That's a great deal of work to get an agent that's a whole lot less capable.
Much better to allow full Bash but run in a sandbox that controls file and network access.