# Defense-in-Depth Score: GitHub Copilot Chat (VS Code)

**Repo:** https://github.com/microsoft/vscode (`extensions/copilot`) · **Commit:** `7f20cdad4f4ab923272e91e330a7701c52706fc7` · **Reviewed:** 2026-10-03
**What it is:** GitHub Copilot Chat and agent mode, now in the VS Code repo
**Category:** Coding
**Scored configuration:** Local agent mode in VS Code, fresh install in a trusted workspace, Default Permissions level, no sandbox, no custom settings.
**Agent surface (default):** code execution yes · filesystem write yes · network egress yes · external credentials yes · persistent memory yes · untrusted input yes · third party extensions yes · sub agents yes · external communication opt-in

## Score: 3.3 / 10.0 (Minimal)

| # | Criterion | S | C | D | B | Raw | Cap | Score | Confidence |
|---|---|---|---|---|---|---|---|---|---|
| C1 | Identity & least privilege | L0 | L1 | L1 | L1 | 0.17 | — | **0.17** | High |
| C2 | Approval gates | L3 | L2 | L1 | L2 | 0.53 | G2 | **0.25** | High |
| C3 | Tool & action scoping | L2 | L2 | L1 | L0 | 0.35 | — | **0.35** | High |
| C4 | Code-execution isolation | L2 | L2 | L0 | L1 | 0.35 | G1 | **0.35** (alt) | High |
| C5 | Untrusted input blast radius | L2 | L2 | L2 | L2 | 0.50 | — | **0.50** | High |
| C6 | Memory, context & configuration integrity | L0 | L1 | L1 | L1 | 0.17 | — | **0.17** | High |
| C7 | Third-party extensions | L1 | L1 | L2 | L1 | 0.30 | — | **0.30** | High |
| C8 | Secrets & sensitive-data protection | L2 | L1 | L1 | L1 | 0.33 | — | **0.33** | High |
| C9 | Audit & traceability | L2 | L3 | L2 | L1 | 0.53 | — | **0.53** | Medium |
| C10 | Limits & kill switch | L1 | L1 | L2 | L1 | 0.30 | — | **0.30** | High |


Copilot agent mode asks before every terminal command, untrusted web fetch and non-read-only MCP tool, and the dialog shows the exact command. Those commands then run unsandboxed as you, with all your credentials in the environment. The biggest gap is that a repository's .github/hooks files load automatically once you trust the workspace, which Copilot requires. A preToolUse hook in one of those files can approve tool calls on your behalf, and hooks run shell commands without asking. File edits in the workspace and writes to the global memory tool also happen without approval.

## Critical gaps
- Repository-controlled hook files (.github/hooks/*.json) load by default in trusted workspaces, and a preToolUse hook returning 'allow' bypasses the tool approval gate for any tool, including the terminal. (ASI02, ASI09, ASI04, T10; C2) — [src/vs/workbench/contrib/chat/common/promptSyntax/config/promptFileLocations.ts:213](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/common/promptSyntax/config/promptFileLocations.ts#L213); [src/vs/workbench/contrib/chat/common/promptSyntax/service/promptsServiceImpl.ts:1280-1282](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/common/promptSyntax/service/promptsServiceImpl.ts#L1280-L1282); [extensions/copilot/src/extension/prompts/node/panel/toolCalling.tsx:300-328](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/prompts/node/panel/toolCalling.tsx#L300-L328); [src/vs/workbench/contrib/chat/browser/tools/languageModelToolsService.ts:878-880](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/browser/tools/languageModelToolsService.ts#L878-L880)
- Agent terminal commands, hooks and MCP stdio servers run on the host as the user with no sandbox by default; the terminal sandbox is off by default. (ASI05, T11; C4) — [src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts:530-541](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts#L530-L541); [src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/toolTerminalCreator.ts:151-159](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/toolTerminalCreator.ts#L151-L159); [extensions/copilot/src/platform/chat/node/hookExecutor.ts:51](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/platform/chat/node/hookExecutor.ts#L51)

## Criterion details

### C1 Identity & least privilege — 0.17 (high)

Copilot's own GitHub sign-in asks only for the user:email scope by default, and the GitHub MCP server that would act on GitHub with the user's token is off by default. Everything else runs with the developer's own authority. Agent terminals inherit the full VS Code environment, which includes cloud, git and SSH credentials, and nothing is scrubbed or scoped. File tools check whether a path is inside the workspace and ask before going outside it, but nothing narrows what the shell can do once a command is approved.

