Copilot CLI sandbox network bypass prompt: allow Sume hosts

Copilot CLI 1.0.92-3 offers a network bypass prompt when the sandbox proxy blocks a destination. Which Sume hosts to expect and when to approve.

5 min readSume
All posts

When a sandboxed shell command in Copilot CLI hits a destination the sandbox proxy blocks, version 1.0.92-3 (2026-10-02) now offers a network bypass prompt instead of just failing. If the destination is one of Sume's documented hosts, approving it for that command is reasonable; for everything else, read the host first.

This applies to shell commands such as curl against Sume's API, not to the MCP connection Copilot CLI itself holds.

What the prompt covers

The release notes say sandboxed commands offer a bypass whenever the proxy blocks a destination. Sandbox CA commands arrived earlier, in v1.0.91.

At a glance

Hosts a Sume shell command may reach, read 2026-10-03.
HostPurpose
mcp.sume.comHosted MCP server at /mcp
api.sume.comREST API and Agent Completions
Unlisted hostsReview before approving

Sume hosts you may see

Sume's documented endpoints are https://mcp.sume.com/mcp for MCP and https://api.sume.com for the REST API, including Agent Completions at /v1/agent/completions. Results can also be hosted on Sume media domains.

Approve per command, not permanently, and confirm that the API key in the command is the one you intend to use.

  • mcp.sume.com for MCP.
  • api.sume.com for REST and agent runs.
  • Treat any other host in a Sume-related command as unexpected.

Limits and what is not verified

I did not verify which media hostnames a given result URL will use, so check the host in the prompt rather than trusting this table for downloads. The prompt wording in the release notes is brief and I did not capture its exact text.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume