I really like this idea of sandboxing agents into containers but I'm not sure if Docker's security model is robust enough to contain the agent.
There's a lot of configuration options also prone to errors.

https://nanoclaw.dev/blog/nanoclaw-docker-sandboxes/

Run NanoClaw in Docker Sandboxes with One Command | NanoClaw Blog

Every agent gets its own isolated container inside a micro VM. No dedicated hardware needed. No complex setup.

NanoClaw