You already have an agent freely doing stuff on your machine. Subagents prompts are a weird place to draw a line. It's not like you're reading everything the agent is doing in any case, let's not kid ourselves.
I was about to do the same with Sol + Ultra, but then discovered this encryption issue that prevents me from doing the same for sub-agents.
Personally I do, these tools aren't mature enough to be used without supervision
No. Agents run in VMs. Assume anywhere you’re running an agent will be compromised, because eventually, it will be.
The only reason most people haven’t is luck, they didn’t happen to install Axios or Tanstack at a certain time.