You are confusing CPU-level security with filesystem-level security.
I'm curious - how do you expect an LLM harness to build and test executables without being able to build and execute executables?