- **S L0:** The terminal tool runs commands as the OS user with the full inherited environment (ambient cloud, gh, SSH and git credentials); only Copilot's own GitHub token requests minimal scopes. — [src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/toolTerminalCreator.ts:151-159](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/toolTerminalCreator.ts#L151-L159); [extensions/copilot/src/platform/authentication/common/authentication.ts:25](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/platform/authentication/common/authentication.ts#L25); searched `rg -n -S 'scrub|sanitizeEnv|delete env'` in `src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/toolTerminalCreator.ts` → 0 hits (Agent terminals add variables to the inherited environment; nothing is removed.) (verified)
  - *To reach the next level:* No per-tool or per-capability credential narrowing for the shell; ambient credentials reach every approved command.
- **C L1:** Built-in file tools check workspace containment before reading or editing outside it, while the terminal, hooks and MCP stdio servers get the full process environment. — [extensions/copilot/src/extension/tools/node/readFileTool.tsx:428-431](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/tools/node/readFileTool.tsx#L428-L431); [extensions/copilot/src/extension/tools/node/editFileToolUtils.tsx:858-859](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/tools/node/editFileToolUtils.tsx#L858-L859); [extensions/copilot/src/platform/chat/node/hookExecutor.ts:51](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/platform/chat/node/hookExecutor.ts#L51); [src/vs/workbench/api/node/extHostMcpNode.ts:64](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/api/node/extHostMcpNode.ts#L64) (verified)
  - *To reach the next level:* Subprocesses (terminal, hooks, MCP servers) inherit ambient credentials instead of passing through the same scoping.
- **D L1:** The default is the user's own identity; Copilot's token asks only for user:email, but the permissive repo/workflow scope set is requested by several features on demand. — [extensions/copilot/src/platform/authentication/common/authentication.ts:25](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/platform/authentication/common/authentication.ts#L25); [extensions/copilot/src/platform/authentication/common/authentication.ts:31](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/platform/authentication/common/authentication.ts#L31); [extensions/copilot/src/platform/configuration/common/configurationService.ts:1187](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/platform/configuration/common/configurationService.ts#L1187) (verified)
  - *To reach the next level:* No near-minimal default for tool execution; the shell has the user's full authority from the first approved command.
- **B L1:** A hijacked session that gets a command approved reaches every service the user's shell can reach; the per-call terminal approval is an independent layer that still holds. — [src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/toolTerminalCreator.ts:151-159](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/toolTerminalCreator.ts#L151-L159); [src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/tools/runInTerminalTool.ts:1276](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/tools/runInTerminalTool.ts#L1276) (verified)
  - *To reach the next level:* Credentials reachable from the agent are long-lived and span multiple systems; nothing limits them to one project.
- **Cap:** none

### C2 Approval gates — 0.25 (high)

By default every terminal command needs a click on a dialog that shows the exact command line. Commands are parsed with tree-sitter, and auto-approve rules only take effect after the user accepts a one-time warning. Web fetches to untrusted domains, MCP tools without a read-only hint, and edits to sensitive or out-of-workspace files also ask first. Ordinary file edits inside the workspace are auto-approved by default, and that covers code the user will later run. The decisive problem is that a repository's .github/hooks/*.json is loaded automatically once the workspace is trusted, which is required to use Copilot at all. A preToolUse hook in that file can answer 'allow' and approve any tool call, so a cloned repo can switch the gate off.

