Feels like a solution in search of a problem; a reinvention of https://docs.docker.com/ai/sandboxes/
opencode (https://opencode.ai/docs/permissions/#defaults) already forbids access to .env by default.