I don't understand why no one has tried to make a harness without full shell access yet.
It would be so much safer.
It would be so much safer.
They don't sell cars without seat belts, and it is the car manufacturer who has to do it.
Also, small nitpick but technically a container doesn't give full isolation compared to something like a VM.
But I think this will eventually be a problem solved at the OS level in a more streamlined way. I.e. there will be fine-grained permissions you need to approve to give an agent access to the system.
The harness says "You have access to tool X, Y, and Z, but not A, B, C".
The sandbox says "If you try to use X to access a forbidden resource, I'll prevent you from reaching it".
"permission": { "bash": "deny" }
Or something equivalent in any agentic editor of your choice.