Yea I've been running claude and codex with full permissions for a while but it has always made me feel uneasy. I knew it was fairly easy to fix with a docker container but didn't get around to it through sheer inertia until I built this project.