By · Keel Automation · October 4, 2026

The sandboxed coding agent is not a finished security desk

On October 1, 2026, GitHub Copilot CLI 1.0.91 put a fuller sandbox CA lifecycle on the record: `copilot sandbox ca` commands to check, create, trust, rotate, and remove proxy CA trust (including unattended Windows setup), with `/sandbox ca install` becoming `create` and `trust`. The same release said complete, statically analyzable read-only shell pipelines can enter execution-evidence review, while incomplete or unbound pipelines still need explicit approval. It also offered a sandbox network bypass for Node/npm EACCES socket denials on Windows, let sandboxed commands run on Windows versions without filesystem enumeration support (with a warning that PowerShell's current location may be wrong), and flushed pending telemetry on CLI shutdown with a bounded delay when telemetry is still initializing. The day before, 1.0.90 (September 30, 2026) added `--mcp-github-auth` to scope GitHub account auth to approved MCP server origins, plus session-scoped read-only directory approvals on path access prompts. On October 2, 2026, Samir Haddad at Threat Frontier summarized Air Security's Plugin4Shell research (published September 17, 2026): a pinned plugin commit SHA can be bypassed when a branch is named after that SHA, because Git can resolve the branch instead of the commit; Bitbucket and self-hosted Git allow 40-hex branch names, while GitHub rejects them, so GitHub-hosted plugins sit outside that path. Claude Code was patched in 2.1.179 (June 17, 2026), Codex in 0.146.0 (July 29, 2026, PR #34644 Verify Git plugin SHA checkouts); as of Threat Frontier's publication, GitHub Copilot had no patch shipped, and Google said it will not patch Gemini CLI (retiring). Defensive mitigations in that write-up: prefer GitHub-hosted plugins for Copilot until a patch lands, inventory Bitbucket and self-hosted plugins, and verify HEAD equals the pinned SHA after checkout in your own tooling. Locally, on September 30, 2026, Tampa Electric filed with the Florida Public Service Commission, as Jada Williams reported for Tampa Bay 28 (WFTS): large-load customers at or above 50 MW would bear full cost of service so those costs are not shifted to general ratepayers; contracts of at least 20 years, early-termination penalties, three years' notice, and financial assurances up to $2 million per MW for some customers; LLCS-1 capped at 1 GW combined, then a second class with project-specific costs; anticipated prep of 600 MW storage and 600 MW generation tied to Big Bend modernization plus new transmission; foreign-entity restrictions per Florida law with ownership affidavits; no major data center proposal currently under review in Hillsborough, while the county discusses cooling water and a possible moratorium on AI-focused data centers (source wording) while policies develop; Cherie Jacobs of TECO said existing customers come first and large-load customers foot the bill; PSC review could take months into early next year. A useful sandbox CA rotation, a cleaner pipeline approval split, an MCP origin scope flag, or a local large-load ratepayer firewall is not a finished security desk that names who owns CA trust, incomplete versus complete pipeline approvals, MCP GitHub auth origins, plugin host inventory and HEAD-equals-pin checks, and who stamps that a sandboxed coding agent is not the same as a named human ownership policy for the security floor.

A useful sandbox is not security-desk ownership

The fastest way to confuse a sandboxed coding agent with a finished security desk is to treat "the CA trusted and the pipeline got through review" like the whole job. Someone sees copilot sandbox ca rotate succeed on Windows, a complete read-only pipeline land in execution-evidence review, and a sticky note that says MCP origins are scoped, and the loop feels closed. The quieter questions arrive when an incomplete pipeline still needs a human yes, when a plugin pin looks honored but HEAD never got compared to the pinned SHA, when nobody can name who owns Bitbucket versus GitHub-hosted plugin inventory, or when a local utility files a ratepayer firewall and the shop still cannot name who owns cost and trust the same way.

