> How can people be so naive as to run something like Claude anywhere other than in a strictly locked down sandbox that has no access to anything but the single git repo they are working on (and certainly no creds to push code)?
Because it is much easier to do and failure rate is quite low.
(not saying that it is a good idea)