Also (in case people haven't already seen this), I recently discovered Docker now has an easy way to run agents in a sandbox, ie:
docker sandbox run claude ~/project-a