A warm editorial cartoon of an office worker at a desk with sticky notes reading SANDBOX CA HOLD and PIPELINE REVIEW, while a small friendly robot offers pipeline review folders, white minimal background, bold black outlines, soft cell shading, narrative humor.

What Copilot CLI 1.0.91 and 1.0.90 put on the record

GitHub's Copilot CLI changelog for 1.0.91, dated October 1, 2026, is plumbing, not a model launch. Sandbox CA trust becomes an explicit lifecycle: check, create, trust, rotate, and remove, including unattended Windows setup. The older /sandbox ca install path becomes create and trust. That matters because sandboxed HTTPS interception only works when the proxy CA is actually trusted; a one-shot "install" hope is not the same as a seat that can diagnose, rotate, and remove.

The same release draws a sharper line on shell pipelines. Complete, statically analyzable read-only pipelines can enter execution-evidence review. Incomplete or unbound pipelines still require explicit approval. TerminalBlog's October 1, 2026 note on 1.0.91 restates that split in plain language: if the CLI can prove the read-only pipeline is safe at parse time, it can flow into evidence review; if variables, subshells, or unbound pieces keep it incomplete, a human still approves.

Windows operators get two more sandbox notes. There is an offer of sandbox network bypass for Node/npm EACCES socket denials. Sandboxed commands can run on Windows versions without filesystem enumeration support, with a warning that PowerShell's current location may be wrong. Shutdown also flushes pending telemetry before exit, with a bounded delay when telemetry is still initializing.

Version 1.0.90, dated September 30, 2026, adds two ownership-shaped flags that belong next to the CA story. --mcp-github-auth scopes GitHub account auth to approved MCP server origins. Session-scoped read-only directory approvals land on path access prompts. That is already a security-desk question: who owns the CA trust seat after rotate, who decides complete versus incomplete pipeline approval, who maintains the MCP origin allowlist, and who stamps session directory approvals instead of treating every path prompt as ambient permission.

Plugin4Shell is unfinished ownership for plugin install trust

Treat "we pinned a commit SHA" as a finished security desk and you will get the dry-run that feels finished and the Tuesday morning where a branch named like a SHA redirected checkout and nobody owned the HEAD check.

On October 2, 2026, Samir Haddad at Threat Frontier summarized Air Security's Plugin4Shell research, published September 17, 2026. At a high level, pinning a marketplace plugin to a reviewed commit SHA is meant to guarantee the installed code matches review. Air Security showed that when a branch is named after that 40-character SHA, Git can resolve the branch instead of the commit, so a repo owner can redirect checkout while the pin still looks honored. Bitbucket and self-hosted Git servers allow those 40-hex branch names. GitHub rejects them, so GitHub-hosted plugins are out of scope for that path. Claude Code was patched in 2.1.179 (June 17, 2026). Codex was patched in 0.146.0 (July 29, 2026), with PR #34644 verifying Git plugin SHA checkouts by resolving HEAD after checkout. As of Threat Frontier's publication, GitHub Copilot had no patch shipped. Google said it will not patch Gemini CLI, which it is retiring.

The article's defensive mitigations stay on the ownership side of the desk: prefer GitHub-hosted plugins for Copilot until a patch ships; inventory Bitbucket and self-hosted plugins; and in your own tooling, verify HEAD equals the pinned SHA after checkout. That is not an exploit walkthrough. It is the dull assertion that a pin is a request until someone owns the post-checkout proof.

Security desk CA trust label pulsing beside pipeline review note
A useful sandbox CA rotation is useful. Naming who owns CA trust, complete versus incomplete pipeline approval, MCP GitHub auth origins, plugin host inventory, HEAD-equals-pin after checkout, and who stamps that a sandboxed coding agent is not a finished human ownership policy is still the security desk.
A warm editorial cartoon of a whiteboard labeled PIPELINE APPROVAL with sticky notes for statically analyzable, incomplete unbound, MCP origin scope, and plugin HOST inventory, and a small friendly robot holding a CHECK HEAD not equal PIN note, white minimal background, bold outlines, soft cell shading, human warmth.

