Can this be sandboxed? I've been running OpenClaw in a VM on macOS, which seems more resource intensive than necessary.