But, in any case, why put in effort doing something people don't expect or ask for? We can assume everyone running agents is either a) using their own sandbox, or b) doesn't care. I think we can guess which category most people fall into. You could maybe argue about responsibility, but I don't think you can argue about "serious engineering".
Exactly. It's not as though it's difficult. It never occurred to me to not do this from day one, and it astonishes me that anyone runs this stuff bare metal. Since then, I've brought several other people on board, and that's all they've ever seen: I don't think they'd know how to run outside a sandbox, and that's just fine.
True! Why did we bother with devcontainers anyway? Who asked for permissions on tool calls? Only those weird security people care about putting whats effectively a CNC rootkit inside a sandbox. Its not about seriously protecting the user against our AI slop inevitably typing `rm -rf work /` and deleting their entire drive.