Local large-load firewalls still need named ownership

Tampa Bay is a useful place to hold that checklist against a different kind of "useful capability is not finished ownership" story.

On September 30, 2026, Tampa Electric filed with the Florida Public Service Commission. Jada Williams at Tampa Bay 28 (WFTS) reported the shape of the proposal: large-load customers with expected peak demand of 50 megawatts or more would bear full cost of service (generation, transmission, storage, distribution, and related grid costs) so those costs are not shifted to the general body of ratepayers. Contracts would run at least 20 years, with early-termination penalties, three years' notice, and financial assurances that can reach $2 million per megawatt for some customers. The first class, LLCS-1, would be capped at 1 gigawatt combined; after that, a second class would use project-specific costs. TECO's filing anticipates preparation that includes 600 megawatts of storage, 600 megawatts of generation tied to Big Bend modernization, and new transmission. Foreign-entity restrictions under Florida law, with ownership affidavits, sit in the same filing. There is no major data center proposal currently under review in Hillsborough County; county leaders are discussing cooling-water limits and a possible moratorium on AI-focused data centers (source wording) while land-use policies develop. Cherie Jacobs of TECO said the responsibility is to protect existing customers, and that incoming large-load customers have to foot the bill. PSC review could take months and stretch into early next year.

That is a serious local signal that useful capacity planning still leaves ownership questions on the table. It is not a Keel energy claim, and inventing one would not help. The parallel is cost and trust ownership, not a utility pitch: when sandbox CA tools, pipeline approval splits, and plugin pins get easier to turn on, someone still has to own the policy seat the way TECO's filing tries to keep large-load costs from landing on everyone else.

A warm editorial cartoon of a hand stamping SECURITY DESK OWNER on a checklist covering CA trust seat, incomplete pipeline approval, MCP GitHub auth origins, plugin host inventory, and TECO-style cost ownership parallel, white minimal background, bold outlines, soft cell shading, human warmth.

What Keel will and will not claim

I work at Keel Automation, a Tampa Bay automation agency. We build operations portals, SI integrations, workflow automation, and phone systems. Cole Junck is the owner and founder. We are not going to invent a Copilot CLI sandbox engagement, a Plugin4Shell remediation win, a TECO tariff consulting story, a customer quote from Threat Frontier, or a Keel large-load energy claim, because we have not published one. What the public record already shows is enough: a useful sandbox CA lifecycle is not a finished security-desk owner, a complete-pipeline evidence path is not a finished incomplete-pipeline approval seat, an MCP origin scope flag is not a finished plugin-host inventory, and a local ratepayer firewall filing is not a named human stamp for who owns trust when coding agents get more sandboxed.

A dull security-desk ownership checklist

The test I would run this week is intentionally dull. Write down who owns the Copilot CLI sandbox CA seat that can check, create, trust, rotate, and remove proxy CA trust, including unattended Windows setup, and who reviews that seat after 1.0.91. Write down who decides when a complete, statically analyzable read-only pipeline may enter execution-evidence review versus when an incomplete or unbound pipeline still needs explicit approval. Write down who owns --mcp-github-auth origin allowlists and session-scoped read-only directory approvals from 1.0.90. Write down who inventories plugins hosted on Bitbucket or self-hosted Git versus GitHub-hosted sources for Copilot, and who prefers GitHub-hosted plugins until a Plugin4Shell patch ships. Write down who verifies HEAD equals the pinned SHA after checkout in your own tooling, not only in vendor installers. Write down, separately, how a TECO-style large-load cost firewall (full cost of service on the customer that causes it, long contracts, financial assurances, ratepayer protection) fits your own security desk so a local utility filing and a coding-agent changelog do not get confused with a finished human ownership policy. If those answers are shrugs, you do not have a finished security desk. You have a sandboxed coding agent and a hope that the next CA rotate stamps itself.

