Sandboxing is a solved problem, there are dozens of providers of firecracker instances to run your agent in.
The problem to be solved is how do you define task-specific least privilege versions of your coding agent.
The problem to be solved is how do you define task-specific least privilege versions of your coding agent.
Its integration for Claude Code: https://github.com/tenuo-ai/claude-governance
Is the difference with your script mostly that you choose to impose a stricter sandbox profile (and not allow any user-approved exceptions at runtime)?