What does everyone do about security with this tool? Are you running it in an Nvidia sandbox (can’t recall the product name), a docker instance, or just yolo on your computer?
I'm running it a rootless podman container it set up itself while still running directly on the host. I map the .pi directory into the container so all the sessions and skills persist. Then it's just a matter of mapping the current project folder into the container.
Firecracker can be used for sandboxing. I'm not currently using the Pi + Firecracker combination but I think it's a very useful one. But the best sandbox solution probably depends on what you want to do.