- **S L3:** Per-call approval shows the exact command line (user-editable), URL or file, with risk tiers (default allow/deny rules, sensitive-file patterns, read-only hints) deciding what needs a human. — [src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/tools/runInTerminalTool.ts:1231-1233](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/tools/runInTerminalTool.ts#L1231-L1233); [src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/tools/runInTerminalTool.ts:1276](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/tools/runInTerminalTool.ts#L1276); [src/vs/workbench/contrib/chat/electron-browser/builtInTools/fetchPageTool.ts:262-269](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/electron-browser/builtInTools/fetchPageTool.ts#L262-L269); [src/vs/workbench/contrib/mcp/common/mcpLanguageModelToolContribution.ts:232-238](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/mcp/common/mcpLanguageModelToolContribution.ts#L232-L238) (verified)
  - *To reach the next level:* Argument-level policy exists only for terminal commands; MCP and other tools have no parsed-argument allow/deny rules.
- **C L2:** Terminal, fetch, MCP and sensitive-file edits traverse the gate, but non-sensitive workspace edits are auto-approved by default and MCP read-only hints are self-declared by the server. — [src/vs/platform/chat/common/chatSettings.ts:66-68](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/platform/chat/common/chatSettings.ts#L66-L68); [src/vs/workbench/contrib/mcp/common/mcpLanguageModelToolContribution.ts:232-238](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/mcp/common/mcpLanguageModelToolContribution.ts#L232-L238); [src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/tools/commandLineAnalyzer/commandLineAutoApproveAnalyzer.ts:109](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/tools/commandLineAnalyzer/commandLineAutoApproveAnalyzer.ts#L109) (verified)
  - *To reach the next level:* The auto-approved set is not a verified read-only allowlist: file writes inside the workspace (including code later run by tests or scripts) skip the human.
- **D L1:** Approval is on by default (Default permission level, YOLO only via an application-scope setting plus a warning dialog), but workspace hook files load automatically in trusted workspaces and a preToolUse hook returning 'allow' auto-approves the call. — [src/vs/workbench/contrib/chat/browser/chat.shared.contribution.ts:752](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/browser/chat.shared.contribution.ts#L752); [src/vs/workbench/contrib/chat/browser/chat.shared.contribution.ts:808-812](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/browser/chat.shared.contribution.ts#L808-L812); [src/vs/workbench/contrib/chat/browser/tools/languageModelToolsService.ts:1459-1460](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/browser/tools/languageModelToolsService.ts#L1459-L1460); [src/vs/workbench/contrib/chat/common/promptSyntax/config/promptFileLocations.ts:213](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/common/promptSyntax/config/promptFileLocations.ts#L213); [src/vs/workbench/contrib/chat/browser/chat.shared.contribution.ts:2243-2247](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/browser/chat.shared.contribution.ts#L2243-L2247); [src/vs/workbench/contrib/chat/common/promptSyntax/service/promptsServiceImpl.ts:1280-1282](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/common/promptSyntax/service/promptsServiceImpl.ts#L1280-L1282); [extensions/copilot/src/extension/prompts/node/panel/toolCalling.tsx:300-328](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/prompts/node/panel/toolCalling.tsx#L300-L328); [src/vs/workbench/contrib/chat/browser/tools/languageModelToolsService.ts:878-880](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/browser/tools/languageModelToolsService.ts#L878-L880) (verified)
  - *To reach the next level:* Hooks from the workspace should need their own trust decision and should never be able to auto-approve tool calls.
- **B L2:** Agent file edits are tracked in a chat editing session that can be kept or undone, but approved shell commands (rm, git push, deploys) are irreversible. — [src/vs/platform/chat/common/chatSettings.ts:66-68](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/platform/chat/common/chatSettings.ts#L66-L68); [src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/tools/runInTerminalTool.ts:1276](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/tools/runInTerminalTool.ts#L1276) (verified)
  - *To reach the next level:* No checkpoint or dry-run for terminal side effects, and no rate limit on consequential actions or approval prompts.
- **Cap:** G2 — A file in the repository (.github/hooks/*.json, loaded by default once the workspace is trusted) can return permissionDecision 'allow' from a preToolUse hook and auto-approve any tool call.

### C3 Tool & action scoping — 0.35 (high)

The file tools are fairly careful. They resolve symlinks and real paths, reject null bytes and Windows device paths, and ask before touching anything outside the workspace or under the home dotfiles. The default tool set is very broad, though: a raw shell, arbitrary URL fetch, file writes, notebook execution, VS Code commands and memory are all enabled out of the box. The shell takes arbitrary strings, and the auto-approve rules are filters rather than bounds.

- **S L2:** File tools use realpath plus workspace containment and path sanitisation, but the terminal accepts arbitrary command strings filtered only by allow/deny rules. — [extensions/copilot/src/extension/tools/node/editFileToolUtils.tsx:903](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/tools/node/editFileToolUtils.tsx#L903); [extensions/copilot/src/extension/tools/node/editFileToolUtils.tsx:858-859](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/tools/node/editFileToolUtils.tsx#L858-L859); [extensions/copilot/src/extension/tools/node/editFileToolUtils.tsx:742-746](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/tools/node/editFileToolUtils.tsx#L742-L746); [src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/tools/runInTerminalTool.ts:1231-1233](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/tools/runInTerminalTool.ts#L1231-L1233) (verified)
  - *To reach the next level:* General tools (raw shell, arbitrary URL fetch) are not replaced by narrow, allowlisted operations.
- **C L2:** Most built-in tools validate paths or URLs; MCP tools are passed through with only the server's own schema. — [extensions/copilot/src/extension/tools/node/readFileTool.tsx:428-431](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/tools/node/readFileTool.tsx#L428-L431); [src/vs/workbench/contrib/mcp/common/mcpLanguageModelToolContribution.ts:232-238](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/mcp/common/mcpLanguageModelToolContribution.ts#L232-L238) (verified)
  - *To reach the next level:* No shared validation layer that extension/MCP tools inherit.
- **D L1:** Write, exec and network tools (run_in_terminal, fetch_webpage, edit/create, memory) are enabled by default in agent mode; users can deselect tools in the picker. — [extensions/copilot/package.json:1137](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/package.json#L1137); [src/vs/platform/chat/common/chatSettings.ts:66-68](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/platform/chat/common/chatSettings.ts#L66-L68) (verified)
  - *To reach the next level:* Default tool set is not read-only; write/exec need no explicit enabling.
- **B L0:** A misused (approved) shell command reaches the whole machine as the user. — [src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/toolTerminalCreator.ts:151-159](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/toolTerminalCreator.ts#L151-L159) (verified)
  - *To reach the next level:* Tool reach is not limited to the project, nor bounded in quantity.
- **Cap:** none

### C4 Code-execution isolation — 0.35 (high)

Agent terminal commands, workspace hooks, tasks and MCP stdio servers run directly on the host as the user, because the terminal sandbox (chat.agent.sandbox.enabled) is off by default. When a user turns the sandbox on, commands are wrapped with @vscode/sandbox-runtime (bubblewrap or Seatbelt), which keeps the filesystem mostly read-only. Leaving the sandbox requires a per-call confirmation. Network is still allowed by default, dev-tool configs and registry tokens stay readable, and hooks are never sandboxed. The default protection against a bad command is the approval dialog, not isolation.

- **default configuration** (default; raw 0.00 → 0.00)
  - **S L0:** Default execution is a same-user VS Code terminal on the host with no isolation. — [src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts:530-541](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts#L530-L541); [src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/toolTerminalCreator.ts:151-159](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/toolTerminalCreator.ts#L151-L159) (verified)
    - *To reach the next level:* No OS-level isolation in the default configuration.
  - **C L0:** No execution path is sandboxed by default; hooks spawn processes on the host with the full environment. — [src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts:530-541](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts#L530-L541); [extensions/copilot/src/platform/chat/node/hookExecutor.ts:51](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/platform/chat/node/hookExecutor.ts#L51) (verified)
    - *To reach the next level:* The main exec tool is not sandboxed by default.
  - **D L0:** The sandbox setting defaults to Off. — [src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts:530-541](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts#L530-L541) (verified)
    - *To reach the next level:* Sandbox is opt-in.
  - **B L0:** Commands run with the user's home directory, credentials and full network. — [src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/toolTerminalCreator.ts:151-159](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/toolTerminalCreator.ts#L151-L159); [src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts:530-541](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts#L530-L541) (verified)
    - *To reach the next level:* Default execution is host-equivalent.
- **opt-in terminal sandbox (chat.agent.sandbox.enabled)** (alt; raw 0.35, cap G1 → 0.35) ← counted
  - **S L2:** Opt-in sandbox wraps commands with @vscode/sandbox-runtime (bubblewrap/Seatbelt) keeping the filesystem mostly read-only, but network access is allowed by default. — [src/vs/platform/sandbox/common/terminalSandboxEngine.ts:298](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/platform/sandbox/common/terminalSandboxEngine.ts#L298); [src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/tools/runInTerminalTool.ts:193](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/tools/runInTerminalTool.ts#L193); [src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts:568-574](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts#L568-L574) (verified)
    - *To reach the next level:* Network is not denied by default, which the L3 OS-sandbox anchor requires.
  - **C L2:** Terminal commands and (by default) MCP/LSP servers run in the sandbox when enabled; hooks and tasks still spawn on the host. — [src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts:629-635](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts#L629-L635); [extensions/copilot/src/platform/chat/node/hookExecutor.ts:51](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/platform/chat/node/hookExecutor.ts#L51) (verified)
    - *To reach the next level:* Hooks and other spawned paths bypass the sandbox.
  - **D L0:** Off by default; when on, leaving the sandbox needs a per-call confirmation. — [src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts:530-541](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts#L530-L541); [src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/tools/runInTerminalTool.ts:1268-1270](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/tools/runInTerminalTool.ts#L1268-L1270) (verified)
    - *To reach the next level:* Not on by default.
  - **B L1:** Inside the sandbox, the workspace is writable, network is open and dev-tool configs (including registry tokens) are readable by default. — [src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts:568-574](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts#L568-L574); [src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts:647-654](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts#L647-L654) (verified)
    - *To reach the next level:* Network egress is unrestricted and credentials remain readable.
- **Cap:** G1 — Opt-in mechanism: off in the scored default configuration.

### C5 Untrusted input blast radius — 0.50 (high)

Prompt injection is not detected. What limits a hijacked session is that the dangerous outbound and execution paths ask a human first: terminal commands, fetches to untrusted URLs (where the fetched content is also reviewed before it reaches the model), and non-read-only MCP tools. Remote images in chat output are blocked. Workspace file edits and user-memory writes still happen without approval, so injected content can quietly change code or plant persistent notes. Approval does not depend on whether untrusted content has been read, and tool descriptions or workspace files are treated the same as the user's own instructions.

