Preliminary research
Wrestling with a Python: Escaping Copilot Studio’s AI-Guarded Sandbox
How We Got Admin Access to Every Copilot Studio Agent Sandbox on Earth
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
Investigates Copilot Studio’s LLM guard and in-process Python restrictions separately. Introspection reveals sandbox code, a legacy execution path carries an encoded payload into worker modules, and output and process-startup experiments map the resulting permissions. The analysis distinguishes interpreter escape from underlying host virtualization boundaries.
Record
- Document
- How We Got Admin Access to Every Copilot Studio Agent Sandbox on Earth
- Researcher
- Simon Maxwell-Stewart, Ryan Hausknecht and Phantom Labs®
- Published by
- BeyondTrust
- Topic
- AI
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Simon Maxwell-Stewart, Ryan Hausknecht and Phantom Labs®, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .