Preliminary research
Wrestling with a Python: Escaping Copilot Studio’s AI-Guarded Sandbox
AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.
Investigates Copilot Studio’s LLM guard and in-process Python restrictions separately. Introspection reveals sandbox code, a legacy execution path carries an encoded payload into worker modules, and output and process-startup experiments map the resulting permissions. The analysis distinguishes interpreter escape from underlying host virtualization boundaries.
Record
- Researcher
- Simon Maxwell-Stewart, Ryan Hausknecht and Phantom Labs®
- Published by
- BeyondTrust
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Simon Maxwell-Stewart, Ryan Hausknecht and Phantom Labs®, first published at the original source. Preserved copies are kept so the citation survives its host.