- **S L2:** Exec and egress (terminal, untrusted-domain fetch, non-read-only MCP tools) require approval; writes inside the workspace and memory writes do not. — [src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/tools/runInTerminalTool.ts:1276](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/tools/runInTerminalTool.ts#L1276); [src/vs/workbench/contrib/chat/electron-browser/builtInTools/fetchPageTool.ts:262-269](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/electron-browser/builtInTools/fetchPageTool.ts#L262-L269); [src/vs/workbench/contrib/chat/electron-browser/builtInTools/fetchPageTool.ts:284](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/electron-browser/builtInTools/fetchPageTool.ts#L284); [src/vs/platform/chat/common/chatSettings.ts:66-68](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/platform/chat/common/chatSettings.ts#L66-L68) (verified)
  - *To reach the next level:* No Rule-of-Two enforcement: state-changing tools (edits, memory) remain unattended after untrusted content is read.
- **C L2:** Web fetches and MCP open-world results get result review; workspace files, tool descriptions and MCP read-only tool results enter context with no distinction. — [src/vs/workbench/contrib/chat/electron-browser/builtInTools/fetchPageTool.ts:284](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/electron-browser/builtInTools/fetchPageTool.ts#L284); [src/vs/workbench/contrib/mcp/common/mcpLanguageModelToolContribution.ts:240-241](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/mcp/common/mcpLanguageModelToolContribution.ts#L240-L241) (verified)
  - *To reach the next level:* Tool descriptions and workspace file contents are not treated as untrusted.
- **D L2:** Approval is on by default; the user can switch a session to Bypass Approvals or Autopilot from the permissions picker. — [src/vs/workbench/contrib/chat/browser/chat.shared.contribution.ts:752](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/browser/chat.shared.contribution.ts#L752); [src/vs/workbench/contrib/chat/browser/tools/languageModelToolsService.ts:1401-1404](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/browser/tools/languageModelToolsService.ts#L1401-L1404) (verified)
  - *To reach the next level:* Disabling via the session picker is not tied to an explicit operator flag with a warning in every path.
- **B L2:** Exfiltration (shell, untrusted fetch) and irreversible shell actions need approval; unattended actions are reversible workspace edits and memory writes; remote images are blocked. — [src/vs/workbench/contrib/chat/browser/widget/chatContentMarkdownRenderer.ts:24](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/browser/widget/chatContentMarkdownRenderer.ts#L24); [src/vs/workbench/contrib/chat/electron-browser/builtInTools/fetchPageTool.ts:262-269](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/electron-browser/builtInTools/fetchPageTool.ts#L262-L269); [src/vs/platform/chat/common/chatSettings.ts:66-68](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/platform/chat/common/chatSettings.ts#L66-L68); [extensions/copilot/src/extension/tools/node/memoryTool.tsx:274](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/tools/node/memoryTool.tsx#L274) (verified)
  - *To reach the next level:* Unattended workspace edits and persistent memory writes remain possible after a hijack.
- **Cap:** none

### C6 Memory, context & configuration integrity — 0.17 (high)

The memory tool is on by default. It lets the model write user-scope notes to global storage without approval, and the start of those notes is injected into every new agent chat in every workspace as 'your persistent user memory', so one injection can persist across all future sessions. Instruction files and workspace hooks load silently once the workspace is trusted. Edits to .vscode/*.json, .mcp.json, hook and custom-agent files always ask first. Workspace MCP servers need both workspace trust and a separate server-trust prompt, which is shown again whenever the definition changes.

