Skip to content

copilot --acp ignores --sandbox and sandbox.enabled; shell commands run unsandboxed #5089

Description

@JereStay-MSFT

Describe the bug

In ACP mode (copilot --acp), the local sandbox is never applied, even when the CLI is started
with --sandbox --experimental and settings.json has sandbox.enabled: true and
allowBypass: false. A shell write to a path in sandbox.userPolicy.filesystem.readonlyPaths
succeeds. The same COPILOT_HOME, policy, and prompt in -p mode are blocked by the OS sandbox.

Evidence from the two sessions:

copilot -p ... --sandbox copilot --acp --sandbox
Write to read-only path Blocked: Access to the path '...\tests\Locked.txt' is denied. Succeeded, exit 0
events.jsonl tool telemetry sandboxApplied:"true", sandboxed:true sandboxApplied:"false"
Debug log, shell diagnostics n/a sdk shell exit {... "sandbox":false ...}
Debug log, telemetry cli_sandbox:"true", config_sandbox_enabled:"true" No cli_sandbox or config_sandbox_* fields

session/new exposes the config options mode, model, reasoning_effort, agent and
allow_all. None of them is a sandbox option, so an ACP client has no other way to enable it.

Affected version

GitHub Copilot CLI 1.0.94-5.

Steps to reproduce the behavior

  1. Create a git repo with a file tests\Locked.txt that contains original.

  2. Create an empty COPILOT_HOME folder, copy your config.json into it (for auth), and add
    this settings.json, using the absolute path of the repo's tests folder:

    {
      "sandbox": {
        "enabled": true,
        "allowBypass": false,
        "userPolicy": {
          "filesystem": { "readonlyPaths": ["C:\\path\\to\\repo\\tests"] },
          "network": { "allowOutbound": true, "allowLocalNetwork": true }
        }
      }
    }
  3. Control (-p): from the repo root, with COPILOT_HOME set to that folder, run:

    copilot -p "Use only the powershell tool. Run exactly: Set-Content tests\Locked.txt changed  then report the exit code and any error verbatim. Do not retry." --sandbox --experimental --allow-all-tools --log-level debug
    

    Result: exit code 1, Access to the path '...\tests\Locked.txt' is denied. The file still
    contains original.

  4. ACP: with the same COPILOT_HOME and working directory, start
    copilot --acp --sandbox --experimental --log-level debug from an ACP client. Send
    initialize, then session/new, then a session/prompt with the same text. Approve the
    shell permission request with allow_once.

  5. Result: the command exits 0, and tests\Locked.txt now contains changed.

  6. Compare COPILOT_HOME\session-state\<id>\events.jsonl for the two sessions: -p records
    sandboxApplied:"true", while ACP records sandboxApplied:"false".

Expected behavior

ACP sessions apply the local sandbox in the same way as interactive and -p sessions when
--sandbox is passed or sandbox.enabled is true. If that isn't intended, ACP should expose
the sandbox as a session/new config option, or fail clearly at startup instead of running
unsandboxed.

Additional context

Activity

  1. added
    area:non-interactiveNon-interactive mode (-p), CI/CD, ACP protocol, and headless automation
    area:permissionsTool approval, security boundaries, sandbox mode, and directory restrictions
    and removed on Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:non-interactiveNon-interactive mode (-p), CI/CD, ACP protocol, and headless automationarea:permissionsTool approval, security boundaries, sandbox mode, and directory restrictions

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions