...or...just hear me out now...we could limit it in the harness.
Don't give it shell access, just predefined tools.
Don't give it shell access, just predefined tools.
One of the demos I run is how easy it is to circumvent the harness limits. For example, I can configure a harness not to access file `secrets.txt`. But, then I can immediately have it create a Python file that can read any file and have it read `secrets.txt`.
At the end of the day, "please" isn't security. You want to know that the agent can only do and access the things it should access.