- **S L0:** The model can create or edit user memory with no confirmation and it is re-injected into new chats as trusted context. — [extensions/copilot/src/extension/tools/node/memoryTool.tsx:188-189](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/tools/node/memoryTool.tsx#L188-L189); [extensions/copilot/src/extension/tools/node/memoryTool.tsx:274](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/tools/node/memoryTool.tsx#L274); [extensions/copilot/src/extension/tools/node/memoryContextPrompt.tsx:49](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/tools/node/memoryContextPrompt.tsx#L49); [extensions/copilot/src/extension/prompts/node/agent/agentPrompt.tsx:365](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/prompts/node/agent/agentPrompt.tsx#L365) (verified)
  - *To reach the next level:* Memory writes are not gated, validated or expired.
- **C L1:** Security-relevant config files (.vscode/*.json, .mcp.json, hook and agent files) require edit confirmation; memory and instruction files do not. — [extensions/copilot/src/extension/tools/node/editFileToolUtils.tsx:711-714](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/tools/node/editFileToolUtils.tsx#L711-L714); [extensions/copilot/src/extension/tools/node/editFileToolUtils.tsx:812-823](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/tools/node/editFileToolUtils.tsx#L812-L823) (verified)
  - *To reach the next level:* Memory stores and instruction files are uncontrolled.
- **D L1:** User memory is one global namespace shared by all workspaces; repo and session memory are separated by storage scope. — [extensions/copilot/src/extension/tools/node/memoryTool.tsx:274](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/tools/node/memoryTool.tsx#L274); [extensions/copilot/src/extension/tools/node/memoryContextPrompt.tsx:49](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/tools/node/memoryContextPrompt.tsx#L49) (verified)
  - *To reach the next level:* User-scope memory is not isolated per workspace or session.
- **B L1:** Poisoned user memory persists across all of the user's sessions and workspaces and can steer tool use (still subject to approval). — [extensions/copilot/src/extension/tools/node/memoryContextPrompt.tsx:49](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/tools/node/memoryContextPrompt.tsx#L49); [extensions/copilot/src/extension/prompts/node/agent/agentPrompt.tsx:365](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/prompts/node/agent/agentPrompt.tsx#L365) (verified)
  - *To reach the next level:* No human review or rollback of memory before it is re-injected.
- **Cap:** none

### C7 Third-party extensions — 0.30 (high)

No third-party extension code runs without consent. MCP servers defined in a workspace need workspace trust plus a per-server trust prompt, which is shown again when the server definition changes, and the install_extension tool asks before installing anything. The trust prompt shows the server's name and origin rather than the exact command. Package versions are whatever the configuration says, often an unpinned npx package, and stdio servers inherit the full process environment.

- **S L1:** MCP servers come from user- or workspace-chosen configuration with no pinning or integrity check; re-trust is keyed to the definition, not the package contents. — [src/vs/workbench/contrib/mcp/common/mcpRegistry.ts:231-243](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/mcp/common/mcpRegistry.ts#L231-L243) (verified)
  - *To reach the next level:* No version pinning or integrity verification of launched servers.
- **C L1:** Trust prompts cover MCP server definitions and the install-extension tool asks for confirmation; nothing verifies what is actually executed. — [src/vs/workbench/contrib/mcp/common/mcpRegistry.ts:231-243](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/mcp/common/mcpRegistry.ts#L231-L243); [extensions/copilot/src/extension/tools/node/installExtensionTool.tsx:99-101](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/tools/node/installExtensionTool.tsx#L99-L101) (verified)
  - *To reach the next level:* No verification for any extension type.
- **D L2:** Workspace-defined servers need workspace trust and an explicit per-server trust choice, but the dialog shows a label and origin link rather than the command. — [src/vs/workbench/contrib/mcp/common/mcpRegistry.ts:231-243](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/mcp/common/mcpRegistry.ts#L231-L243); [src/vs/workbench/contrib/mcp/common/mcpRegistry.ts:326](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/mcp/common/mcpRegistry.ts#L326) (verified)
  - *To reach the next level:* The trust prompt does not show the exact command and package that will run, and workspace scope can still propose servers.
- **B L1:** stdio MCP servers are separate processes started with a copy of the full process environment. — [src/vs/workbench/api/node/extHostMcpNode.ts:64](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/api/node/extHostMcpNode.ts#L64) (verified)
  - *To reach the next level:* Extension processes get the full environment instead of a scrubbed one.
- **Cap:** none

### C8 Secrets & sensitive-data protection — 0.33 (high)

BYOK API keys and auth sessions are kept in VS Code's SecretStorage, which is backed by the OS keychain. A regex secret filter exists but only runs on events exported to cloud session sync. Nothing is redacted from prompts sent to the model, from local logs or transcripts, or from the environment of agent terminals. Agent terminals inherit every long-lived credential in the user's environment. Content-bearing GitHub telemetry is sent only when the account's telemetry flag allows it.

