How in the world MCP is going to be more secure? It introduce a big surface layers for injection attacks and supply chain attacks..
rm -rf ~
but sandboxing in general is not an easy problem.
On unix, you can easily create a new user account, switch to it (or ssh or setup vnc), and run the tool there. If users are enough for servers on the internet, they can be for your workstation (unless there’s something like copyfail, but you can make do with a vm then).