I"m really digging this: https://agent-safehouse.dev. A few days ago I got to trigger happy hitting enter with claude while doing some git stuff and gave it permission to overwrite my .gitconfig. I'd like for that to not happen again.
Agent Safehouse
Sandbox your LLM coding agents on macOS. Kernel-level enforcement via sandbox-exec — deny-first, composable, zero dependencies.