- **S L2:** Credentials are stored in SecretStorage (OS keychain) and a secret-pattern filter exists, but it is not applied to model-bound content or logs. — [extensions/copilot/src/extension/byok/vscode-node/byokStorageService.ts:96](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/byok/vscode-node/byokStorageService.ts#L96); [extensions/copilot/src/extension/chronicle/vscode-node/remoteSessionExporter.ts:1360](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/chronicle/vscode-node/remoteSessionExporter.ts#L1360); searched `rg -n -S 'filterSecrets|redactSecrets'` in `extensions/copilot/src/extension/prompt extensions/copilot/src/extension/prompts extensions/copilot/src/platform/endpoint extensions/copilot/src/platform/requestLogger` → 0 hits (No secret filtering on prompt construction, endpoint or request-logger paths; the filter is used only for cloud session export.) (verified)
  - *To reach the next level:* No redaction before model-bound messages or local logs.
- **C L1:** Only the cloud session export path is filtered. — [extensions/copilot/src/extension/chronicle/vscode-node/remoteSessionExporter.ts:1360](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/chronicle/vscode-node/remoteSessionExporter.ts#L1360); searched `rg -n -S 'filterSecrets|redactSecrets'` in `extensions/copilot/src/extension/prompt extensions/copilot/src/extension/prompts extensions/copilot/src/platform/endpoint extensions/copilot/src/platform/requestLogger` → 0 hits (No secret filtering on prompt construction, endpoint or request-logger paths; the filter is used only for cloud session export.) (verified)
  - *To reach the next level:* Logs, transcripts, model-bound messages and subprocess environments are unprotected.
- **D L1:** Telemetry is on by default; content-bearing 'enhanced' telemetry depends on the account-level opt-in flag in the Copilot token. — [extensions/copilot/src/platform/telemetry/common/ghTelemetryService.ts:247](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/platform/telemetry/common/ghTelemetryService.ts#L247) (verified)
  - *To reach the next level:* Content-free telemetry is not opt-in and redaction is not always on.
- **B L1:** Long-lived user credentials in the environment are reachable by every agent terminal (after approval). — [src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/toolTerminalCreator.ts:151-159](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/toolTerminalCreator.ts#L151-L159); searched `rg -n -S 'scrub|sanitizeEnv|delete env'` in `src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/toolTerminalCreator.ts` → 0 hits (Agent terminals add variables to the inherited environment; nothing is removed.) (verified)
  - *To reach the next level:* Credentials reachable from the agent are long-lived and not scoped.
- **Cap:** none

### C9 Audit & traceability — 0.53 (medium)

VS Code saves every chat session by default to its own workspaceStorage folder, outside the project. Each saved tool call records the tool id, call id, the terminal command line, the result, how it was approved (by the user, a setting, a hook, or auto-approve) and a sub-agent invocation id. A JSONL transcript with tool arguments is also written whenever hooks are configured, and OpenTelemetry export is available as an option. The records are not tamper-evident, and the agent's own terminal can edit or delete them. Storage is best-effort, and a failed write does not stop the agent.

- **S L2:** Persisted chat sessions record each tool invocation with its id, tool-specific data, result and confirmation reason, plus sub-agent ids. — [src/vs/workbench/contrib/chat/common/model/chatProgressTypes/chatToolInvocation.ts:454-465](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/common/model/chatProgressTypes/chatToolInvocation.ts#L454-L465); [src/vs/workbench/contrib/chat/common/model/chatSessionStore.ts:73](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/common/model/chatSessionStore.ts#L73) (verified)
  - *To reach the next level:* No tamper-evident storage or full actor attribution (requesting principal) with standard export on by default.
- **C L3:** All tool calls, including MCP and sub-agent calls, go through the core tool service and are persisted with approval/denial state. — [src/vs/workbench/contrib/chat/common/model/chatProgressTypes/chatToolInvocation.ts:454-465](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/common/model/chatProgressTypes/chatToolInvocation.ts#L454-L465); [extensions/copilot/src/extension/prompts/node/panel/toolCalling.tsx:340](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/prompts/node/panel/toolCalling.tsx#L340) (verified)
  - *To reach the next level:* Configuration changes, memory writes and credential use are not separately recorded.
- **D L2:** On by default and stored in VS Code's workspaceStorage outside the workspace, but writable by the agent's own (user-level) terminal. — [src/vs/workbench/contrib/chat/common/model/chatSessionStore.ts:73](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/common/model/chatSessionStore.ts#L73) (verified)
  - *To reach the next level:* The record is written where the model's tools can alter it.
- **B L1:** Storage errors are reported and the session continues; writes are batched rather than per action. — [src/vs/workbench/contrib/chat/common/model/chatSessionStore.ts:185-198](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/common/model/chatSessionStore.ts#L185-L198) (inferred)
  - *To reach the next level:* Records are not durably flushed per action and failures do not block actions.
- **Cap:** none

### C10 Limits & kill switch — 0.30 (high)

The agent loop stops after chat.agent.maxRequests requests per turn (50 by default) and then asks the user whether to continue. Autopilot can raise that silently, up to 200. The stop button cancels pending tool calls. There is no session wall-clock limit, cost limit or token budget in the extension. Terminal timeouts only stop the tool from waiting and leave the process running. Sub-agents get their own loops, but nesting is off by default.

