Are we sandboxing AI agent harness process, or the environment it executes commands in?
Ideally, they should run in _different_ sandboxes.
The environment might corrode the harness (e.g. rogue npm/pip packet would manipulate agent harness config).