I've been giving coding agents more autonomy lately, letting them run shell commands unattended for longer stretches, and I don't have a good answer for how people actually gate that beyond "run it in a container and hope. " A container limits blast radius but doesn't stop the agent from reading ...

Source: [Hacker News](https://news.ycombinator.com/item?id=49556858)

Sponsored