Skip to content Skip to footer

How to Use New AI Coding Assistant Features Without Losing Control of Secrets and Costs

What Happened

GitHub Copilot added Claude Haiku 5.5 for fast, high-volume coding work across supported interfaces, with a gradual rollout and usage billed at provider list pricing. Copilot CLI can now discover compatible models running in local Ollama, but developers must explicitly add a discovered model to their session. Local sandboxing is generally available in Copilot CLI, the Copilot app, and VS Code sessions using Agent Host. [2][7][6]

GitHub also made stacked pull requests generally available on github.com. On the security side, its context-aware secret detection can flag likely credentials that lack a recognizable token format. AI-detected password alerts are available to covered customers, while AI checks in push protection remain an opt-in private preview for eligible customers. [9][5]

The available information does not establish new releases for Cursor, Windsurf, Replit, Sourcegraph, JetBrains, Continue.dev, or VS Code 1.141 and 1.142. One confirmed VS Code change is a fix in version 1.139.0 or later for undercounted Copilot agent activity in usage metrics. [8]

Why It Matters to Businesses

More agent-assisted development increases the volume of code and commands teams must review. GitHub reports that AI agents now participate in one in three pull requests. Its data does not show a clear rise in the prevalence of detected secrets, but revoking an exposed credential manually takes about 40 days on average. The practical priority is to prevent exposure and shorten response time, not assume developers have become less careful. [3]

Model choice, local execution, and smaller pull requests can improve workflow flexibility. They do not replace controls: a local model does not automatically make Copilot CLI offline or disable telemetry, and a sandbox does not determine whether generated code is correct. [7][6]

Kimbodo Engineering Perspective

We would treat these releases as separate controls with different jobs. Use a fast model for bounded edits and routine terminal tasks; require stronger review for changes to authentication, data access, or infrastructure. Run agent commands inside an enforced sandbox, scan for secrets before pushes, and use stacked pull requests where smaller review units genuinely clarify dependencies. GitHub’s preview results for stacks are encouraging, but they are not a forecast for every repository. [2][6][5][9]

How We Would Implement It

  • Set execution boundaries: enable organization-enforced Copilot sandbox policies for supported sessions, limiting filesystem, network, and credential access to what each workflow needs. [6]
  • Define model routes: approve cloud models by task and cost; test Ollama models for tool calling and streaming before adding them to Copilot CLI. Verify offline requirements separately, including remote-provider configuration and telemetry settings. [2][7]
  • Protect the delivery path: keep conventional secret scanning and push protection in place, pilot AI-detected checks on selected repositories, and define credential-revocation ownership. [3][5]
  • Measure and review: adopt stacks for dependent changes, require human approval for sensitive code, and update VS Code to 1.139.0 or later before relying on new Copilot agent-usage reports. [9][8]

Risks, Costs and Security

Sandboxing is included with Copilot at no additional cost, but model usage and AI-based security checks have different billing rules. The private-preview AI push-protection checks will consume GitHub AI Credits when the announced usage change takes effect; administrators should set a SKU-level budget and, where available, enable the option that stops usage at the limit. Budget alerts alone do not cap spend. [6][2][5]

Expect gaps in historical metrics: agent activity missed by affected IDE versions cannot be backfilled, although billing was unaffected. Treat reported productivity changes cautiously until developers have updated their tools. [8]

Where Kimbodo Comes In

Kimbodo builds and operates this in production for businesses — see our AI Application Development practice, or Estimate My AI Application.

Sources

  1. [2] Claude Haiku 5.5 in GitHub Copilot
  2. [3] Secret protection must scale with software
  3. [5] Purpose-built model for leaked secret detection
  4. [6] Local sandboxing for GitHub Copilot now generally available
  5. [7] Discover local models in GitHub Copilot CLI
  6. [8] Update your IDE to restore agent activity in Copilot usage metrics
  7. [9] Stacked pull requests generally available

Leave a comment

0.0/5