> This isn't any sort of fancy or interesting sandboxing, this is shelling out to "docker run", and not even using docker as well as it could.
That doesn’t sound right - the LLM told them it was a fantastic idea!