...or...just hear me out now...we could limit it in the harness.
Don't give it shell access, just predefined tools.
What if it puts malicious code into test file and you allow `npm run test `?
What if it puts malicious code into test file and you allow `npm run test `?