That's what they are actually doing.
I think quite opposite, agents need to come with all permissions possible, highlighting that it's actually the OS responsibility to constrain it.
It's kind of dumb to except a process to constrain itself.
A non-deterministic process at that. Coding agents are basically "curl into sh" pattern on steroids
A non-deterministic process at that. Coding agents are basically "curl into sh" pattern on steroids