Ask HN: How are you sandboxing AI agents and developer CLIs? | Dark Hacker News