Finding / github-copilot-cli

2026-09-21-github-copilot-cli-1-0-83-sandbox-grants-file-tools-read-access-to-token-bearing-dev-config-by-default

1.0.83 sandbox grants file tools read access to token-bearing dev config by default. Sandboxed file tools now read the same developer-tool paths as sandboxed shell commands, “including token-bearing registry config such as ~/.npmrc”. The opt-out is sandbox.allowDevToolAccess: false.

Channel: tagged-release. Half: defect. Date: 2026-09-04.

Operator consequence: Re-audit: the sandbox’s default read set now includes registry credentials for the agent’s file tools, not only its shell. If your threat model is prompt injection exfiltrating tokens, set allowDevToolAccess to false, and check that any managed/MDM policy uses the new key name (the 1.0.79 rename means an old allowDevToolCaches: false does nothing).

Receipt

Finding metadata

Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0

Finding ID: 2026-09-21-github-copilot-cli-1-0-83-sandbox-grants-file-tools-read-access-to-token-bearing-dev-config-by-default

Profile citations

Source links

Primary links, including exact changelog lines when available.