Jesus.
Just containerize Claude.
How is this not common practice already?
Are people really ok with a third party agent running out of their home directory executing arbitrary commands on their behalf?
Pure insanity.
That or setup a sandbox for paths you want / don't want touched.
That or setup a sandbox for paths you want / don't want touched.