Run AI coding agents in a per-project sandbox that keeps your real dev environment. Your shell, mise-managed tools and editor configs come with you; SSH keys, cloud credentials, .env files and sibling projects stay out. bubblewrap on Linux, Docker or a libkrun microVM elsewhere, plus an optional MITM proxy that logs and filters every request.