This is the only kind of agent security that makes sense to me. Constrain it like you would any other subprocess. Unprivileged OS users, SELinux, firewalls, VMs... Unikernels? eBPF?
That argument is letting the perfect be the enemy of the good.
There is no perfect security.
Then either fix them or put it in a stronger kind of sandbox. Or what would you propose? Anything that doesn't constrain arbitrary processes is weak against and AI just writing a program to do the thing that it itself its prevented from doing.