This is the only kind of agent security that makes sense to me. Constrain it like you would any other subprocess. Unprivileged OS users, SELinux, firewalls, VMs... Unikernels? eBPF?
Escalations to root are a dime the bucket.
Escalations to root are a dime the bucket.