Why not just run the assistant as a user with limited permissions? Your OS likely supplies all the handcuffs you're going to need.