Move Copilot CLI user settings into ~/.copilot/settings.json
Copilot CLI v1.0.93 reads user settings only from ~/.copilot/settings.json (keys in ~/.copilot/config.json are ignored), opens command sandboxing to every user via /sandbox and --sandbox, adds enterprise permissions.limitTo domain boundaries, and honors --context long_context at startup.Why this loop
v1.0.93 silently changes where Copilot CLI loads user settings: only ~/.copilot/settings.json is read, so any user-setting keys left in ~/.copilot/config.json stop applying. Command sandboxing is now available to all users with /sandbox and --sandbox; sandbox local-network allowlists include localhost and loopback, so isolated shell commands can still reach local services. Enterprises can set permissions.limitTo to keep network requests inside managed domains. Start with --context long_context and confirm the real window via /context. MCP server config changes apply between turns without restarting; plugin skill commands remain after reloading enabled plugins. GitHub.com Connector users can expand GitHub CLI permissions in place and retry instead of switching sign-in. Model picker recommendations now prioritize GPT-6.1 Sol, GPT-6 Astra/Luna, and Claude 5.5.
Proposed actions
- Upgrade GitHub Copilot CLI to v1.0.93, then move every user-setting key from ~/.copilot/config.json into ~/.copilot/settings.json (create it if missing). v1.0.93 ignores user-setting keys left in config.json.
- Start Copilot CLI with
copilot --sandboxor, in an active session, run/sandboxso command sandboxing is on; localhost and loopback are now on the sandbox local-network allowlist. - For managed installs, set enterprise permissions.limitTo to your approved domain list so Copilot CLI network requests stay inside those boundaries.
- Launch long-context work with
copilot --context long_context, then run/contextand confirm the shown context allowance matches the long_context window. - Edit MCP server config mid-session and continue—the new servers apply between turns with no restart. After reloading enabled plugins, confirm plugin skill commands are still listed. If a GitHub.com Connector lacks the GitHub CLI scope, expand permissions in place and retry instead of switching sign-in.
Agent prompt
Paste into your agent or query via MCP (get_agent_prompt) — free, no extra AI costAGENTS.md / CLAUDE.md / GEMINI.md rule update
DevAgentRadar → Repo Harness Rule Patch
Goal: update our repository's permanent harness instructions based on this release.
Update the file that tool actually reads. Do not dump everything into one file.
- Claude Code → CLAUDE.md plus
.claude/(skills, hooks, settings, agents, commands). It does not read AGENTS.md natively; start CLAUDE.md with@AGENTS.md. - Codex, Copilot, Cursor, Factory Droid, Grok Build, Roo Code, Goose, OpenCode, Amp, Zed, Aider → AGENTS.md.
- Gemini CLI / Antigravity → GEMINI.md. AGENTS.md only if
context.fileNameis set. - Cursor glob-scoped rules →
.cursor/rules/*.mdc(plain.mdis ignored), not a second constitution. - Codex MCP →
.codex/config.toml, not.mcp.json. - Copilot extra instructions →
.github/copilot-instructions.md; custom agents →.github/agents/. - Windsurf →
.windsurf/rules(do not assume AGENTS.md). - Cline →
.clinerules. - Procedures → a skill (
SKILL.md). Enforcement the model must not skip → a hook. Isolated roles → subagents. - Do not fork the same rule into three tool files.
Context
Assistant: GitHub Copilot CLI Proposal: Move Copilot CLI user settings into ~/.copilot/settings.json Summary: Copilot CLI v1.0.93 reads user settings only from ~/.copilot/settings.json (keys in ~/.copilot/config.json are ignored), opens command sandboxing to every user via /sandbox and --sandbox, adds enterprise permissions.limitTo domain boundaries, and honors --context long_context at startup. Primary source: https://github.com/github/copilot-cli/releases/tag/v1.0.93
Why it matters
v1.0.93 silently changes where Copilot CLI loads user settings: only ~/.copilot/settings.json is read, so any user-setting keys left in ~/.copilot/config.json stop applying. Command sandboxing is now available to all users with /sandbox and --sandbox; sandbox local-network allowlists include localhost and loopback, so isolated shell commands can still reach local services. Enterprises can set permissions.limitTo to keep network requests inside managed domains. Start with --context long_context and confirm the real window via /context. MCP server config changes apply between turns without restarting; plugin skill commands remain after reloading enabled plugins. GitHub.com Connector users can expand GitHub CLI permissions in place and retry instead of switching sign-in. Model picker recommendations now prioritize GPT-6.1 Sol, GPT-6 Astra/Luna, and Claude 5.5.
Suggested actions
- Upgrade GitHub Copilot CLI to v1.0.93, then move every user-setting key from ~/.copilot/config.json into ~/.copilot/settings.json (create it if missing). v1.0.93 ignores user-setting keys left in config.json.
- Start Copilot CLI with
copilot --sandboxor, in an active session, run/sandboxso command sandboxing is on; localhost and loopback are now on the sandbox local-network allowlist. - For managed installs, set enterprise permissions.limitTo to your approved domain list so Copilot CLI network requests stay inside those boundaries.
- Launch long-context work with
copilot --context long_context, then run/contextand confirm the shown context allowance matches the long_context window. - Edit MCP server config mid-session and continue—the new servers apply between turns with no restart. After reloading enabled plugins, confirm plugin skill commands are still listed. If a GitHub.com Connector lacks the GitHub CLI scope, expand permissions in place and retry instead of switching sign-in.
Config surfaces this release may change
- settings files (high confidence) — check your repo before applying
After you finish
Do not report this as applied to DevAgentRadar. You cannot write the visitor's loop.
Tell the human: open https://devagentradar.com/proposals/github-copilot-cli-v1-0-93-move-copilot-cli-user-settings-into-copilot-s and mark Applied, Skipped, or Failed. Proposal id: 9d29e7f2-85fe-470a-8137-8d3ec265c02f
Instructions:
- Read the existing context files and settings for the tools in this repo.
- Draft an explicit Git diff. Update ONLY agent harness rules or tool configuration.
- Call out deprecated flags, obsolete habits, or changed permission boundaries.
- Do not touch application logic.
Start with the proposed diff and say which layer and which tool's file it belongs in.
Your loop
This browser · no sign-in · not shared as “you”After you run the prompt
Only you can mark this. Agents cannot write your loop.
Your decision stays on this device. A public tally appears after a few votes.