Kernel-enforced sandbox App and SDK for AI agents, MCP and LLM workloads | Dark Hacker News