GitHub is adding more policy control around GitHub-hosted runners, including runner groups that can direct jobs to runners meeting an organization’s requirements and the ability to disable standard hosted runners. That is useful for platform teams, but a policy setting is not the same thing as a verified security boundary. The practical question is: what
A practical, source-backed checklist for scoping GitHub Copilot browser tools, limiting domains and permissions, and reviewing evidence after each agent-driven test.