Software 44981 Published by

Visual Studio Code 1.141 makes cross-platform sandboxing generally available in the Copilot agent host across Windows, macOS, and Linux to limit what autonomous agents can reach on your machine. The update also lets you continue agent sessions live between VS Code, the Copilot app, and the Codex CLI without reloading, while a new grid layout helps you juggle multiple conversations at once. Microsoft is tightening enterprise control with enforceable sandboxing, session attribution telemetry, and a smoother migration to unified managed settings, and finally retired the single-value github-enterprise.uri setting in favor of a list-based alternative. It's a consolidating release that doubles down on VS Code's pivot from a code editor to a control center for code-writing agents.



Visual Studio Code 1.141 Adds Cross-Platform Sandboxing for AI Agents

Microsoft has shipped Visual Studio Code 1.141, a stable release that leans hard into making autonomous coding agents safe enough to leave running unattended. The headline move is cross-platform sandboxing for the Copilot agent host, but the update also chases down the small frictions that pile up when agent sessions stick around longer than they used to.

The broader story here is that VS Code has spent the last year turning itself from a place where you write code into a control center for code-writing agents. That pivot started with the Agent Host architecture announced in August 2026, which pulled long-running sessions out of the editor window and into their own process. One. Four. One is the first build to harvest most of that infrastructure's practical payoff.

Screenshot_from_2026_02_20_08_38_56

Sandboxing, finally everywhere

The security piece is the one worth your attention. Microsoft has made sandboxing generally available in the Copilot agent host across Windows, macOS, and Linux, which directly addresses the nagging question of what an autonomous agent can actually reach on your machine when you've walked away from your desk.

Sandboxing restricts how terminal commands and their child processes touch files and the network, and it can also cover locally launched MCP servers and language servers if you turn it on. The idea is to blunt the damage from prompt injection, model mistakes, untrusted dependencies, and those servers you installed without reading the docs.

Here's the honest part. Microsoft is upfront that sandboxing adds protection rather than replacing endpoint security. A sandboxed process still runs on your machine under your account, so any granted network access, extra paths, stored credentials, or ability to break out of the sandbox weakens the whole idea.

There are platform prerequisites you should know about. macOS needs nothing. Linux and WSL2 require you to install bubblewrap and socat, and WSL version 1 is not supported. Windows needs a September 8, 2026 security update applied, and Windows support itself is still experimental.

The feature is toggled with the chat.agent.sandbox.enabled setting, which defaults to off. There is a Chat: Open Worktree Cleanup editor in there somewhere too. Everything is granular like network domains, read-write and read-only paths, denied paths, credential use for Git and the GitHub CLI, and a /sandbox policy slash command shows you what's actually in effect for a session. Worth noting that sandboxing holds even when you've picked "Allow all."

Keeping sessions alive

The rest of 1.141 is about making agent life less fiddly, and the theme is continuity. The Copilot harness, the piece that assembles context, runs the agent loop, and applies code changes, now runs on the GitHub Copilot SDK, the same runtime behind the standalone Copilot app and the Copilot CLI.

That means a session started in VS Code should behave like one started in your terminal. The Agent Host decouples the session from the window that spawned it, so you can close the folder, close the window, and come back later without losing state.

New conversations launched in the Copilot CLI or the GitHub Copilot app are now detected as external sessions the moment the first request goes out. Codex users can do the same thing, picking up a ChatGPT or Codex CLI chat and continuing it in VS Code with history intact. You can switch back later. Because only one app can message a chat at a time, VS Code shows a "This chat is open in another app" banner when that app still holds the session. Fully quit the app and hit Retry.

The grid is another win. The Agents window now has a two-dimensional layout where you can drag sessions into splits, resize panes, and maximize one when you need to focus, then snap back to the grid. It mirrors the editor's own multi-pane flexibility, which is what makes watching several sessions at once actually practical.

The boring stuff that matters

Autonomous sessions create isolated Git worktrees to keep their changes separate from your workspace. Over time those pile up, and nothing cleaned them. The new worktree cleanup editor shows how much space dormant sessions are hogging, lets you filter by inactivity, and deletes what you pick. Active, running, needs-input, and pinned sessions are off-limits.

GitHub Enterprise gets a fix too. If you use Copilot through a GHE.com account while your source sits on GitHub Enterprise Server, you could never be signed into both at once before. The new list-based github-enterprise.uris setting accepts multiple instances and labels each account with its host, so monalisa - octocat.ghe.com stays distinguishable from the rest. Existing credentials migrate automatically.

On the enterprise side, admins can now require sandboxing and stop it from being bypassed through unified Copilot managed settings, using a sandbox block with an allowBypass: false flag. There's also a new telemetry option that attributes sessions to specific users and machines, which is a big deal for accountability if your security team has been asking questions.

The small stuff

Not everything is serious. The frosted-glass pop-ups are back as an option (workbench.modernUIFrostedGlass), and you can now choose between connected and pill-style tabs. Block pasting across multiple lines is in too, which helps enormously with columnar text, a task every developer has cursed at at some point.

And the VS Code pet has finally gotten a name. It's Blobby, summonable with /vscode-pet, customizable with /blobby, and unlockable further as you hit milestones. A genuinely tiny detail, but it's the kind of thing that shows up in release notes only when people actually care.

Two settings are deprecated: the old single-value github-enterprise.uri and legacy sandbox device policies. VS Code still reads the old GitHub setting until you switch, and the old ChatAgentSandboxEnabled policy now supplies a default rather than forcing it.

Keep in mind that all of this consolidates rather than revolutionizes. There are no new languages, no paradigm shifts. This is the sound of a tool maturing, persistent sessions, cross-app continuity, grids, and a sandbox that makes autonomy survivable. The shift is from "look what the agent can do" to "look how well I can manage what it's doing," and 1.141 moves firmly in that direction.

Head here to download the release.