Coding agents will cheerfully run whatever they generate, and most have your shell, SSH keys, and AWS creds one `rm -rf` away. Sandboxing is the cheapest insurance you can buy.
Options split into VMs, containers, and the OS-native path: Seatbelt on macOS, seccomp-bpf and Landlock on Linux.
Current favorite: nono.sh. CLI wrapper, no daemon, profile per project. Writing one takes 30 seconds, so I actually do it.
Sketched by Ian, formatted by AI.