logoalt Hacker News

LelouBiltoday at 1:20 AM0 repliesview on HN

Don't even need a separate user if you're on linux (or wsl), just use the sandbox feature, you can specify allowed directories for read and/or write.

The sandbox is powered by bubblewrap (used by Flatpaks) so I trust it.