You can use an alias, which takes priority over $PATH. e.g. I have this in .zhsrc to override the "claude" executable to run it in the OS sandbox:
alias claude="sandbox-exec -f ~/agents-jail.sb ~/.local/bin/claude --dangerously-skip-permissions"
How does your sandbox ruleset look? I've been using containers on Linux but I don't have a solution for macOS.
How does your sandbox ruleset look? I've been using containers on Linux but I don't have a solution for macOS.