Guardrails for agents running on your personal box

I’m currently running opencode and claude as my own user. typically with tmux / bash.

If I don’t give the AI general permission to run everything it’s really increasing friction and capabilities A LOT. So I really would prefer it to run unsupervised. However, I still will typically watch it because I’m just not entirely free of paranoia something terrible will happen.

So I was wondering if there are some guardrails I can put up that won’t be relying on the harness. I was thinking something along the lines of creating a seperate AI user with read permissions on the stuff it wants to read but without write permissions for my home directory. I think this wouldn’t be to hard to do with ACLs, but I was wondering if this is the best way to go about it.

others have probably had similar thought and came up with solutions already, what are your takes?

Best regards, some RandomNewbie.

Terrible in what ways?

File deletion?
Code changes?
Document sniffing?
Secretly installing a sleeper botnet node for the impeding Skynet takeover?

All of the above? I mostly thought about write / deletion, as these would be the most pita. I don’t think I care to much about document sniffing or secret bot net agents. Or deem the risk acceptable.

You can create a Dockerfile with all your standard tooling in it (compilers, interpreters, build systems, etc.) as well as your harnesses like Opencode. Then -v your workspace and ~/.config/opencode. Create a user in the Dockerfile and have it run as that user instead of root. You can give it your UID so it can read/write to the workspace in the volume mount.

You can set the entrypoint to your harness (e.g. opencode). Alternatively you can set the entrypoint to something like cat or sleep, then just exec into the running container to start the harness or whatever other tools you want.

I’ve been meaning to do this myself. I do tend to run Opencode and Claude Code just as my regular user and it’s starting to worry me too.