GitHub put sandbox CA lifecycle commands, complete versus incomplete pipeline review, Windows sandbox bypass notes, MCP GitHub auth scoping, and session directory approvals on the record. Threat Frontier put Plugin4Shell's unfinished pin ownership in plain view, with Claude Code and Codex patched and Copilot still waiting as of publication. Williams put the local reminder loud that useful large-load prep still leaves who-pays ownership on the table. The research path can still be useful. The useful question is whether anyone owns the CA trust seat, incomplete pipeline approval, MCP origin scope, plugin host inventory, HEAD-equals-pin, and the human stamp before the next sandboxed session pretends the desk closed itself.

Sources

  1. GitHub Copilot CLI changelog, versions 1.0.91 (October 1, 2026) and 1.0.90 (September 30, 2026), on copilot sandbox ca check/create/trust/rotate/remove including unattended Windows setup; /sandbox ca install becoming create and trust; complete statically analyzable read-only pipelines entering execution-evidence review versus incomplete or unbound pipelines needing explicit approval; sandbox network bypass for Node/npm EACCES on Windows; sandboxed commands on Windows without filesystem enumeration support (PowerShell location warning); CLI shutdown telemetry flush; --mcp-github-auth origin scoping; and session-scoped read-only directory approvals. https://raw.githubusercontent.com/github/copilot-cli/main/changelog.md
  2. TerminalBlog, "GitHub Copilot CLI 1.0.91 Just Fixed the Windows Sandbox Nightmare , CA Trust, Network Bypass, and Safer Shutdown," October 1, 2026, secondary commentary on the 1.0.91 CA command set, Windows npm EACCES bypass, legacy Windows sandbox warning, telemetry flush, and complete versus incomplete pipeline approval line. https://terminalblog.com/blog/github-copilot-cli-1-0-91-sandbox-ca-network-fixes/
  3. Samir Haddad / Threat Frontier, "Plugin4Shell: A Pinned Commit SHA Didn't Stop Repo Owners Swapping Plugin Code in Claude Code, Codex, Copilot and Gemini CLI," October 2, 2026, summarizing Air Security research published September 17, 2026, on branch-named-like-SHA checkout redirection; Bitbucket/self-hosted in scope and GitHub-hosted out of scope; Claude Code 2.1.179 (June 17, 2026) and Codex 0.146.0 (July 29, 2026, PR #34644) patches; Copilot with no patch as of publication; Gemini CLI will not be patched (retiring); and defensive mitigations to prefer GitHub-hosted Copilot plugins, inventory Bitbucket/self-hosted plugins, and verify HEAD equals pinned SHA after checkout. https://threatfrontier.com/articles/plugin4shell-pinned-sha-bypass-claude-code-codex-copilot-gemini-cli
  4. Jada Williams / Tampa Bay 28 (WFTS), "TECO proposes sweeping safeguards as Florida prepares for data center growth," on Tampa Electric's September 30, 2026 Florida PSC filing; ≥50 MW large-load customers bearing full cost of service; ≥20-year contracts, early-termination penalties, three years' notice, financial assurances up to $2M per MW; LLCS-1 1 GW cap then project-specific second class; 600 MW storage and 600 MW generation tied to Big Bend modernization plus new transmission; foreign-entity restrictions and ownership affidavits; no major Hillsborough data center proposal under review; county discussion of cooling water and a possible moratorium on AI-focused data centers (source wording); Cherie Jacobs on protecting existing customers; and PSC review possibly stretching into early next year. https://www.tampabay28.com/news/local-news/tampa-metro-west-hillsborough-county/teco-proposes-sweeping-safeguards-as-florida-prepares-for-data-center-growth

Read something that sounds like your shop?

Fifteen minutes with Cole. We will tell you what we would fix first and what it costs.

Call (813) 902-4763

Related: more articles · operations portals · business phone + SI

CallText