The downside is that it requires access to more than it technically needs (Claude keys for example). I’m working on a version where you sandbox the agent’s Bash tool, not the agent itself. https://github.com/Kiln-AI/Kilntainers
How about using bash-tool to intercept the commands and then passing them onto the containers?
Then how about running Claude Code or your harness of choice inside bubblewrap with a shim/stub for the base binary?
If you're using an agent tool that already includes an existing bash tool which calls host OS, just remove that one and add this.
Claude Code seemed to be able to reach outside its own sandbox sometimes, so I lost trust in it. Manually wrapping it in sandbox-exec solved the issue.
This may also have bugs but having a single setup for your sandbox reduces the surface area & frankly I have significantly more trust in literally any individual dev creating a free generic open-source tool than I do in a company selling frontier models as a service & vibe-coding[0] an afterthought companion cli at 80k loc/mo.