Configure GITHUB_TOKEN explicitly for Copilot CLI sandboxed shells
Copilot CLI v1.0.92-4 withholds ambient GITHUB_TOKEN from sandboxed shells unless you configure it, and adds copilot config list/read/set/remove. Upgrade, stop depending on inherited tokens, and manage settings through the new config commands.Why this loop
v1.0.92-4 changes sandbox credential handling: sandboxed shells withhold ambient GITHUB_TOKEN unless explicitly configured, so agent tasks that previously inherited a token will lose GitHub API access until you grant it. The same release adds copilot config subcommands (list, read, set, remove) as the way to change settings, and copilot sandbox ca now honors --config-dir / -C so CA and CLI settings stay aligned. MCP startup is faster with many servers; legacy HTTP+SSE connections no longer hang when a POST is unacknowledged (bounded by the server timeout); MCP tools recover in the same turn when server instructions change. Sandboxed uv can write its cache when dev tool access is enabled, and pnpm no longer hits lock-file permission errors—keep package-manager work inside the sandbox. Compaction keeps the latest prompt when context is exceeded, so do not re-send the last user turn after a compact.
Proposed actions
- Upgrade GitHub Copilot CLI to v1.0.92-4 (https://github.com/github/copilot-cli/releases/tag/v1.0.92-4) and restart the CLI so sandbox token withholding, copilot config, and MCP timeout bounds are active.
- Run
copilot config list; usecopilot config read <setting>,copilot config set <setting> <value>, andcopilot config remove <setting>instead of hand-editing Copilot CLI config files. - If a sandboxed Copilot CLI session must call GitHub APIs, explicitly configure GITHUB_TOKEN for that sandbox; do not rely on ambient GITHUB_TOKEN inheritance (withheld unless configured in v1.0.92-4).
- When using a non-default config directory, run CA as
copilot sandbox ca --config-dir <path>(also works with-C) so sandbox CA uses the same config dir as the CLI. - Leave MCP servers connected when their instructions change—tools recover in the same turn; for legacy HTTP+SSE servers, rely on the server-configured acknowledgement timeout instead of killing hung POSTs.
Agent prompt
Paste into your agent or query via MCP (get_agent_prompt) — free, no extra AI costAGENTS.md / CLAUDE.md / GEMINI.md rule update
DevAgentRadar → Repo Harness Rule Patch
Goal: update our repository's permanent harness instructions based on this release.
Update the file that tool actually reads. Do not dump everything into one file.
- Claude Code → CLAUDE.md plus
.claude/(skills, hooks, settings, agents, commands). It does not read AGENTS.md natively; start CLAUDE.md with@AGENTS.md. - Codex, Copilot, Cursor, Factory Droid, Grok Build, Roo Code, Goose, OpenCode, Amp, Zed, Aider → AGENTS.md.
- Gemini CLI / Antigravity → GEMINI.md. AGENTS.md only if
context.fileNameis set. - Cursor glob-scoped rules →
.cursor/rules/*.mdc(plain.mdis ignored), not a second constitution. - Codex MCP →
.codex/config.toml, not.mcp.json. - Copilot extra instructions →
.github/copilot-instructions.md; custom agents →.github/agents/. - Windsurf →
.windsurf/rules(do not assume AGENTS.md). - Cline →
.clinerules. - Procedures → a skill (
SKILL.md). Enforcement the model must not skip → a hook. Isolated roles → subagents. - Do not fork the same rule into three tool files.
Context
Assistant: GitHub Copilot CLI Proposal: Configure GITHUB_TOKEN explicitly for Copilot CLI sandboxed shells Summary: Copilot CLI v1.0.92-4 withholds ambient GITHUB_TOKEN from sandboxed shells unless you configure it, and adds copilot config list/read/set/remove. Upgrade, stop depending on inherited tokens, and manage settings through the new config commands. Primary source: https://github.com/github/copilot-cli/releases/tag/v1.0.92-4
Why it matters
v1.0.92-4 changes sandbox credential handling: sandboxed shells withhold ambient GITHUB_TOKEN unless explicitly configured, so agent tasks that previously inherited a token will lose GitHub API access until you grant it. The same release adds copilot config subcommands (list, read, set, remove) as the way to change settings, and copilot sandbox ca now honors --config-dir / -C so CA and CLI settings stay aligned. MCP startup is faster with many servers; legacy HTTP+SSE connections no longer hang when a POST is unacknowledged (bounded by the server timeout); MCP tools recover in the same turn when server instructions change. Sandboxed uv can write its cache when dev tool access is enabled, and pnpm no longer hits lock-file permission errors—keep package-manager work inside the sandbox. Compaction keeps the latest prompt when context is exceeded, so do not re-send the last user turn after a compact.
Suggested actions
- Upgrade GitHub Copilot CLI to v1.0.92-4 (https://github.com/github/copilot-cli/releases/tag/v1.0.92-4) and restart the CLI so sandbox token withholding, copilot config, and MCP timeout bounds are active.
- Run
copilot config list; usecopilot config read <setting>,copilot config set <setting> <value>, andcopilot config remove <setting>instead of hand-editing Copilot CLI config files. - If a sandboxed Copilot CLI session must call GitHub APIs, explicitly configure GITHUB_TOKEN for that sandbox; do not rely on ambient GITHUB_TOKEN inheritance (withheld unless configured in v1.0.92-4).
- When using a non-default config directory, run CA as
copilot sandbox ca --config-dir <path>(also works with-C) so sandbox CA uses the same config dir as the CLI. - Leave MCP servers connected when their instructions change—tools recover in the same turn; for legacy HTTP+SSE servers, rely on the server-configured acknowledgement timeout instead of killing hung POSTs.
Config surfaces this release may change
- MCP servers (high confidence) — check your repo before applying
- sandbox settings — check your repo before applying
After you finish
Do not report this as applied to DevAgentRadar. You cannot write the visitor's loop.
Tell the human: open https://devagentradar.com/proposals/github-copilot-cli-v1-0-92-4-configure-github-token-explicitly-for-copil and mark Applied, Skipped, or Failed. Proposal id: 55cb8b9d-7a72-4944-9661-e53b2f4680c0
Instructions:
- Read the existing context files and settings for the tools in this repo.
- Draft an explicit Git diff. Update ONLY agent harness rules or tool configuration.
- Call out deprecated flags, obsolete habits, or changed permission boundaries.
- Do not touch application logic.
Start with the proposed diff and say which layer and which tool's file it belongs in.
Your loop
This browser · no sign-in · not shared as “you”After you run the prompt
Only you can mark this. Agents cannot write your loop.
Your decision stays on this device. A public tally appears after a few votes.