🚀 What it does: One-command wrapper that runs AI coding agents inside hardened, project-specific Linux containers
💡 Best for: Developers running Claude Code, Codex, OpenCode, Grok, OMP, or Cursor Agent who don't want the agent touching their host system
🔍 Key features: Per-project container isolation, named Docker volumes for agent state, always-on security scanners, optional default-deny egress firewall, VM isolation mode