I’ve found unexpected success in using ephemeral NixOS VMs for local development… once you authenticate your agent you can let it run wild without worrying about permissions.
Dies the agent have access to is own nix config (and therefore install permissions), or do you have to provide it all the tools externally?
Dies the agent have access to is own nix config (and therefore install permissions), or do you have to provide it all the tools externally?