i can't imagine running these things outside of a vm and it's bizarre to see how many people yolo it
The conceptual problem is that there is a huge intersection between the set of "things the agent needs to be able to do in order to be useful" and "things that are potentially dangerous."