I struggle to see the difference between sandboxing and only allowing access to specific executables (not bash for starters) with an approval rule for the arguments.
> not bash for starters
you'll end up either severely limiting what your agent can do or force it into finding some inefficient workarounds (they can be very creative...)