- **S L1:** Only an iteration cap per turn is enforced; terminal timeouts stop tracking but do not kill the process. — [extensions/copilot/src/extension/intents/node/toolCallingLoop.ts:1449-1454](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/intents/node/toolCallingLoop.ts#L1449-L1454); [src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts:852](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts#L852); searched `rg -n -S 'wallClock|maxDuration|maxCost|tokenBudget'` in `extensions/copilot/src/extension/intents/node/toolCallingLoop.ts` → 0 hits (No wall-clock, cost or token budget in the agent loop.) (verified)
  - *To reach the next level:* No wall-clock or cost/token cap enforced in code.
- **C L1:** The cap applies to the top-level loop; sub-agents run their own loops with their own limits. — [extensions/copilot/src/extension/intents/node/toolCallingLoop.ts:1449-1454](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/intents/node/toolCallingLoop.ts#L1449-L1454); [src/vs/workbench/contrib/chat/common/tools/builtinTools/runSubagentTool.ts:325](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/common/tools/builtinTools/runSubagentTool.ts#L325) (verified)
  - *To reach the next level:* Sub-agents and spawned processes do not count against the same budget.
- **D L2:** Default of 50 requests per turn is operator-configurable; Autopilot extends it up to 200. — [src/vs/workbench/contrib/chat/browser/chat.shared.contribution.ts:2980-2983](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/browser/chat.shared.contribution.ts#L2980-L2983); [extensions/copilot/src/extension/intents/node/toolCallingLoop.ts:1449-1454](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/extensions/copilot/src/extension/intents/node/toolCallingLoop.ts#L1449-L1454) (verified)
  - *To reach the next level:* The model's mode (Autopilot) can raise the limit and there is no hard ceiling across turns.
- **B L1:** Stopping cancels pending tool invocations, but background terminal processes keep running and there is no spend ceiling. — [src/vs/workbench/contrib/chat/browser/tools/languageModelToolsService.ts:539-541](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/chat/browser/tools/languageModelToolsService.ts#L539-L541); [src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts:852](https://github.com/microsoft/vscode/blob/7f20cdad4f4ab923272e91e330a7701c52706fc7/src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts#L852) (verified)
  - *To reach the next level:* Stopping leaves processes running; no tight time or cost ceiling.
- **Cap:** none

## Rule-of-Two check
[A] untrusted input: fetch_webpage, workspace files and MCP results enter context (src/vs/workbench/contrib/chat/electron-browser/builtInTools/fetchPageTool.ts:262) · [B] sensitive data/systems: read_file reads any workspace file without confirmation, including .env (extensions/copilot/src/extension/tools/node/readFileTool.tsx:405) · [C] state change / egress: workspace edits auto-approved by default (src/vs/platform/chat/common/chatSettings.ts:67); shell and fetch egress after approval (src/vs/workbench/contrib/terminalContrib/chatAgentTools/browser/tools/runInTerminalTool.ts:1276) · Same default session? Yes

## Highest-impact improvements
1. Require a dedicated trust prompt that shows the commands in workspace hook files before loading them, and never let workspace-scoped preToolUse hooks return 'allow'. — C2 D L1→L3, +0.100 before caps (Playbook 5)
2. Turn the terminal sandbox on by default with network denied, and run hooks and tasks inside it. — C4 D L0→L3, +0.150 before caps (Playbook 3 step 1)
3. Require approval for user-scope memory writes and present memory as untrusted data with provenance. — C6 S L0→L2, +0.150 before caps (Playbook 2)
4. Scrub credential variables (cloud, gh, SSH agent) from the agent terminal environment by default. — C1 C L1→L2, +0.075 before caps (Playbook 4)
5. Add a session wall-clock and token budget and kill background terminal processes on stop. — C10 S L1→L2, +0.075 before caps (Playbook 3 step 3)

## Re-audit log
- No changes.

## Limitations
- Static source review of the pinned commit only; nothing was executed, installed, or probed.
- The scored subpath (extensions/copilot) delegates tool approval, the terminal tool, fetch, MCP and chat persistence to VS Code core; the relevant core files under src/vs/ were reviewed and cited because the extension's agent loop invokes tools through them.
- Experiment-controlled settings (sandbox enablement, timeouts, GitHub MCP) were scored at their code defaults; server-side experiments may change them for some users.
- The shipped Microsoft build's product.json may add trusted domains that let fetch skip confirmation; the OSS product.json at this commit has none and was not checked further.
- Alternate harnesses in the same extension (Copilot CLI sessions, Claude agent sessions, cloud agent delegation, BYOK providers) were not scored; only local agent mode was.
- No reviewer-injection text was found in the reviewed paths.
