It seems unwise not to implement sandbox measures just because the chance of misuse has gotten lower.
Plan was never a sandbox or a permissions system
Yes, but plan mode wasn’t that.
You can use Docker’s sbx or similar VM/containers for that.
What? Nothing to do with that
Plan was never a sandbox or a permissions system