I don't even give it full disk access.
I have written a tool to easily run the agents inside a container that mounts only the current directory.