My $0.02; I use pi every day, it's always running somewhere for various kinds of tasks (no vibe coding). I run it in `sbh`, a slop cannon wrapper around `bubblewrap` that ensures that the agent only has access to things it could possibly need. The code is short and you can audit it yourself.
I run it like `sbh --net pi` or `sbh --net --docker pi` depending if I want the agent to have docker access. The result is that ~/src/my-project gets mounted as `/w/home/lion/src/my-project` and any LLM I've tried understands that this is a sandbox implicitly.
I strongly suggest everyone who uses a harness, of any kind, to copy it and edit it to better suit one's setup.
lionkor · · focus · HN ↗
I run it like `sbh --net pi` or `sbh --net --docker pi` depending if I want the agent to have docker access. The result is that ~/src/my-project gets mounted as `/w/home/lion/src/my-project` and any LLM I've tried understands that this is a sandbox implicitly.
I strongly suggest everyone who uses a harness, of any kind, to copy it and edit it to better suit one's setup.
sbh: <a href="https://github.com/lionkor/sbh" rel="nofollow">https://github.com/lionkor/sbh