandbox artifacts/ports back to the host application
If this already exists and I missed it, a docs pointer would be great.
Motivation
Many agentic SDK use cases need more than tool allow/deny decisions. They need a concrete execution boundary for untrusted or model-directed work:
- coding agents that edit files and run tests without touching the host directly
- multi-tenant SaaS apps embedding Copilot agent workflows
- eval harnesses that need reproducible, isolated workspaces
- agents that install packages or run scripts
- MCP servers that should be constrained to specific filesystem/network scopes
- workflows that produce artifacts the host app can inspect after the run
The README says the SDK can enable first-party tools that perform filesystem operations, Git operations, and web requests. Permission hooks are useful for policy, but they are not a replacement for OS/container-level isolation.
Prior art / comparison
OpenAI Agents SDK has a first-class sandbox concept where the agent runtime can connect to local/Docker/hosted sandbox providers and the sandbox owns files, commands, ports, mounts, and persisted state.
Anthropic also has sandbox-runtime (srt), a lightweight sandboxing tool designed for agent/MCP/server process isolation using OS sandbox primitives and network/filesystem restrictions.
It would be valuable for Copilot SDK to expose an equivalent integration surface, while still preserving the existing Copilot SDK tool and hook model.
Proposed API direction
One possible shape:
const session = await client.createSession({
model: "gpt-4.1",
sandbox: {
provider: "docker", // or "local", "hosted", custom provider adapter
image: "ghcr.io/example/copilot-agent-sandbox:latest",
workspace: {
mounts: [
{ source: "/path/to/repo", target: "/workspace/repo", mode: "rw" },
],
persist: true,
},
network: {
allow: ["github.com", "registry.npmjs.org"],
default: "deny",
},
resources: {
cpu: 2,
memoryMb: 4096,
timeoutSeconds: 1800,
},
},
onPermissionRequest: async (req) => ({ kind: "approved" }),
});
- Lenguaje dominante
- TypeScript
- Estrellas
- 10.5k
- Forks
- 1.5k
- Merge medio
- 1 d 11 h
- PR fusionados (30 d)
- 81
Preparar el entorno
Inicia el contenedor de desarrollo del proyecto en tu navegador, con tu propia cuenta de GitHub.
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de github/copilot-sdk
-
Clarify SDK architecture and in-process runtime transportPosiblemente ocupada @KalebCole la tomó hace 3 días. Abiertodocumentation
Dificultad 1/5 Menos de una hora Aptitud para principiantes 92/100
github/copilot-sdk#2804 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Python ModelLimits drops max_output_tokens from model metadataPosiblemente ocupada @HDMowri la tomó hace 5 días. Abiertobug
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
github/copilot-sdk#2798 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
github/copilot-sdk#2793 ·
Los mantenedores suelen responder en 1 día
-
agentic-workflows
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
github/copilot-sdk#2782 ·
Los mantenedores suelen responder en 1 día
-
Rust: subagent lifecycle hooks are logged as unknownPosiblemente ocupada @hackberry-lab la tomó hace 7 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
github/copilot-sdk#2781 ·
Los mantenedores suelen responder en 1 día
Todos los issues de github/copilot-sdk
Issues similares
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
AOSSIE-Org/DebateAI#611 ·
Los mantenedores suelen responder en 3 días
-
Upgrade node-libzim to 4.7.0Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
openzim/mwoffliner#2933 ·
Los mantenedores suelen responder en 1 día
-
Use the README category name for website links and submissionsPosiblemente ocupada @dajiaohuang la tomó hoy. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
birobirobiro/awesome-shadcn-ui#647 ·
Los mantenedores suelen responder en 2 días
-
Twake Drive picker: closePicker() never destroys the intent (stop() is on the promise returned by start(), not by create())Posiblemente ocupada @chibenwa la tomó hoy. Abiertoclaude
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
linagora/twake-calendar-frontend#1498 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Add: Valea Prahovei TV RO SDAbiertocheck:passed streams:add
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
Los mantenedores suelen responder en 1 día