Copilot CLI 1.0.92 keeps ambient GITHUB_TOKEN out of sandboxed shells

Copilot CLI 1.0.92 strips ambient GITHUB_TOKEN from sandboxed shells while Git can use masked credentials when sandbox authentication is enabled.

GitHub Copilot CLI 1.0.92, published on 2026-10-05, withholds ambient GITHUB_TOKEN from sandboxed shells unless credential sharing is explicitly configured. Sandboxed Git scripts can still authenticate with masked credentials and SSH remote rewrites. The change separates the parent shell's ambient token from the credential path used by a Git operation.

Key facts

  • GitHub published stable Copilot CLI 1.0.92 at 19:42 UTC on 2026-10-05.
  • The 1.0.92 release notes say sandboxed shells withhold ambient GITHUB_TOKEN unless explicitly configured.
  • The same release notes say sandboxed scripts running Git use masked credentials and SSH remote rewrites.
  • The 1.0.92-3 pre-release, published at 22:06 UTC on 2026-10-02, introduced the Ctrl+E environment picker and masked Git credentials with SSH remote rewrites.
  • The 1.0.92-4 pre-release, published at 19:32 UTC on 2026-10-04, is the first release in this sequence whose notes mention withholding ambient GITHUB_TOKEN.
  • At the 2026-10-06 review, 1.0.93-0 was a newer pre-release. GitHub published it at 23:47 UTC on 2026-10-05 with fixes for warmed language servers when sandboxing is disabled and expansion of truncated compact shell commands.

How Copilot CLI handles ambient credentials

Local sandboxing is off by default and experimental in Copilot CLI. When enabled, Copilot uses Microsoft eXecution Container (MXC) to apply operating-system restrictions. GitHub documents Seatbelt on macOS and bubblewrap on Linux. This is process, filesystem and network containment, not a separate virtual machine or container.

Copilot CLI 1.0.92 changes the shell environment boundary. A GITHUB_TOKEN present in the parent shell is withheld from a sandboxed shell unless the user explicitly configures credential sharing. Git uses a separate path. The 1.0.92 release notes say sandboxed scripts that run Git authenticate with masked credentials and SSH remote rewrites.

That distinction matters. A shell script cannot rely on the parent's ambient GITHUB_TOKEN by default, but Git can still work when the sandbox's authentication settings make a credential available. The release does not turn sandboxed execution into a blanket secret scrubber.

How Copilot CLI configures local sandbox credentials

Inside an interactive Copilot CLI session, /sandbox opens four tabs: General, Auth, Filesystem and Network. The Auth tab controls three relevant choices:

  • Authenticate git injects a GitHub token so HTTPS Git works inside the sandbox without a credential helper. It is on by default.
  • Authenticate gh exports GH_TOKEN for the GitHub CLI without allowing gh to read its stored credentials. It is on by default.
  • Allow keychain access lets sandboxed commands use the macOS Keychain. It is off by default.

The documented session commands are:

/sandbox enable
/sandbox
/sandbox policy

/sandbox enable turns on local sandboxing. /sandbox opens the settings interface. /sandbox policy shows the effective filesystem policy after automatic grants and managed settings are applied. Enterprise-managed settings can lock individual values, and a policy may allow a command to run outside the sandbox after an approval prompt.

What Copilot CLI 1.0.92 does not guarantee

Withholding ambient GITHUB_TOKEN closes one default credential path. It does not prove that no credential is reachable by a sandboxed process. The Auth settings can intentionally provide Git or GitHub CLI credentials, macOS keychain access can be enabled, and sandbox bypass may be allowed. Check the effective policy and Auth settings before treating a sandboxed Git operation as credential-free.

Sources

Last verified: 2026-10-06.

Spotted an outdated or wrong claim? Agents can report it with evidence throughPOST /api/feedback; an editor checks every report. See llms.txt for the agent API.