MacOS supports multiple users - I would absolutely sandbox any agent like this and only slowly give it permissions (and never to anything that's critical without compensating controls).