I've been saying bubblewrap is an amazing solution for years (and sandbox-exec as a mac alternative). This is the only way i run agents on systems i care about
> run agents on systems i care about
You must not care about those systems that much.
> run agents on systems i care about
You must not care about those systems that much.