Sandbox isolation is only slightly important, you don't need to make it fancy, just a plain old VM. The really important thing is how you control capabilities you give for the agent to act on your behalf.
But managing granular permissions is hard. The common denominator with all these discussions is people want to apply the minimal amount of thinking possible.
But managing granular permissions is hard. The common denominator with all these discussions is people want to apply the minimal amount of thinking possible.