Afaik, code running inside https://github.com/dagger/container-use can still access files outside the current directory.