You should absolutely be running your AI agent inside _some_ kind of sandbox. I put together a list of 19 mostly open-source ones here: https://pleasedonotescape.com/ along with a list of non-project-solutions
I mean this is a problem with many coworkers too, so you deal with it in the same way: limit what they can do to creating pull requests.