Microsoft Execution Containers go GA so coding agents only touch the files and hosts you allow
Announced Oct 7, MXC takes one JSON policy (writable and read-only paths, network, desktop access) and enforces it outside the agent with AppContainer on Windows, Seatbelt on macOS, or Bubblewrap on Linux, plus Windows-only session and WSL containers and an experimental microVM. Copilot, Codex, Replit, OpenClaw, and LM Studio already support it with Claude Code listed as coming, and a Learning mode logs what an agent tried to reach so you can write a least-privilege policy.