Copilot · GitHub · Prompt injection · GitHub Blog
To learn more, see “Customizing the agent firewall for Copilot cloud agent” in the GitHub Docs
Compiled by KHAO Editorial — aggregated from 3 sources. See llms.txt for citation guidance.
★ Tier-1 Source
Copilot cloud agent includes a built-in agent firewall to control Copilot’s internet access and help protect against prompt injection and data exfiltration.
Key facts
- Copilot cloud agent includes a built-in agent firewall to control Copilot’s internet access and help protect against prompt injection and data exfiltration
- Organization admins can now manage the agent firewall across all repositories in their organization
- This makes it easier to roll out Copilot cloud agent at scale with the right defaults and guardrails for your needs
- By default, all settings allow each repository to decide, preserving existing behavior
Summary
Organization admins can now manage the agent firewall across all repositories in their organization. Turn the firewall on or off across all repositories, or allow each repository to decide. Add entries to an organization-wide custom allowlist, covering all repositories (e.g., allowing access to an internal package registry).