1. This is why I use podman
2. I have little to no sympathy for anyone running an AI agent with their full user permissions outside of a container or VM